The Hidden Cost of “Just Add a Compliance Checkbox”: A Healthcare Engineer’s Field Notes

https://hackernoon.imgix.net/images/2jqChkrv03exBUgkLrDzIbfM99q2-i2822f6.jpeg

There’s a phrase I’ve heard in roughly fifty different conversations across roughly fifteen different teams over the years. The wording varies; the meaning is the same.

“Can we just add a compliance checkbox?”

The version of the question is usually about a feature that handles regulated data. The team wants to ship. The compliance review hasn’t happened yet, or has happened and produced concerns. Somebody on the team — sometimes a product manager, sometimes an engineer, sometimes a director of engineering — proposes adding language to the privacy notice, or a configuration flag, or a button somewhere in the admin panel, that will satisfy the review. The team can ship. Compliance is, technically, addressed. Everybody moves on.

This works almost never. The work that compliance actually requires is not a checkbox. It’s a set of architectural commitments that change how the system handles data, who can access what, what gets...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more