Open-source HIPAA compliance company policies
catalyzeio.github.io
catalyzeio.github.io
We removed the license restriction and changed it to CC BY-SA 4.0. Thank you for the feedback!
EDIT: Yeah, it seems like there are some far reaching not-understood legal implications of the "NC" license. Ok, we're going to re-commit and re-issue these with the BY-SA. Should be up in a few minutes.
I'm definitely not a lawyer and would like to hear from one interpreting the license for this use case, but it sounds like that could be interpreted to mean not okay to use for a business if it generated a commercial advantage, like HIPAA compliance.
Clarification from your lawyer (published on your site) would be good if you aren't okay switching to a more permissive license.
Suggestion: name them "FREE HIPAA DOCS AVAILABLE AT [URL]" and use a license requiring attribution, should make them hard to resell?
Disclaimer: I am involved with HIPAA-COW on the Security, Risk and soon the Technical Security working groups; we release a lot of information to help people.
I can dive deep into the actual regulations later if we know we have to comply. Right now I need to kinda figure out the lay of the land. Where other services like Aptible or Catalyze fit in the ecosystem. Like {X} is the problem, {Y} is the regulation set and {Z} is the way to comply/resolve it.
HIPAA is a very large, encompassing bill that provides numerous protections for patients. In particular, it provides the necessary legal requirements preventing healthcare providers from disclosing personally identifiable information - typically, things like SSN, name + date of birth, name + zipcode, etc. Anything that could possibly be used by someone to identify who the patient is should not be discloses. HIPAA also lists some technology requirements, but if memory serves me correctly, it only goes so far as to say "industry-standard practices". There's also numerous parts of HIPAA that pertain to billing and insurance, but I don't do billing so I can't speak too much on those.
Another bill to check out would be HITECH.
Would you mind sharing your email (mine is in my profile) in case I wanna bounce off a few Qns? I promise to keep it short. TIA.
http://www.quora.com/Where-is-the-dividing-line-in-building-...
I just sent you an email too. Hopefully I can help out a bit.
1) Never handle any US protected health information in any way at all, or 2) Push this off entirely to a partner.
If you are operating in the US in healthcare, at the very least you will need to audit yourself to ensure (1).