TrueVault does more and costs less than AWS. We also save you hundreds of dev hours.
The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of protected health information (PHI).
AWS will sign a BAA, but they only cover the Physical Safeguards (e.g. facility access controls, etc.). TrueVault handles both the Technical and Physical Safeguards.
With AWS you still need to build your own HIPAA compliant application stack. The technical requirements include:
-encryption and decryption
-key management
-key rotation
-access control
-unique user identification
-emergency access
-automatic logoff
-audit controls
-mechanism to authenticate electronic PHI
-person or entity authentication
-transmission security
-integrity controls
I've been working on a mobile application for doctors and healthcare teams the past few months. We are a startup and will be going into beta testing with real users near the end of Q1.
I was interested in your last post on HN, as I've found it nearly impossible to sift through the bureaucratic cruft of HIPAA, HITECH, HL7, and all the other standards. A blog post on the topic would be amazing -- "What does HIPAA-compliant mean?".
The main fear I have about using your service is trusting a brand-new company for hosting. What reassurances can you provide that relying on you for my infrastructure will not screw me over if something happens to your company?
If you read deeper into HIPAA and AWS, you'll find it really isn't. It's possible to create mostly-HIPAA-compliant infrastructures using AWS but that's a lot of work and you still don't have a lot of information that HIPAA often requests, like datacenter and server access logs.
jameskilton is correct. AWS and Firehost give you a "HIPAA Compliant-Ready" environment (Firehost's own marketing line). It's ready for you to implement your own encryption cluster, key management and rotation system, network security, software security, etc.
Comments
AWS is also HIPPA compliant.
http://aws.amazon.com/compliance/
TrueVault does more and costs less than AWS. We also save you hundreds of dev hours.
The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of protected health information (PHI).
AWS will sign a BAA, but they only cover the Physical Safeguards (e.g. facility access controls, etc.). TrueVault handles both the Technical and Physical Safeguards.
With AWS you still need to build your own HIPAA compliant application stack. The technical requirements include: -encryption and decryption -key management -key rotation -access control -unique user identification -emergency access -automatic logoff -audit controls -mechanism to authenticate electronic PHI -person or entity authentication -transmission security -integrity controls
I've been working on a mobile application for doctors and healthcare teams the past few months. We are a startup and will be going into beta testing with real users near the end of Q1.
I was interested in your last post on HN, as I've found it nearly impossible to sift through the bureaucratic cruft of HIPAA, HITECH, HL7, and all the other standards. A blog post on the topic would be amazing -- "What does HIPAA-compliant mean?".
The main fear I have about using your service is trusting a brand-new company for hosting. What reassurances can you provide that relying on you for my infrastructure will not screw me over if something happens to your company?
Hey vonseel - we are reaching out to you via email. We can share with you a few details about TrueVault that'll surely give you confidence.
If you read deeper into HIPAA and AWS, you'll find it really isn't. It's possible to create mostly-HIPAA-compliant infrastructures using AWS but that's a lot of work and you still don't have a lot of information that HIPAA often requests, like datacenter and server access logs.
jameskilton is correct. AWS and Firehost give you a "HIPAA Compliant-Ready" environment (Firehost's own marketing line). It's ready for you to implement your own encryption cluster, key management and rotation system, network security, software security, etc.