4 ms·
No, you don't have to, but we take security very very seriously. However, we are not a covered entity in the eyes of HIPAA, but we do go above and beyond their
by dmillar 17y ago
No, you don't have to, but we take security very very seriously. However, we are not a covered entity in the eyes of HIPAA, but we do go above and beyond their guidelines for storing and transmitting patient data.
- tricky 17y agoWow, I've been kicking around an idea for a DICOM startup but I fear the HIPAA... Maybe I shouldn't. Thank you for that.
- arohner 17y agoA previous day job of mine was at a company that does DICOM viewing and transmission. They did/do it pre- and post- HIPAA. HIPAA isn't too bad for software vendors. Just keep your records in order, and follow basic software engineering & security practices. They like to see documentation, especially design docs and test plans. The FDA comes out every year or two, and of course they keep digging until they find something to ding you on, just so the inspector looks like they're doing their job. EDIT: I now realize I was conflating FDA certification and HIPAA, though you'll probably have to deal with both while doing DICOM.