You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
How to require 2-factor authentication or multi-factor authentication (or client-side end-to-end encryption) for consumers of Observable Framework dashboards?
#1454
For the health care use cases at @onefact, we rely on @observablehq's Framework regularly.
However, for clinicians to be able to make predictions and decisions (or financial engineers at hospitals/hospital-connected entities like private equity fund resource allocators), we need to comply with federal laws like the Health Insurance Portability and Accountability Act.
I was able to confirm with the @observablehq team that the platform is not HIPAA-compliant unfortunately, so we are rolling our own feature.
Does anyone else need this?
Happy to make this contribution from @onefact as we have some headcount for the summer.
Examples of our tests with Observable so far that I can share (the work with clinicians and clinics is private by federal law, as protected health information is unable to be shared or we will lose a lot of money due to the HIPAA violations):
HTH happy to chat if anyone else needs this feature, our focus is hospitals, tertiary care centers, and clinics in low- and middle-income countries that tend to need on-device compute (due to internet connectivity), but HIPAA-compliance is still the gold standard we start from for these use cases 🙏
This discussion was converted from issue #1450 on June 12, 2024 16:25.
Heading
Bold
Italic
Quote
Code
Link
Numbered list
Unordered list
Task list
Attach files
Mention
Reference
Menu
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
-
For the health care use cases at @onefact, we rely on @observablehq's Framework regularly.
However, for clinicians to be able to make predictions and decisions (or financial engineers at hospitals/hospital-connected entities like private equity fund resource allocators), we need to comply with federal laws like the Health Insurance Portability and Accountability Act.
I was able to confirm with the @observablehq team that the platform is not HIPAA-compliant unfortunately, so we are rolling our own feature.
Does anyone else need this?
Happy to make this contribution from @onefact as we have some headcount for the summer.
Examples of our tests with Observable so far that I can share (the work with clinicians and clinics is private by federal law, as protected health information is unable to be shared or we will lose a lot of money due to the HIPAA violations):
Examples with de-identified semi-public health care data I've trained language models (e.g. http://arxiv.org/abs/1904.05342) on:
HTH happy to chat if anyone else needs this feature, our focus is hospitals, tertiary care centers, and clinics in low- and middle-income countries that tend to need on-device compute (due to internet connectivity), but HIPAA-compliance is still the gold standard we start from for these use cases 🙏
Beta Was this translation helpful? Give feedback.
All reactions