Live data from Hacker News

Launch HN: Delve (YC W24) – HIPAA compliance as a service

news.ycombinator.com

31–40 of 116 posts

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#31

Every org that starts out with an compliance oriented SaaS in my experience ends up migrating out of it eventually because when they grow - they have more capital to build their own infrastructure as hire more engineers who do not want to deal with kinks of a SaaS abstraction. If you are using Vanta or Drata at early staging and opt for HIPAA framework, you do get the list of controls that you have to implement that…

Thanks for the transparency and thoughts on this! We provide a lot of active elements, such as our infrastructure logging/monitoring dashboard, email alerts, and code vulnerability scans every time you git push, so that we aren't just a one-time purchase. We help you be proactive about preventing breaches instead of just integrating with your AWS API and passively monitoring. One of the biggest things about HIPAA is…

Solutions like this wont work in large orgs that have lead to huge ACVs.

Would be more happy if you prove me wrong.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#32

We have investor pressure to use specific cloud providers. This is the Healthcare version of Walmart not letting their partners use AWS. Due to their (Amazon, Google) vertical integration slowly moving in on healthcare turf, many healthcare partners/payers/investors are adding contractual pressure to exit AWS or GCP and move to Azure specifically. Wondering how your cloud support in general looks. Your previews are a…

We currently support AWS but use terraform for deployment, which is pretty cloud agnostic. So far, we haven't gotten any major requests for expanding to other cloud providers and most of our incoming customers are already on AWS anyways.

One of the main reasons why healthcare players were moving onto Azure was for in-built HIPAA compliant OpenAI access. We've been able to help our customers directly sign BAAs with OpenAI so this wasn't a concern.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#33
post #28

I remember early in Google Cloud I was working with a Google PM on health-related projects (Google Cloud Genomics). The PM was our ostensible expert on HIPAA, and explained many details (such as BAA). The one funny thing they said is "there is no such thing as HIPAA compliance, that term is meaningless". And I don't really understand what they meant, but I think they must have been wrong (even though they were suppos…

You PM is right. Unlike SOC2, you dont get a certification. More details here [1] [1] https://compliancy-group.com/what-is-a-hipaa-certification/

Maybe. But Google Cloud has adopted the compliance terminology: https://cloud.google.com/security/compliance/hipaa

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#34
post #28

I remember early in Google Cloud I was working with a Google PM on health-related projects (Google Cloud Genomics). The PM was our ostensible expert on HIPAA, and explained many details (such as BAA). The one funny thing they said is "there is no such thing as HIPAA compliance, that term is meaningless". And I don't really understand what they meant, but I think they must have been wrong (even though they were suppos…

Your PM was probably referencing the fact there is no audit requirement — HIPAA is self attestation.

HIPAA compliance can be boiled down to “implement best security practices, record every request & transaction, and enforce zero trust to the truest exist possible.” Once you've done your due diligence with this, you can self attest compliance.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#35

We have investor pressure to use specific cloud providers. This is the Healthcare version of Walmart not letting their partners use AWS. Due to their (Amazon, Google) vertical integration slowly moving in on healthcare turf, many healthcare partners/payers/investors are adding contractual pressure to exit AWS or GCP and move to Azure specifically. Wondering how your cloud support in general looks. Your previews are a…

Interesting, haven't heard of this. Always figured aws and gcp were ahead of azure in terms of Healthcare

They are, so I want to smash my face in once a month or so when this boogeyman is dragged up out of hell during executive calls

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#36
post #24

Looks great, and I wish this existed 2 years ago when I started building a HIPAA compliant product! But I immediately had a few questions and am hesitant to book a demo (I'm quite time poor): 1. What clouds do you support? 2. What does the infrastructure look like, what services does it use? 3. Do I get locked into a particular orchestration or deployment setup? We prefer k8s for example.

Thanks for the question!

1) We’ve made the conscious decision to start with AWS support, as our ICP is primarily on AWS (80%+). We plan to roll out GCP and Azure once we have sufficient coverage on AWS services.

(2) When you’re onboarded, we deploy a series of base resources (IBNLT networking resources, notification services, logging services). You can then select from a library of supported resources for your application-specific environment.

(3) To directly answer your question — no you are not locked in and can change as you see fit. Also, because we deploy infrastructure in your own cloud, you're able to go in anytime and make custom modifications to your infrastructure.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#37

We have investor pressure to use specific cloud providers. This is the Healthcare version of Walmart not letting their partners use AWS. Due to their (Amazon, Google) vertical integration slowly moving in on healthcare turf, many healthcare partners/payers/investors are adding contractual pressure to exit AWS or GCP and move to Azure specifically. Wondering how your cloud support in general looks. Your previews are a…

We currently support AWS but use terraform for deployment, which is pretty cloud agnostic. So far, we haven't gotten any major requests for expanding to other cloud providers and most of our incoming customers are already on AWS anyways. One of the main reasons why healthcare players were moving onto Azure was for in-built HIPAA compliant OpenAI access. We've been able to help our customers directly sign BAAs with Op…

> for in-built HIPAA compliant OpenAI access

Sorry but what?

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#39

Earlier quoted context omitted.

We currently support AWS but use terraform for deployment, which is pretty cloud agnostic. So far, we haven't gotten any major requests for expanding to other cloud providers and most of our incoming customers are already on AWS anyways. One of the main reasons why healthcare players were moving onto Azure was for in-built HIPAA compliant OpenAI access. We've been able to help our customers directly sign BAAs with Op…

> for in-built HIPAA compliant OpenAI access Sorry but what ?

A lot of healthcare companies are wanting to use GPT4, Whisper, and other LLMs from OpenAI, but these aren't HIPAA compliant out of the box. You still have to sign a BAA with OpenAI and get on their zero data retention (ZDR) plan.

Because of the close partnership with Microsoft and OpenAI, Azure makes it easy to get HIPAA compliant access to certain OpenAI models without having to go through OpenAI directly. This is why a lot of AI healthcare companies were building on Azure at first. Hope this clarifies!

Post reply on HN