Launch HN: Delve (YC W24) – HIPAA compliance as a service

A new HIPAA-focused platform that bundles compliant AWS infrastructure with automated checklists, policies, and monitoring tools is drawing interest as a way for healthcare startups to avoid stitching together services like Vanta, Drata, and traditional PaaS hosting. Commenters probe how it handles BAAs, multi-cloud support, larger frameworks like SOC 2 and HITRUST, and whether its “one-click compliant infrastructure” can really cover the legal, human, and process side of HIPAA, which remains largely self-attested. Many see clear value for early-stage companies and resource‑constrained organizations, but question long-term fit for larger enterprises, potential vendor lock‑in, unclear pricing, and marketing claims that risk overstating third‑party validation.

Product positioning vs. existing tools

  • Compared frequently to Aptible, Vanta, Drata, Secureframe, OneTrust/Tugboat.
  • Delve pitches itself as: Heroku-like HIPAA-compliant deployment + Vanta-style checklist and automation, plus prewritten policies and infra templates.
  • Existing vendors are said to already offer compliance dashboards and automation; some participants argue Delve’s differentiation is narrower than claimed.

Market fit, TAM, and long‑term viability

  • Several commenters note many “compliance hosting” startups churn customers once they grow and build in-house DevSecOps.
  • Concern that focusing on early-stage HIPAA startups is a small, transient market; some recommend targeting broader GRC or larger orgs’ security teams.
  • Delve says HIPAA is just an entry point; SOC 2 is imminent, broader GRC and moving upstream are on the roadmap.
  • Others highlight nonprofit agencies and small public entities as a good niche that lacks in-house expertise.

Technical architecture & cloud/vendor constraints

  • Current support is AWS-only, deployed into the customer’s account via Terraform; future GCP/Azure support is “down the line.”
  • Claims that Terraform is “cloud agnostic” are challenged; others say customers mainly care about the perception.
  • Delve exposes only safe configuration toggles and blocks risky ones (e.g., public data stores).
  • Handles BAAs guidance, including AWS and select third parties; also helps with OpenAI HIPAA usage and Azure/OpenAI tradeoffs.
  • Questions raised about k8s/orchestration lock-in; Delve says customers can modify infra but within compliance-guardrailed constraints.

Compliance scope, auditors, and HIPAA nuances

  • HIPAA is described as self-attested, without a formal “certification”; Delve aligns its controls with auditors’ frameworks and claims its workflow has been reviewed, not certified.
  • Discussion clarifies covered entities vs business associates; Delve explicitly targets the latter, not individual therapists or small cash-only providers.
  • Some argue HIPAA technical compliance is relatively straightforward; human behavior, processes, and liability are the hard parts.
  • HITRUST is mentioned as often required by larger healthcare orgs; overlap with SOC 2 is noted.

Website, messaging, and sales process

  • Multiple participants find the website too thin, demo-gated, and unclear on scope (infra-only vs full compliance).
  • Suggestions: richer product docs, detailed security/compliance pages, fewer superficial FAQs, less emphasis on badges, more on reports and BAAs.
  • Thin marketing content leads some to doubt real-world HIPAA experience; Delve acknowledges and promises a revamp.

Pricing and business concerns

  • Many request concrete pricing; Delve only states a fixed annual fee, no usage-based markup, and AWS-billing in the customer’s account.
  • Some see prior “HIPAA PaaS” offerings as overpriced wrappers over AWS and warn Delve against repeating that model.

Broader ecosystem & risk

  • Concerns raised about trackers, ad pixels, and data brokers undermining privacy; Delve says it does vendor risk assessments and recommends removing or BAA-ing trackers, but offers limited technical control over them.
  • Large healthcare organizations’ reluctance to rely on small vendors is tied to liability and survivability risk.