Live data from Hacker News

Launch HN: Delve (YC W24) – HIPAA compliance as a service

news.ycombinator.com

41–50 of 116 posts

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#42

We have investor pressure to use specific cloud providers. This is the Healthcare version of Walmart not letting their partners use AWS. Due to their (Amazon, Google) vertical integration slowly moving in on healthcare turf, many healthcare partners/payers/investors are adding contractual pressure to exit AWS or GCP and move to Azure specifically. Wondering how your cloud support in general looks. Your previews are a…

I'm in banking and we have similar pressure to leave AWS, but for different reasons. Simply too many banking services are already on AWS, and if a single could goes down it mustn't take most of banking infrastructure of a country.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#43

Does this relate to HITRUST as well? I know the pain of those audits as I worked for healthcare companies that had them and a lot of the rules are similar.

It's slightly similar but HITRUST is still more comprehensive and is built on the CSF framework.

HITRUST was initially developed as the answer to HIPAA compliance, although the framework has now been rebranded as industry-agnostic. Hence, there is a good amount of overlap as you mentioned.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#44

So this is for AWS style hosting, and there is no pricing info. I am interested in this and will be someone could be pitching this to many others, but I want it with cpanel cloud hosting not aws/git/whatever.

You’re correct, we are putting our engineering focus into designing an enjoyable experience with AWS as our launch pad, and broadening our supported cloud providers as we continue to build out.

I’ve only seen and personally used CPanel for on-prem management (paired with WHMCS for billing), which is not something I’ve come across so far here. Happy to talk about this more though if you have time.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#45
post #27

Sort of related: it seems like compliant providers and services are carrying the burden of patient privacy in good faith, securing the front door. Meanwhile, there are open tent flaps on the sides and back. It's hard to do the right thing while there are minimal regs and enforcement on the rest of the ecosystem. Eg, Tracking on medical sites let Meta go to town -- https://www.theverge.com/2022/8/2/23288612/meta-hospt…

Yes, you’re correct in your assertion that infrastructure policies are just one part of the puzzle. In conjunction with our preconfigured deployments, we provide customers a set of legal policies we’ve worked with former US Attorneys to closely align with the spirit of HIPAA enforcement. We’ve all seen the countless byteDance and Meta cookie data leakage headlines on insurance and healthcare portals, and provide customers with notice to remove trackers, or sign BAAs with user metrics companies where possible.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#46

My 5 second reaction having managed a large organization in a compliance/regulatory driven environment is that these regulations need to be part of the orgs DNA or long term you’ll be buried by an audit. It’s not something you bolt on.

Yes, exactly. This is a similar battle IT folks face with implementing best practices with it comes to cyber hygiene, and the sooner it’s solidified, the better (shift left approach). That's been our current approach with helping early stage health tech startups, and will be a tough but rewarding battle as we move towards organizations with established practices (be it good or bad). Curious to talk more with you about this if you have time.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#47
post #24

Looks great, and I wish this existed 2 years ago when I started building a HIPAA compliant product! But I immediately had a few questions and am hesitant to book a demo (I'm quite time poor): 1. What clouds do you support? 2. What does the infrastructure look like, what services does it use? 3. Do I get locked into a particular orchestration or deployment setup? We prefer k8s for example.

Thanks for the question! 1) We’ve made the conscious decision to start with AWS support, as our ICP is primarily on AWS (80%+). We plan to roll out GCP and Azure once we have sufficient coverage on AWS services. (2) When you’re onboarded, we deploy a series of base resources (IBNLT networking resources, notification services, logging services). You can then select from a library of supported resources for your applic…

Many thanks for the answers. In reply to 3, can you clarify the details of what deployment snd orchestration tools you set up for your customers? And if we are able to make modifications to the underlying infra, is there some kind of process that prevents changes that break HIPAA compliance?

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#48
> Most companies that process health information in the US need to become HIPAA compliant

I appreciated what Delve is doing for these kind of companies but what about non-tech small companies & individual therapists that process health data? We enlist the services of multiple behavioral / mental health providers and most of them use personal devices / SMS / GMail for transmitting PHI[1]. I understand this may not be the target audience for Delve but getting these kind of companies HIPAA-compliant is a real need.

[1] https://www.hhs.gov/answers/hipaa/what-is-phi/index.html

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#49

> Most companies that process health information in the US need to become HIPAA compliant I appreciated what Delve is doing for these kind of companies but what about non-tech small companies & individual therapists that process health data? We enlist the services of multiple behavioral / mental health providers and most of them use personal devices / SMS / GMail for transmitting PHI[1]. I understand this may not be…

It's an interesting point you raise. You're correct in that our current target audience primarily covers the companies that provide services to healthcare providers instead of actual healthcare providers.

For more context, HIPAA breaks companies into two categories: (1) Covered Entities, which are healthcare providers, health plans, and healthcare clearinghouses, and (2) Business Associates, which are companies that process PHI on behalf of Covered Entities.

Behavioral/mental health providers fall into the Covered Entity category, and their requirements under HIPAA are different than those of Business Associates. Our services are currently focused on supporting Business Associate needs.

Post reply on HN