Live data from Hacker News

Launch HN: Delve (YC W24) – HIPAA compliance as a service

news.ycombinator.com

111–116 of 116 posts

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#111

Every org that starts out with an compliance oriented SaaS in my experience ends up migrating out of it eventually because when they grow - they have more capital to build their own infrastructure as hire more engineers who do not want to deal with kinks of a SaaS abstraction. If you are using Vanta or Drata at early staging and opt for HIPAA framework, you do get the list of controls that you have to implement that…

Thanks for the transparency and thoughts on this! We provide a lot of active elements, such as our infrastructure logging/monitoring dashboard, email alerts, and code vulnerability scans every time you git push, so that we aren't just a one-time purchase. We help you be proactive about preventing breaches instead of just integrating with your AWS API and passively monitoring. One of the biggest things about HIPAA is…

I'd say your offering seems to fill a void for nonprofit agencies like mine, and possibly public entities (like counties) who don't have the internal staffing/expertise to spin up and monitor HIPAA-compliant infrastructure, and are responsible for integrating health data from disparate sources.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#112

How does this compare to OneTrust and Tugboat?

Of course! Tugboat by OneTrust provides compliance checklist and preparation tools (i.e. InfoSec policies, audit management, controls mappings).

We provide a similar compliance checklist/preparation tool to Tugboat, as well as HIPAA-compliant infrastructure and technical configurations. We’ll set up your application on compliant infrastructure deployed in your cloud, integrate CI/CD pipelines, and provide real-time logging/monitoring. Providing the technical piece that's compliant out of the box lets you save weeks of manual work configuring it yourself.

By covering you not only on an administrative/compliance front, but also on a technical/cybersecurity front, we help you actively enforce good security and monitor compliance comprehensively.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#113
post #25

Well that'll be a fun name change. Are you Delve , or Microsoft Delve? https://support.microsoft.com/en-us/office/what-is-delve-131... Aside that, neat idea.

Ah, we're the other Delve - the one that doesn't come with an Office subscription but makes your office HIPAA compliant.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#114

Earlier quoted context omitted.

However, if you want to do business with any reasonable size of healthcare org, you're eventually gonna have to get a HITRUST report.

That's true. Curious what your experience has been with HITRUST

Layoffs caught me before we finished the audit so I can’t say with full confidence. However, if you have a SOC 2 type 2 report, you’re probably 90% of the way there. They’re not perfect overlaps but it’s more like a circle viewed with astigmatism than the Mastercard logo.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#115

It does more than just protecting sensitive health information, it also governs how billing works, so if you've ever wondered why some Dr. you never met is sending you bills in the thousands of dollars; HIPAA is where you can find out why!

Spoiler: Anyone who touches the patient, anyone who has a conversation with the patient, anyone who measures stuff of the patient, doctors consulted by doctors also get to charge. So that's why suddenly every nurse wants to talk to you, check your blood pressure, and a different nurse wants your blood oxygenation… and that guy that walked by who greeted the doctor seeing you, and talked about how much the 49ers sucke…

No, that is not at all why.

There are avenues for billing via consult (eg doc to doc conversations), but what you claim is very far from the truth.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#116
post #42

Earlier quoted context omitted.

I'm in banking and we have similar pressure to leave AWS, but for different reasons. Simply too many banking services are already on AWS, and if a single could goes down it mustn't take most of banking infrastructure of a country.

I work at a mega bank and I haven't heard this angle yet. We are pushing lots to cloud. We have "yes, we're serious" resiliency and regulatory requirements though. Regulatory is where a country in which we do business has requirements for how we run our infrastructure. Luxembourg is notorious for being the most demanding.

https://dantheengineer.com/bank-of-england-worried-about-con...
Post reply on HN