17 ms·
Love that you guys are addressing more than just the security rule - we found the technical parts of HIPAA the simplest to address. Are you planning on having e
by timjschwartz 12y ago
Love that you guys are addressing more than just the security rule - we found the technical parts of HIPAA the simplest to address. Are you planning on having employee training modules and customizable policies and procedures? How do you help guide companies through the Privacy components?
- laurenstill 12y agoThis is what I'm most curious about. The technical/security side is only 1/3 of HIPAA, how do you turnkey the remainder? How do you scale/automate preforming repeat RAs, etc, across different clients?
- chasb 12y agoWe are constantly improving how much we automate, but the major goal is to make sure that if manual work needs to be done, Aptible is doing it, not our customers. Preparing training materials is a good example. Each of our customers get three types of training: basic HIPAA privacy and security training for everyone; developer training, specific to their stack; and security officer training. We customize that training. We may modularize it later, but only if we can maintain the quality and experience. We spend as much time with each customer as they want, but we don't bill for support and we don't bill for consulting. At first it seems higher-priced than some options, but there are no hidden costs.
- chasb 12y agoYes, we agree. Most of what turns HIPAA compliance into a murky time-suck is in the administrative requirements and documentation. We'll have a separate page on the site explaining this next week, but we break compliance management down into 5 main areas: - Risk Assessment - Policies and Procedures - Training - Ops - Incident Response Conceptually, they form a cycle. Each area feeds the next, with ops/incident response feeding back into risk analysis. We have a suite of tools to help with each stage of the cycle. Each step requires a different mix of: 1. Automation 2. Manual work on our part, and 3. Manual work by our customers Our overall goal is to drastically reduce #3 while helping our customers run amazing compliance programs that reduce risk and give everyone involved (devs, management, their customers, federal regulators) insight into what is going on inside their organization.
- timjschwartz 12y agoThanks for the update - look forward to seeing what you roll out. One interesting feature to add at some point would be helping companies incorporate their BAA into their user agreement (this is how Practice Fusion does it - http://www.practicefusion.com/pages/user-agreement.html http://www.practicefusion.com/pages/user-agreement.html).