Live data from Hacker News

Ask HN: How do I set up a HIPAA-compliant server?

news.ycombinator.com

41–50 of 54 posts

Re: Ask HN: How do I set up a HIPAA-compliant server?

#41
post #18

There are a few options if you want HIPAA compliance. Note that "HIPAA compliance" is somewhat of a loaded term in that there aren't many super-technical benchmarks to meet, but a general "do-good" attitude including (but not limited to) some of the following points: - Physical server isolation: you cannot have other instances sniffing around in your deallocated garbage memory. - Encrypted data stores: physical theft…

Does HIPAA really require "physical server isolation"? I wasn't able to find anything specifying that in my reading. (Encrypting data at rest is definitely required. I suspect the S3 functionality was built to address the requirement.) AFAICT the whole "can't do HIPAA in the cloud" meme arose from the reluctance of cloud services to sign BAAs, Google only got on board with that earlier this year.

no it is not (i have passed VA/DoD audits without)

Re: Ask HN: How do I set up a HIPAA-compliant server?

#42

It's not just the server - it's the storage, accessibility (compartmentalization), and transmission of sensitive data (PHI and PII) at all levels. There is a lot more to HIPAA/HITECH than just server configuration - there are legal agreements you have to enter into as well (BAA's), insurance requirements, and potentially a lot more. I'd suggest you work with a company that has a lot of experience in this area before…

A lot of HIPAA complience also has to do with due dilegence. My organization recently when through a long period of training that covered everything from building access logs to the way we do employee password resets. Unfortunately there aren't hard, static rules that define it. On the positive side- I've learned to love the compliance. Most of it is common sense things (like not giving out info over the phone to any…

+1 do these things because they are actually good engineering practices. be a good custodian of any user's trust.

i think some companies try for the quick buck and in the name of cost savings run a shoddy operation. ymmv.

ps - do not try making said quick buck in health care. contrary to VC bets otherwise, it doesnt exist. plan for a very very long haul.

Re: Ask HN: How do I set up a HIPAA-compliant server?

#43
post #22

(Disclosure: I'm a co-founder of Aptible.) As noted in other comments, most of HIPAA is not technical. Most of the requirements relate to risk assessment, policies, training, incident response, etc. With that in mind, I'm going to quickly run down all of the major moving parts and then cover some of the technical considerations for setting up a server. HIPAA has three main rules you need to comply with: 1. The Privac…

> $3500/month. > $0.10/Hour Additional App/Database Containers $0.40/GB/Month Additional Storage. ¡Ay, caramba! Thanks for at least giving me a source to cite in grant applications!

Where I work at Catalyze, we offer a starting package beginning at $500/mo that includes one database container and one server. Or, if your application only required a secure backend, prices start as cheap as $100/month. We have a calculator here to compare prices: https://catalyze.io/platform-as-a-service/

We've been building applications with both startups and large healthcare organizations like the VA. I'd love to talk with you more to see what your needs are. Feel free to hit me with an email (mark@catalyze.io) with any questions.

Good luck!

Re: Ask HN: How do I set up a HIPAA-compliant server?

#44
post #23
post #21

We have audited HIPAA compliant hosting, at a reasonable price: https://www.atlantic.net/hipaa-compliant-hosting/

I hope you point out to your customers that compliance is a lot more than just a hosting account. Everything from specifications of the design of your office network to policies for employees talking while on smoke breaks.

Agreed. Anyone that you choose for HIPAA-compliant hosting should be able to outline their policies. Where I work at Catalyze, ours are here:

https://catalyze.io/hipaa/ https://catalyze.io/policy/

And we've gone through a HITRUST audit to validate these claims:

https://catalyze.io/compliance/

Re: Ask HN: How do I set up a HIPAA-compliant server?

#45
post #36

If you are trying to set up a service for processing or storing PHI, you may be interested in DNAnexus ( https://dnanexus.com/ ), which focuses on compliant high throughput data analysis and storage for genome information, but can be used to store other types of PHI data. (Full disclosure, I work at DNAnexus). Email in profile if you want to go into specifics.

