So if one of my friends has Crohn's and I search for it to understand what I should be aware of, my rates would go up? HIPAA specifically prohibits the sharing of medical information unless needed for care. If there is any one here that we should be annoyed at it's the insurance companies. Hospitals are losing money and the insurance companies are posting record profits.
There are natural "gyres" in the oceans that collect garbage - see this link for the "Great Pacific garbage patch" (https://en.m.wikipedia.org/wiki/Great_Pacific_garbage_patch). It's about the size of Texas and has a significant amount of plastic in it, although of smaller sizes. That would seem to be a great place to focus these collection and conversion efforts.
Author of that doc here. I cannot agree with you more. I have tried to be a bit more polite about that point of view. It's is complicated and very unnecessarily so at times. Lots of gaps as well. The main hope I have is that there are a lot of players involved in this (such as BIDMC) who could drive some change.
IMHO, this is a long game. What if every branded product (or ones that cared enough or could afford it) shipped with a dash button or was given one at checkout? What would brands pay for that? Customers wouldn't have to. And yes, I see the anti-incentive for a Safeway to disintermediate themselves unless Amazon was the delivery agent anyway. I can see brands willing to try this out. Given the amount of money spent on promotions and coupons with no clear, trackable value, this seems like something they would get behind once some basic metrics are in place.
I agree that you should not be tied to any solution that you choose. From what you're describing, it seems as though you'd like the entire backend to be portable. From a BaaS perspective, as you can imagine, that's a bit challenging. What we have done there is to document our APIs well and will shortly give you the ability to export your data as well. What you might be more interested in is our PaaS solution (https://www.catalyze.io/platform-as-a-service/) - that will allow you to use Heroku buildpacks to deploy you service onto our compliant infrastructure = so essentially if it works on Heroku, it will work on the Catalyze PaaS (or vice versa). We're hard at work on this and have a couple customers using it. We hope to have a public release very very shortly.
Full transparency - I'm one of the founders of Catalyze. Yes, we do. We've been through a couple of 3rd party HIPAA audits. You're absolutely right - HIPAA is more than just backend security. All our internal policies are documented here (http://catalyze.io/policy) and their mapping to HIPAA is documented here (http://catalyze.io/hipaa).