Hacker News new | ask | show | jobs
by viraptor 3783 days ago
Why are you sure there was a HIPAA violation? HIPAA includes disaster recovery plan, which is what they should be doing now.

I guess it wasn't a great plan if it's a week in and they're still dealing with it, but still...

1 comments

Well, there are plenty provisions under the security chapter, funnily enough now that I look at it again (been long time) it seems both 'accountability' (tracking every media in and out) and 'protection from malicious software' are not listed as required. duh.

The emergency mode operation plan is however listed as required, and this place was basically shut for a week.

I remembered it being more stringent that what it really is.

Yes, I'd love for HIPAA to say: if we're talking about a medical centre, you've got to be able to snapshot and reimage within X hours with data loss of less than Y hours. One can dream...
Part of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow.

Another standard may be needed for the larger businesses.

Totally agree, but in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery. Regularly operate in each datacenter and you have Sustained Resiliency. A small business probably won't have staff to maintain such a solution but surely this is a space for a nice niche startup?
> in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery

Things that look simple on the surface are often not easy to implement in practice - especially when you're not starting with a green field.

Why am I not starting with a greenfield? In my example I did mention a niche start up.
That won't work you'd need the whole datacwnter to comply with the security restriction you can't just have the data in a place where you don't know whom can access
That's not true actually. You can be HIPAA compliant while storing data on AWS. https://aws.amazon.com/compliance/hipaa-compliance/
Part of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow.

We're at the point where some company could sell a comprehensive software package for small practices that includes disaster recovery.