Hacker News new | ask | show | jobs
by codingdave 90 days ago
How difficult was it to get HIPAA compliant in order to ask for health info from consumers?
1 comments

Good question. HIPAA applies to covered entities (insurers, hospitals) and their business associates. We're neither - users are entering their information anonymously to do plan comparison. That said, we treat the data very carefully - we don't sell it, don't share it, and enrollment (where PII is collected) is on Healthcare.gov.