@PatientNotesApp is now HIPAA compliant. US medical professionals no longer need to spend hours a week writing their notes and letters - just let PatientNotes do it for you in seconds.
Some of the best compliance folks in the industry at
@Zendesk taught me about SOC2 Type II, HIPAA, ISO 27001:2013 and FebRAMP LI-SaaS. Combined with
@lox's experience at Block (Cash App) and
@buildkite, we understood many of the controls we would need to put in place but didn't know how long it would take.
Many of the templates that we could find online and did purchase to assist in this process were incredibly outdated. The biggest theme is they are written for companies who all work in a single office building.
The
@PatientNotesApp team is a remote team. We spent the time to thoughtfully adjust each of the policies to be remote-first. The other adjustments we had to make were mostly due to out-dated policies. For example, our password policy follows the NIST guidelines (Length > complexity, no monthly resets, obsessive 2FA, etc).
Tara, our Head of Compliance, led us through the policy drafting process on “compliance Tuesdays”. The rigorous focus of dedicating a whole day each week, combined decades of experience working in strong compliance environments allowed us to become HIPAA compliant in late December 2023.
After monitoring our controls for a couple of months, we now feel confident that we’ll be able to consistently maintain HIPAA compliance going forward.