3 ms·
Yes, we agree. Most of what turns HIPAA compliance into a murky time-suck is in the administrative requirements and documentation. We'll have a separate page o
by chasb 12y ago
Yes, we agree. Most of what turns HIPAA compliance into a murky time-suck is in the administrative requirements and documentation.
We'll have a separate page on the site explaining this next week, but we break compliance management down into 5 main areas:
- Risk Assessment
- Policies and Procedures
- Training
- Ops
- Incident Response
Conceptually, they form a cycle. Each area feeds the next, with ops/incident response feeding back into risk analysis.
We have a suite of tools to help with each stage of the cycle. Each step requires a different mix of:
1. Automation
2. Manual work on our part, and
3. Manual work by our customers
Our overall goal is to drastically reduce #3 while helping our customers run amazing compliance programs that reduce risk and give everyone involved (devs, management, their customers, federal regulators) insight into what is going on inside their organization.
- timjschwartz 12y agoThanks for the update - look forward to seeing what you roll out. One interesting feature to add at some point would be helping companies incorporate their BAA into their user agreement (this is how Practice Fusion does it - http://www.practicefusion.com/pages/user-agreement.html http://www.practicefusion.com/pages/user-agreement.html).