A couple of notes:
Knowing that YOU audit things is nice, but I also want you to be audited by a 3rd party in some formal context (SSAE, ISO27000, whatever).
You guys are apparently really early, but if I'm going to build a HIPAA app, and you're the ones holding my data, we're going to have to sign a legally binding flowdown agreement: that's not usually compatible with 'click to sign up' style stuff. Have you had a legal team look at how that process is supposed to work?
Are you actually hosted on AWS (I know the marketing page is Heroku, but I understand that doesn't mean the actual app is)? Have you signed a business associate agreement with your cloud provider, if you're using one?
In fact, there's no mention of legal anything anywhere on your site (SLA, ToS, etc.) I assume some of this is behind the customer signup link? It really needs to be out front - anybody doing HIPAA has (as you should know!) pretty intense legal/regulatory issues to make sure are contractually guaranteed.
And, beyond all that, and this might just be me:
I have no fucking clue what your system provides? It looks like it's an HTTP data store, but that could mean a million things. Is it more like S3 or something like Redis?
That said, the site is good looking! If you want to put out 'rapid start' type stuff, you should probably have significantly more api and other information out on the public page (assuming it's behind the signup link).