Live data from Hacker News

Launch HN: Delve (YC W24) – HIPAA compliance as a service

news.ycombinator.com

11–20 of 116 posts

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#11

How do you beat https://www.aptible.com/ ?

Great question! Aptible is great for deploying HIPAA-compliant applications, but you still have to purchase another solution for completing the legal policies and compliance checklist, such as Vanta. Think of us like Aptible + Vanta. Because you deploy your application through us, we can give you deep insights into your security and compliance. For example, we give you legal policies that have already been customized…

Hi! Aptible founder here. I wanted to make an important correction here.

Aptible has a built-in Security & Compliance Dashboard [0] that supports compliance automation and reporting (PDF and API exports) for HIPAA, HITRUST and other security frameworks. You can see a demo of the entire platform, including this Dashboard, in our "Aptible in 10 Minutes" video. [1]

You can also integrate Aptible with Vanta, Drata or another compliance automation tool, if you're running the self-hosted version of Aptible that runs in your own AWS account. If you do, you can expect fully passing tests for HIPAA and SOC 2 in Vanta or Drata with zero additional configuration. Most Aptible customers find our built-in dashboard sufficient, and don't feel the need to buy Vanta/Drata separately to ensure HIPAA compliance.

[0] https://www.aptible.com/docs/intro-compliance-dashboard [1] https://www.youtube.com/watch?v=mhNzGO9KbWY

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#12

Every org that starts out with an compliance oriented SaaS in my experience ends up migrating out of it eventually because when they grow - they have more capital to build their own infrastructure as hire more engineers who do not want to deal with kinks of a SaaS abstraction. If you are using Vanta or Drata at early staging and opt for HIPAA framework, you do get the list of controls that you have to implement that…

Thanks for the transparency and thoughts on this!

We provide a lot of active elements, such as our infrastructure logging/monitoring dashboard, email alerts, and code vulnerability scans every time you git push, so that we aren't just a one-time purchase. We help you be proactive about preventing breaches instead of just integrating with your AWS API and passively monitoring. One of the biggest things about HIPAA is that it isn't just your initial setup that matters, it's how you manage compliance on an ongoing basis that's important for maintaining security and privacy.

We're also growing with our customers and moving upstream, and keeping in mind exactly what you said about preventing SaaS churn. As we do this, we're following the core thesis that compliance should bridge legal, DevOps, and cybersecurity, and when you combine all these you can get much deeper insights into security and can integrate deeper within an organization to provide more proactive measures.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#16
post #7

is there pricing information?

We charge a fixed annual fee — zero usage-based costs.

We deploy all on your own AWS cloud so you're not paying any marked up fees or being faced with surprise bills.

If you have any thoughts on this would love to hear them!

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#17
post #4

I didn't see the mention of BAAs anywhere. Do you handle getting that signed with vendors like AWS?

Yes! We outline BAA requirements in our compliance checklist (i.e. we'll provide the exact steps of how to get a BAA with AWS and remind you to get BAAs with other 3rd parties). We're also building out a small network of 3rd party vendors that we work closely with to help our customers get BAAs signed quick and offer discounts to those 3rd parties' services.

Do you enter into a BAA with all of your customers?

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#18

Earlier quoted context omitted.

Great question! Aptible is great for deploying HIPAA-compliant applications, but you still have to purchase another solution for completing the legal policies and compliance checklist, such as Vanta. Think of us like Aptible + Vanta. Because you deploy your application through us, we can give you deep insights into your security and compliance. For example, we give you legal policies that have already been customized…

Hi! Aptible founder here. I wanted to make an important correction here. Aptible has a built-in Security & Compliance Dashboard [0] that supports compliance automation and reporting (PDF and API exports) for HIPAA, HITRUST and other security frameworks. You can see a demo of the entire platform, including this Dashboard, in our "Aptible in 10 Minutes" video. [1] You can also integrate Aptible with Vanta, Drata or ano…

Thanks for sharing this! The demo is very neat and it's great to see other companies also prioritizing security and compliance.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#20
We have investor pressure to use specific cloud providers. This is the Healthcare version of Walmart not letting their partners use AWS. Due to their (Amazon, Google) vertical integration slowly moving in on healthcare turf, many healthcare partners/payers/investors are adding contractual pressure to exit AWS or GCP and move to Azure specifically. Wondering how your cloud support in general looks. Your previews are all AWS-centric
Post reply on HN