Cool! I had not heard of dnanexus before. Looking forward to checking it out.

Re: Ask HN: How do I set up a HIPAA-compliant server?

#46

Earlier quoted context omitted.

> $3500/month. > $0.10/Hour Additional App/Database Containers $0.40/GB/Month Additional Storage. ¡Ay, caramba! Thanks for at least giving me a source to cite in grant applications!

Where I work at Catalyze, we offer a starting package beginning at $500/mo that includes one database container and one server. Or, if your application only required a secure backend, prices start as cheap as $100/month. We have a calculator here to compare prices: https://catalyze.io/platform-as-a-service/ We've been building applications with both startups and large healthcare organizations like the VA. I'd love to…

Hmmm... 8GB max? That doesn't cut it for the amount of claims data I generally deal with. Any rationale behind that limit?

Re: Ask HN: How do I set up a HIPAA-compliant server?

#47
Hi,

training-hipaa.net provides Server Disaster Recovery Plan Template which is the part of HIPAA Compliance.

This Server Recovery Plan documents the strategies, personnel, procedures and resources necessary to recover the server following any type of short or long term disruption. You can find more information about this over here http://www.training-hipaa.net/template_suite/Server_recovery...

Re: Ask HN: How do I set up a HIPAA-compliant server?

#48
post #22

(Disclosure: I'm a co-founder of Aptible.) As noted in other comments, most of HIPAA is not technical. Most of the requirements relate to risk assessment, policies, training, incident response, etc. With that in mind, I'm going to quickly run down all of the major moving parts and then cover some of the technical considerations for setting up a server. HIPAA has three main rules you need to comply with: 1. The Privac…

This is all great advise. I would just strongly emphasize that HIPAA compliance has significantly more to do with the soft guidelines than meeting technical specifications.

Part of what makes HIPAA compliance challenging from a techies perspective is that there are very few proscriptive rules. A lot of implementation is left up to the provider to provide flexibility but the justification for all those decisions needs to be defensible.

A couple last items I would add: Not only do you need a BAA with any service provider you use you will also need one for any contractor who has access to PHI you are responsible for. As of the latest set of rules this also applies to any subcontractors that your contractors may use.

You will also need named privacy and security officers who are responsible for the overall program and will be the first ones HHS and OCR will ask for should you be audited.

Re: Ask HN: How do I set up a HIPAA-compliant server?

#49
post #22

(Disclosure: I'm a co-founder of Aptible.) As noted in other comments, most of HIPAA is not technical. Most of the requirements relate to risk assessment, policies, training, incident response, etc. With that in mind, I'm going to quickly run down all of the major moving parts and then cover some of the technical considerations for setting up a server. HIPAA has three main rules you need to comply with: 1. The Privac…

Depending on what function you are providing for HIPAA-covered entities, you may need to also deal with the Transactions and Code Sets rule, though the rules related to PHI are usually all people are aware of.

One should also note that the Breach Notification rule, through its definition of what constitutes unsecured PHI, actually sneaks in technical requirements that entities dealing with PHI probably should treat as near-mandatory for encryption, etc., since, even though they aren't strictly mandatory, significantly impact the likelihood of a reportable breach.

Re: Ask HN: How do I set up a HIPAA-compliant server?

#50
post #22

(Disclosure: I'm a co-founder of Aptible.) As noted in other comments, most of HIPAA is not technical. Most of the requirements relate to risk assessment, policies, training, incident response, etc. With that in mind, I'm going to quickly run down all of the major moving parts and then cover some of the technical considerations for setting up a server. HIPAA has three main rules you need to comply with: 1. The Privac…

Curious-- do you define a running database system (e.g. MySQL) to contain "data at rest", "data in transit" or neither?

My reading says "neither". Conservative move is "encrypt everything" but curious if others have passed/failed a HIPAA audit with a standard MySQL or SQL Server system (assuming you have individual ID access & logging).

Post reply on HN