> A couple of fields could be imported by integrating with existing EMR/EHR through HL7, but at this early stage I don't envision any integration and these fields will be input manually. The MVP works this way, for example (and has been used in a few hospitals).
In that case, yeah, hospitals will tend to differ very significantly; once you go beyond the HL7 world, any hope of a standardized interface goes out the window. Expect hospitals to run their own copies of your database in that case, and expect them to be very strict about what access you get.
> Does this mean you've seen off-site hosted apps using these HIPAA PAAS providers being used by hospitals "in production" (so to speak)?
I've yet to see a HIPAA-complaint PaaS vendor in use by an actual hospital, but it's worth mentioning that at least one such vendor - Catalyze - claims Blue Shield and the VA hospitals as customers.
I have, however, seen off-site EMRs in use by hospitals, particularly (as I mentioned previously) CPSI (though the hospital I worked for - which was, at the time, apparently CPSI's largest customer - eventually strongarmed them into providing support for an onsite server). Such EMRs are typically hosted on hardware owned and operated by the vendor.
Most hospital districts, multi-facility providers, etc. will opt for a single installation of an EMR throughout all their locations. Usually this will be facilitated using a provider-wide VPN, so that'll probably help your particular usecase somewhat. In most cases, this is as close as you're going to get to "off-site" once you get to larger providers, though - again - deviations from this are not entirely unheard of.
> Is this regardless of using a HIPAA-compliant PAAS, or only in the case where we don't? I'm already dreading the answer ;)
HIPAA-compliant PaaS products are pretty new, so this answer will undoubtedly change over time, but currently, such a PaaS will only flatten that expontential curve to maybe a linear one. Small hospitals and clinics will certainly be interested, since many of them dread having to manage any sort of IT infrastructure, to the point of even contracting out to their competitors in some cases (as I witnessed firsthand) instead of trying to do anything themselves. Once they've gone forward with their own IT department, however, the chances of even a HIPAA-compliant PaaS being deemed suitable starts to dwindle, and emphasis on self-hosted solutions grows stronger and stronger.