|
|
|
|
|
by GolfyMcG
3929 days ago
|
|
Would love to get a response to this. We are required to be HIPAA compliant and started out on Heroku. We basically only had a prototype built and didn't have any clients yet, so we didn't really care. After a weeks of paying for Heroku we got a very standard sales call from Heroku. They were checking-in/trying to up-sell us on some stuff. They asked us what we needed, and I responded with, "We need to be HIPAA compliant - what do we need to do to make that happen on Heroku?" The sales rep immediately replied along the lines, "We don't do that." He ended the call shortly after that, clearly uninterested in our money. Since then, we started using Aptible (https://www.aptible.com)and they are AWESOME. The biggest difference for us is that they also provide the legal documentation and advice to working through HIPAA compliance. They're totally willing to go beyond just being a PaaS and really start to blend into a moderate level of legal counsel. Only downside is that their premium service entails a premium price. |
|
Most of HIPPA compliance (from an IT perspective) is having a comprehensive security policy and documenting that you're doing certain activities with the appropriate frequency: risk analysis, security audits, auditing user accounts and privileges, security training for users, etc.
I think the biggest barrier to getting HIPPA compliance on more infrastructure providers is that infrastructure providers are engineering organizations, and HIPAA is mostly a CYA activity for lawyers (plus some easy, obvious OPSEC).