424 karma · joined February 9, 2013
http://www.linkedin.com/in/treyswann
Inside the Nike+ FuelBand is a triaxial accelerometer based pedometer. I can get my head around that. But, how do you track a baby's kick count?
Can't wait for the CC feature. Awesome!
What does your early customer look like? What size organization?
How will you get big companies with large sales teams to adopt Abacus?
Did I read in the comments that you can link to my corporate card charges? That would be ideal.
Let's say I wanted to Unbabel something from German to English. How long is 'Can take some time?'
Also, how long does it take to Unbabel something given 'Regular service' conditions?
Last question, how long before 'Unbabel' catches on as a verb?
Immersion is clearly the way to go when learning a new language. I learned more French trying to haggle with the waiter for more ice in Biarritz, than I ever did in Madame Lefebvre’s class.
I like that Cambly pairs me with a friendly native speaker rather than a professional teacher. And, I’m a big fan of the on-demand marketplace idea.
Questions for Cambly:
1) Users are required to download a separate app for each language. As you add more languages a user may be learning French and Spanish simultaneously. Are there plans to merge everything into one app so that I can toggle between two different languages?
2) Do you find that users are selecting tutors based on attractiveness?
I love how you can actually use their "web scraper for anyone" on the blog post. Very cool!
Streak is great! We were looking for a lightweight CRM that our team would actually use. Streak does everything we need it to and it does not require our team to dramatically change their work flow.
Everything is right inside Gmail and so for us, at this stage, Streak is perfect. Plus, tracking feature is cool. Easy way to see if an email has been read.
Rapportive (https://rapportive.com) is really what makes our direct sales possible. And, Streak plays nice with Rapportive.
Search functionality will be released by the end of January.
The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of protected health information (PHI).
AWS will sign a BAA, but they only cover the Physical Safeguards (e.g. facility access controls, etc.). TrueVault handles both the Technical and Physical Safeguards.
With AWS you still need to build your own HIPAA compliant application stack. The technical requirements include: -encryption and decryption -key management -key rotation -access control -unique user identification -emergency access -automatic logoff -audit controls -mechanism to authenticate electronic PHI -person or entity authentication -transmission security -integrity controls
The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of protected health information (PHI). AWS, FireHost, and Rackspace are great! But, HIPAA compliant hosting providers like these only provide a HIPAA ready environment. They will sign a Business Associate Agreement (BAA), but they only handle the Physical Safeguards mandated by HIPAA. If you use a HIPAA compliant hosting provider you still have to spend months developing a HIPAA compliant application stack within that environment.
In contrast, TrueVault provides all client-side and server-side functionalities required by HIPAA, and works just like any other API service. The typical TrueVault integration takes days and saves months of development time.
Plus, if you want AWS to sign a BAA you need to use dedicated instances and each instance hour is 10% more than the standard fee. So your meter starts at $1,500/month if you want to become HIPAA compliant with AWS. FireHost starts at $1,115/month and you are charged a $250 premium for each HIPAA ready instance.
"AWS enables covered entities and their business associates subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA) to leverage the secure AWS environment to process, maintain, and store protected health information and AWS will be signing business associate agreements with such customers."
http://gigaom.com/2013/10/12/armed-with-apis-developers-will...
SUMMARY: The rise of APIs as a source for web services and data means that developers don’t have to reinvent the wheel on every feature — they can source it from an API. This trend brings about the composable enterprise.
Most startups fail because they aren’t hitting their target growth rate, not because they failed to build a product that works.
You have to fight to grow. Evaluate how much time you spent building your product, and then invest just as much time in growth-related activities.
I'm interested to hear what everyone thinks. Will Codecademy be able to "connect people learning on the site with opportunities that fit their skill sets?"
To clarify, a Business Associate is any entity that uses or discloses PHI on behalf of a Covered Entity. Furthermore, a Business Associate is any person who, on behalf of a Covered Entity, performs (or assists in the performance of) a function or activity involving the use or disclosure of PHI.
If you use our JavaScript widgets so that you never actually touch PHI, then you may be able to avoid the Administrative Safeguards. But, if you handle PHI and then send it to TrueVault you will need to comply with the Administrative components of HIPAA.
The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of electronic protected health information.
HIPAA compliant hosting handles the Physical Safeguards, a set of rules and guidelines that focus on the physical access to protected health information (PHI).
TrueVault handles both the Physical and Technical Safeguards (Encryption and Decryption, Key Management, Key Rotation, Access Control, Unique User Identification, Emergency Access, Automatic Logoff, Audit Controls, Mechanism to Authenticate Electronic PHI, Person or Entity Authentication, Transmission Security, and Integrity Controls). This is all stuff that you would have to build yourself if you use AWS, FireHost, or Rackspace.
You’re right; Administrative Safeguards should not be ignored. The administrative components are really important when implementing a HIPAA compliance program; you are required to assign a Privacy Officer, complete a risk assessment, implement employee training, review policies and procedures, and execute Business Associate Agreements (BAAs) with partners you share protected health information (PHI) with. I think that Accountable does a great job with the Administrative Safeguards. Accountable offers HIPAA compliance management tools that keep your business legal. Checkout -- http://www.accountablehq.com/
Consumer-originated data, even though it is health data, is not protected health information (PHI) as covered by HIPAA. But, when that health data is shared with a Covered Entity (a doctor, hospital, insurance plan, or other HIPAA-defined CE) then it becomes PHI. And, the app handling the PHI needs to be HIPAA compliant.
People want information, not data. When an app takes health data and feeds it up to a doctor for diagnosis, analysis, advice, or treatment, then that data becomes PHI and your app needs to be HIPAA compliant.
TrueVault is also the first to cover customers under a comprehensive Privacy/Data Breach Insurance policy. As a result, TrueVault is able to indemnify our customers for, from, and against regulatory fines and the cost of breach remediation.
We offer a 30-day free trial, so you can play around with our API without entering a credit card. Caveat -- don’t send us any real PHI until we sign a BAA.
Please feel free to test it out, and if you have any questions shoot me an email. trey@truevault.com
We get to see a wide variety of use cases, happy to share our experiences.
Stripe is really just used for comparison purposes. Using Stripe makes you PCI compliant, and using TrueVault makes you HIPAA compliant. Also it demonstrates that TrueVault is not a consumer facing document storage solution (not a HIPAA compliant Dropbox). You access data in TrueVault via our API and native clients.
Bottom line, if your application needs to be HIPAA compliant it’s a pain. If you push your protected health information (PHI) to TrueVault, then you don’t have to spend months and months developing your own HIPAA compliant infrastructure.