22 ms·
Show HN: Kate's App
Caregiving is a natural, human act of compassion and caring, and most of us, at some point, will rely on someone to help us with our health care (> 70%) or be tasked with helping someone else (> 10%).
Kate's App is a tool to coordinate doctor contact information, prescriptions, pharmacies, appointments, notes, and other information with family and caregivers, and do it safely and privately. This is not a clinic portal, and is not associated with any insurance or medical providers.
The app is 95% complete, and is entirely usable as is (for any interested beta users). I intend to clean up the rest of it, and go GA within a few weeks. In the meantime, I would love to answer any questions or hear helpful critiques.
BTW, Show HN is the best.
- TrainedMonkey 2y agoWho owns the data and where it is stored?
- warkdarrior 2y agoAlso, how identifiable is the data? Can a (US state) government agency subpoena data for individual users? Does the app/company fall under HIPAA regulation? If it does, what security & privacy measures are in place to guarantee compliance? If it does not, what security & privacy measures are in place to prevent government fishing expeditions? Finally, what security & privacy measures are in place to prevent app developer having a change of heart about selling the data? What if, say, United Healthcare offers to buy the app and the data for $1B?
- bhpreece 2y ago> app developer having a change of heart Yes. Two features high on my list of todos: 1) download all your data; 2) delete all data from the site. The second is a bit more complicated, since multiple family members may have access to the same data, and may have different opinions on deleting it. I'll work it out. Otherwise, you have only my integrity. I'm not looking to sell it, but I would love to hand this over to someone with more resources and bigger pockets. If I ever do, I would want those reassurances from them first, and I would definitely give all users fair warning, so they can pull out if they don't have the same confidence I do.
- ygjb 2y ago> The second is a bit more complicated, since multiple family members may have access to the same data, and may have different opinions on deleting it. I'll work it out. I know it's been said elsewhere, but you need a lawyer. This isn't something for you to work out, it's something for you to clearly understand your legal obligations, and what your exposure is based on which jurisdictions a user might log in from.
- bhpreece 2y ago> you need a lawyer Legal advice is part of working it out.
- klibertp 2y agoAs someone under civil law jurisdiction, I have a hard time parsing this: > This isn't something for you to work out, it's something for you to clearly understand your legal obligations Like, is it really impossible to "understand your legal obligations" without help from a lawyer? Is it supposed to be like that? Why? Are the laws explicitly written to be impossible to understand if you're not a lawyer? I might have lucked out, but in the few instances where I had doubts, just reading the relevant code gave me all the advice I needed. They are written to be clear and unambiguous as much as possible - in effect, they're tedious and wordy but perfectly understandable. It's easy to recognize the complex or unclear parts because they really stand out from the rest - and that's when you ask a lawyer. Of course, if there's a significant penalty or otherwise stakes are high, consulting with a lawyer is a good idea. But the notion of "the people" only ever interacting with "the law" through intermediaries is... strange? Then again, you don't generally risk being shot in the head for arguing with a policeman here, which might or might not be a separate issue.
- netdevphoenix 2y agoYou can't possibly pretend to understand the laws from every single country. That is the reason why you need a lawyer. This app targets all countries in the world. Even if it was just for the US, you would need one.
- kmoser 2y agoAnd is it encrypted at rest and in transit? If so, what level of encryption? Are keys ever stored in the app?
- otterley 2y agoIf you're dealing with personal health information (PHI), I would advise you to temporarily close your site and hire a lawyer straight away. Whenever you touch this kind of data, regulatory regimes like HIPAA may apply, and you need to be extremely careful. There's not a HIPAA compliance or even a privacy policy statement available on your front page. See https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg... as a starting point. We might be able to recommend a lawyer to you if you tell us which state you're located in.
- bhpreece 2y agoI would appreciate a recommendation. I'm in Minnesota.
- brentjanderson 2y agoIANAL either but if I were you, I’d start here: https://www.vanta.com/products/hipaa https://www.vanta.com/products/hipaa or look for competitors. And perhaps look at Stripe Atlas for getting my corporate ducks in a row to start with. https://stripe.com/atlas https://stripe.com/atlas Wading into that to get oriented, you would then be better equipped to have at least a baseline. A corporate attorney would be the next step to verify what you’re doing. Minnestar.org hosts networking events that may be useful for finding people in the intersection of tech, healthcare, and law. Attend and get some face time to find people who may want to help. Lots of corporate centers in Minneapolis (assuming you’re in or near the twin cities), including healthcare. Depending on financial considerations, you may be able to find on ramps to grants, investors, or donors to fund compliance. Not sure on that though, but it’s possible. Good luck!
