This is just going to be a list of SSO / HIPPA compliant Auth systems for me to dig deeper into.
No, Replit auth & firebase are not a viable option.
Posting here in hopes it helps someone even years down the road… Unless replit decides to fully abandon the discourse instance all together.
IBM Verify is a cloud-native Identity-as-a-Service
(IDaaS) platform that centralizes identity and
access management for both workforce and
consumer users, offering features like single sign-
on, multifactor authentication, and passwordless
login....
Cut down on manual work and free up resources with automated compliance designed specifically for the healthcare industry, including pre-built frameworks like HIPAA, HITRUST, SOC 2, and NIST.
Check my evaluation of 40+ SSO tools, out of which these top 6 help optimize data security workflows, strengthen authentication, and prevent breaches.
https://www.cloudflare.com/learning/access-management/what-is-sso/
Whats wrong with Firebase?
It can be HIPAA compliant, but it isn’t out of the box. You have to upgrade to Identity Platform and sign a BAA: Identity Platform: HIPAA Implementation Guide | Google Cloud
Seeing GCP specifics not firebase specifics there.
I just found a plethora of docs. On using GC for hippa compliance.
Firebase isn’t suitable. Thanks for the info tho.
I use most all things Google in HIPAA env all the time. ¯\_(ツ)_/¯
Good thread on it here:
I am working on a healthcare app that will ultimately be used by hospitals. I was deciding on my backend stack, and was considering doing authentication using Firebase and using cloud functions for backend calls. Would this tech stack be feasible for...
9 points | 10 comments — u/atman171
I don’t want a Google sales pitch Eric
Thanks though I’ll check it out.
I’m sure there are many more viable options that don’t require GCP vendor lock in.
Google as a company isn’t something I’m looking forward to working with.
I’m not pitching you anything. But you gave false information about Firebase not being HIPAA capable, which I’m correcting, so that others have the full picture.
No I did not give false information Eric
lol
It’s not hippa compliant out of the box just like you said
I’m really tired of you inferring and then implying authority. It’s waxing and posturing you know it.
I don’t know what you’re talking about, man. Take care!