|
|
|
|
|
by jabzd
3579 days ago
|
|
We're in the healthcare space so we have to own our hardware and co-locate. Being a small outfit, sometimes it's so frustrating trying to find the right resources online these days related to racking and configuring your own bare metal! I can definitely appreciate the 6 weeks to 6 seconds. We recently added a new database server because we were really struggling at peak times. The 5 weeks it took between ordering the $25k server, configuring base os, racking it, replicating current data to it, and then choreographing the switch was brutal. Due to the nature of our product, it had to be a zero-downtime switch. Somedays, I wish it was as simple as clicking upgrade instance on AWS RDS. Other days, I make myself feel better by calculating the thousands I'm saving a month. |
|
Vendors will say all manner of things regarding how HIPAA compliance requires you to buy their most expensive services, but the HIPAA legislation and related rules are almost silent with regards to implementation requirements that map to actual technologies you could actually use. "Quote me the subsection of the Security Rule you are referring to; it will look like 164.308(a)(5)(ii)(D)." is dispositive of this sort of thing.
That's a real thing, by the way. The requirement, in its entirety: "Do you have procedures for creating, changing, and safeguarding passwords?" Did you see the point where it requires hashing the passwords? No, you didn't, because HIPAA doesn't require hashing passwords. It requires you to have some method of "safeguarding" passwords written down somewhere.
[Edit: Parent has clarified that they're dealing with standard paperwork at clients rather than the legislation itself, which makes sense (and, also, oww).]