Hacker News new | ask | show | jobs
by masonhensley 2102 days ago
My experience - primarily in healthcare data as a vendor... Employers & Insurance.

Client security teams have been very reasonable on deviations to their massive spreadsheet checklists.

On one hand, I think that if you, as a vendor, reply back with a few "well, we do X instead of Y in the same spirit" they will probably believe & trust your answers more than a spreadsheet returned in 2 hours with "yes/in compliance" for each question.