Point taken. Not sure what Oakland has to do with it — we're located across the street from Kaiser Permanente's headquarters of 11,000 people in Oakland — but I think I see where you're coming from. You don't know us. And you deserve the best level of security.
Some more background on us: I worked at Disqus for 3 years. I spent time on the Product team and helped engineer some of their tools too. Owen is a fantastic engineer who spent 4 years at Intel and Oracle before that. We know security, we know scale. We're fully HIPAA-compliant; we even worked with Amazon directly to ensure this. Everything is encrypted and no data is stored on the device.
What could we do differently to put your mind at ease about this? Are there specific technical points you have in mind?
This is a problem that desperately needs to be solved and we're solving it for the people who need it solved most: people who really need their real health records with them right now, whether to show at their next doctor appointment or to family at home or friends on the other side of the country.
Yes, AWS started signing BAAs on June 18th, 2013. FireHost and Rackspace will also sign a BAA.
"AWS enables covered entities and their business associates subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA) to leverage the secure AWS environment to process, maintain, and store protected health information and AWS will be signing business associate agreements with such customers."
Comments
Point taken. Not sure what Oakland has to do with it — we're located across the street from Kaiser Permanente's headquarters of 11,000 people in Oakland — but I think I see where you're coming from. You don't know us. And you deserve the best level of security.
Some more background on us: I worked at Disqus for 3 years. I spent time on the Product team and helped engineer some of their tools too. Owen is a fantastic engineer who spent 4 years at Intel and Oracle before that. We know security, we know scale. We're fully HIPAA-compliant; we even worked with Amazon directly to ensure this. Everything is encrypted and no data is stored on the device.
What could we do differently to put your mind at ease about this? Are there specific technical points you have in mind?
This is a problem that desperately needs to be solved and we're solving it for the people who need it solved most: people who really need their real health records with them right now, whether to show at their next doctor appointment or to family at home or friends on the other side of the country.
Thanks for your thoughts.
I took the liberty of emailing you on the address on your HN profile :)
Did Amazon sign a Business Associate Agreement (BAA)? I know in the past that prevented clients of mine from using AWS in the healthcare space.
Yes, AWS started signing BAAs on June 18th, 2013. FireHost and Rackspace will also sign a BAA.
"AWS enables covered entities and their business associates subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA) to leverage the secure AWS environment to process, maintain, and store protected health information and AWS will be signing business associate agreements with such customers."
http://aws.amazon.com/compliance/