4 ms·
It can be! https://aws.amazon.com/compliance/hipaa-compliance/ https://aws.amazon.com/compliance/hipaa-compliance/
by yureka 11y ago
It can be! https://aws.amazon.com/compliance/hipaa-compliance/ https://aws.amazon.com/compliance/hipaa-compliance/
- clarkevans 11y agoWhile Amazon offers a business associate agreement ("BAA"), our legal review found it to be unacceptable -- the BAA we were privately provided last year significantly deviates from the standard language recommended by the U.S. Department of Health and Human Services [1]. Notably, Rackspace's BAA is public [2] (I'm not associated with Rackspace) and reasonably supports the standard language (I am not a lawyer). [1] http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/contractprov.html http://www.hhs.gov/ocr/privacy/hipaa/understanding/covereden... [2] http://www.rackspace.com/en-us/information/legal/hipaabaa http://www.rackspace.com/en-us/information/legal/hipaabaa
- FLGMwt 11y agoWould you happen to remember any issues your team had with Amazon's BAA that they didn't have with Rackspace's?
- deleted 11y ago[deleted]
- clarkevans 11y agohttps://www.prometheusresearch.com/how-amazon-reminded-us-that-not-all-business-associates-agreements-baa-are-created-equal/ https://www.prometheusresearch.com/how-amazon-reminded-us-th... (2014) In particular, Amazon's agreement included: A clause that puts all of the burden for securing data on the CE. No terms outlining how the BA would respond to breaches of unsecured PHI. Lack of specification about the BA’s level of access to PHI. A non-disclosure clause. EDIT: Google Cache for this page... http://webcache.googleusercontent.com/search?q=cache:tzvzlVGSuwAJ:https://www.prometheusresearch.com/how-amazon-reminded-us-that-not-all-business-associates-agreements-baa-are-created-equal/ http://webcache.googleusercontent.com/search?q=cache:tzvzlVG...