- bhpreece 2y agoThank you. I'll look into all of this.
- roegerle 2y agoAre they a covered entity?
- TemptedMuse 2y agoYeah... this is a lawsuit waiting to happen. Medical data is NOT something you handle with a hobby project. No privacy policy, no real information about the owner behind it. Seems all "trust me, it's private, I pinky swear".
- actionfromafar 2y agoIf it was all running locally, I could see someone getting away with it, possibly. At this point, it's just a tool?
- TemptedMuse 2y agoYeah; self-hosted and open source I would be more open to it. This is just kinda sketchy.
- mkoryak 2y agoThat, and also let me tell you about a thing called margins. They help text not run into the edges of the screen. I don't blame you for not using them though since evidently you never looked at your page on mobile ;)
- bhpreece 2y agoI look at my page on mobiles all the time. The lack of margins really pisses me off.
- dflock 2y agoGreat idea! - What country/ies do you accept users from and which jurisdiction do you store their data in? - Get a HIPPA/GDPR/PHIPA audit by a legal professional ASAP!
- bhpreece 2y agoThis information is all in the U.S. I haven't looked at international issues. I'll need to put it on my list.
- getwiththeprog 2y agoIt might be easier to launch internationally first. Many places on the planet put good will in healthcare as more important than the almighty dollar. I have dealt with lawyers a number of times. Costs can spiral out of control very quickly, so take time to think over how much you are willing to spend and what your end goals are.
- i_love_retros 2y ago> You data will not be sold, shared, or given away. Your medical data is the most private data you have, and we respect that. So you're hack proof and idiot employee proof?
- metalliqaz 2y agoIs any company?
- InsideOutSanta 2y agoNo, but I guess a product like this should be built in a way that the company doesn't have access to unencrypted data in the first place.
- cess11 2y agoApparently, and they'll never enter bankruptcy proceedings and get sold that way.
- kmoser 2y agoThe claim doesn't say they won't be hacked. The implication is that they won't willingly do those things.
- hk__2 2y agoThe header link of static pages like https://katesapp.org/static/What%20Is%20Kate's%20App.html https://katesapp.org/static/What%20Is%20Kate's%20App.html doesn’t work.
- curious_cat_163 2y agoI think you might want to heed the advice about privacy regulations in the other threads. Just thought, I'd share what I think about the substance of the idea (not the implementation). I think a big untold story in the US healthcare system is how it shifts the burden of coordinating care to patients and/or their loved ones. To be sure, there is a lot of decisions that the individual (or their NoK) should be making but the amount of paperwork that flies around and lack of coordination between say an insurance company and the provider is astounding. This becomes very pronounced for every corner case and the entire machinery is wired to record things in myriad systems but somehow not make things better when it comes to the core outcomes -- providing healthcare. Every entity in the food chain is out to (and does!) make a buck. Meanwhile, there is a wait time of > 30 days to meet one's primary care physician over a video chat! So, I absolutely LOVE your idea. The implementation probably requires a lot of iterations here. One suspects that there are ways in which a consumer facing app could make some real money to level the playing field in favor of the patient while being a sustainable busienss.
- bhpreece 2y agoThank you for the encouragement.
- gwbas1c 2y agoI don't want to repeat other comments here; but this app smells of a very dangerous attitude: Built with love by novices with grand intentions, with complete blindness to the real consequences that happen when novices are ignorant in their field. If your goal is to "find a learning project," I suggest finding a very different "learning project." Otherwise, keep "Kate's app" private, word-of-mouth, invite-only for under 20 people. The 1980s and 1990s are long-gone, you can no longer "learn as you go" when the consequences of your application malfunctioning have real-world implications. --- A few years ago, my employer used an HR app that appeared built by a novice. In that time period; they sent me a PDF with tax information for half the people in the company; and then they royally screwed up the tax information sent to the IRS for me.
