Live data from Hacker News

Ask HN: HIPAA Hosting?

news.ycombinator.com

31–34 of 34 posts

Re: Ask HN: HIPAA Hosting?

#31

Earlier quoted context omitted.

I thought "Two-Factor Authentication" referred to an RSA SecurID or something similar. Am I wrong? Why do you say "it's usually misused"?

A SecurID would work. ("Something you know, plus something you have or something you are.") The majority of the cases where I've seen it used so far are in websites or other services that are just asking you for a second piece of information you know -- like a challenge question, passphrase, or the like. ...it looks like Firehost is using Phone Factor ( http://www.phonefactor.com/ ) for their second factor authentica…

The issue I'd have with this setup is reception. In our Hospital there are a lot of places with little or no reception; Radiology and Lab are two main examples. Due to all of the lead they have around there is no signal.

We had looked at iPhones for CC processing over cellular networks, but the lack of a consistent signal killed that. Which sucks because that would have been much easier and cheaper as a temporary solution than what we are doing now.

Re: Ask HN: HIPAA Hosting?

#32
post #6

HIPAA is more about documenting your intended process, and your actual actions, than it is about requiring any particular solutions provider. For example, it's entirely possible to build a HIPAA compliant web app on AWS: http://aws.typepad.com/aws/2009/04/white-paper-creating-hipa... My company is in the middle of this, and we haven't encountered any deal-breakers so far.

A system built from scratch can meet HIPAA, and HITECH, without much more than good security. The issue is often with companies that give security an afterthought or have older software that needs to be "made secure."

The key to that link is encryption; it gets Amazon off the hook for a lot of things.

Re: Ask HN: HIPAA Hosting?

#33

Earlier quoted context omitted.

A few responses to this post: 1. Log Management is required for PCI and HIPAA compliance. We use a product called LogLogic and review all required logs on a daily basis and remediate anything that comes up. LogLogic is the solution we put into place: http://www.loglogic.com 2. External vulnerability scans on the application and network layer. 3. Managed A/V protection. We have customers on Windows and Linux. Also det…

Thanks for responding! Regardless of any debate over the merits of the specific things you guys do, it's clear that you have put a lot of work into your service, and you are at least describing some of what you do, instead of saying, "magic (now with hand waving)". If you don't mind my asking -- if it doesn't give away any sensitive or proprietary information -- where would you say the majority of the $845/mo is goin…

You're absolutely welcome.

The majority of our "costs" are built into our security layers. We're providing DDoS protection, Web Application Firewall Protection, Managed Redudant Firewalls, and more. The enterprise-grade level technology we purchase is in the seven-figures. So for starting at $200 a month (secure server with FireHost) you're protected by seven-figures in security equipment. So there's economies of scale which allows us to do this, it's just cannot be low-cost.

And as you said, there's of-course the environment is fully managed, we have engineer costs to ensure the integrity of your environment is constantly maintained.

Let me know if you have additional questions.

Re: Ask HN: HIPAA Hosting?

#34
post #20

Earlier quoted context omitted.

I was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows pl…

"Highly Secure Data Center Environment", but no SAS70 certification... hmm.

We do have our SAS70 and know that SAS70 has nothing to do with real security. It's just controls that an organization sets and gets audited on.

Also, the SAS70 is going away for the SSAE 16. Read more here: http://www.csoonline.com/article/622277/sas-70-replacement-s...

Post reply on HN