5 ms·
how can you even consider launching a service like this without being fully audited for HIPPA and ISO 27001. all i see on their site is boiler plate sec that in
by rdxm 12y ago
how can you even consider launching a service like this without being fully audited for HIPPA and ISO 27001. all i see on their site is boiler plate sec that in no way addresses the reality of the business domain they want to operate in.
you'd be insane to put your data into something like this without those controls in place. moreover, they are asking for serious regulatory trouble launching without it.
this one business challenge that will not be solved in the valley. this problem will eventually be solved by the large industry players in insurance and hospital management in a model similar to that of the DTCC..
- angersock 12y agoYou sound like a shill for Epic. This business challenge is only going to be solved by startups, because all of the existing players rely on it being such a fucked system. They're not going to fix anything.
- Pacabel 12y agoThis is absurd. So rdxm is a "shill" merely because he or she pointed out some very real and important issues surrounding this sort of technology, and then also pointed out the fact that established players are best prepared to handle such challenges? Huh? If you're going to make such accusations, or even just hint at them, please provide us with at least some real evidence to show that rdxm is being directly compensated by one or more of the industry incumbents for posting that comment. Since I doubt very much that you can provide that evidence, I think it would be appropriate for you to apologize to rdxm and to the rest of the community here.
- angersock 12y agoEh, I'd expect somebody shilling for Epic or any of the other major vendors to sound the same way--which is exactly what I said, no more no less. I'm not going to apologize. The problem with bandying about "HIPPA [sic]" and random ISO security standards is that it only serves to dampen enthusiasm for fixing the staggeringly pervasive issues of mismanagement and technological obsolescence. Anybody can come up with a "no" or a problem--"but but but HIPAAaaaaa" is a common refrain from people who want to sound like they know something but who lack the talent or skill to fix the fucking thing.
- markolschesky 12y agoI used to work at Epic. I don't think that we had shills. I think we had more farmers employed than marketing staff when I was there, honestly. All jokes aside, I think the passing of the ACA has changed things drastically. With insurance companies no longer able to make more money by charging more money/denying coverage to the sick, they are slowly becoming more active on coming up with ways to be innovative on making patient care more streamlined and affordable. Sometimes they'll work with startups (Aetna CarePass comes to mind), and they definitely should. But, sometimes they'll go it alone as well. It's exciting to see it all play out right now in the industry.
- apu 12y agoProtip: accusing someone of sounding like a shill rarely leads to productive discussion.
- thetylerhayes 12y agoHey I don't work at Picnic but I do work at Prime. Picnic and Prime do similar things. I've met the Picnic team. They're great, and so is Picnic. They understand HIPAA. I'll let @nogaleviner speak to the specifics of their HIPAA considerations but I do want to clear up some general things up about HIPAA since we've (as has Picnic) been working on this for a year or two now. 1. It's HIPAA, not HIPPA. 2. The "P" in HIPAA stands for Portability (h/t @katgleason). The salient parts of HIPAA for this conversation are: a. HIPAA makes what Picnic does possible. The overall point of HIPAA is to open up data, to let patients say to their doctor "I want my medical record" and require doctors to fulfill that request. The September 2013 update to HIPAA even said that if a patient asks for their records electronically, their doctor has to provide them electronically. Without HIPAA, Picnic probably wouldn't exist. b. HIPAA does stipulate two Rules: the Security Rule and the Privacy Rule. In a nutshell, these rules don't prescribe specific implementations but do require general considerations. The high-level overview is: data has to be encrypted in transit and at rest, all data access has to be logged (for auditing), and employees have to be HIPAA-trained. Generally speaking if you build something that meets a decently high level of conventional web security standards, you could probably meet the technical requirements for HIPAA. Now this is important: while b) is true, this actually only applies to entities who are required to be HIPAA-compliant, i.e., medical care providers. Technically Picnic isn't a care provider and therefore does not need to be HIPAA-compliant. That doesn't mean Picnic doesn't take security and privacy very seriously. And I can tell you they do: their site is SSL-enabled and they know what they're doing. Again, just speaking to the HIPAA points here, not the business considerations. Hope that helps clear some things up.
- nogaleviner 12y agoThanks, Tyler. We'll said.
- dr_ 12y agoAlthough they may not technically have to be HIPAA compliant, they certainly have to allow some of their clients - specifically medical providers - maintain HIPAA compliance. In general, with respect any health tech startup that stores or transmits personal health information, if you try to tell a client that you don't technically have to be HIPAA compliant, it's gonna raise red flags. Assuming you are following the appropriate HIPAA rules, it's best to just say you are HIPAA compliant.