One of the main reasons why healthcare players were moving onto Azure was for in-built HIPAA compliant OpenAI access. We've been able to help our customers directly sign BAAs with OpenAI so this wasn't a concern.
Sorry but what?
Because of the close partnership with Microsoft and OpenAI, Azure makes it easy to get HIPAA compliant access to certain OpenAI models without having to go through OpenAI directly. This is why a lot of AI healthcare companies were building on Azure at first. Hope this clarifies!
Nothing could be further from the truth.
Another POV is that the compliance companies sell the holistic social experience of compliance. The people for whom this matters need checkboxes and don’t mind paying for consulting disguised as a CSA. In fact they may even prefer it.
Completely get where you’re coming from w.r.t. organizations looking to check a box. If we wanted to sell to those organizations, we would stop short of architecting their infrastructure and implementing best practices. A checkbox is never enough, and a point in time review can be easily gamed.
We're (now only partially) on Azure for reasons stated upthread: desire from the industry. We've partially moved since, and the experience as a whole has soured me on Azure as a reliable cloud provider (I've had to engage with support far more often). Their support, in particular, is terrible¹, and a lot of their offerings IME are less stable or harder to work with than AWS. I'm now moderately experienced with GCP, and I think GCP has them beat, too.
¹missed SLAs, a huge desire to close tickets prematurely, failures to address things asked of them, really bad communication skills, constantly divorcing replies into new threads, dredging up asked & answered stuff, repeatedly asking questions covered in the original ticket's opening set of answers, asking the customer for stuff they should know, etc.
Regulatory is where a country in which we do business has requirements for how we run our infrastructure. Luxembourg is notorious for being the most demanding.
I haven't done healthcare stuff in GCP or Azure so I can't compare, but AWS is _not_ a blocker for HIPAA.
My understanding is that Google will not agree to any of the liability provisions inherent to a BAA, no matter how large your size.
> Google will enter into Business Associate Agreements with customers as necessary under HIPAA.
Huh! That's a pleasant surprise.