Notably, Rackspace's BAA is public [2] (I'm not associated with Rackspace) and reasonably supports the standard language (I am not a lawyer).
[1] http://www.hhs.gov/ocr/privacy/hipaa/understanding/covereden... [2] http://www.rackspace.com/en-us/information/legal/hipaabaa
In particular, Amazon's agreement included: A clause that puts all of the burden for securing data on the CE. No terms outlining how the BA would respond to breaches of unsecured PHI. Lack of specification about the BA’s level of access to PHI. A non-disclosure clause.
EDIT: Google Cache for this page... http://webcache.googleusercontent.com/search?q=cache:tzvzlVG...
https://aws.amazon.com/compliance/hipaa-compliance/#What_Ser...?
HIPAA doesn't actually protect you as much as you'd think--for example everyone who is signed on as a business partner (and similarly HIPAA qualified) can, if memory serves, view records.