Show HN: Aptible – Deployment platform to automate HIPAA compliance
aptible.com
aptible.com
We have a development tier (read: not HIPAA-compliant) for playing around with[0]. Fair warning, we do require a credit card.
We will be hanging out here for a few hours, answering questions and chatting.
tel mentioned this, but Amazon allows organizations to store protected health information (PHI) provided they use dedicated machines in their own VPC. I recently had to migrate our company into this model to get our BAA signed.
I like what you've built, but I think you might be missing the real pain point. I agree that it's a hassle to setup a compliant infrastructure on Amazon. But, this is a one-time process. Most serious healthcare IT companies (and startups) will undertake this responsibility themselves to have tight control over their infrastructure.
The real challenge is maintaing the system and providing access control as the system grows. We handle upwards of 50K clinical notes a day. When we encounter an issue we have to be able to track which note caused the problem and get access to it all within the confines of our system.
Our access policy requires:
1. Connection to the dedicated VPC 2. SSH access to specific instances
Here's what I regard as the real problem ---> Once you're SSH'd onto the instance, you can do basically anything. There's no front-end for manipulating PHI. I could scp every PHI document onto my laptop.
I could elaborate some more if you like.
We help customers control access to systems storing ePHI by tying SSH and database access to the same role-based access controls used for administering the web dashboard. We also log and audit all actions taken by these authenticated users once they've established an SSH session or database connection, so identifying or disconfirming a potential breach becomes much easier.
Can you expand more on "generate all of the documentation, audit logs, and explanatory materials you need to demonstrate compliance with every aspect of HIPAA."?
Also, with QSM requirements for the vast majority of other healthcare regulations, you need to explicitly address them in documentation to be compliant. Does Aptible address this, or only HIPAA?
Re: documentation, a major part of our platform is our compliance dashboard, where we track your compliance status in real time, as both a high-level status report (think Travis CI for HIPAA), and as more formal (custom) documentation which you can use for sales purposes, or in case of an audit.
As for QSM requirements (and other regulatory/compliance requirements in general), we're focused on covering 100% of HIPAA's requirements, but our technology and our compliance backend support a wide array of frameworks. We can help customers with all of these specific needs. Please let me know if I can provide a more specific answer!
We're focused on HIPAA only right now, but are built to support other frameworks and reporting standards.
(I'm working on a product that may eventually use this – left my email on their website and Chas got in touch and we ended up on a Skype call)
A couple of questions - mostly about performance. While heroku offers fantastic start for early and small size startups, one of the issues off late are it's performance issues when you reach certain growth stage. I realize that you are not working directly off AWS instances but using docker. How are heroku dynos different from aptible containers?
Most of the performance advantage comes from 2 facts:
1. An Aptible production customer shares NO resources with other customers, from the load balancing layer down to the app container layer. So, performance is never going to be degraded as a result of resource contention from other customers.
2. Container CPU and RAM constraints are flexible on Aptible. While we set defaults for both of these container constraints, we can adjust them for specific customer applications that may be more CPU- or RAM-intensive.
1. Providing an end-to-end PaaS that supports all app services and databases that a customer needs to run. 2. Providing a compliance management dashboard, where customers can track their compliance status and maintain all the documentation they'd need to show to an auditor, or a customer concerned with their compliance status. Because we manage the entirety of a customer's technical operations, most of this documentation can be generated with minimal input from the customer.
I think HIPAA-BaaS are great products to get storing PHI (Protected Health Information) immediately. I'm working with companies in health tech right now that are working with hospitals, but not storing patient data. BaaS, from startups like Catalyze/TrueVault/Medable, provide a quick and easy way to get started on that path and determine if it's a good long-term strategy for your company. But, once you're dealing with enough patient data crunching, the rest of your application stack will really need to be secure. That's where PaaS products like Catalyze/Aptible come in.
(Disclaimer: I work for Catalyze)
EDIT: Medable, not Medible.
What size/type of company is the target market?
In order to host a HIPAA-compliant application on Amazon, there is a $1,500/month per-zone fee. This does not even count the actual server or storage costs, let alone the costs of building (and then maintaining) a complaint server application plus managing the documentation for it.
You also have to pay this fee again if you want to host the application in a second region (e.g. for failover/redundancy).
So, an extra $2000/month to forget about all of those is a signficant cost, but still a reasonable price.
The other thing I'll add is that there are no hidden costs and no gotcha fees. A Prod account gets you all of the help, training, and extra time from us you need to be successful. We don't consult and we never bill for our time.
