Live data from Hacker News

Ask HN: HIPAA Hosting?

news.ycombinator.com

21–30 of 34 posts

Re: Ask HN: HIPAA Hosting?

#21
post #7

Had to research this before. Firehost is one of the names that came up often: http://www.firehost.com/secure-hosting/hipaa Their plans start from $845 monthly. No affiliation, just passing info along. You can't just rely on the provider though. All the server hardening in the world wouldn't help with apps that don't comply fully. Some of the audit requirements are bound to be very specific to the nature of your app.

I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…

[deleted]

Re: Ask HN: HIPAA Hosting?

#22
post #10

One other issue to consider is that just because your hosting provider's infrastructure is HIPPA compliant doesn't mean your application is. There are still a ton of privacy issues within the application, plain text HTTP, user authentication, etc.

Yep - we're aware of all that, and we can handle the various app-level changes... we just don't want to be in the "ongoing server maintenance" business.

Re: Ask HN: HIPAA Hosting?

#23
post #4

The first company that gets to a certified HIPAA and PCI hosting cloud is going to have to figure out what to do with the buckets of cash they have lying around. I think for the enterprise PCI certification will be the event that gets the big (non-tech) guys out of running their own infrastructure. I would imagine that it would be the same for medical. As for you immediate question, I am sorry I can't help I don't kn…

I agree it would be great, I've gotten letters from Amazon that it is hipaa compliant but not PCI, and from rackspace that it is pci compliant but not hipaa.

Re: Ask HN: HIPAA Hosting?

#24
post #7

Had to research this before. Firehost is one of the names that came up often: http://www.firehost.com/secure-hosting/hipaa Their plans start from $845 monthly. No affiliation, just passing info along. You can't just rely on the provider though. All the server hardening in the world wouldn't help with apps that don't comply fully. Some of the audit requirements are bound to be very specific to the nature of your app.

I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…

I thought "Two-Factor Authentication" referred to an RSA SecurID or something similar. Am I wrong? Why do you say "it's usually misused"?

Re: Ask HN: HIPAA Hosting?

#25
post #4

The first company that gets to a certified HIPAA and PCI hosting cloud is going to have to figure out what to do with the buckets of cash they have lying around. I think for the enterprise PCI certification will be the event that gets the big (non-tech) guys out of running their own infrastructure. I would imagine that it would be the same for medical. As for you immediate question, I am sorry I can't help I don't kn…

I agree it would be great, I've gotten letters from Amazon that it is hipaa compliant but not PCI, and from rackspace that it is pci compliant but not hipaa.

I did not know that Rackspace is PCI compliant. Thanks for that info.

Re: Ask HN: HIPAA Hosting?

#26

Earlier quoted context omitted.

I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…

I thought "Two-Factor Authentication" referred to an RSA SecurID or something similar. Am I wrong? Why do you say "it's usually misused"?

A SecurID would work. ("Something you know, plus something you have or something you are.")

The majority of the cases where I've seen it used so far are in websites or other services that are just asking you for a second piece of information you know -- like a challenge question, passphrase, or the like.

...it looks like Firehost is using Phone Factor (http://www.phonefactor.com/) for their second factor authentication. I'm not sure what I think of that. On the one hand, it's marginally better than a password. On the other hand, it's only marginally better than a password. Unlike a SecurID, phones are pretty easy to compromise -- especially smart phones.

Re: Ask HN: HIPAA Hosting?

#27
post #7

Had to research this before. Firehost is one of the names that came up often: http://www.firehost.com/secure-hosting/hipaa Their plans start from $845 monthly. No affiliation, just passing info along. You can't just rely on the provider though. All the server hardening in the world wouldn't help with apps that don't comply fully. Some of the audit requirements are bound to be very specific to the nature of your app.

I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…

A few responses to this post:

1. Log Management is required for PCI and HIPAA compliance. We use a product called LogLogic and review all required logs on a daily basis and remediate anything that comes up. LogLogic is the solution we put into place: http://www.loglogic.com

2. External vulnerability scans on the application and network layer.

3. Managed A/V protection. We have customers on Windows and Linux. Also detects malware and trust me - enough Linux threats out there as well.

4. GB network connectivity is absolutely correct.

5. Two-factor authentication is something you know (username and password) and something you have (dongle, ID, etc). Our two-factor is powered by phonefactor and is a great way to serve this need.

6. We use other methods to ensure this doesn't happen. (Encryption and Database Monitoring with strict rules).

7. Correct.

8. It's an absolute requirement for an organization going after HIPAA compliance to have a business associate agreement (google it for more info) and we're BAA friendly where most hosting providers are not.

