Had to research this before. Firehost is one of the names that came up often: http://www.firehost.com/secure-hosting/hipaa Their plans start from $845 monthly. No affiliation, just passing info along. You can't just rely on the provider though. All the server hardening in the world wouldn't help with apps that don't comply fully. Some of the audit requirements are bound to be very specific to the nature of your app.
I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…
Ask HN: HIPAA Hosting?
21–30 of 34 posts
Re: Ask HN: HIPAA Hosting?
#22One other issue to consider is that just because your hosting provider's infrastructure is HIPPA compliant doesn't mean your application is. There are still a ton of privacy issues within the application, plain text HTTP, user authentication, etc.
Re: Ask HN: HIPAA Hosting?
#23The first company that gets to a certified HIPAA and PCI hosting cloud is going to have to figure out what to do with the buckets of cash they have lying around. I think for the enterprise PCI certification will be the event that gets the big (non-tech) guys out of running their own infrastructure. I would imagine that it would be the same for medical. As for you immediate question, I am sorry I can't help I don't kn…
Re: Ask HN: HIPAA Hosting?
#24Had to research this before. Firehost is one of the names that came up often: http://www.firehost.com/secure-hosting/hipaa Their plans start from $845 monthly. No affiliation, just passing info along. You can't just rely on the provider though. All the server hardening in the world wouldn't help with apps that don't comply fully. Some of the audit requirements are bound to be very specific to the nature of your app.
I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…
Re: Ask HN: HIPAA Hosting?
#25The first company that gets to a certified HIPAA and PCI hosting cloud is going to have to figure out what to do with the buckets of cash they have lying around. I think for the enterprise PCI certification will be the event that gets the big (non-tech) guys out of running their own infrastructure. I would imagine that it would be the same for medical. As for you immediate question, I am sorry I can't help I don't kn…
I agree it would be great, I've gotten letters from Amazon that it is hipaa compliant but not PCI, and from rackspace that it is pci compliant but not hipaa.
Re: Ask HN: HIPAA Hosting?
#26Earlier quoted context omitted.
I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…
I thought "Two-Factor Authentication" referred to an RSA SecurID or something similar. Am I wrong? Why do you say "it's usually misused"?
The majority of the cases where I've seen it used so far are in websites or other services that are just asking you for a second piece of information you know -- like a challenge question, passphrase, or the like.
...it looks like Firehost is using Phone Factor (http://www.phonefactor.com/) for their second factor authentication. I'm not sure what I think of that. On the one hand, it's marginally better than a password. On the other hand, it's only marginally better than a password. Unlike a SecurID, phones are pretty easy to compromise -- especially smart phones.
Re: Ask HN: HIPAA Hosting?
#27Had to research this before. Firehost is one of the names that came up often: http://www.firehost.com/secure-hosting/hipaa Their plans start from $845 monthly. No affiliation, just passing info along. You can't just rely on the provider though. All the server hardening in the world wouldn't help with apps that don't comply fully. Some of the audit requirements are bound to be very specific to the nature of your app.
I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…
1. Log Management is required for PCI and HIPAA compliance. We use a product called LogLogic and review all required logs on a daily basis and remediate anything that comes up. LogLogic is the solution we put into place: http://www.loglogic.com
2. External vulnerability scans on the application and network layer.
3. Managed A/V protection. We have customers on Windows and Linux. Also detects malware and trust me - enough Linux threats out there as well.
4. GB network connectivity is absolutely correct.
5. Two-factor authentication is something you know (username and password) and something you have (dongle, ID, etc). Our two-factor is powered by phonefactor and is a great way to serve this need.
6. We use other methods to ensure this doesn't happen. (Encryption and Database Monitoring with strict rules).
7. Correct.
8. It's an absolute requirement for an organization going after HIPAA compliance to have a business associate agreement (google it for more info) and we're BAA friendly where most hosting providers are not.