- diggan 2y agoHow do you know that the authors are novices with "complete blindness" to real consequences? Where are you getting the "find a learning project" goal from? It sucks that you've been burnt by that before, but it sounds like your employer was the one who screwed you there, not the author of the application.
- ygjb 2y agoUh, this is appears to be an application that collects data that is regulated in most legal jurisdictions, lacks a published terms of use, doesn't have a published privacy policy, and at first glance is missing rudimentary security controls related to TLS and content security. The sparse documentation makes claims about privacy and security, but there is no evidence to back those claims.
- tantalor 2y agoThey don't know, it's a total guess. That's why they hedge with phrases like "smell" and "if your goal..."
- threatofrain 2y agoTotal guess implies that they closed their eyes and made a random choice. There's a reason why the top posts, including one by a lawyer (who recommends immediately shutting down the site before getting advice), are saying caution is very warranted.
- roegerle 2y agoSo HIPAA isn't rocket science and HHS provides plenty of HIPAA guidance. Kate's App isn't providing healthcare so HIPAA doesn't apply.
- otterley 2y agoThe site might be deemed a Business Associate, depending on the specific facts, which we don't fully possess. That's why I recommended the owner seek counsel.
- roegerle 2y agoA business associate to who? The user?
- bagels 2y agoA covered entity (eg. doctor, nurse, etc.)
- yunwal 2y agoHow could this app possibly be considered a business associate to a provider? The provider has no idea it’s even being used, let alone a formal association with the application.
- bagels 2y ago"Kate's App is a tool created to support medical caregivers" The landing page doesn't make it clear whether providers are expected to use it or not.
- otterley 2y agoLook up the definition of “provider” in HIPAA’s text. The definition is extremely broad and doesn’t just cover doctors and pharmacists.
- rgbrgb 2y agoSounds like many have privacy/compliance concerns. A bit of horizontal padding is all I ask.
- bhpreece 2y agoI would love to find a good web page designer.
- cess11 2y agoWho is on the board and what experience in the field do they have? I couldn't find a privacy policy so it's likely to be criminal to supply this software to EU citizens.
- motohagiography 2y agocontra view to these comments: keep going. I worked in health information privacy and security longer than all of them and the number of sincere people in it is diminishingly small. the field has become infested with gatekeeper nerds and petty bureaucrats who insist you pay their toll to proceed, or demoralized and cynical opportunists who just go along to get along. sure, there are risks, but take them. make a thing for people who take care of other people. this is for a woman who takes care of her husband with alzheimers, or a man who takes care of his wife with parkinsons. fuck the system. make something someone wants. good luck.
- nkozyra 2y ago"Keep going" is great advice, but what we're looking at here isn't ready for primetime by any stretch.
- bhpreece 2y agoThank you. You get it.
- TemptedMuse 2y ago> "I worked in health information privacy and security longer than all of them" What a claim to make.
- g-b-r 2y ago> fuck the system This app is the system, with a "trust me bro" approach to privacy and security. Its creator is probably well intentioned, but this is likely to result in bad things for its users.
- bhpreece 2y agoI could use your experience. Would you be willing to chat offline?
- rafram 2y agoPrivacy concerns aside, I don't really understand what the point of this is, to be honest. You can already add family/caregivers as authorized users on a MyChart (Epic) profile, which is an actual source of truth, not a separate data store that you need to update manually. This seems like a good experiment in building a CRUD app, but I'd recommend doing that with something with less liability.
- diggan 2y ago> I don't really understand what the point of this is, to be honest [...] on a MyChart (Epic) profile As someone who never heard of either MyChart nor Epic, I'm guessing it could be useful for people like me who don't have those things.
- bhpreece 2y agoNot really. MyChart (which is provided by Epic) is a way for doctors and clinics to communicate with patients. Although you could give you doctor access to your information on Kate's App, that's not the purpose, and they probably don't want it.
- rat87 2y agoI could understand epic since I think that's mainly for doctors but don't most hospital systems use MyChart or similar portals nowadays to let patients access access their appointments/payment/lab results/doctor notes/etc
- mrlonglong 2y agoNo. Absolutely not. You will be held legally responsible if you have breaches.
