gruntwork-io / gruntwork-io/gruntwork-io.github.io
We can't claim we have a "HIPAA compliant" reference architecture — Use "HIPAA eligible" instead
- Dominant language
- HTML
- Stars
- 43
- Forks
- 43
- PR merge metrics
- No merged PRs in 30d
Description
As reported in [this Slack message](https://gruntwork-io.slack.com/archives/C0275GS2FKM/p1627910644063300):
> We should call the HIPAA Ref Arch, "HIPAA eligible", as HIPAA compliance can only be conferred by an auditor.
As such we should do a scan of the language we're using to make sure we aren't overstating it. Since there's nothing contractual about the waitlist I don't think there's any potential legal ramifications yet, but it would be best to abide by the rules. We can probably talk about user's needs/goals in terms of compliance, just not our infrastructure itself, e.g. "Reach HIPAA compliance faster by building atop our HIPAA eligible reference architecture…"
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.