5 ms·
As somebody working in the healthcare industry, this is the killer feature for me: >Q. What level of security and compliance does Microsoft Teams support? >A.
by commandar 10y ago
As somebody working in the healthcare industry, this is the killer feature for me:
>Q. What level of security and compliance does Microsoft Teams support?
>A. Microsoft Teams is expected to be Office 365 Tier C compliant at launch. This broad set of global compliance and data protection requirements includes ISO 27001, ISO 27018, EUMC, SOC 1 Type I & II, SOC 2 Type I and II, HIPAA and FERPA. Microsoft Teams also enforces two-factor authentication, single sign on through Active Directory and encryption of data in transit and at rest.
The last time I'd looked into it, Slack was explicitly not HIPAA-compliant and therefore a non-starter for my team. We've basically had to stick to a combination of Hangouts for general chat and internal email for any HIPAA-covered data, so this would be a big win for us.
- ianai 10y agoAdhering to industry compliance specs definitely opens the possibility of a captive audience.
- brudgers 10y agoOr serving unserved organizations, or both, depending on how one looks at it.
- commandar 10y agoI mean, like I said above, my team would love to be using Slack, but it's legally impossible for us to use in a way that would improve our current workflow. And honestly, that's not just limited to Slack; it's not at all unusual for me to run into slick new technologies and products that I'd love for us to be able to use, but things like "not breaking Federal laws" get in the way. Sometimes it does take an 800lbs gorilla like Microsoft stepping in to get those techs our way because Microsoft's customer base has to worry about that sort of thing.
- brudgers 10y agoFor many organizations, running something like RocketChat inhouse might be an alternative...I mean, how many of Slack's features add most of the value?
- commandar 10y agoThen you have to provision hardware to run it and someone to set it up and admin it. And deal with backups and data retention, etc. Healthcare IT teams tend to run ridiculously lean. There's a much stronger business case for paying a few bucks per user/month than take up expensive and generally highly limited sysadmin time rolling your own.
- brudgers 10y ago[IANAL] Chat's may or may not be deemed business records by a prudent attorney and therefore it may be possible to not retain them for reasons similar to those under which computer logs are not maintained. That might make complying with non-realtime HIPAA requirements simpler. Relative to IT requirements, the trend is toward much higher ratios of machines to IT staff due to virtualization and orchestration. I suspect that over time, healthcare organizations will get more containers. Anyway, I was not thinking just about healthcare...nor thinking that lack of slack is one of the significant areas in which improvement is needed in the now.
- commandar 10y agoI think the broader point is that in any industry that's heavily regulated enough that built-in regulatory compliance is a selling point, is it really worth the hassle of taking on that potential liability yourself when it can be outsourced for <$100/year/user?
- brudgers 10y agoI have not read the terms and conditions for Microsoft's Office online services, however, I would not expect that Microsoft explicitly assumes much liability for regulatory compliance on behalf of customers under them. I tend to doubt that Microsoft would be a first choice target for litigation by a reasonably prudent lawyer or regulatory body these days. Anyway, there are organizational cultures where free is almost too much money per employee per year...cause I've worked in a few.
- agumonkey 10y agoCould you tell us what desires you have and what issues the healthcare industry is hitting with computer based tech ? As an ex computer fanatics I wanted to make medicine all digital and smooth (naive), I see it's not there, yet I'm not in Health so I have no idea what are the reasons. I expect "world chaos" to be part of them.
- commandar 10y agoIf I'm understanding your question correctly, the single biggest obstacle in healthcare informatics today is interoperability. The industry grew up in a pretty ad hoc way and the result is that closed-off silos of data are pretty much the norm; every vendor has their own ideas about how data should be handled, and getting different systems talking to each other is a full-time job (my job, coincidentally). HITECH and the ACA have forced the industry to start making meaningful steps toward real interop, but I'd say we're at least a decade out from it being less of a nightmare than it is now.
- agumonkey 10y agoI thought it was more than data interchange. Like more than inefficient commputer programs/interfaces, costs, lack of competition from entry barrier due to high amount of legislation/regulation. I'd love to work in Health IT, what's your company's name ?
- cscharenberg 10y agoI agree. Integration is exceedingly complex. Data is stored and interpreted differently in every system, even if they share the same EMR, due to configuration differences in workflow, data setup, software versions, etc. You can't exchange data without thoroughly understanding the clinic workflows that generated it or will be using it. It's all time-consuming and hard. I work on a patient portal consuming data from the EMR, and even that is tremendously complicated to present medical data safely and correctly to a person. -- Sibling comment mentioned wanting to work in Health IT. The big market problem in healthcare is small companies doing good innovation (usable patient-side workflows, modern clinical tools, shiny things) running into the consolidated, massive EMR systems. The first question when they approach a healthcare system will be "Are you integrated with Epic/Cerner/whatever?" and if not, they will be sent away. Or be ready to embark on a very long, slow process and integrate deeply into workflows, data APIs, etc. When a system consolidates their EMR (driven by real needs but also Meaningful Use incentives), it forces standardization and special one-offs become much harder. Getting a doctor interested in using a new device or software means working within the whole EMR - the staff doesn't have the time or leeway to go use tools that don't integrate, just because a doctor really wants it. That doctor needs to align large groups, get agreement, and it's going to take a lot of time and money. It all comes down to interoperability/integration. Building cool stuff in healthcare is really easy since most of the tech in use is outdated and slow moving. But interoperability - required to sell into healthcare systems - is really, really tough.
- monkmartinez 10y agoWow that is huge... HIPPA is a massive headache for industries that have typically been very "blue collar" Ie. EMS/Firefighting. We are always looking for ways to communicate more effectively, especially for our most at risk citizens (coordinating agencies). This could be an almost real-time notification system... hmm.
- dr_ 10y agoThat's good to know. Microsoft previously had a product called Microsoft Lync, which was HIPAA compliant (and was used as the chat protocol in my hospital system). It later became Skype for Business - although we still use it as Lync. I'm not certain if Skype for Business was ever considered to be HIPAA compliant however.
- dogma1138 10y agoIt is they only changed the branding the executable is even called lync.
- deleted 10y ago[deleted]
- gshulegaard 10y agoHaving worked briefly in the HIPAA compliant EMR sector, I am honestly surprised by this. Last I checked HIPAA rules were quite lackadaisical when it came to securing patient facing web portals. But I am very out of date and had never thought about applying HIPAA compliance to inter-team communications... Glad you pointed this out! Really makes me look at Teams in a different (decidedly more positive) light. Not that I saw it negatively...it just seemed kind of neutral, like Yet-Another-Microsoft-Product that is entering last year's exciting new market.
- ohsimtabem 10y agoSince lot of people is talking about HIPPA compliance. Have you heard about https://teamstitch.com/product/ https://teamstitch.com/product/ (nope, not affiliated in any way) When it came out it was basically a copy cat of Slack, with HIPAA and other security standards compliance. (now they've updated the ui)