3 ms·
For systems you control, yes even if what you've described takes a fair amount of work to get to. The main issue is that for software that wasn't built healthca
by twunde 3y ago
For systems you control, yes even if what you've described takes a fair amount of work to get to. The main issue is that for software that wasn't built healthcare first, the strict privacy wasn't a requirement. Retrofitting your software and workflows can be a hell of a lot of work. Add in that you now need to verify that all the vendors you use are also compliant with the terms of your BAA.
For most non healthcare first SAAS providers you either do a major rebuild or you end up with a healthcare specific cluster which is missing some of your tools (although it's worth pointing out that many more vendors particularly in the observability space are now HIPAA compliant.)
- jollofricepeas 3y agoGood point. HIPAA controls are pretty simple. I think any mature company (not startups) will have them or is working towards them. Mature vendors just don’t want to abide by breach notification guidelines which is why they use it as leverage to ask for more $$$.