gruntwork-io / gruntwork-io/gruntwork-io.github.io

We can't claim we have a "HIPAA compliant" reference architecture — Use "HIPAA eligible" instead

Open
#530 0 comments 0 reactions 1 assignee Claimed by @zackproser View on GitHub
Dominant language
HTML
Stars
43
Forks
43
PR merge metrics
No merged PRs in 30d

Description

As reported in [this Slack message](https://gruntwork-io.slack.com/archives/C0275GS2FKM/p1627910644063300):
> We should call the HIPAA Ref Arch, "HIPAA eligible", as HIPAA compliance can only be conferred by an auditor.

As such we should do a scan of the language we're using to make sure we aren't overstating it. Since there's nothing contractual about the waitlist I don't think there's any potential legal ramifications yet, but it would be best to abide by the rules. We can probably talk about user's needs/goals in terms of compliance, just not our infrastructure itself, e.g. "Reach HIPAA compliance faster by building atop our HIPAA eligible reference architecture…"

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.