Live data from Hacker News

Launch HN: Delve (YC W24) – HIPAA compliance as a service

news.ycombinator.com

1–10 of 116 posts

Launch HN: Delve (YC W24) – HIPAA compliance as a service

#1
Hey, HN! We're Karun and Selin, co-founders of Delve (https://getdelve.com). We help companies get HIPAA compliant fast, with 1-click infrastructure, streamlined legal policies, and real-time monitoring. Here’s a quick demo: https://youtu.be/mQbb5mprsUA.

HIPAA is a US federal law passed back in 1996 that sets standards for protecting sensitive health information. Here’s an article that breaks it down pretty simply: https://www.getdelve.com/blog/quick-guide-to-hipaa.

Most companies that process health information in the US need to become HIPAA compliant, a process that can be long and expensive. At our previous health tech company, we spent 6 weeks (and tens of thousands of dollars) on getting compliant. We had to complete a lot of manual work, even after purchasing an industry-standard compliance solution, and felt like we were hitting checkboxes with little confidence in our security. We realized that many parts of the compliance process could be streamlined and simplified, which led us to building Delve.

To get HIPAA compliant, you need (1) secure infrastructure, (2) legal policies, and (3) logging/monitoring. At Delve, we help startups with all three. We provide 1-click HIPAA compliant infrastructure deployed in your cloud and a CI/CD pipeline to update infrastructure from git push (think Heroku but HIPAA compliant). Then, we provide legal policies, paperwork, and a complete task list customized to your infrastructure setup. Finally, we have a real-time monitoring dashboard to help oversee compliance, track system activity, and review logs.

One thing we noticed the first time we ever got HIPAA compliant was that we had to use many tools along the way. We bought an industry-standard HIPAA compliance solution, hired a HIPAA DevOps contractor to help configure secure infrastructure, and worked with lawyers to adapt the boilerplate legal policies that our compliance solution had provided. When building Delve, we worked hard to give you everything you need in one place, reducing the hassle and cost.

We currently charge on an annual flat-fee basis. However, we’re still exploring our pricing model (flat-fee vs. usage-based vs. combination of both), and if you have any thoughts to share on that, we’d love to hear them.

We’re really excited about making it easier to build in healthcare and removing compliance bottlenecks. Thrilled to share this with you and hear your comments!

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#5
Every org that starts out with an compliance oriented SaaS in my experience ends up migrating out of it eventually because when they grow - they have more capital to build their own infrastructure as hire more engineers who do not want to deal with kinks of a SaaS abstraction.

If you are using Vanta or Drata at early staging and opt for HIPAA framework, you do get the list of controls that you have to implement that also include cloud specific configuration changes that you need to do. And these changes are one time thing, continuously monitored by the framework.

My argument is that, the target market you trying sell - early stage HIPAA compliance market is not difficult anymore.

I hope this feedback helps you to foresee possible problems.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#6

How do you beat https://www.aptible.com/ ?

Great question! Aptible is great for deploying HIPAA-compliant applications, but you still have to purchase another solution for completing the legal policies and compliance checklist, such as Vanta.

Think of us like Aptible + Vanta. Because you deploy your application through us, we can give you deep insights into your security and compliance. For example, we give you legal policies that have already been customized to your infrastructure setup. Similarly, we provide a logging/monitoring dashboard that is designed to meet what auditors look for in your infrastructure setup. Putting all your compliance solutions in one place lets us streamline the path to compliance.

Re: Launch HN: Delve (YC W24) – HIPAA compliance as a service

#9
post #4

I didn't see the mention of BAAs anywhere. Do you handle getting that signed with vendors like AWS?

Yes! We outline BAA requirements in our compliance checklist (i.e. we'll provide the exact steps of how to get a BAA with AWS and remind you to get BAAs with other 3rd parties).

We're also building out a small network of 3rd party vendors that we work closely with to help our customers get BAAs signed quick and offer discounts to those 3rd parties' services.

Post reply on HN