How are 2 party consent states handled?
Is this HIPPA compliant?
How are 2 party consent states handled?
Is this HIPPA compliant?
The blog posts also mention French trained ML.
> Cedille is a new open source French language model created by Coteries. It is trained to understand and write French and is also the largest model of its kind for French. Cedille is trained using large databases of publicly available content on the internet filtered for toxic content.
Expanding into the US, yes - they would need to deal with HIPAA, but until they do they likely don't need to.
Secure and HIPAA-eligible
Audio, transcripts, and notes are not stored by Nabla
HIPAA-eligible and GDPR compliant
SOC 2 and ISO 27001 certifications in progress
Digging deeper (https://www.nabla.com/blog/privacy-security/):This data processing is done on Nabla's servers, which are powered by the HIPAA and GDPR compliant Google Cloud Platform (GCP), and on HIPAA-eligible LLM servers.
EDIT:
I was very curious about this and did a bit of research. The answer to it is squishy. It seems to be mostly a marketing term. The best definition I found was this:
"A service that is HIPAA eligible is one that is capable of being configured in a way that could meet HIPAA compliance requirements, but you have to know how to do it, it doesn’t happen ‘out of the box.’"
https://www.cleardata.com/articles/hipaa-eligible-hipaa-comp...
So it sounds great but doesn't actually mean that much.
The second you said that in a pitch to executive leadership, they'd realize you have no idea how to operate in healthcare.
* they may be HIPAA-compliant (ie: they fulfill the requirements), * they haven't gone through a HIPAA-certification (no third-party cert), * they aren't using services that aren't HIPAA-certifiable
The latter point is important, because there are some services (ie: firebase) that apparently won't be HIPAA compliant. Some services are HIPAA-compliant if configured correctly. AWS has a list. I believe google does too.
There are a bunch of HIPAA guides out there.
So as a demo, it's not a big deal. But if they start selling this they need at least to be HIPAA-compliant with certification on the roadmap.
HITRUST is a third party audit with higher standards than HIPAA. That is not a self-attestation.
I’ve spent a bunch of time in this space. Most of the major players offer HIPAA compliant services and sign BAAs. As of now, I don’t believe OpenAI offers a BAA, so this is dead in the water.
Here's AWS's list of HIPAA-eligible services. HIPAA-eligible is technology provider specific:
https://aws.amazon.com/compliance/hipaa-eligible-services-re...
Here's google's:
https://cloud.google.com/security/compliance/hipaa-complianc...
In general it means that the service may not be HIPAA compliant by default, but can be configured to be HIPAA compliant.
HITRUST is something else and it outside the scope of this discussion IMO. Not sure why you brought that up.
The is no certification requirement, so there is nothing to ”stand up in court”. Straight from the horse's mouth:
Are we required to “certify” our organization’s compliance with the standards of the Security Rule?
Answer: No, there is no standard or implementation specification that requires a covered entity to “certify” compliance.
https://www.hhs.gov/hipaa/for-professionals/faq/2003/are-we-...
https://www.scribeamerica.com/what-is-a-medical-scribe/
> A Medical Scribe is a revolutionary concept in modern medicine. Traditionally, a physician's job has been focusing solely on direct patient contact and care. However, the advent of the Electronic Health Record (EHR) created an overload of documentation and clerical responsibilities that slows physicians down and pulls them away from actual patient care. To relieve the documentation overload, physicians across the country are turning to Medical Scribe services.
> A Medical Scribe is essentially a personal assistant to the physician; performing documentation in the EHR, gathering information for the patient's visit, and partnering with the physician to deliver the pinnacle of efficient patient care.
https://www.hhs.gov/hipaa/for-professionals/covered-entities...
> If a covered entity engages a business associate to help it carry out its health care activities and functions, the covered entity must have a written business associate contract or other arrangement with the business associate that establishes specifically what the business associate has been engaged to do and requires the business associate to comply with the Rules’ requirements to protect the privacy and security of protected health information.
"If you handle, store or transmit protected health information (PHI) to or from a covered entity then you need to be HIPAA compliant."
Source: https://github.com/truevault/hipaa-compliance-developers-gui...
----
The posted software is absolutely free to be non-HIPAA compliant. They're not a covered entity and without a relationship with a covered entity, they're not a business associate. However, without a relationship with a covered entity, they're also unlikely to generate any meaningful revenue.
When a covered entity (a HIPAA-required provider) does business with a private non-covered entity _and_ that transaction involves HIPAA controlled information, they must enter into a Business Associate Agreement (BAA). This effectively forces the private entity to maintain the same HIPAA standard as the provider.
A private company is absolutely free to build non-HIPAA compliant software, but they completely unlikely to get any healthcare providers to actually use it.