Thanks for the help, I appreciate it.
> You basically need to fully commit to being HIPAA compliant if you go directly with a service.
Do you mind explaining that a little more? Are there specific actions that need to be taken in order to be HIPAA compliant if no data is being saved on the server?