Launch HN: Delve (YC W24) – HIPAA compliance as a service
A new HIPAA-focused platform that bundles compliant AWS infrastructure with automated checklists, policies, and monitoring tools is drawing interest as a way for healthcare startups to avoid stitching together services like Vanta, Drata, and traditional PaaS hosting. Commenters probe how it handles BAAs, multi-cloud support, larger frameworks like SOC 2 and HITRUST, and whether its “one-click compliant infrastructure” can really cover the legal, human, and process side of HIPAA, which remains largely self-attested. Many see clear value for early-stage companies and resource‑constrained organizations, but question long-term fit for larger enterprises, potential vendor lock‑in, unclear pricing, and marketing claims that risk overstating third‑party validation.
Product positioning vs. existing tools
- Compared frequently to Aptible, Vanta, Drata, Secureframe, OneTrust/Tugboat.
- Delve pitches itself as: Heroku-like HIPAA-compliant deployment + Vanta-style checklist and automation, plus prewritten policies and infra templates.
- Existing vendors are said to already offer compliance dashboards and automation; some participants argue Delve’s differentiation is narrower than claimed.
Market fit, TAM, and long‑term viability
- Several commenters note many “compliance hosting” startups churn customers once they grow and build in-house DevSecOps.
- Concern that focusing on early-stage HIPAA startups is a small, transient market; some recommend targeting broader GRC or larger orgs’ security teams.
- Delve says HIPAA is just an entry point; SOC 2 is imminent, broader GRC and moving upstream are on the roadmap.
- Others highlight nonprofit agencies and small public entities as a good niche that lacks in-house expertise.
Technical architecture & cloud/vendor constraints
- Current support is AWS-only, deployed into the customer’s account via Terraform; future GCP/Azure support is “down the line.”
- Claims that Terraform is “cloud agnostic” are challenged; others say customers mainly care about the perception.
- Delve exposes only safe configuration toggles and blocks risky ones (e.g., public data stores).
- Handles BAAs guidance, including AWS and select third parties; also helps with OpenAI HIPAA usage and Azure/OpenAI tradeoffs.
- Questions raised about k8s/orchestration lock-in; Delve says customers can modify infra but within compliance-guardrailed constraints.
Compliance scope, auditors, and HIPAA nuances
- HIPAA is described as self-attested, without a formal “certification”; Delve aligns its controls with auditors’ frameworks and claims its workflow has been reviewed, not certified.
- Discussion clarifies covered entities vs business associates; Delve explicitly targets the latter, not individual therapists or small cash-only providers.
- Some argue HIPAA technical compliance is relatively straightforward; human behavior, processes, and liability are the hard parts.
- HITRUST is mentioned as often required by larger healthcare orgs; overlap with SOC 2 is noted.
Website, messaging, and sales process
- Multiple participants find the website too thin, demo-gated, and unclear on scope (infra-only vs full compliance).
- Suggestions: richer product docs, detailed security/compliance pages, fewer superficial FAQs, less emphasis on badges, more on reports and BAAs.
- Thin marketing content leads some to doubt real-world HIPAA experience; Delve acknowledges and promises a revamp.
Pricing and business concerns
- Many request concrete pricing; Delve only states a fixed annual fee, no usage-based markup, and AWS-billing in the customer’s account.
- Some see prior “HIPAA PaaS” offerings as overpriced wrappers over AWS and warn Delve against repeating that model.
Broader ecosystem & risk
- Concerns raised about trackers, ad pixels, and data brokers undermining privacy; Delve says it does vendor risk assessments and recommends removing or BAA-ing trackers, but offers limited technical control over them.
- Large healthcare organizations’ reluctance to rely on small vendors is tied to liability and survivability risk.