4 ms·
Evaluating this for a client, I’m unclear on how this works with PHI under HIPAA, do I still need a BAA? This comment started as a joke and now I’m genuinely t
by cpfohl 5y ago
Evaluating this for a client, I’m unclear on how this works with PHI under HIPAA, do I still need a BAA?
This comment started as a joke and now I’m genuinely thinking about it; also from the disk usage claims which make it clear they’re not storing the data, would a service like require a BAA? It’d have to be encrypted at rest, so assuming that was true, and assuming that the data actually got stored (presumably as cold storage) I’m thinking it’d still require BAAs…
- disillusioned 5y agoIt's kind of Schrodinger's PHI. By the time you check to see if it exists, it definitely both does and does not but not provably so either way so... there, then.