▲ | Bjartr 8 days ago | ||||||||||||||||
I don't read others' warnings as fear mongering. Rather, they are genuinely offering concrete steps to be taken to avoid problems that frequently arise in this domain. "Go talk to a lawyer" is not an attempt to scare or some impossible abstract advice. It's a very concrete, and very reasonable step that really ought to be taken early on in this effort. Maybe everyone here is off base. How might the app developer determine this? By talking to a lawyer. | |||||||||||||||||
▲ | rabidonrails 7 days ago | parent [-] | ||||||||||||||||
Maybe fear mongering is overstating but... Speaking to a lawyer is not the first step when building something in this domain (unless you already have someone bankrolling you). In this case there's an app that this guy built for families to use. It's obviously in it's infancy. The helpful advice here would be about posting that this is in beta or maybe reading the HIPAA guidelines and ensuring that he's adhering to those guidelines where applicable. Focus on tightening up security. What's his plan to ensure that data in encrypted in transit and at rest? What kind of monitoring will the app have? Does he need to be thinking about intrusion detection? Will he need to enforce 2FA? Does he need to stop everything and start speaking to lawyers? Probably not. | |||||||||||||||||
|