9. It's redundant meaning if there's a physical firewall fail there's no loss in connectivity.

10. This protects your web application from the biggest threats on the net. Learn more here: http://www.owasp.org/index.php/Web_Application_Firewall

11. We block DDoS attacks everyday. Not all of them are high bandwidth. Google slowloris dos and learn more as an example.

12. Couldn't be more wrong. =)

13. Read #12

14. Congrats for being responsible.

15. Our datacenter meets strict requirements for redundancy and security as would other top facilities.

16. It's a nice security feature and integrates with our two-factor authentication. If your network is open to SSH (or other management ports) there's a lot to discuss.

Regarding the price, shop other managed hosting providers and you will find none that's transparent on what they offer and display pricing. Go ahead and secret shop them and you will see how low we've priced the FireHost's solution.

Also, we have our SAS70. However, that's going away for the SSAE 16 standard FYI.

Hope that helps and best of luck!

Re: Ask HN: HIPAA Hosting?

#28
post #7

Had to research this before. Firehost is one of the names that came up often: http://www.firehost.com/secure-hosting/hipaa Their plans start from $845 monthly. No affiliation, just passing info along. You can't just rely on the provider though. All the server hardening in the world wouldn't help with apps that don't comply fully. Some of the audit requirements are bound to be very specific to the nature of your app.

This is absolutely correct. Your managed hosting company has a portion of the responsibility for HIPAA compliance which is why we say "Compliance Ready".

An organization has to have their own application specific needs met, business and process controls, database table obfuscation, etc. etc.

What's important is selecting a provider who has all the hosting needs met to achieve compliance with your auditor and will execute a business associate agreement as required.

Best of luck with your search.

Re: Ask HN: HIPAA Hosting?

#29

Earlier quoted context omitted.

I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…

A few responses to this post: 1. Log Management is required for PCI and HIPAA compliance. We use a product called LogLogic and review all required logs on a daily basis and remediate anything that comes up. LogLogic is the solution we put into place: http://www.loglogic.com 2. External vulnerability scans on the application and network layer. 3. Managed A/V protection. We have customers on Windows and Linux. Also det…

Thanks for responding! Regardless of any debate over the merits of the specific things you guys do, it's clear that you have put a lot of work into your service, and you are at least describing some of what you do, instead of saying, "magic (now with hand waving)".

If you don't mind my asking -- if it doesn't give away any sensitive or proprietary information -- where would you say the majority of the $845/mo is going? Are there tremendous administrative costs, other business expenses (insurance?), or does that actually represent your infrastructure cost?

Re: Ask HN: HIPAA Hosting?

#30

Earlier quoted context omitted.

A few responses to this post: 1. Log Management is required for PCI and HIPAA compliance. We use a product called LogLogic and review all required logs on a daily basis and remediate anything that comes up. LogLogic is the solution we put into place: http://www.loglogic.com 2. External vulnerability scans on the application and network layer. 3. Managed A/V protection. We have customers on Windows and Linux. Also det…

Thanks for responding! Regardless of any debate over the merits of the specific things you guys do, it's clear that you have put a lot of work into your service, and you are at least describing some of what you do, instead of saying, "magic (now with hand waving)". If you don't mind my asking -- if it doesn't give away any sensitive or proprietary information -- where would you say the majority of the $845/mo is goin…

I work in IT at a health network; specifically doing compliance, audit and IT security. We have to keep logs for decades from every system used to "transmit, store or process ePHI." A LOT of time is spent chasing shadows when a patient thinks someone might have looked at their record.

Sure there are people who abuse the system but more time is spent on the false positives. Usually there is an innocent reason someone knows why the concerned patient was in the hospital; like they were shopping for baby clothes and put on a lot of weight recently.

With changes in HITECH the requirements for reporting are going to get broader, increasing the cost. Some of this can be planned for but much of it is just man hours to gather, report and store information.

The longest case I have been involved with is just over 2 years of litigation against a physician. The physician was found innocent but all of the emails, medical records, voice mails, etc that might pertain to that specific situation have to be preserved. Access logging is the largest use of disk space in our organization; around several GB per day.

For a hosting organization there is less to save, but there is also additional work in isolating systems. We have a significant investment in datacenter operations and lease the EMR out to specialty practices in our area. Most of the effort with external organizations is talking to their auditor of choice to prove that our systems are secure and isolated, running reports to show who has access to their data or what people did and the extra process to verify each change that affects their information or part of the system. Some of the extra steps are to address Accounting for Disclosures.

Post reply on HN