4 ms·
It's not just the lack of API's that makes it hard for digital health startups, a big hurdle is the perceived lack of security of a cloud based solution in rega
by paxtonab 11y ago
It's not just the lack of API's that makes it hard for digital health startups, a big hurdle is the perceived lack of security of a cloud based solution in regards to health care data.
A friend of mine works for a digital health startup, and the majority of the RFP's they receive automatically disqualify them if they have anything hosted in the "cloud", so they are forced to buy and maintain all of their own servers.
In addition to these costs (which could already be considered prohibitively expensive) they have to use enterprise versions of proven ETL and BI tools for the perceived added security benefits (i.e. they can't use open source).
- kat 11y agoThere are HIPAA certified cloud servers out there. I think the bigger problem is having tight security when integrating. It is considered safer to integrate behind a firewall (on an intranet) than worry about how to pass data between cloud-based software and locally hosted 3rd party databases/software
- dankohn1 11y agoI believe this is out-of-date. Our healthcare startup has passed in-depth security reviews from multiple huge carriers, and we operate in the cloud and use tons of open source. (We're hiring Rails devs!) It is a meaningful effort to be HIPAA-compliant, that prevent us, for example, from using lots of cool SaaS services. The bigger issue for us is that each integration still has customizations associated with it, because of a lack of agreement about what fields mean.