Live data from Hacker News

Launch HN: Delve (YC W24) – HIPAA compliance as a service

news.ycombinator.com

91–100 of 116 posts

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#91
post #42

We have investor pressure to use specific cloud providers. This is the Healthcare version of Walmart not letting their partners use AWS. Due to their (Amazon, Google) vertical integration slowly moving in on healthcare turf, many healthcare partners/payers/investors are adding contractual pressure to exit AWS or GCP and move to Azure specifically. Wondering how your cloud support in general looks. Your previews are a…

I'm in banking and we have similar pressure to leave AWS, but for different reasons. Simply too many banking services are already on AWS, and if a single could goes down it mustn't take most of banking infrastructure of a country.

I work at a mega bank and I haven't heard this angle yet. We are pushing lots to cloud. We have "yes, we're serious" resiliency and regulatory requirements though.

Regulatory is where a country in which we do business has requirements for how we run our infrastructure. Luxembourg is notorious for being the most demanding.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#92
post #70

So what you may have already discovered, is HIPAA compliance, HiTrust certification, BAAs, etc are table stakes for servicing covered entities in the healthcare space. They are all preludes, however, to agreeing to liability amounts/indemnification in the actual contract. This is why, as an example, most healthcare orgs end up moving away from Google. Google (to my knowledge, which includes large deals at F50 level),…

> This is also why larger healthcare orgs are reticent to work with smaller, less well capitalized startups in the ecosystem. The liability alone should something go wrong would potentially vaporize your company

While this sounds very dramatic, aren't the "less well capitalized startups" in your scenario the ones responsible for their own HIPAA violations, and not the larger healthcare orgs?

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#93
post #23

Healthcare CIO/VP here. Some thoughts to help you improve your communication to potential customers, AKA what I look for when I am evaluating a platform for healthcare use: The website is too thin, it looks like you're really heavily relying on meetings to get customers rather than the product itself. I think you should dedicate some resources to fleshing out the website A LOT with more information because it actuall…

If it's only compliance then, why not go with the other vendors like Vanta etc?

No idea.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#94
post #66
post #42

Earlier quoted context omitted.

I'm in banking and we have similar pressure to leave AWS, but for different reasons. Simply too many banking services are already on AWS, and if a single could goes down it mustn't take most of banking infrastructure of a country.

I figured most of the big banks still use AS400s. Have they finally shed those?

Surely mainframes?

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#95
post #23

Healthcare CIO/VP here. Some thoughts to help you improve your communication to potential customers, AKA what I look for when I am evaluating a platform for healthcare use: The website is too thin, it looks like you're really heavily relying on meetings to get customers rather than the product itself. I think you should dedicate some resources to fleshing out the website A LOT with more information because it actuall…

Thank you for these insights! We're in the midst of revamping our website so your feedback was very well timed. We will let you know when we release the updated version of our website. In the meantime, summarizing some of your points: 1. We'll certainly update our website to be more comprehensive about our exact infrastructure setup and security best practices. We're releasing a security page that specifically detail…

Good luck! We need more competitors in this space, and healthcare IT is a decade or mode behind everyone.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#96
post #92
post #70

So what you may have already discovered, is HIPAA compliance, HiTrust certification, BAAs, etc are table stakes for servicing covered entities in the healthcare space. They are all preludes, however, to agreeing to liability amounts/indemnification in the actual contract. This is why, as an example, most healthcare orgs end up moving away from Google. Google (to my knowledge, which includes large deals at F50 level),…

> This is also why larger healthcare orgs are reticent to work with smaller, less well capitalized startups in the ecosystem. The liability alone should something go wrong would potentially vaporize your company While this sounds very dramatic, aren't the "less well capitalized startups" in your scenario the ones responsible for their own HIPAA violations, and not the larger healthcare orgs?

There's also the business risk that a company you depend on goes poof and you're left scrambling (scrambling doesn't work well in healthcare IT, so much of it is bespoke and barely working... projects that look like they should work routinely fail years later in at integration setting everything back three years... it's a mess).

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#98
post #70

So what you may have already discovered, is HIPAA compliance, HiTrust certification, BAAs, etc are table stakes for servicing covered entities in the healthcare space. They are all preludes, however, to agreeing to liability amounts/indemnification in the actual contract. This is why, as an example, most healthcare orgs end up moving away from Google. Google (to my knowledge, which includes large deals at F50 level),…

Completely agreed. Trust and credibility are harder to prove for startups trying to contract to large health organizations, which is why a HIPAA compliance report or active monitoring from a 3rd party can be really helpful. Some large hospitals even turn away calls from startups for this exact reason. Compliance is table stakes. It's important to address HIPAA early and be able to attest to your compliance and security.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#99

Earlier quoted context omitted.

We currently support AWS but use terraform for deployment, which is pretty cloud agnostic. So far, we haven't gotten any major requests for expanding to other cloud providers and most of our incoming customers are already on AWS anyways. One of the main reasons why healthcare players were moving onto Azure was for in-built HIPAA compliant OpenAI access. We've been able to help our customers directly sign BAAs with Op…

While you're right about the access to AI models on Azure, I wouldn't tie my infrastructure to Azure just for that. Sure, you might have to use them for that service, but ship the queries in & the results back to a cloud of choice; especially LLMs in most uses cases won't represent a huge amount of data; the costs of egress We're (now only partially) on Azure for reasons stated upthread: desire from the industry. We'…

Sorry to hear that your experience with Azure has been sub-par. I know there was a sizable wave of people that migrated over to Azure for the AI models but haven't heard too much from them since. Interesting to hear about your experience...

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#100

Earlier quoted context omitted.

> I haven't done healthcare stuff in GCP My understanding is that Google will not agree to any of the liability provisions inherent to a BAA, no matter how large your size.

Someone else linked to https://cloud.google.com/security/compliance/hipaa which says: > Google will enter into Business Associate Agreements with customers as necessary under HIPAA. Huh! That's a pleasant surprise.

I've heard that that page is outdated and instead if you sign into G Suite as an admin, go to the admin console (admin.google.com/ac/companyprofile/legal) and then go to "Security and Privacy Additional Terms" you can review sign a BAA.
Post reply on HN