- bhpreece 2y agoThank you everybody for your comments. Comments on legal issues: I absolutely agree and 100% plan to get legal advice. In the meantime, if you have personal experience, I would love to learn from you. Comments on HIPAA: I'm 99% sure this does not apply, since the site is for patients and their families, and no doctors, clinics, hospitals, or insurance companies are involved. All information comes from the family, and stays in the family. Comments on security: This is a huge issue for me. I've followed best practices as nearly as I can, but I've also been asking around to find out who could do a comprehensive security audit, but haven't yet found anybody I trust. Does anybody have any recommendations on how to find someone? Comments on terms of use, etc: Yes, this needs to be done, but I figured the terms of use are of no use until there's something to use. Comments on "novice" and "learning projects": Yes this was absolutely built with love and grand intentions, and no, I'm not a novice. I wrote this because my adult daughter died of cancer recently, and we really could have used this. If I can help others deal with the pain of diseases like this, then I'm going to try. I'll work through the problems as they come up. Aside from the security audit, I'm also looking for someone who'll do a much more professional design and L&F for the site. Another issue I can really use advice on is how to show this to the people who need it. People who aren't dealing with the problem right now, aren't interested. How do I reach the maybe 5% to 10% of people who have the need right now?
- Tarrosion 2y agoI'm sorry for your loss, and I hope that helping others through this project helps you find some solace. IMHO, it's a mark of character that your response to having a problem is "I want to help other people so they suffer this problem less than I did."
- jimt1234 2y agoI'm sorry about your daughter. ... I, too, recently lost a close relative to cancer, and yes, understanding and knowing how to navigate everything involved would've helped greatly.
- ygjb 2y ago> Comments on security: This is a huge issue for me. I've followed best practices as nearly as I can, but I've also been asking around to find out who could do a comprehensive security audit, but haven't yet found anybody I trust. Does anybody have any recommendations on how to find someone? The best first step is to conduct a review yourself; you may want to hire or recruit a volunteer to do a security review, but you can kick it off yourself by using free, open source tools to scan your application, your code, and your environment. Your first stop should be https://developer.mozilla.org/en-US/observatory https://developer.mozilla.org/en-US/observatory because there are some simple, prescriptive improvements you can make. Your second stop should be using a container or cloud security scanning tool to check for vulnerable configurations and packages. There are a myriad of tools available, like Trivy for container scanning, Prowler https://github.com/prowler-cloud/prowler https://github.com/prowler-cloud/prowler or ScoutSuite https://github.com/nccgroup/ScoutSuite https://github.com/nccgroup/ScoutSuite for scanning your cloud environments, etc Your third stop should be https://www.zaproxy.org/ https://www.zaproxy.org/, which is a free download you can use, and https://www.zaproxy.org/getting-started/ https://www.zaproxy.org/getting-started/ is a great way to get started. This will help you quickly identify low hanging fruit that can be found through automated scanning. Your fourth stop should be running language appropriate static analysis tools against your application. There are too many to mention, but here is a good starting list: https://owasp.org/www-community/Source_Code_Analysis_Tools https://owasp.org/www-community/Source_Code_Analysis_Tools All of these will give you quick, tactical things you can address. Once you get through any critical findings (which frequently, but not always means they are directly exploitable without additional effort) you should threat model your application, and build a plan for security - https://owasp.org/www-community/Threat_Modeling https://owasp.org/www-community/Threat_Modeling
- harvey9 2y agoPutting aside all the legal issues, I would like to see more details of what it does before I sign up. Seems like you need to register yourself and then get all your family/carers to register and then link their accounts to yours? There should be some screen shots of the app in action (with dummy data of course). Shame this is such a legal minefield. I do not think you should put this on GA.
- bhpreece 2y ago> screenshots High on my list. Or youtube, or something like that.
