Remix.run Logo
john_strinlai 5 hours ago

they have comment/request for information sessions for HIPAA rule proposals, which your input would be valued.

tptacek 3 hours ago | parent [-]

I don't think the rule would be better with more detailed vulnerability scanning requirements! All these things inexorably become races to the bottom.

sonofhans 2 hours ago | parent [-]

Yes, exactly, the rules are intentionally broad and vague. You can wave paper at most of them and technically succeed. And then when you release accidentally PHI for the first time and your bullshit comes to light, your chickens will come home to roost. Doing a good job on compliance is less about security and more about staying out of jail.

akerl_ 11 minutes ago | parent [-]

The ideal flow here is:

1. Do good security and operations.

2. Overlap the minimum subset of your existing good security and operations as evidence for whatever compliance regimes help you get paid.

3. Get paid.

Nobody is suggesting that you bullshit the auditors. They’re suggesting not letting the auditors accidentally trick you into letting step 2 get in front of step 1.