Hacker News new | ask | show | jobs
by _callcc 3158 days ago
> Create a protocol or API spec on top of HTTPS or something else and use it.

This is basically what they've done with EDI/X12 over AS2, which was also mandated by HIPAA. The problem is that EDI is a pain to work with as a data format and hooking up to other trading partners can take weeks of coordination between IT teams (sending "implementation guidelines" back and forth). When EDI is the alternative it's not hard to see how the fax machine survives.