- what logging and auditing is in place for telling a physician (who is ultimately responsible to his/her patients for their data) who accessed and/or changed data?
- are routine logs provided to users?
- how are backups done, and where do backups of data live?
- who, if anyone, at "drchrono" and/or any server farms used has access to my patient's data and/or backups?
- what is the retention policy for data? How do I get rid of data if needed (drilled all the way down through backups)?
- regardless of any verbiage about "never sharing data with a third party", what policy does "drchrono" have around dealing with subpoenas for patient information?
- what special precautions, if any, are in place for additional privacy around mental health and drug dependence issues?
The mashable advertisement indicates "All the data storage is HIPAA-compliant, as well." Is it? I'm a little confused by the following (difficult to parse) fragment on the website:
"The environment at drchrono currently encompasses the highest level of security as well as the Health Insurance Portability and Accountability Act of 1996 (HIPAA) security tenets that of the proposed regulations."
Perhaps someone from drchrono could let a potential user know if they actually claim "HIPAA compliance", and if so, reassure the user with details of how "compliance" was determined (ie via audit? - and who exactly is the "team of security experts" advertised?)
Less marketing-speak, more facts would be helpful.