Live data from Hacker News

Launch HN: Delve (YC W24) – HIPAA compliance as a service

news.ycombinator.com

101–110 of 116 posts

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#101

Earlier quoted context omitted.

We absolutely agree. HIPAA compliance for startups is only the beginning for us. We're rolling out SOC2 soon and then will use these as a foundation to moving upmarket. Our end goal isn't to work with startups to automate compliance - we're using this as a launchpad to going upstream in the GRC space.

I have an opinion about that too. It is super competitive and very democratised. Last I checked there platforms that would charge just $2500 per year for their GRC platform. That's pretty low in my opinion. As a founder, I'll ask you why not start with the actually value proposition or goal you want to achieve right away. Why are you making your jouney very convoluted?

You bet. We get an interesting mix offering Heroku-like deployment with Vanta-style compliance preparation. We're not just an annual subscription-based GRC checklist that passively monitors, we're an active tool that enforces security on a technical front and runs checks every time an engineer git pushes. We also don't charge usage-based fees, so no one is charged an additional 10x of their AWS usage cost, which any large organization would with good reason want to churn.

It's been an effective entry point into the market for us -- establishing a foundation with companies that need to become compliant for the first time and building out core compliance features is a great stepping stone. Lets you work with additional customers while building out your larger product visions.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#102
post #89

Earlier quoted context omitted.

Good question, these trackers typically come in the form of developer installed pixels / trackers, making this situation a function of human choice. During onboarding, we conduct a supply chain vendor risk assessment, identify which vendors we can help facilitate a BAA agreement with, and which vendors (if any) need to be removed from a deployment. From there we provide the resources to initiate a communication chann…

Point-in-time supply chain vendor risk assessments are nice, but they cannot control realtime website behavior. Customers may want more configurability in this area so that they they can remove certain dataflows instead of only being able to bluntly remove whole vendors.

That's valid, and it varies on a case-by-case basis. You might want to track user behavior on your landing page but not on your provider-facing internal application. Flexibility, configurability, and proper risk assessment is key here.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#103
post #87

Earlier quoted context omitted.

It's an interesting point you raise. You're correct in that our current target audience primarily covers the companies that provide services to healthcare providers instead of actual healthcare providers. For more context, HIPAA breaks companies into two categories: (1) Covered Entities, which are healthcare providers, health plans, and healthcare clearinghouses, and (2) Business Associates, which are companies that…

> … providers fall into the Covered Entity category … If doctor etc is a Covered Entity then that doctor is most likely a Provider, but is every doctor providing healthcare a really CE? I wouldn’t have said no but I don’t track it ultra closely so I’m curious what’s the latest? My first three results matched my expectation but they could easily be out of date… https://www.epatientdave.com/2020/02/03/hipaa-you-arent-a…

Yup! Not every provider is classified as a Covered Entity and not every healthcare business is classified as a Business Associate. It's where the nuances of HIPAA law come into play.

For example, you could be a medical app that processes pages and pages of medical data from an individual, but if you're not doing it on behalf of a Covered Entity, then you won't be subject to HIPAA.

In cases like these, as well as certain therapist examples and other scenarios described in the final article you provided, HIPAA is not applicable. It's still good practice to have proper security measures in place, since there could be other governing bodies regulating you (e.g. the FTC, https://www.ftc.gov/news-events/news/press-releases/2018/10/...), but you're not regulated under HIPAA.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#104
post #97

This looks really Great!!! Quick Question: How are the features and services different from what is offered by Drata and Secureframe?

Thank you - we really appreciate it!

Drata and Secureframe provide a compliance checklist and integrate with some of your vendors (i.e. AWS, Github, etc.) to passively monitor your configurations and flag concerns.

We provide the same compliance checklist that Drata and Secureframe does, and also give you HIPAA compliant technical configurations. We'll deploy your application with infrastructure that's compliant out of the box, provide CI/CD pipelines, and a real-time monitoring/logging solution. We do a lot of work on our end to block attacks, proxy you through our firewalls, and automate your DevOps/delay your need to hire a DevOps team. These are all things you'd have to manually configure on Drata and Secureframe. By automating this, we save you weeks of work.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#105
post #23

Healthcare CIO/VP here. Some thoughts to help you improve your communication to potential customers, AKA what I look for when I am evaluating a platform for healthcare use: The website is too thin, it looks like you're really heavily relying on meetings to get customers rather than the product itself. I think you should dedicate some resources to fleshing out the website A LOT with more information because it actuall…

If it's only compliance then, why not go with the other vendors like Vanta etc?

Good question. Vanta offers a compliance checklist and integrates with your service providers (such as AWS, Github, etc.) to continuously monitor your system settings and highlight potential issues.

Similarly, we provide a compliance checklist like Vanta, along with HIPAA-compliant technical infrastructure and technical configurations. We’ll set up your application on compliant infrastructure deployed in your cloud, furnish CI/CD pipelines, and provide real-time logging/monitoring.

We do a lot of active work to prevent attacks, route your traffic through our protective firewalls, and automate DevOps/delay your need to hire a DevOps team. These are tasks you'd have to complete manually if you were to go with Vanta. By automating them, we save you weeks of work.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#106

Earlier quoted context omitted.

You PM is right. Unlike SOC2, you dont get a certification. More details here [1] [1] https://compliancy-group.com/what-is-a-hipaa-certification/

However, if you want to do business with any reasonable size of healthcare org, you're eventually gonna have to get a HITRUST report.

That's true. Curious what your experience has been with HITRUST

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#107

theres a number of dead bodies in this space. it sounds like a great idea but once companies get big theyll diy. so your only market will be early startups for 1-3 years max and then theyll churn bf they ever get big enough to pay you what it's worth to get them on your platform in rhe first place. look at aptible and datica.

Thanks for sharing that insight. It's a stepping stone and it's critical to move quick.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#108

Great take! However, I wonder how you differentiate from platforms like Vanta? They already provide the monitoring and compliance framework you'll need anyway at some point. Frankly (and I don't want to sound too negative here) I doubt that a "one click compliant infrastructure" can work without knowing anything about the use case / application / dependencies of a company. Remember, it's not just about your system, i…

Thanks for that! And good question. Vanta offers a compliance checklist and integrates with your service providers (such as AWS, Github, etc.) to continuously monitor your system settings and flag potential vulnerabilities.

We provide a similar compliance checklist to Vanta, as well as HIPAA-compliant infrastructure and technical configurations. We’ll set up your application on compliant infrastructure deployed in your cloud, integrate CI/CD pipelines, and provide real-time logging/monitoring. Providing the technical piece that's compliant out of the box lets you save weeks of manual work configuring it yourself and having Vanta's API integration/AWS audit manager check it.

We use terraform to automate the infrastructure deployment process in a modular fashion. When you deploy with us, we take a dockerfile and basic information about your infrastructure setup, such as your availability region, RDS configs, instance sizes, etc. to deploy your application. This lets us support a variety of use cases and needs.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#109
post #60

What if I want to use the service but keep my already hipaa compliant hosting platform?

Nice question.

If you're using another platform to manage the infrastructure/hosting, you'd be able to integrate with us to complete the remaining parts necessary to get HIPAA compliant (i.e. the legal policies, compliance task list, risk assessments, vendor reviews, etc.).

That being said, a lot of our customers prefer migrating over to our infrastructure because many hosting services charge high usage-based fees for HIPAA compliance and it ends up being cheaper to deploy straight onto AWS, where they can use their AWS credits, for their infrastructure management.

Post reply on HN