Our customers are typically deciding between using TrueVault or a HIPAA compliant hosting provider. The customer is facing a build vs. buy decision.
The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of protected health information (PHI). AWS, FireHost, and Rackspace are great! But, HIPAA compliant hosting providers like these only provide a HIPAA ready environment. They will sign a Business Associate Agreement (BAA), but they only handle the Physical Safeguards mandated by HIPAA. If you use a HIPAA compliant hosting provider you still have to spend months developing a HIPAA compliant application stack within that environment.
In contrast, TrueVault provides all client-side and server-side functionalities required by HIPAA, and works just like any other API service. The typical TrueVault integration takes days and saves months of development time.
Plus, if you want AWS to sign a BAA you need to use dedicated instances and each instance hour is 10% more than the standard fee. So your meter starts at $1,500/month if you want to become HIPAA compliant with AWS. FireHost starts at $1,115/month and you are charged a $250 premium for each HIPAA ready instance.
"In contrast, TrueVault provides all client-side and server-side functionalities required by HIPAA"
Maybe I am misunderstanding, but you seem to be saying that a customer's application is automatically HIPAA compliant by using TrueVault. I get that you take care of the HIPAA storage piece, but how do you make their entire application HIPAA compliant?
Comments
How is TrueVault better than AWS?
Our customers are typically deciding between using TrueVault or a HIPAA compliant hosting provider. The customer is facing a build vs. buy decision.
The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of protected health information (PHI). AWS, FireHost, and Rackspace are great! But, HIPAA compliant hosting providers like these only provide a HIPAA ready environment. They will sign a Business Associate Agreement (BAA), but they only handle the Physical Safeguards mandated by HIPAA. If you use a HIPAA compliant hosting provider you still have to spend months developing a HIPAA compliant application stack within that environment.
In contrast, TrueVault provides all client-side and server-side functionalities required by HIPAA, and works just like any other API service. The typical TrueVault integration takes days and saves months of development time.
Plus, if you want AWS to sign a BAA you need to use dedicated instances and each instance hour is 10% more than the standard fee. So your meter starts at $1,500/month if you want to become HIPAA compliant with AWS. FireHost starts at $1,115/month and you are charged a $250 premium for each HIPAA ready instance.
"In contrast, TrueVault provides all client-side and server-side functionalities required by HIPAA"
Maybe I am misunderstanding, but you seem to be saying that a customer's application is automatically HIPAA compliant by using TrueVault. I get that you take care of the HIPAA storage piece, but how do you make their entire application HIPAA compliant?