Is it compliant to store HIPAA data provided by my customers in JIRA?
This. As there's no such thing as HIPAA certifications, compliance comes from your specific business rules and configuration. In addition to your configuration, the global support and operations teams at Atlassian will have access to your data per https://www.atlassian.com/hosted/security
I am really trying to determine if I can use JIRA for support for our customers. Some issues reported by customers involves PHI, such as on 8/1/13 Jane Doe had a A&D service and it was not approved correctly. This would be considered HIPAA data, and my question is, is JIRA OnDemand
That is roughly what I'm getting at - you'll need to go through your requirements and investigate whether Jira can match them. We can't give you a simple yes or no because we don't know what your entire set of requirements might be.
Even then, looking at the case you've just presented, the answer is only "probably", because it depends on how you decide to configure it. It'll certainly track all the data you enter and update, but whether it's compliant with your interpretation of the hipaa rules is still up to you.
Your best bet is probably to email sales@atlassian.com and ask them through that channel.
HIPAA is not the only regulatory set of requirements that software and services that Atlassian provides will need to deal with. Rather than send thousands of compliance questions to Atlassian's sales force (whom I'm assuming are not legal and regulatory experts on how Atlassian's products and services are utilized in various different industries), why not take the bull by the horns, and proactively provide the certifications and assurance for these customers that they've all been begging for? I work for one of those Fortune 100 companies who has not endorsed the use of your developement products because we continually receive these types of evasive answers from Atlassian. The problem is... your products are some of the best we've seen... we simply cannot risk using unassured, non-certified software products or services in one of the largest payment systems on the planet.
One thing that can help you be HIPAA compliant is making sure that sensitive data is not stored in places where it shouldn't and that access to it is properly audited. For this you can use our recently released PII Protector for JIRA add-on. It monitors sensitive PII like credit card numbers, social security numbers, addresses, etc. stored in Atlassian JIRA, reports it, provides admins with a convenient UI to manage it, to audit access to it, and optionally to hide or to erase it.
It looks like you're new here. Sign in or register to get started.