HN user

kgosser

143 karma

www.harqen.com

Posts10
Comments80
View on HN

Educating the startup community on the complexities and necessity of HIPAA is important. I'm glad Aptible is helping the YC community.

To tack on to my colleague at Catalyze: We provide two thorough guides to both HIPAA and HITRUST. If anyone is looking for a deep dive on either topic, you can access the guides here:

https://catalyze.io/hipaa-compliance

https://catalyze.io/hitrust

The guides are a thorough summary and aggregation of all our content spread throughout the web, which is why they are behind a form. If you would like to access all the content directly, it's largely all available for free as separate entries in our Academy:

https://catalyze.io/learn

You are correct in understanding there is a bifurcation between the infrastructure and application levels. You, as the software developer, will be largely responsible for the application-level security and privacy. The infrastructure obligations are extremely complex and go much deeper than you might imagine upon first blush.

For the ease of math, let's say at the infrastructure level it takes "10" things be HIPAA compliant. An IaaS vendor like AWS will do about 1/10th of it, and do it very well. Mostly the firewall and physical safeguards. They do sign a BAA and claim to be HIPAA Compliant, but you need to keep in mind that it's only for a fraction of what you're ultimately responsible for. The other 9/10ths is nontrivial. It includes things like encryption, monitoring, vulnerability scanning, breach policies, how you handle your logs. Lots of things.

The difference between hosting on AWS vs. hosting on Heroku will be how many of those 9/10ths Heroku will automate for you, and then—here's the kicker—that they agree to in their Business Association Agreement with you. Even if they do the other 9/10ths, if they won't sign a BAA with you, then you're still at risk.

In essence AWS is an IaaS vendor who will sign a BAA that does a few compliant things, but you still have a long long journey ahead of you. You could build your own, certainly, on either AWS or Heroku. You could also look for a HIPAA Compliant Platform as a Service (PaaS) who automates the other 9/10ths and then signs a BAA for those things. The company I work for, Catalyze, is just that. We basically are the other 9/10ths on top of AWS, sign a BAA for it, and stand behind you with a HITRUST Certification.

The guide we wrote up on HIPAA Compliance might be of use to you: https://catalyze.io/hipaa-compliance. Also, our Academy entries might be helpful to understand the complexities: https://catalyze.io/learn.

For some super nerdy technical explanations, take a look at how Catalyze approaches the other "9/10ths" here: https://hipaa.catalyze.io

Speaking from a HIPAA point of view, the amount of complexity you must manage to build your own compliant environment on AWS is extremely high. HIPAA's controls account for block level encryption, managing your logs a certain way, and many many more things.

Furthermore, compliance is more than just doing the right thing. It's proving that you are compliant. There is immeasurable value with selecting a vendor who is audited to be HIPAA Compliant or HITRUST Certified because then the risk is offloaded to someone with credibility in the marketplace via a Business Associate Agreement. If you wanted to build your own HIPAA compliant stack on AWS, and you want to be taken as credible when trying to sell to a CIO at a hospital, then you will need to go through the procedure of becoming HITRUST Certified as well.

Otherwise you will just be nibbling at the edges and taking on all the risk while hampering your business model.

This means for people who work remotely but live in Seattle. So for example, someone who works remotely for a company in NY but lives in Seattle. This would be a spot for all those people to work so they feel like a community.

In 2013 the Internet traffic I actually do generate is much more secure than the Internet traffic I generated 20 years ago.

For someone to be successful in 1993 to use the Internet, you had to be knowledgable enough to do the things you're talking about. I'd wager roughly 97%+ of the population is not smart enough, which is why Bruce's statements are in effect true.

Tell me again how this is different than Malcolm Gladwell? Same format, same insight-porn result, yet this guy is heralded by you all and Gladwell is eviscerated. Confusing, really.

Two.js 13 years ago

Ah cool. Yeah, I instantly thought of use cases like Forecast.io's weather animations for your library. I think this is a _major_ trend about to explode, and approaching it with a JS library instead of animated GIFs seems like it has big potential.

Check out www.forecast.io to see the UI polish I'm talking about.

Two.js 13 years ago

Was forcast.io's animations an inspiration for this?

Very impressed. Great job!

Betaworks.com getting hammered right now. I hope they are better at managing Instapaper ops!

I tease, I tease. In all seriousness, congrats to Marco. A real hero of The Internet.

Contrast is the root of attention.

Anything can be used to contrast. They chose a picture of a laptop. It's not your standard MacBook Air on a Crate & Barrel table a la ÜberConference.

I think it was smart.

Also, side note: I think it's interesting that we have shifted to default choice as Mac in these images. If you don't show a Mac product, then you're not pumping your brand the right way. That's an interesting observation.

I think a worthy discussion question is:

Are rounded corners a bad thing, and not a part of the "flat design" movement?

My 2¢: I'm not sure they are a bad thing. I think you can still have a flat design and use rounded corners. Frankly, I dislike when buttons are flat _and_ right-angled because too much affordance is lost.

Max Lynch and Ben Sperry are super talented. They are also getting really good at marketing! Great copywriting!