- Terretta 2y agoEDIT: Developer included this in a summary: "Comments on HIPAA: I'm 99% sure this does not apply, since the site is for patients and their families, and no doctors, clinics, hospitals, or insurance companies are involved. All information comes from the family, and stays in the family." Insofar as no providers or non-family use this, developer may have a point: my comment's covered-entity reasoning can be disregarded. --- Not saying don't do YouTube, there's a persona who wants to learn from being talked to and shown. But there's a less online (socially noisy) persona who prefers to read, see, and take in information far faster than a video. So don't skip the screenshots! PS. I participated in the first patient centered groupware app 15 years ago, sold to the provider networks, so all providers a patient is ping-ponged to can interact as if a virtual team with the patient. Your idea is viable, and giant hospital networks will buy it. But the top comment on this thread is likely dead right. You likely need to be HIPAA compliant for the providers to participate, regardless whether you sold the app to the patient or to the providers. Because unlike a personal notes app, your entire premise is info sharing among parties. There is possibly a model for this that is technically outside HIPAA, but what you're showing / saying doesn't sound like it's navigated that. Even if you use that potentially compliant model, it's then highly unlikely the providers will play ball, as then they'd have to be running as many apps as they have patients and they are too busy and already have to know too many systems. Even if they felt like setting a precedent of installing whatever apps patients ask them to use (they don't), the last thing they want is yet another place to redundantly key in information/communications. (They are required to have a record.) To get around that, you'd have to integrate with what they have, and boom, HIPAA again.
- thecosas 2y agoSome feedback: * More screenshots/use cases. * Information about who you are/why it's called Kate's App. I think that especially for single/small dev teams, this can really help build trust and interest. * Said elsewhere, but a publicly available privacy policy. Also not seeing any after signing up. Big red flag. * IMO, don't have usernames AND emails at sign up. Choose one. * Needs padding on either side. Other formatting issues too, but that was the most glaring one.
- bhpreece 2y agoThank you. They're all in my kanban now.
- 1vuio0pswjnm7 2y agohttps://www.ftc.gov/business-guidance/resources/mobile-health-apps-interactive-tool https://www.ftc.gov/business-guidance/resources/mobile-healt...
- bhpreece 2y agoI wasn't aware of that site. Thank you.
- deleted 2y ago[deleted]
- globular-toast 2y agoWho is Kate?
- netdevphoenix 2y agoI would guess it is OP's deceased daughter
- bagels 2y agoConfused: Who uses this, the patient or the medical staff (nurses and doctors, etc.)? "Organize your support team for your health care." "Kate's App is a tool created to support medical caregivers"
- joseda-hg 2y agoBased on a quick glance, neither, a Caretaker uses it for someone under their care,
- andrewstuart 2y ago>> You data will not be sold, shared, or given away. Your medical data is the most private data you have, and we respect that. Unfortunately the bad actors have destroyed trust so much that I don't trust anyone no matter the words nor how authentic you sound.
- netsharc 2y agoIt's hard to give trust when there's not a single mention on that site of who "we" are...
- scripturial 2y agoHow do you know your app is legal to distribute in each country you are distributing in? Anything with the word “medical” in it can be a potential legal mess due to well intentioned but ultimately difficult to manage issues. If you can’t answer that question you really need to listen to the people telling you to take it down until you can work it out.
- netdevphoenix 2y agoThis is a lovely idea. Very HN like in the good sense. Sadly, it is also vert HN like in the not so good sense. Unlike the software world, the real world is not ours to program as we see fit. In the real world, laws matter. And I am concerned that you haven't really read upon the consequences of doing an app like yours without any due diligence. You can't just use people's health data like that. Anyone using this app could potentially sue you as you are likely breaking the law of the country you live in (I am going to guess it is an Anglo-Saxon country). You should asap bring the app down, contact all users, send them their info, delete them from your servers, notifying them of that and get a lawyer specialising in health related law. With their assistance, you can build an organisation to build the app. This should also limit your liability.
- Over2Chars 2y agoI am not sure that if you choose to freely share your medical information with people of your choice, it's protected or governed by HIPAA or protected PII, per se. For example, I believe Brooke Shields told the world she had post-partum depression and was prescribed some anti-depressant and felt it helped her. https://www.webmd.com/depression/postpartum-depression/features/brooke-shields-depression-struggle https://www.webmd.com/depression/postpartum-depression/featu... That's "medical information" about "a prescription". She could have, instead, shuffled it into some rando app, and shared it with her family. I don't think any HIPAA laws were broken. Of course, US laws https://www.hhs.gov/hipaa/for-professionals/faq/190/who-must-comply-with-hipaa-privacy-standards/index.html https://www.hhs.gov/hipaa/for-professionals/faq/190/who-must... The above doesn't describe anything about private parties. If this "Kate" is some rando app developer, they can do whatever they like. Anyone who is willing to trust a random developer with their information can do so afaict. IANAL and YMMV etc.
