Earlier quoted context omitted.
It's a weird topic. I always laugh about how "difficult" HIPAA compliance is often portrayed as in online forums. It's a reminder to me of how important due diligence is. Of the various regulatory regimes, HIPAA is not particularly challenging, and if it is, I'd be concerned with doing business with the entity in other contexts.
What I laugh about is that more than once I have had to explain HIPAA to my corp lawyer. I've had actual discussions where the lawyers proposed an immense amount of work, followed by me explaining that our work doesn't fall into the scope of HIPAA and therefore we do not need to comply with it or get any certification or sign a BAA at all. "But... .but .... we should comply anyway just to be on the safe side!".
Launch HN: Delve (YC W24) – HIPAA compliance as a service
81–90 of 116 posts
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#82Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#83Healthcare CIO/VP here. Some thoughts to help you improve your communication to potential customers, AKA what I look for when I am evaluating a platform for healthcare use: The website is too thin, it looks like you're really heavily relying on meetings to get customers rather than the product itself. I think you should dedicate some resources to fleshing out the website A LOT with more information because it actuall…
1. We'll certainly update our website to be more comprehensive about our exact infrastructure setup and security best practices. We're releasing a security page that specifically details this. This should address your comments on adding more product information.
2. Interesting insights on removing the blog. We've actually received positive feedback on our 2-minute quick guide to HIPAA and some of our current customers found us exclusively through that blog post. We're also soon to roll out a small collection of blogs featuring auditors/CISOs/etc. and particularly for startup founders new to HIPAA, we've found that these can be helpful educational tools.
3. Clarifying our product, we're focused on both deploying apps on compliant infrastructure and providing a general compliance checklist suite. We help get computers, humans, and processes compliant - it's all in one. We're not just limited to computers.
4. We're fleshing out our FAQ and will move info around as mentioned in point 1.
5. We provide a compliant report to companies that work with us, not just a badge. Here's an example: https://app.getdelve.com/blandai
Thanks again for the thorough breakdown and feedback here! We're taking it all to heart and will reply to this comment once we've rolled out an updated version.
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#84Healthcare CIO/VP here. Some thoughts to help you improve your communication to potential customers, AKA what I look for when I am evaluating a platform for healthcare use: The website is too thin, it looks like you're really heavily relying on meetings to get customers rather than the product itself. I think you should dedicate some resources to fleshing out the website A LOT with more information because it actuall…
> I was ready to get more info, now that I see it may be focused on app development only, I don't care about it, as honestly getting computers compliant is a lot easier than getting humans and processes compliant. If you're not just focused on development, this reinforces the website problem. Same situation. I was just about to write this exact comment. I don't need a platform, AWS already has plenty of services that…
We totally agree. And to clarify, we don't just provide the technical compliance checklist (AWS Audit Manager already has all that), we provide the comprehensive list of tasks and policies that you need to put in place to be prepared for a complete audit. This spans terraform for technical infra setup all the way to 20+ legal policies (BC/DR Policies, Asset Management Policies, Access Control Policies, etc.)
> In my experience no customers will ever ask if you're HIPAA compliant.
For startups and earlier companies, being HIPAA compliant (whether it's a compliance badge on the footer of your website or a compliance report that you send to customers) is immensely helpful in the sales process. It signals credibility and trust. Sometimes this can be the difference between getting a sales call vs. not.
> A more detailed website would change that a lot.
We completely agree. We're rolling out a new version of the website taking to heart all the feedback you've given and will reply here in the coming days once we've pushed the updates.
> It's also not clear to me how this whole setup works with legal.
We're not replacing your legal counsel nor are we guaranteeing compliance. We're giving you the tools to be compliant that we've revised and refined with the help of auditors. At the end of the day, if you intentionally deploy an application that posts people's medical data to Twitter or you leave your computer unlocked on a subway, we can't take liability for that :)
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#85Earlier quoted context omitted.
