[google-appengine] Re: HIPAA requirements vs. AppEngine security guidelines

2009-07-08 Thread Andrew Badera
On Tue, Jul 7, 2009 at 10:11 PM, GenghisOne wrote: > > Andy > > Thanks for the heads-up... > > The link to that paper is here and it makes for a good read... > http://awsmedia.s3.amazonaws.com/AWS_HIPAA_Whitepaper_Final.pdf > Thanks for the link. Bookmarked it this time. --ab --~--~-~--

[google-appengine] Re: HIPAA requirements vs. AppEngine security guidelines

2009-07-08 Thread nathanr
On Jul 8, 12:23 am, Jeff Enderwick wrote: > I say go hire a HIPAA consultant who can answer such questions > authoritatively. This is good advice. You really don't want to be basing legal decisions on a third-party's statements. I'd have your attorney review each service's documents directl

[google-appengine] Re: HIPAA requirements vs. AppEngine security guidelines

2009-07-07 Thread Jeff Enderwick
I say go hire a HIPAA consultant who can answer such questions authoritatively. I've been through FIPS before, and you would not believe the odd lawyeresque contrivances used to get certified. With HIPAA you are in the same realm, and so you should hire yourself the appropriate barrister. $.02,

[google-appengine] Re: HIPAA requirements vs. AppEngine security guidelines

2009-07-07 Thread GenghisOne
Andy Thanks for the heads-up... The link to that paper is here and it makes for a good read... http://awsmedia.s3.amazonaws.com/AWS_HIPAA_Whitepaper_Final.pdf Unfortunately after I skimmed through it I felt a little unsettled about AppEngine's security model...probably just my limited understan

[google-appengine] Re: HIPAA requirements vs. AppEngine security guidelines

2009-07-07 Thread Andrew Badera
There's a whitepaper by Amazon on the topic. Google it, it's been a few months since I looked at it, don't have a link offhand, sorry. Thanks- - Andy Badera - and...@badera.us - Google me: http://www.google.com/search?q=andrew+badera - This email is: [ ] bloggable [x] ask first [ ] private On

[google-appengine] Re: HIPAA requirements vs. AppEngine security guidelines

2009-07-06 Thread GenghisOne
Does anyone know if Amazon's EC2 platform is HIPAA-compliant? On Jul 6, 12:44 pm, richard emberson wrote: > Not going to happen. The IT requirements for Google would > cost far more than the couple of applications that might > need HIPAA. They would have to have a completely > separate group wit

[google-appengine] Re: HIPAA requirements vs. AppEngine security guidelines

2009-07-06 Thread richard emberson
Not going to happen. The IT requirements for Google would cost far more than the couple of applications that might need HIPAA. They would have to have a completely separate group with their own machines, passwords, procedures, etc. with a real wall (both material wall and software/hardware wall) b