- Terretta 2y agoEDIT: Developer included this in a summary: "Comments on HIPAA: I'm 99% sure this does not apply, since the site is for patients and their families, and no doctors, clinics, hospitals, or insurance companies are involved. All information comes from the family, and stays in the family." Insofar as no providers or non-family use this, developer may have a point: my comment's covered-entity reasoning can be disregarded. --- > Anyone who is willing to trust a random developer with their information can do so afaict. No, not "anyone" in a multi-party app when "someone" is regulated. This reasoning (a patient can choose to disclose) doesn't apply here, as the app expects providers to info-share new info, ongoing. The providers are regulated, they have to keep records, and their sides of their tools have to be covered. That said, even some U.S. national insurance companies bury a clause in their agreement where, to your point, the patient agrees to sort of declassify their info such that it's (the insurer company's theory goes) no longer considered HIPAA and the insurance company can go bananas with it (e.g., sell it to drug companies). I had lawyers look into this on behalf of our firm benefits, and we challenged that clause. The national insurance company everyone has heard of instantly gave us a new employee insurance agreement without that clause, which suggests to me they knew it was dicey. (Imagine pinging Google and them dropping a clause from their TOS "just for you". That would only happen if they knew it didn't have legs.) But, dicey or not, it suggests a path to try if you want to attempt this!
- Bengalilol 2y agoIs this app for US people only? Do you know that all big companies are breaking their knees on that special subject of privacy and medicine? It is hosted by: HOSTINGER US Organization name: Hostinger International Ltd. IP address: redacted AS(autonomous system) number and organization: AS47583 Hostinger International Limited AS name: AS-HOSTINGER Reverse DNS of the IP: katesapp.org City: Phoenix Country: United States
- getwiththeprog 2y agoGreat idea, keep up the good work. Would be nice to have a calender (weekly? monthly?) on landing page after log in to see what to prepare for the week.
- rabidonrails 2y agoI think the fear-mongering here has spiraled out of control. This app seems to be a place that patients (and their caregivers read:family) can upload and share data amongst themselves. While you might not fall directly under HIPAA laws (as I don't think you a covered entity nor a Business Associate) you definitely are aware that you will have PHI and thus you have to protect it - especially if you're saying that it's "Private" and "Secure." I'd focus on making sure that all data is encrypted in transit and at rest and that all systems on your side are locked down. You and anybody that might have access to your database shouldn't have free access this data. I'd read through some of the HIPAA guidelines especially from the business associate side and conform to those. Don't be scared by everyone here. Read up on the HIPAA guidelines, check out HITRUST, never take your eye off security. Keep getting better. If you're worried, you can always consult a lawyer or even an auditor for some advice (I'm neither).
- Bjartr 2y agoI don't read others' warnings as fear mongering. Rather, they are genuinely offering concrete steps to be taken to avoid problems that frequently arise in this domain. "Go talk to a lawyer" is not an attempt to scare or some impossible abstract advice. It's a very concrete, and very reasonable step that really ought to be taken early on in this effort. Maybe everyone here is off base. How might the app developer determine this? By talking to a lawyer.
- rabidonrails 2y agoMaybe fear mongering is overstating but... Speaking to a lawyer is not the first step when building something in this domain (unless you already have someone bankrolling you). In this case there's an app that this guy built for families to use. It's obviously in it's infancy. The helpful advice here would be about posting that this is in beta or maybe reading the HIPAA guidelines and ensuring that he's adhering to those guidelines where applicable. Focus on tightening up security. What's his plan to ensure that data in encrypted in transit and at rest? What kind of monitoring will the app have? Does he need to be thinking about intrusion detection? Will he need to enforce 2FA? Does he need to stop everything and start speaking to lawyers? Probably not.
- dailydetour123 2y agoI like the principle of making information easier to share and more accessible for those who need it. However, from the perspective of someone who uses WhatsApp a lot, I think a decent chunk of this info could be shared in a WhatsApp group that includes relevant stakeholders - assuming there is a way to include the medical professional’s input. I would imagine in Europe that is how people might already be solving this problem. I think additionally it is generally an uphill battle to get people to adopt and incorporate another messaging/comms platform into their day-to-day life. It doesn’t mean it’s not important or right what you’ve built, just that in my experience people resist (and ultimately don’t use) additional platforms for messaging/sharing info outside the ones they might already have.
