|
|
|
|
|
by freshpots
1196 days ago
|
|
From their main page (https://www.nabla.com/), the mention HIPAA: Secure and HIPAA-eligible Audio, transcripts, and notes are not stored by Nabla
HIPAA-eligible and GDPR compliant
SOC 2 and ISO 27001 certifications in progress
Digging deeper (https://www.nabla.com/blog/privacy-security/):This data processing is done on Nabla's servers, which are powered by the HIPAA and GDPR compliant Google Cloud Platform (GCP), and on HIPAA-eligible LLM servers. |
|
EDIT:
I was very curious about this and did a bit of research. The answer to it is squishy. It seems to be mostly a marketing term. The best definition I found was this:
"A service that is HIPAA eligible is one that is capable of being configured in a way that could meet HIPAA compliance requirements, but you have to know how to do it, it doesn’t happen ‘out of the box.’"
https://www.cleardata.com/articles/hipaa-eligible-hipaa-comp...
So it sounds great but doesn't actually mean that much.