5 ms·
I worked in medical tech for a few years, there are a few reasons people aren't going to flood into that sector. 1.) Regulation, HIPAA is a massive pain to dea
by psaintla 12y ago
I worked in medical tech for a few years, there are a few reasons people aren't going to flood into that sector.
1.) Regulation, HIPAA is a massive pain to deal with, the rules nebulous and require significant process that is expensive and time consuming.
2.) Violations of HIPAA lead to fines and even lawsuits from the office of civil rights. It used to be that Business Associates could hide behind the medical institutions to avoid this but with the Omnibus rules you'll face massive fines that will easily bankrupt any startup.
3.) The entire healthcare sector is extremely risk averse, slow moving and you cannot work around them you have to work with them which means you're going to move slowly too.
4.) You will HAVE to integrate with dozens of other ancient applications that medical institutions use, some of which have no documentation or publicly available source code. I hope you like searching through hundreds of pages of outdated HL7 and X12 documentation to figure out how a specific vendor screwed up their implementation.
5.) Large medtech companies regularly snuff out competition through lobbying and leveraging existing relationships in the medical community. So you've got a killer new medical app that will change the world? Big deal, your competition has three doctors who are leaders in their field(and conveniently board members). They will tell all of their buddies at the next American Cardiology Conference that your app is garbage. I hope you've got some big names associated with your startup and you can pay them handsomely.
6.) The medical field is a data hell. Some of it unstructured and non-sensical, much of it is structured but has no validation. That field you are getting from a third party API for albumin levels which was documented as g/dL, was actually entered in mg/L from the years 06/2004-12/2008, mg/dL from 09/2003-05/2004 and the proper documented g/dL for all other dates. Why was it that way? No one knows. You have to keep track of things like that for one field in one database for a single department in a medical institution with a few dozen departments that don't cooperate. Worst of all, it WILL change on you without you knowing.
- ia 12y agofrom my experience, this is all 100% accurate. medtech is a shit show. however, from another perspective, it's exactly the type of "schlep" that mints millionaires.
- psaintla 12y agoI totally agree, but it's not going to be the kind of quick money making endeavor that attracts people from finance.
- eropple 12y ago> 1.) Regulation, HIPAA is a massive pain to deal with, the rules nebulous and require significant process that is expensive and time consuming. > 2.) Violations of HIPAA lead to fines and even lawsuits from the office of civil rights. It used to be that Business Associates could hide behind the medical institutions to avoid this but with the Omnibus rules you'll face massive fines that will easily bankrupt any startup. I agree with the last two-thirds of your post, but this doesn't match my experience. HIPAA is basically a bunch of "best effort" stuff and you can do shockingly little in terms of security and be fine by any audit I've ever seen. Unencrypted data at rest, encrypted data with keys on disk on the same machine, no SSL anywhere including external endpoints...and the auditors never asked or looked.
- gknoy 12y agoThat sounds dangerously similar to saying, "... you don't have to actually follow the law, because no one checks, and you'll never get caught". Maybe it's my inner pessimism, or maybe I'm channeling Woody Allen, but I'd expect that I would end up being the poster child for What Not To Do were I to run a company that knowingly slacked off on HIPAA.
- eropple 12y agoNo, I'm saying that HIPAA and its related case law are vague enough to make "best effort" a matter of very permissive interpretation. The shitty state of technology and security (I do platform engineering/infrastructural stuff, so this matters to me) in medical startups, even worse than startups in general, is why I don't work for one anymore; I like sleeping at night.
- jskonhovd 12y agoIf you are interested in some studies on HIPAA compliance, I would suggest reading the work by Dr. Annie I. Antón on requirements engineering. http://www4.ncsu.edu/~aianton/ http://www4.ncsu.edu/~aianton/ HIPAA is seriously complex piece of legislation.
- psaintla 12y agoMy experience was vastly different and that's the problem. These aren't guidelines they are laws and you're at the mercy of whoever is investigating you. I'd rather not give too many details but one of the companies I worked for was fined a large amount of money after a security breach that was the fault of the hospital and not our application.