Live data from Hacker News

Launch HN: Delve (YC W24) – HIPAA compliance as a service

news.ycombinator.com

21–30 of 116 posts

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#21

Earlier quoted context omitted.

Yes! We outline BAA requirements in our compliance checklist (i.e. we'll provide the exact steps of how to get a BAA with AWS and remind you to get BAAs with other 3rd parties). We're also building out a small network of 3rd party vendors that we work closely with to help our customers get BAAs signed quick and offer discounts to those 3rd parties' services.

Do you enter into a BAA with all of your customers?

Yes, we sign sub-BAAs with our customers.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#22

It does more than just protecting sensitive health information, it also governs how billing works, so if you've ever wondered why some Dr. you never met is sending you bills in the thousands of dollars; HIPAA is where you can find out why!

Yes! HIPAA was initially rolled out for the portability and continuity of health insurance coverage.

But over the years, with the enactment of the Privacy Rule, Security Rule, HITECH Act, Omnibus Rule, etc., HIPAA's implications have been shaped quite a bit.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#23
Healthcare CIO/VP here. Some thoughts to help you improve your communication to potential customers, AKA what I look for when I am evaluating a platform for healthcare use:

The website is too thin, it looks like you're really heavily relying on meetings to get customers rather than the product itself. I think you should dedicate some resources to fleshing out the website A LOT with more information because it actually looks like a potentially useful product, but I'm not going to commit to a presentation just for more info. This is a red flag, as in my experience companies with little public info and who want to share everything in demos/meetings have a lot of warts they try to hide by a highly curated meeting experience.

Cancel the blog portion, it's 2024 and no one cares about company blogs. No one ever DID, but they were popular for a hot minute anyway, and that minute is gone. Don't blog and take that time to flesh out the website dramatically. Right now your sole blog post is a 2 minute intro to HIPAA. Anyone who doesn't know what HIPAA is will not be a customer, so this post isn't helping you at all. I think your #1 priority this week should be flooding the website with information about the product. How-To guides, detailed descriptions of features, videos, even an interactive demo would be great.

I'm not sure if your product is narrow and focused on helping code compliant apps, or if you're a general compliance checklist suite. The latter is WAY more useful than the former. If you're the former, I'd suggest expanding your scope to get more business. when I thought this was an enhanced HIPAA compliance suite, I was ready to get more info, now that I see it may be focused on app development only, I don't care about it, as honestly getting computers compliant is a lot easier than getting humans and processes compliant. If you're not just focused on development, this reinforces the website problem.

Kill your FAQ: "How is Delve different?" Please flesh this out to about 1,000-1,500 words on another page and go into more detail. "Has Delve been reviewed by HIPAA auditors?" Don't tell me, link me to your PDF compliance reports. "How do I know your infrastructure is secure?" Combine this with the question above and link me to your PDF compliance reports. Then make it it's own page like with the question above. "How can I show my customers that I’m HIPAA compliant?" Again, it's 2024, no one cares about badges, they want BAAs and compliance reports. People understand today that a little badge on a webpage means nothing. This isn't even a question you should be answering, actually. Only your customers can answer that through knowledge of their customer base.

You look like a promising startup, I hope you accept this critique from a decision maker in your target audience in the spirit it's offered. It's not meant to say you're bad or dumb, you just need to spend some real time on the website and information shared with potential clients. Right now you look interesting, but not enough for me to reach out yet. A more detailed website would change that a lot.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#24
Looks great, and I wish this existed 2 years ago when I started building a HIPAA compliant product!

But I immediately had a few questions and am hesitant to book a demo (I'm quite time poor):

1. What clouds do you support? 2. What does the infrastructure look like, what services does it use? 3. Do I get locked into a particular orchestration or deployment setup? We prefer k8s for example.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#26

We have investor pressure to use specific cloud providers. This is the Healthcare version of Walmart not letting their partners use AWS. Due to their (Amazon, Google) vertical integration slowly moving in on healthcare turf, many healthcare partners/payers/investors are adding contractual pressure to exit AWS or GCP and move to Azure specifically. Wondering how your cloud support in general looks. Your previews are a…

Interesting, haven't heard of this. Always figured aws and gcp were ahead of azure in terms of Healthcare

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#27
Sort of related: it seems like compliant providers and services are carrying the burden of patient privacy in good faith, securing the front door. Meanwhile, there are open tent flaps on the sides and back. It's hard to do the right thing while there are minimal regs and enforcement on the rest of the ecosystem.

Eg, Tracking on medical sites let Meta go to town -- https://www.theverge.com/2022/8/2/23288612/meta-hosptials-su...

Eg, Patient data brokers: "Currently, under HIPAA there is no law prohibiting the use of healthcare data shared via marketing practices." -- https://www.beckershospitalreview.com/healthcare-information...

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#28
I remember early in Google Cloud I was working with a Google PM on health-related projects (Google Cloud Genomics). The PM was our ostensible expert on HIPAA, and explained many details (such as BAA). The one funny thing they said is "there is no such thing as HIPAA compliance, that term is meaningless". And I don't really understand what they meant, but I think they must have been wrong (even though they were supposed to be the subject matter expert).

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#29
post #23

Healthcare CIO/VP here. Some thoughts to help you improve your communication to potential customers, AKA what I look for when I am evaluating a platform for healthcare use: The website is too thin, it looks like you're really heavily relying on meetings to get customers rather than the product itself. I think you should dedicate some resources to fleshing out the website A LOT with more information because it actuall…

If it's only compliance then, why not go with the other vendors like Vanta etc?

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#30
post #28

I remember early in Google Cloud I was working with a Google PM on health-related projects (Google Cloud Genomics). The PM was our ostensible expert on HIPAA, and explained many details (such as BAA). The one funny thing they said is "there is no such thing as HIPAA compliance, that term is meaningless". And I don't really understand what they meant, but I think they must have been wrong (even though they were suppos…

You PM is right. Unlike SOC2, you dont get a certification. More details here [1]

[1] https://compliancy-group.com/what-is-a-hipaa-certification/

Post reply on HN