4 ms·
Pertaining to your edit, apologies for over-simplifying originally. You are absolutely correct that the Security Rule is very very vague. Many HIPAA audits bare
by jabzd 10y ago
Pertaining to your edit, apologies for over-simplifying originally. You are absolutely correct that the Security Rule is very very vague. Many HIPAA audits barely reference the Security Rule and instead use stronger rule sets. Unfortunately, HIPAA is generally documentation of policies as opposed to true technical guidance and requirements. We're also an 8 year old SaaS company so many of our agreements pre-date the "cloud" catching up from a complicance perspective. At the speed of healthcare, I imagine it'll take another decade for the industry to realize that an AWS cloud is probably more secure than something a 10 person organization can cobble together.
- patio11 10y agoA running joke for me is the healthcare providers which are worried whether our firm will use "a database" which "could be hacked" instead of, to make up something which clearly has never been said by anyone regulated in the United States, saving all patient information as drafts in the office manager's hotmail account.
- leesalminen 10y agoIt's just a draft though. If you don't hit send, clearly it's not in a "database".
- dennisgorelik 10y agoIf you saved email draft into Outlook - it is a database. If your computer is hacked, then attacker would be able to extract information from that Outlook database.
- leesalminen 10y agoSorry, my sarcasm did not come off properly :)