Every org that starts out with an compliance oriented SaaS in my experience ends up migrating out of it eventually because when they grow - they have more capital to build their own infrastructure as hire more engineers who do not want to deal with kinks of a SaaS abstraction. If you are using Vanta or Drata at early staging and opt for HIPAA framework, you do get the list of controls that you have to implement that…
Thanks for the transparency and thoughts on this! We provide a lot of active elements, such as our infrastructure logging/monitoring dashboard, email alerts, and code vulnerability scans every time you git push, so that we aren't just a one-time purchase. We help you be proactive about preventing breaches instead of just integrating with your AWS API and passively monitoring. One of the biggest things about HIPAA is…
Launch HN: Delve (YC W24) – HIPAA compliance as a service
111–116 of 116 posts
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#112How does this compare to OneTrust and Tugboat?
We provide a similar compliance checklist/preparation tool to Tugboat, as well as HIPAA-compliant infrastructure and technical configurations. We’ll set up your application on compliant infrastructure deployed in your cloud, integrate CI/CD pipelines, and provide real-time logging/monitoring. Providing the technical piece that's compliant out of the box lets you save weeks of manual work configuring it yourself.
By covering you not only on an administrative/compliance front, but also on a technical/cybersecurity front, we help you actively enforce good security and monitor compliance comprehensively.
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#113Well that'll be a fun name change. Are you Delve , or Microsoft Delve? https://support.microsoft.com/en-us/office/what-is-delve-131... Aside that, neat idea.
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#114Earlier quoted context omitted.
However, if you want to do business with any reasonable size of healthcare org, you're eventually gonna have to get a HITRUST report.
That's true. Curious what your experience has been with HITRUST
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#115It does more than just protecting sensitive health information, it also governs how billing works, so if you've ever wondered why some Dr. you never met is sending you bills in the thousands of dollars; HIPAA is where you can find out why!
Spoiler: Anyone who touches the patient, anyone who has a conversation with the patient, anyone who measures stuff of the patient, doctors consulted by doctors also get to charge. So that's why suddenly every nurse wants to talk to you, check your blood pressure, and a different nurse wants your blood oxygenation… and that guy that walked by who greeted the doctor seeing you, and talked about how much the 49ers sucke…
There are avenues for billing via consult (eg doc to doc conversations), but what you claim is very far from the truth.
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#116Earlier quoted context omitted.
I'm in banking and we have similar pressure to leave AWS, but for different reasons. Simply too many banking services are already on AWS, and if a single could goes down it mustn't take most of banking infrastructure of a country.
I work at a mega bank and I haven't heard this angle yet. We are pushing lots to cloud. We have "yes, we're serious" resiliency and regulatory requirements though. Regulatory is where a country in which we do business has requirements for how we run our infrastructure. Luxembourg is notorious for being the most demanding.