AWS is fine for building out HIPAA services. They have a decent portal at https://aws.amazon.com/compliance/hipaa-compliance/ explaining their compliance, which services you can use, and how to get them to sign a Business Associate Agreement (BAA). I haven't done healthcare stuff in GCP or Azure so I can't compare, but AWS is _not_ a blocker for HIPAA.
> I haven't done healthcare stuff in GCP My understanding is that Google will not agree to any of the liability provisions inherent to a BAA, no matter how large your size.
> Google will enter into Business Associate Agreements with customers as necessary under HIPAA.
Huh! That's a pleasant surprise.
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#86Earlier quoted context omitted.
No you're right for sure. Aptible is mentioned a few commends down, and is/was basically the same business (compliance focused hosting for small startups). Now Aptible has seemingly pivoted away from that focus and are now trying to compete in the PaaS space. There are a couple of obvious reasons here. 1. You're limiting your TAM to just healthcare startups. Why? 2. After not that long, it doesn't make financial sens…
We absolutely agree. HIPAA compliance for startups is only the beginning for us. We're rolling out SOC2 soon and then will use these as a foundation to moving upmarket. Our end goal isn't to work with startups to automate compliance - we're using this as a launchpad to going upstream in the GRC space.
As a founder, I'll ask you why not start with the actually value proposition or goal you want to achieve right away. Why are you making your jouney very convoluted?
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#87> Most companies that process health information in the US need to become HIPAA compliant I appreciated what Delve is doing for these kind of companies but what about non-tech small companies & individual therapists that process health data? We enlist the services of multiple behavioral / mental health providers and most of them use personal devices / SMS / GMail for transmitting PHI[1]. I understand this may not be…
It's an interesting point you raise. You're correct in that our current target audience primarily covers the companies that provide services to healthcare providers instead of actual healthcare providers. For more context, HIPAA breaks companies into two categories: (1) Covered Entities, which are healthcare providers, health plans, and healthcare clearinghouses, and (2) Business Associates, which are companies that…
If doctor etc is a Covered Entity then that doctor is most likely a Provider, but is every doctor providing healthcare a really CE?
I wouldn’t have said no but I don’t track it ultra closely so I’m curious what’s the latest? My first three results matched my expectation but they could easily be out of date…
https://www.epatientdave.com/2020/02/03/hipaa-you-arent-a-co...
https://www.stevenslee.com/health-law-observer-blog/is-a-cas...
https://www.americares.org/wp-content/uploads/globalassets/_...
Anyway re the parent, my fourth result uses therapist as the example of uncovered providers, which would have been my guess
https://www.consumerreports.org/health/health-privacy/guess-...
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#88Earlier quoted context omitted.
> [we] provide customers with notice to remove trackers, or sign BAAs with user metrics companies where possible Do you provide any technical solutions to help your customers control these trackers in accordance with HIPAA and privacy laws, or do you refer your customers to third-party privacy solutions to accomplish this? You expressed disdain for "hitting checkboxes," yet your solutions to this specific problem app…
Good question, these trackers typically come in the form of developer installed pixels / trackers, making this situation a function of human choice. During onboarding, we conduct a supply chain vendor risk assessment, identify which vendors we can help facilitate a BAA agreement with, and which vendors (if any) need to be removed from a deployment. From there we provide the resources to initiate a communication chann…
Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service
#89Earlier quoted context omitted.
> [we] provide customers with notice to remove trackers, or sign BAAs with user metrics companies where possible Do you provide any technical solutions to help your customers control these trackers in accordance with HIPAA and privacy laws, or do you refer your customers to third-party privacy solutions to accomplish this? You expressed disdain for "hitting checkboxes," yet your solutions to this specific problem app…
Good question, these trackers typically come in the form of developer installed pixels / trackers, making this situation a function of human choice. During onboarding, we conduct a supply chain vendor risk assessment, identify which vendors we can help facilitate a BAA agreement with, and which vendors (if any) need to be removed from a deployment. From there we provide the resources to initiate a communication chann…