9. It's redundant meaning if there's a physical firewall fail there's no loss in connectivity.
10. This protects your web application from the biggest threats on the net. Learn more here: http://www.owasp.org/index.php/Web_Application_Firewall
11. We block DDoS attacks everyday. Not all of them are high bandwidth. Google slowloris dos and learn more as an example.
12. Couldn't be more wrong. =)
13. Read #12
14. Congrats for being responsible.
15. Our datacenter meets strict requirements for redundancy and security as would other top facilities.
16. It's a nice security feature and integrates with our two-factor authentication. If your network is open to SSH (or other management ports) there's a lot to discuss.
Regarding the price, shop other managed hosting providers and you will find none that's transparent on what they offer and display pricing. Go ahead and secret shop them and you will see how low we've priced the FireHost's solution.
Also, we have our SAS70. However, that's going away for the SSAE 16 standard FYI.
Hope that helps and best of luck!
Re: Ask HN: HIPAA Hosting?
#28Had to research this before. Firehost is one of the names that came up often: http://www.firehost.com/secure-hosting/hipaa Their plans start from $845 monthly. No affiliation, just passing info along. You can't just rely on the provider though. All the server hardening in the world wouldn't help with apps that don't comply fully. Some of the audit requirements are bound to be very specific to the nature of your app.
An organization has to have their own application specific needs met, business and process controls, database table obfuscation, etc. etc.
What's important is selecting a provider who has all the hosting needs met to achieve compliance with your auditor and will execute a business associate agreement as required.
Best of luck with your search.
Re: Ask HN: HIPAA Hosting?
#29Earlier quoted context omitted.
I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…
A few responses to this post: 1. Log Management is required for PCI and HIPAA compliance. We use a product called LogLogic and review all required logs on a daily basis and remediate anything that comes up. LogLogic is the solution we put into place: http://www.loglogic.com 2. External vulnerability scans on the application and network layer. 3. Managed A/V protection. We have customers on Windows and Linux. Also det…
If you don't mind my asking -- if it doesn't give away any sensitive or proprietary information -- where would you say the majority of the $845/mo is going? Are there tremendous administrative costs, other business expenses (insurance?), or does that actually represent your infrastructure cost?
Re: Ask HN: HIPAA Hosting?
#30Earlier quoted context omitted.
A few responses to this post: 1. Log Management is required for PCI and HIPAA compliance. We use a product called LogLogic and review all required logs on a daily basis and remediate anything that comes up. LogLogic is the solution we put into place: http://www.loglogic.com 2. External vulnerability scans on the application and network layer. 3. Managed A/V protection. We have customers on Windows and Linux. Also det…
Thanks for responding! Regardless of any debate over the merits of the specific things you guys do, it's clear that you have put a lot of work into your service, and you are at least describing some of what you do, instead of saying, "magic (now with hand waving)". If you don't mind my asking -- if it doesn't give away any sensitive or proprietary information -- where would you say the majority of the $845/mo is goin…
Sure there are people who abuse the system but more time is spent on the false positives. Usually there is an innocent reason someone knows why the concerned patient was in the hospital; like they were shopping for baby clothes and put on a lot of weight recently.
With changes in HITECH the requirements for reporting are going to get broader, increasing the cost. Some of this can be planned for but much of it is just man hours to gather, report and store information.
The longest case I have been involved with is just over 2 years of litigation against a physician. The physician was found innocent but all of the emails, medical records, voice mails, etc that might pertain to that specific situation have to be preserved. Access logging is the largest use of disk space in our organization; around several GB per day.
For a hosting organization there is less to save, but there is also additional work in isolating systems. We have a significant investment in datacenter operations and lease the EMR out to specialty practices in our area. Most of the effort with external organizations is talking to their auditor of choice to prove that our systems are secure and isolated, running reports to show who has access to their data or what people did and the extra process to verify each change that affects their information or part of the system. Some of the extra steps are to address Accounting for Disclosures.