Related Posts
If you have a business in health care or a related industry like health tech, one of the problems you probably face is deciding what kind of solutions you’re going to use to power your business.
On one side of the spectrum, you have point solutions that are built for health care—but they can be really rigid or outdated. On the other side, you have no-code applications, which are exploding in popularity. You’ve got lots of functionality, and you can build custom experiences without the price tag of custom development.
But oftentimes, these no-code solutions aren’t positioned to protect sensitive information. So how do you find a great no-code application that’s also HIPAA compliant? That’s where Knack comes in.
Introducing Knack as a HIPAA-Compliant Platform
Hi, I’m Dan Leeman from AutomationHelpers.com, and we’re a Knack implementation partner.
Oftentimes, software vendors will dance around the issue of being HIPAA compliant. They’ll say something using transitive logic—like, “Well, if AWS is HIPAA compliant and we’re built on AWS, then yeah, we’re HIPAA compliant.”
But you’ll want to make sure you do your research and figure out whether that organization is actually supporting the protection of your data.
What Makes Knack HIPAA Compliant?
The first thing is that Knack will sign a BAA. They’re the business associate, you’re the covered entity, and the BAA describes how you’ll collectively work to protect that data.
Now, if the other software vendors you’re looking at aren’t willing to sign a BAA, that’s probably a sign they’re not taking HIPAA compliance seriously.
Next, Knack is architected on AWS GovCloud. That’s the environment that hosts the most sensitive information and follows the most stringent security and compliance requirements that Amazon has to offer.
Access Controls and Auditing
Next, how are access controls being handled?
In Knack’s case, they manage password requirements, inactivity timeouts, and user roles and permissions—controlling who can see what within the application.
You also want to make sure your software vendor is logging and auditing activity to create an appropriate paper trail. Knack manages changes to access, password changes, logins, and any kind of login attempts happening in the background, creating that audit trail.
Policies, Backups, and Incident Response
Does your vendor have appropriate policies in place?
How are they managing disclosures? What do they do as part of incident response? And are your backups in place in case something happens?
We’re going to show a little bit in the application and also talk about a case study.
Get Started with Knack’s HIPAA-Compliant Plans
Before we do that, I want to take a second to direct you to Knack’s sales page. If you’re interested in their HIPAA-compliant plans, you can contact the sales team. They’ll get back to you with information about how to get started.
Case Study: CureTech’s Customer Portal
Next, let’s talk about CureTech. CureTech is a supplier of durable medical equipment.
They built out a really powerful customer portal using Knack. What they found was that many of their competitors were still using spreadsheets to manage this information.
By building on top of Knack, CureTech was able to automate their business processes. If you want to check out more on CureTech, we’ll link to the case study in the description below.
Building a Practice Management App with Knack
So, Knack is a good tool if you’re looking for a HIPAA-compliant software vendor in the no-code space. But how easy is it to actually build your own application?
In this case, when you’re in the Knack dashboard, you can simply search for a “practice management system.” We’re going to walk through one of the templates they’ve already created.
You’re not restricted to using this, but for many of you, it gives you a leg up to have a system in place that you can modify.
Custom Roles and Permissions in the Template
One of the first things you’ll notice when you spin up this template is the different roles that are already created—doctor/provider, patient, practice owner, office manager, and front- and back-office staff.
This is so important because it allows you to restrict who can do what. If someone doesn’t need access to medical records, they don’t get it. If you’re a patient, you’re restricted to your own relevant information.
If we click on “patient,” we can see all the connections to different tables—like medications, prescriptions, appointments, insurance plans, and emergency contacts.
Viewing and Editing Appointment Data
If I’m logged in as the practice owner, I get access to everything. In the Knack-built application, I can see appointment data and view or edit the service line items. I’ve got notes from past appointments and can easily add new ones using a form.
Now, if I’m logged in as a patient, I can only see my appointment history. I can view the details of those appointments—but with far fewer options. The system doesn’t need the same level of input from me. That gets handled on the back end.
Customizing Views and Automating Workflows
All of this is easy to modify within the Knack UI.
I can view all the pages in our application. If I’m the doctor, I can open a menu to access scheduling pages and appointment details. Let’s say I want to add a new view—I’ve got several types to choose from. I can even add a map to display a location.
Knack also has a built-in automation layer called “Tasks,” where you can do things like send an email after an appointment is complete. You can build custom automations based on the data flowing through your app.
Ready to Get Started?
Now that you’ve seen Knack as a powerful no-code app builder and a HIPAA-compliant solution, you can get started today using the link in the description below.