- dmd 2y agoSpeaking as someone who works in IT in healthcare - you need to close your site down immediately, do not pass Go, etc., and hire a lawyer. You are opening yourself up to practically unlimited liability.
- globular-toast 2y agoAll this legal bullshit could have been avoided if this was a program for people to run on their own computers. Why oh why is this being run as a service?
- bhpreece 2y agoThe main point is to share information. You and your father and your sister are all taking care of your mother with alzheimers. What was the geriatrist's phone number again? As another commenter commented, this would be a good candidate for a local-first app. I'd love to do that at some point.
- 383toast 2y agoTelltale signs of application immaturity like using ids as urls https://katesapp.org/patients/41 https://katesapp.org/patients/41
- gooosle 2y agoWhat's wrong with that?
- mdaniel 2y agohttps://portswigger.net/web-security/access-control/idor https://portswigger.net/web-security/access-control/idor It's not, by itself, deadly but it does lower the safeguards against ACL slip-ups, which could easily exfiltrate the entire customer base
- gooosle 2y agoWhat safeguards? Obfuscating your IDs by... replacing them with one-to-one mapped other IDs?
- mdaniel 2y agoI believe one can readily agree that https://example.com/profiles/gooosle https://example.com/profiles/gooosle and https://example.com/profiles/mdaniel https://example.com/profiles/mdaniel are not sequential and thus not subject to enumeration in any reasonable way. A concrete example of defense against this is: please link to the HN username of an account which has never posted The other very common pattern is https://example.com/profiles/852c1a9a-29ae-4638-9d82-50e0d405840f https://example.com/profiles/852c1a9a-29ae-4638-9d82-50e0d40... or its b36 encoding which are shitty for reading over the phone but otherwise definitely safe from enumeration
- gooosle 2y agoFirst of all exposing IDs and having non-enumerable IDs are completely different things. Second, HN usernames are 100% enumerable. 'asdfgf' is an example of account which has never posted.
- hk1337 2y agoI wouldn't worry too much about what a lot of the comments are saying. I would heed some of the advice about being secure but I wouldn't worry too much about it being a problem or shutting down the app until you have it worked out. I don't want to discourage you because it's always good to have multiple options but I would look at what Cariloop (https://cariloop.com https://cariloop.com) is doing, try and focus it like that but with unique aspect you have they do not. This is only the second caregiving app/service that I have seen.
- bhpreece 2y agoIt looks like Cariloop advises people on how to find medical assistance, is that correct? Is there someplace to get more specific information?
- hk1337 2y agoMy understanding is that it keeps everyone connected. Like, you as a family member may be a caregiver or you may have a nurse or someone else as a caregiver and it can help keep family, caregiver, the person being cared for all in the know on what is happening.
- securingsincity 2y agoVery cool to see Cariloop mentioned here in this conversation. I'm the VP of Engineering at Cariloop. We offer Caregiver support and coaching through our coaches who are nurses and social workers. So one thing they can do is find help for services but they can do a lot in navigating a difficult caregiver situation. Additionally, we do offer medication tracking and other digital caregiving tools. I will also mention like others here, it is important to have things like HIPAA best practices in place for services like this. At Cariloop for example we follow HIPAA best practices, GDPR compliance, and are SOC 2 certified.
- bhpreece 2y agoThank you. I appreciate you taking the time to clarify.
- ciabattabread 2y ago"Simple" "Safe" "Private": Marketing buzzwords without any proof or a reputation. No idea who this person is. Could be some 15 year old scammer in Florida. Could be a billionaire heir in London. No contact information. The domain registration is hidden. What is this "product" solving that is not much different from a shared Google Doc?
- barbazoo 2y agoCould this be used as a community “social network” where seniors or people with disabilities can reach out for specific asks like getting driven to a doctors office or getting a prescription picked up, etc.
- bhpreece 2y agoI'm sorry, no. Access to information is strictly limited only to specific individuals who must be explicitly granted access.
- tlhunter 2y agoNot to be confused with the Kate app (KDE text editor).
