My 5 second reaction having managed a large organization in a compliance/regulatory driven environment is that these regulations need to be part of the orgs DNA or long term you’ll be buried by an audit. It’s not something you bolt on.
Yes, exactly. This is a similar battle IT folks face with implementing best practices with it comes to cyber hygiene, and the sooner it’s solidified, the better (shift left approach). That's been our current approach with helping early stage health tech startups, and will be a tough but rewarding battle as we move towards organizations with established practices (be it good or bad). Curious to talk more with you abou…
Launch HN: Delve (YC W24) – HIPAA compliance as a service
51–60 of 116 posts
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#52I remember early in Google Cloud I was working with a Google PM on health-related projects (Google Cloud Genomics). The PM was our ostensible expert on HIPAA, and explained many details (such as BAA). The one funny thing they said is "there is no such thing as HIPAA compliance, that term is meaningless". And I don't really understand what they meant, but I think they must have been wrong (even though they were suppos…
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#53We have investor pressure to use specific cloud providers. This is the Healthcare version of Walmart not letting their partners use AWS. Due to their (Amazon, Google) vertical integration slowly moving in on healthcare turf, many healthcare partners/payers/investors are adding contractual pressure to exit AWS or GCP and move to Azure specifically. Wondering how your cloud support in general looks. Your previews are a…
Interesting, haven't heard of this. Always figured aws and gcp were ahead of azure in terms of Healthcare
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#54Earlier quoted context omitted.
Thanks for the question! 1) We’ve made the conscious decision to start with AWS support, as our ICP is primarily on AWS (80%+). We plan to roll out GCP and Azure once we have sufficient coverage on AWS services. (2) When you’re onboarded, we deploy a series of base resources (IBNLT networking resources, notification services, logging services). You can then select from a library of supported resources for your applic…
Many thanks for the answers. In reply to 3, can you clarify the details of what deployment snd orchestration tools you set up for your customers? And if we are able to make modifications to the underlying infra, is there some kind of process that prevents changes that break HIPAA compliance?
Under the hood, we define infrastructure using Terraform to explicitly define logical relationships between resources, easily enforce deny by default behavior, and spin up resources with granular access logging by default. We then expose a subset of toggles that users can adjust (compute resources, service connections, silo’d application deployment). Some toggles that may have a business need, but would prove to carry excess risk (such as blanket public exposure of data store’s), are explicitly disallowed. This is a decision that we’ve made and feel offers the ideal balance between flexibility and compliance enforcement.
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#55Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#56Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#57Congratulations on Launch! Would you be plan to expand to Salesforce platform ? I am Salesforce partner would love to connect if you looking for implementation partners.
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#58I remember early in Google Cloud I was working with a Google PM on health-related projects (Google Cloud Genomics). The PM was our ostensible expert on HIPAA, and explained many details (such as BAA). The one funny thing they said is "there is no such thing as HIPAA compliance, that term is meaningless". And I don't really understand what they meant, but I think they must have been wrong (even though they were suppos…
It's a weird topic. I always laugh about how "difficult" HIPAA compliance is often portrayed as in online forums. It's a reminder to me of how important due diligence is. Of the various regulatory regimes, HIPAA is not particularly challenging, and if it is, I'd be concerned with doing business with the entity in other contexts.
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#59Healthcare CIO/VP here. Some thoughts to help you improve your communication to potential customers, AKA what I look for when I am evaluating a platform for healthcare use: The website is too thin, it looks like you're really heavily relying on meetings to get customers rather than the product itself. I think you should dedicate some resources to fleshing out the website A LOT with more information because it actuall…
Same situation. I was just about to write this exact comment. I don't need a platform, AWS already has plenty of services that when set up correctly are fine. And AWS already has the checklist they're showing as the main demo implemented. You can security scan your services and get exactly this checklist.
Basic technical compliance is not the hard part! It's everything else. Like the nice doctor who sends an image by email to investigate a scan after work who ends up being a problem. Or people who share passwords because they can't be bothered to get everyone signed up for a resource. Or someone making a bad decision about what is or isn't PHI because they don't understand the rules clearly. Or the creepy person who searches for their neighbour's medical records, etc.
> "How can I show my customers that I’m HIPAA compliant?" Again, it's 2024, no one cares about badges, they want BAAs and compliance reports.
In my experience no customers will ever ask if you're HIPAA compliant. This is something that comes up in a lawsuit or when a regulator visits. If anything, security stuff scares people away, best to say nothing.
> A more detailed website would change that a lot.
Agreed, the idea that HIPAA will be one click away and we never have to think about it again is silly. Because the website is so thin it comes across as written by someone who has never dealt with HIPAA.
It's also not clear to me how this whole setup works with legal. You cannot outsource compliance. When the state comes knocking one day with a big fine because there's a breach or mistake in whatever Delve is doing, we can't throw up our arms and say, well we have this dashboard that says everything is fine.