Tandon: Startup acquired blood samples through friends with hospital security guards
“Our residual blood sample partnership with this health system was actually nothing more than Deepika being friends with the security guard and the front desk lady. And so we had accumulated hundreds of samples, and they were, you know, anonymized, and, you kno…”
Cacioppo: Companies can legally self-declare HIPAA compliance
“There's HIPAA, which is U.S. Law. You can just declare yourself compliant with HIPAA. Like, you get to decide.”
Reimer: HIPAA compliance is self-attesting and requires no external audit
“The nice thing about HIPAA is it's self-attesting so you don't pay for an external audit or it's not required to basically to claim HIPAA compliance.”
Sadeghi: 23andMe is not HIPAA compliant
“One of the most shocking things about 23 means is it's actually not HIPAA compliant, right? It doesn't follow the gold standard clinical regulations that ensure your data is safeguarded.”
Sharma: Strict HIPAA Regulations Will Hinder US Healthcare AI Startups
“Furthermore, this is one place where there is Difficult regulation called HIPAA in the US that will prevent US startups being able to do well.”
Wang: HIPAA rules currently block patient data from training AI models
“Right now you know, HIPAA and PII and all the PII regulations will more or less prevent patient data from being used to train you know, AI models.”
Walling: Bootstrappers can achieve HIPAA compliance on a tight budget
“HIPAA compliance is not out of the realm of bootstrappers. Now, if you want SOC II compliance, that becomes pretty pricey, pretty quick. HIPAA compliance is different. And of course, this is not legal nor HIPAA advice that I'm giving you, but I have known many…”
Walling: HIPAA-compliant SaaS products must charge premium pricing
“The thing to think about is if you're HIPAA compliant, you need to charge a lot of money for this. Like I've seen SaaS startups that are charging, you know, let's make up some numbers. 20 dollar for the cheapest plan, then a 50 and then a hundred dollar plan. …”
Gil: HIPAA legislation has backfired in many ways for patient good
“HIPAA is kind of interesting from the context of it was an incredibly well intentioned piece of legislation, but the flip side of it is it's really backfired in all sorts of ways in terms of actual patient good.”
Abernethy: HIPAA is outdated and struggles to protect individual privacy today
“Our laws of the past, HIPAA, really contemplated a different world than we live in right now, whereby essentially in 2019 and going forward, it's very hard to maintain privacy of any individual.”
Abernethy: HIPAA-de-identified health data remains likely re-identifiable through modern analytics
“Even information that is de-identified from a HIPAA perspective actually still is probably re-identifiable even in our context.”
Abernethy: Lack of pet HIPAA rules simplifies veterinary health data aggregation
“There's no doggy HIPAA. Now, we have to do the right thing by pets and pet owners, and we need to basically only think about using that information in a way that's good for society, for pets and pet owners. But that being said, many of the impediments, as we t…”
Sethi: Patients can legally demand their medical records via API or email
“Patients are actually outside of HIPAA, so you can ask, as a patient, a HIPAA-qualified entity to do something for you and share your information, whether it's through an API or whether it's through a PDF or email, and they have to do it.”
Machine learning enables data network effects without raw data sharing
“I think with, especially with machine learning, you could learn features from data without having to share the data itself. And that's useful for IP or for HIPAA and so on. So I think there's a lot of ways that one could contribute to network effects without m…”
HIPAA compliance unlocked upmarket healthcare traction for Formstack
“And last year we really started to see some traction in up market, specifically healthcare. We got our product HIPAA compliant and which kind of became this gate that helped us really have very different conversations with customers.”
Tillman claims no competitor can pass enterprise security reviews without data access
“So when you're getting into the large enterprise organizations that are publicly traded and heavily regulated on socks or HIPAA, this is an area that we can only hit on and none of our competitors can walk through these global security reviews, not touching no…”
Ryan Hungate: HIPAA violation penalties reach $50,000 per non-compliant email instance
“And the fee if they break it is 50,000 dollars per instance. So every time I send one email, that's 50 grand.”