- robertlagrant 2y ago> You control who can view your records Is this true? Is the data stored encrypted (or not stored at all in servers)? Or can a sysadmin see it?
- wonder_er 2y agoI feel like at minimum, the information should all be stored in encrypted, unavailable-to-an-admin way. https://guides.rubyonrails.org/active_record_encryption.html https://guides.rubyonrails.org/active_record_encryption.html Basically, all the data in the app would be hidden to everyone except the users. I'm assuming this would be the case, and I'm assuming that you, with prod db access, wouldn't be able to directly read the text that is being written. If that were the case, I'd say your ethical obligation is fulfilled, more or less. (obv implementing application-level 'everything is encrypted' is not trivial, but it makes it so that you couldn't ever see what was being said) I don't believe in political authority, so when people say "But hipaa!" I hear "but I believe in the institution of authority" and I sorta tune out everything else that they say. There's a LOT of people in the world who believe in authority/political authority, and it is tiring. sorry for us all. This app is cool! Well done to you. Hope you don't have to spend thousands on lawyers and don't have to deal with coercive institutions based on the fantasy of political authority.
- Dig1t 2y agoIf you got to https://katesapp.org/static/What%20Is%20Kate's%20App.html https://katesapp.org/static/What%20Is%20Kate's%20App.html and click the "Kate's App" button at the very top of the page, it takes you to a 404. Just FYI if you want to fix that.
- bhpreece 2y agoAlready noted by another user. Thank you.
- Dig1t 2y agoDoes this support FHIR? If not have you considered supporting it? Many health care providers offer export of health records to FHIR format now. You can also retrieve those records on iOS via the HealthKit API. Apple lets you log into your health care provider in the Health app and download all your records from supported providers. You can request access to those records from another app installed on your phone.
- bhpreece 2y agoI have not thought about into this, but I'll need to look into the possibility. This could be a useful feature for an eventual version. Thanks for the idea.
- sineausr931 2y agoArthur Howell, is this you? https://www.linkedin.com/posts/arthur-howell_im-excited-to-share-our-latest-blog-post-activity-7283174075554791425-p_LL/ https://www.linkedin.com/posts/arthur-howell_im-excited-to-s...
- bhpreece 2y agoArthur Howell is not me, and I have no connection with him.
- bhpreece 2y agoThank you again everyone for your comments. Some of them have been helpful. Tomorrow I will take down the HN front page. Your accounts will remain in case you still want to check things out. You can also delete your accounts yourself, or ask to have them deleted. If you want, you will still be able to create a new account from the default main page https://katesapp.org https://katesapp.org. You will need to ask for an access code, but I'm happy to provide one. Edit: Sorry, the option to delete your account has not been uploaded to the server yet. However, email me at the address in my HN account, or contact me through the app, and I'm still happy to delete your account for you if you want. Again, thank you everyone.
- jxaphx 2y agoIANAL and this advice is only applicable to US/HIPAA rules based on my experience building and consulting in this space. HIPAA rules apply to covered entities, and the developer of this app does not appear to be a covered entity. If a covered entity used this service, THEY would be required to enter into a Business Associate Agreement (BAA) with the developer, at which point the developer is on the hook and HIPAA applies. If a covered entity engages with a platform like this, without a BAA, the liability under HIPAA is borne by the Covered Entity whom the rules apply to. That said - if you want to engage with covered entities (and I think that should be a goal) you'll need to have all your ducks in a row before they'll be interested. It's all doable though, dont let the gatekeepers push you out. One thing I've got my eye on right now is Palantir's HealthStart initiative that seeks to streamline the compliance requirements needed to operate in this space legally. Might be worth following if you plan to take this anywhere beyond a hobby. Last note - my statement here is only about HIPAA. There are any number of state and federal level privacy rules where liability may or may not come into play here. Have a privacy policy, follow it, protect other people's data.If you're not confident you know how to do that, find someone who is. We do have a responsibility to our users that goes well beyond our desire to learn and experiment. Good luck!
- bhpreece 2y agoI wasn't aware of HealthStart. Thank you for point it out.
- evolve2k 2y agoThe link is currently returning an Error
- fasten 2y agohow are you ensuring data privacy and security? excited to see it go GA