3 ms·
Out of curiosity, how hard is it to become HIPAA compliant?
by Oculus 12y ago
Out of curiosity, how hard is it to become HIPAA compliant?
- chasb 12y agoThat depends on what you mean. Few of the implementation steps are difficult on their own. The difficulty is more in the number of requirements, their complexity, the judgment calls involved, and keeping track of it all.
- rficcaglia 12y agoit is easy to assert you are hipaa compliant, but more work to actually demonstrate. most requirements overlap with PCI (having built both banking and healthcare systems, PCI is much more demanding if still superficial) the hardest part is paperwork and staff procedures the most expensive part, amd i am not sure if this solution addresses this, is every single hospital customer i have insists on a totally independent 3rd part audit. what that entails is totally arbitrary but it costs ~25-50k per year. they would not, for example, take the internal audit of the vendor providng hipaa compliance as sufficient. however, if the vendor also provided an audit by an external party, i suspect that would work be sure this or any other vendor is willing to sign a BAA with you specific to each customer
- rficcaglia 12y agoalso be aware that some state privacy laws (I'm looking at you Texas!) are much more specific than hipaa and Emr/ehr vendors fall into a different kettle of fish for becoming meaningful use certified which is orthogonal to hipaa. i suspect most consumer health apps can ignore that, though
- semerda 12y agoWell said! Just to add a few more points. On the technology side you want to make sure you have data encrypted "at rest" and "in transit". i.e. At rest means things like running AES encrypted drives for your DB data storage. AWS has docs & case studies on this and is HIPAA compliant. Just don't use RDS, it isn't HIPAA compliant yet.