Thanks for your response!.I'm not exactly sure what HIPAA is, I guess it's like a US version of the UKs General Data Protection Regulations (GDPR).
We have has a good number of customers asking: "are you X compliant?" or "are you Y compliant" and I know that they do not really understand what it is they are asking. It's like they want to use the latest buzz words.
There was a big panic in the UK in 2018 when the GDPR regulation came in, but after talking at length with the Information Commissioner's Office, I realised that most of what was actually required was just plain and simple common sense.
We never claim to be "Anything" compliant, we simply state openly exactly what we do and what we do not do. Then we can let the customer decide if we comply with whatever it is they are worried about.
A device like a router or a piece of software, can never be "compliant" in isolation, the important thing is the environment in which it operates - the people and processes that surround it.
// Log the activity
$target_path = ($_REQUEST["path"] != '') ? $_REQUEST["path"] : $_SERVER["REQUEST_URI"];
file_put_contents('/var/log/fusionpbx/access.log', date("Y-m-d h:i:sa") . "[".$_SESSION["user"]["username"]."@".$_SESSION["user"]["domain_name"]."]: " . $target_path. "\n", FILE_APPEND);
2022-01-11 07:24:35pm[@]: /core/user_settings/user_dashboard.php
2022-01-11 07:24:38pm[adrian@af-test.a2es.uk]: /app/xml_cdr/xml_cdr.php
2022-01-11 07:25:31pm[adrian@af-test.a2es.uk]: /app/xml_cdr/xml_cdr_details.php?id=b7a74eab-32e4-4ac2-a4b8-4f9a9cbaaaf7
Netsapien will take care of the HIPPA so why not use them for the health care customers?Just as an update, as of now I'm considering migrating over to Netsapien just for the fact that they will handle the Hipaa requirements, is this my only solution or is there a way to be HIPAA compliant with Fusion?
Personally I love fusion better because of the flexibility, but this Hipaa thing is driving me crazy and I lost a few customer becuase of not being compliant, can anyone shed some light to this topic?
Lol, after all i wrote the "Why" it very obvious.... I understand why someone who isn't experienced with hipaa would delegate as when your new to this compliancy and can seem intimidating but really it is nothing. But the biggest reason why you don't use netsapien is the same reason you don't use them for all your customers or resell ring central, jive, 8x8 or anything else... if you use your own fusion, you have much more control and larger margins so... in the end just do what your more comfortable with but as stated above hipaa is a joke and if you follow the basics of my previous post you will be fine.Netsapien will take care of the HIPPA so why not use them for the health care customers?
Yeah the fear is important but only completely negligent companies have have ever been healed accountable… best effort by using the stuff I said before is enough…. Read all u want but the fact is I did this for a long time with large companies on large scales… not debating on the forum… if ur not confident then just outsource it and don’t waste time debatingHIPPA compliance can absolutely destroy a business - even an audit can halt company operations. I would take this very seriously as it can mean more than just losing a few clients. I just read this on a website: "With HIPAA penalties as much as $1.5 million per violation, health-related businesses can't afford to not be HIPAA compliant, and this extends to their business partners. Companies paid a staggering $28,683,400 for violations in 2018." Does your business require HIPPA compliance or is this just a customer concern?
Yeah the fear is important but only completely negligent companies have have ever been healed accountable… best effort by using the stuff I said before is enough…. Read all u want but the fact is I did this for a long time with large companies on large scales… not debating on the forum… if ur not confident then just outsource it and don’t waste time debating