Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chasb
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
chasb
4y ago
My 27 year old sister got CAR-T for leukemia earlier this year after a failed stem cell transplant. She's in remission. It's incredible, literally curing cancer.
2.
▲
by
chasb
6y ago
I wrote this a while back for our customers: https://www.aptible.com/hipaa/what-is-a-baa/
3.
▲
by
chasb
7y ago
As a kid I loved "Motel of the Mysteries," reimagining the discovery of our culture today as if it was Howard Carter opening King Tut's tomb. https://www.washingtonpost.com/news/act-four/wp/2016
4.
▲
by
chasb
8y ago
We (Aptible) are distributed-first. Many of our team members really appreciate the flexibility the remote culture brings and use it to spend more time with their families. Shameless plug: We're hiring - https://www.aptible.c
5.
▲
by
chasb
8y ago
Premise: > In North America (perhaps elsewhere) you are required to have at least a Master's degree to practise Psychology and you should have a doctorate if you want any mobility with your practise. Conclusion: > This leads peop
6.
▲
by
chasb
8y ago
The article (and the crisis) pertains to social psychology, not clinical psychology.
7.
▲
by
chasb
8y ago
Literally the only thing the landing page says is the purpose and what your email is used for: "Join the Slack workspace Aptible Gridiron GDPR Slack", and "Verify your email"
8.
▲
by
chasb
8y ago
For anyone interested we (Aptible) made this Slack community to answer questions about GDPR: https://join.slack.com/t/gridiron-gdpr/shared_invite/enQtMzQ... Disclaimer: we are a vendor that makes a SaaS offer
9.
▲
by
chasb
8y ago
(Just a heads up "Ask HN" generally refers to asking the community, not YC itself. I don't think the YC legal team reads this.) I'm a lawyer, YC alum, and have a CIPP/E cert. I took a crack at the "Does GDPR ap
10.
▲
by
chasb
8y ago
It really depend on your reasons for retaining the backups in the first place. GDPR forces you to be able to articulate why you collect or process regulated personal data. If you provide a service that collects or processes data for fair
11.
▲
by
chasb
8y ago
Not in your personal capacity, no. As mentioned in the other comments to this parent, HIPAA only applies to "covered entities" like doctors that take insurance and insurance companies, and their "business associates" tha
12.
▲
by
chasb
9y ago
HN probably doesn't fall within the material scope of GDPR, unless they perform business activity that falls within the scope of EU law that I'm not aware of. That would be different if they marketed/promoted/sold in the
13.
▲
by
chasb
9y ago
The ICO is seen as a leading voice, with some very good guidance, e.g.: https://ico.org.uk/for-organisations/guide-to-the-general-da... They're widely respected, but you're right it remains to be seen whether
14.
▲
by
chasb
9y ago
GDPR puts the burden on the company to comply if it processes any in-scope personal data, regardless of whether it's possible for the data subjects themselves to minimize that data. I'm a lawyer but not your lawyer and I have no i
15.
▲
by
chasb
9y ago
There are a lot of businesses that market and sell in the EU, or that recruit or hire contractors in the EU. GDPR affects not only your CRM, but your marketing and sales stack, your HR stack, and any other part of your business that might t
16.
▲
by
chasb
9y ago
The cost of compliance will fall drastically. My company (Aptible) started in HIPAA and is doing a lot with GDPR. They are very similar in a lot of ways, including the emergence of new systems of record for privacy and security management d
17.
▲
by
chasb
9y ago
The data protection officer does not have to be a full-time role. It can be part of someone's other duties, or performed by a contractor (Art 37 ¶ (6): https://gdpr-info.eu/art-37-gdpr/ ).
18.
▲
by
chasb
9y ago
Proposed, not yet effective: https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...
19.
▲
by
chasb
9y ago
GDPR's "Right of access by the data subject" (Article 15) is here: https://gdpr-info.eu/art-15-gdpr/ The right can only be enforced against a "controller," which is the entity that "determ
20.
▲
by
chasb
9y ago
Be aware, this article is not a list of GDPR requirements. It is, however, a good list of questions that every business processing data in the cloud should be aware of. You need to be able to answer these questions.
21.
▲
by
chasb
9y ago
My company (Aptible) makes a product called Gridiron that does this. All of the data that a requester is entitled to can be pre-structured and organized in a source of truth. That's what Gridiron is.
22.
▲
by
chasb
9y ago
Matt, if you read this, I am so sorry for your loss. My heart goes out to you and your family.
23.
▲
by
chasb
9y ago
(OP) I help run a Rock Health portfolio company and sometimes feel divorced from the outcomes we help enable. I thought this was a great project to show how technology helps real people.
24.
▲
The real-world effects of digital health
(impact.rockhealth.com)
1 points
by
chasb
9y ago
|
1 comments
25.
▲
by
chasb
9y ago
HHS prefers not to use civil monetary penalties, but they hit when they do: https://www.hhs.gov/hipaa/for-professionals/compliance-enfor...
26.
▲
by
chasb
9y ago
GDPR has a lot of parallels to HIPAA and SOC 2. Many developers here have worked with companies subject to HIPAA, or that do SOC 2 reporting. One big difference is that the material scope of GDPR is so extremely broad: it regulates any PII
27.
▲
Aptible (YC S14) is hiring for growth ops
(jobs.lever.co)
1 points
by
chasb
9y ago
28.
▲
by
chasb
9y ago
Aptible | Remote | Multiple technical and non-technical roles for those interested in Internet security https://www.aptible.com/company/ Aptible makes people-centered security products that help SaaS developer teams bu
29.
▲
Aptible (YC S14) is hiring support engineers
(jobs.lever.co)
1 points
by
chasb
9y ago
30.
▲
Do you like ops? Aptible (YC S14) is hiring SREs
(jobs.lever.co)
1 points
by
chasb
9y ago
More ›