A Simple HIPAA Compliant Web Application Using the Catalyze v2 API(catalyze.io)
catalyze.io
A Simple HIPAA Compliant Web Application Using the Catalyze v2 API
https://catalyze.io/blog/a-simple-hipaa-compliant-web-application-using-the-catalyze-v2-api/
3 comments
Unfortunately, securing data on the backend gets one about 5% of the way to HIPAA compliance. Does one have e.g. a written risk assessment and mitigation plan? No? Insta-violation.
Full transparency - I'm one of the founders of Catalyze. Yes, we do. We've been through a couple of 3rd party HIPAA audits. You're absolutely right - HIPAA is more than just backend security. All our internal policies are documented here (http://catalyze.io/policy) and their mapping to HIPAA is documented here (http://catalyze.io/hipaa).
I do not doubt that you are on top of things. Just pointing out that your customers also have to be on top of things, or it is unlikely they will be found compliant if audited.
[deleted]
As someone building a healthcare application, it seems kind of risky to base my entire backend on a third party service that could change, go out of business, make their prices prohibitively expensive, etc. It would be really nice if there was a way for me to have a HIPPA compliant architecture while still using open source technology so if I need to switch off your platform I'm not stuck re-writing my entire backend.
I agree that you should not be tied to any solution that you choose. From what you're describing, it seems as though you'd like the entire backend to be portable. From a BaaS perspective, as you can imagine, that's a bit challenging. What we have done there is to document our APIs well and will shortly give you the ability to export your data as well. What you might be more interested in is our PaaS solution (https://www.catalyze.io/platform-as-a-service/) - that will allow you to use Heroku buildpacks to deploy you service onto our compliant infrastructure = so essentially if it works on Heroku, it will work on the Catalyze PaaS (or vice versa). We're hard at work on this and have a couple customers using it. We hope to have a public release very very shortly.
I really like the look of this. I'm the Founder of Liver Initiative and will be looking to built out my platform soon.
I echo others' concerns. How does it compare with Firehost and their HIPAA solution? http://www.firehost.com/secure-cloud/compliant/hipaa
I echo others' concerns. How does it compare with Firehost and their HIPAA solution? http://www.firehost.com/secure-cloud/compliant/hipaa