That being said, I understand HIPAA compliance (or what it implies) is VERY important and shouldn't be taken lightly...
Preparing training materials is a good example. Each of our customers get three types of training: basic HIPAA privacy and security training for everyone; developer training, specific to their stack; and security officer training. We customize that training. We may modularize it later, but only if we can maintain the quality and experience.
We spend as much time with each customer as they want, but we don't bill for support and we don't bill for consulting. At first it seems higher-priced than some options, but there are no hidden costs.
We'll have a separate page on the site explaining this next week, but we break compliance management down into 5 main areas:
- Risk Assessment
- Policies and Procedures
- Training
- Ops
- Incident Response
Conceptually, they form a cycle. Each area feeds the next, with ops/incident response feeding back into risk analysis.
We have a suite of tools to help with each stage of the cycle. Each step requires a different mix of:
1. Automation
2. Manual work on our part, and
3. Manual work by our customers
Our overall goal is to drastically reduce #3 while helping our customers run amazing compliance programs that reduce risk and give everyone involved (devs, management, their customers, federal regulators) insight into what is going on inside their organization.
One interesting feature to add at some point would be helping companies incorporate their BAA into their user agreement (this is how Practice Fusion does it - http://www.practicefusion.com/pages/user-agreement.html).
Seeing as I live in The Netherlands, and my end users (patients) will be Dutch, I'm bound by Dutch law. I'm no attorney, but I think it will be problematic to store electronic health records in the US.
Seeing as scientists / developers in The Netherlands are at the forefront of ehealth / mhealth development, are The Dutch somewhere on your list Chasb?
Different scenario: me and my Dutch associates would like to launch an ehealth / mhealth product in the US. In the eyes of US law, are we allowed to do this?
The EU's data sovereignty laws present a special set of restrictions, and specific countries like the Netherlands add more. But challenging problems can be valuable problems to solve, so yes, the Dutch are on our list.
At the moment, however, our entire focus is on HIPAA compliance. I tell people this: I am a lawyer, but I am not your lawyer and this is not legal advice. You would certainly want to consult a US attorney, and perhaps form a US subsidiary, but it is possible for a foreign organization to do business in healthcare in the United States. The example at the front of my mind is Royal Phillips and their new partnership with Salesforce[0].
Feel free to email me if you'd like to chat more!
[0] http://www.salesforce.com/company/news-press/press-releases/...
Disclaimer: I work in a similar space.
NIST Special Publications are great resources, and we use them where appropriate, but as I'm sure you know, they're not specific enough to just audit against a single publication and call it a day.
For example, NIST SP 800-66 Revision 1[1]:
1. Only covers the Security Rule 2. Consists of mostly pointers to the other, substantive NIST SPs, and 3. Isn't as detailed as the audit protocol from HHS, which is the entity that will ultimately judge your compliance
Again, all of that said, we love NIST(!) and use their methodologies and guidance (including SP 800-66 Rev 1) extensively.
[0] http://www.hhs.gov/ocr/privacy/hipaa/enforcement/audit/
[1] http://csrc.nist.gov/publications/nistpubs/800-66-Rev1/SP-80...
Also, how much of the existing stuff is written on .NET? I have a feeling that's a pretty popular stack for a lot of small business/enterprise companies, but is harder to support via open source software.
I'm Travis, one of the co-founders of Catalyze - https://catalyze.io. We also offer a HIPAA-compliant platform-as-a-service (PaaS). Our compliant PaaS starts at $500/mo and includes dedicated, encrypted logging, monitoring, backup, disaster recovery, and encryption (at rest and in-transit). We've been through 3 3rd party audits + penetration testing (most recent audit we were 100% in compliance). We're very transparent about HIPAA and open our audits up to customers to use as part of their sales collateral. You can see how we interpret and address HIPAA requirements here - https://catalyze.io/hipaa/ - and you can see our policies here - https://catalyze.io/policy/ (we're open sourcing these in the next couple weeks).
We don't provide policies or risk assessments as a service, but Accountable (http://accountablehq.com/) does a great job with those. Using Catalyze + Accountable starts at $600/mo, about 1/6th of the starting price on the Aptible site; we also offer 60 days to terminate so don't lock you into annual contracts to get that pricing.
We've got some great production customers, with testimonials and use cases on our site, that love our service and support, and have moved over from hosting providers like AWS, Firehost, and Blue Box. I'm happy to answer questions about Catalyze and the compliant cloud space in general.
Our current operational status is available at http://status.aptible.com/
Other than Docker and AWS, there are a bunch of pieces that make the whole thing work, but most of them are custom.