But there are firms that certify you for PCI and HIPAA and im wondering if any devs on here have explored these channels using OpenAI? they stream over https and if we can get the confirmation that they’re not retaining our API data then couldn’t we squirrel are way around into HIPAA compliance? Has anyone tried similar hacks?
While OpenAI offers HTTPS for secure data transmission, achieving HIPAA compliance involves various aspects beyond encryption. HIPAA compliance requires stringent measures to safeguard Protected Health Information (PHI). It’s crucial to assess OpenAI’s services comprehensively against HIPAA requirements, considering data storage, access controls, audit trails, and other factors.
Attempting to “squirrel” around HIPAA compliance may pose legal and ethical risks. It’s advisable to consult with legal and compliance experts to ensure adherence to healthcare data protection regulations. OpenAI may not explicitly provide HIPAA-compliant services, so exploring alternatives with established certifications could be a more secure approach for healthcare-related applications.