Has anyone built a Patient Management System for a US-based entity using Formidable (like this)? I'm mentoring someone in Formidable and she wants to write her own system and I'm wondering about the following topics:
I have not used Formidable to build HIPAA-compliant solutions, but I have had to build HIPAA-compiant systems in my previous life as an IT Director in the healthcare and mental health world(s).
Walter's right: encrypting, and abstracting private health information is key, limiting, logging, and regularly auditing access to it is essential, and encrypting the *entire* backup and recovery cycle - as part of a larger, also compliant risk prevention, response, and remediation plan - is also essential.What I learned along the way: self-audit and document it.
I also learned that even though the world of wp plugins makes life easier for admins, managers, users, clerks, and customers easier on so many levels, precious few meet the stringent data security required for organizational compliance.
But the good news: if you/they are building a practice management solution vs. a patient management solution, the path to yay! may be considerably less difficult. I'd start there: clearly distinguish between patient management and practice management, and plan the system accordingly.It could be that Formidable does not itself have to satisfy HIPAA compliance data security requirements, as long and it supports and doesn't subvert or break the fundamental HIPAA compliance of the system within which it runs. That was a distinction that helped me as me and my team at the time built solutions behind the firewall and out front, for the public customer.
Sounds like a *fun* project! hth
Also: don't forget about SOX compliance if there's any ecommerce involved in your flow. In an individual practice it may not be a big deal, but if you/your client are building an industry solution, HIPAA + SOX compliance will signal to the marketplace that you're a thoughtful and potentially more valuable solution that the run-of-the-mill camt me if you can ISVs.
Please login or Register to submit your answer