Hacker News new | ask | show | jobs
by number6 604 days ago
Never interested me in HIPAA before - I read the post and I found the last paragraph very cool:

> At present, there’s no certification in relation to HIPAA. The agencies that certify health technology don’t approve software or empower independent certifying authorities to accredit business associates or covered entities with a HIPAA attestation. Therefore, there is no official certification to say that we comply with HIPAA.

So everyone who puts this badge on the page is just doing the best effort thing?

1 comments

Yes, but we did undergo the Microsoft Certification process, which includes independent verification of the effectiveness of our security, privacy, and compliance controls done by Microsoft.