HIPAA and client data stored w/ Google's App Engine framework.

57 views
Skip to first unread message

Tony

unread,
Apr 10, 2008, 3:30:29 PM4/10/08
to Google App Engine
Aloha,

I have a question that others may have researched already. The Google
App Engine appears to provide a good avenue to store and manage data
on clients for medium to large healthcare enterprises. That is, a
company could conceivably develop software that stores and updates
protected health information, case notes, etc.

However, protected health information is governed by the Health
Insurance Portability and Accountability Act, which is known to set
expectations for client privacy in most situations.

My question is this: could a client healthcare database/management
tool be completed w/in the Google App Engine's framework and utilized
securely in accordance with HIPAA? I am concerned mostly about the
storage of client data on servers inaccessible to the company's IT and/
or end user.

Any thoughts would be appreciated.
Tony

Jason (Appirio)

unread,
Apr 11, 2008, 12:26:32 AM4/11/08
to Google App Engine
Until there is HTTPS support in AppEngine, it's not a practical
platform for a business app of any sort.

Currently all of your data would be sent in the clear between
AppEngine and your users' browsers. That's a showstopper.

Cast your vote for HTTPS support!
http://code.google.com/p/googleappengine/issues/detail?id=15&colspec=ID%20Type%20Status%20Priority%20Stars%20Owner%20Summary

On Apr 10, 12:30 pm, Tony <trobb...@gmail.com> wrote:
> Aloha,
>
> I have a question that others may have researched already. The Google
> App Engine appears to provide a good avenue to store and manage data
> on clients for medium to large healthcare enterprises. That is, a
> company could conceivably develop software that stores and updates
> protected health information, case notes, etc.
>
> However, protected health information is governed by the Health
> Insurance Portability and Accountability Act, which is known to set
> expectations for clientprivacyin most situations.

networkvillage

unread,
Jun 4, 2008, 2:23:17 PM6/4/08
to Google App Engine
this is a great question - can anyone from google confirm / deny an
intention to support hipaa compliance in the near future

On Apr 10, 3:30 pm, Tony <trobb...@gmail.com> wrote:
> Aloha,
>
> I have a question that others may have researched already. The Google
> App Engine appears to provide a good avenue to store and manage data
> on clients for medium to large healthcare enterprises. That is, a
> company could conceivably develop software that stores and updates
> protected health information, case notes, etc.
>
> However, protected health information is governed by the Health
> Insurance Portability and Accountability Act, which is known to set
> expectations for client privacy in most situations.
>
> My question is this: could a client healthcare database/management
> tool be completed w/in the Google App Engine's framework and utilized
> securely in accordance withHIPAA? I am concerned mostly about the

Mahmoud

unread,
Jun 4, 2008, 3:39:09 PM6/4/08
to Google App Engine
HIPPA compliance requires things as esoteric as excruciatingly
detailed audit trails. I doubt such a feature would be useful outside
of the medical/emr space, and hence I doubt it ever being supported in
the datastore.
Reply all
Reply to author
Forward
0 new messages