3 ms·
So what you may have already discovered, is HIPAA compliance, HiTrust certification, BAAs, etc are table stakes for servicing covered entities in the healthcare
by chevman 3y ago
So what you may have already discovered, is HIPAA compliance, HiTrust certification, BAAs, etc are table stakes for servicing covered entities in the healthcare space.
They are all preludes, however, to agreeing to liability amounts/indemnification in the actual contract.
This is why, as an example, most healthcare orgs end up moving away from Google. Google (to my knowledge, which includes large deals at F50 level), will not contractually agree to any kind of financial or legal liability for data breaches, hacks etc.
Microsoft (and to a lesser extent Amazon) will agree to such terms if you're a big enough account, and generally already have some kind of framework in place with your procurement dept likely that simply needs to be amended.
This is also why larger healthcare orgs are reticent to work with smaller, less well capitalized startups in the ecosystem. The liability alone should something go wrong would potentially vaporize your company, and would definitely lead to uncomfortable conversations with your investors (who maybe, might also have large holdings in the larger healthcare orgs and be incented to not do stupid things that would create massive liabilities!).
- cbg0 3y ago> This is also why larger healthcare orgs are reticent to work with smaller, less well capitalized startups in the ecosystem. The liability alone should something go wrong would potentially vaporize your company While this sounds very dramatic, aren't the "less well capitalized startups" in your scenario the ones responsible for their own HIPAA violations, and not the larger healthcare orgs?
- fluidcruft 3y agoThere's also the business risk that a company you depend on goes poof and you're left scrambling (scrambling doesn't work well in healthcare IT, so much of it is bespoke and barely working... projects that look like they should work routinely fail years later in at integration setting everything back three years... it's a mess).
- selinkocalar 3y agoCompletely agreed. Trust and credibility are harder to prove for startups trying to contract to large health organizations, which is why a HIPAA compliance report or active monitoring from a 3rd party can be really helpful. Some large hospitals even turn away calls from startups for this exact reason. Compliance is table stakes. It's important to address HIPAA early and be able to attest to your compliance and security.