The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of protected health information (PHI).
AWS will sign a BAA, but they only cover the Physical Safeguards (e.g. facility access controls, etc.). TrueVault handles both the Technical and Physical Safeguards.
With AWS you still need to build your own HIPAA compliant application stack. The technical requirements include: -encryption and decryption -key management -key rotation -access control -unique user identification -emergency access -automatic logoff -audit controls -mechanism to authenticate electronic PHI -person or entity authentication -transmission security -integrity controls
I was interested in your last post on HN, as I've found it nearly impossible to sift through the bureaucratic cruft of HIPAA, HITECH, HL7, and all the other standards. A blog post on the topic would be amazing -- "What does HIPAA-compliant mean?".
The main fear I have about using your service is trusting a brand-new company for hosting. What reassurances can you provide that relying on you for my infrastructure will not screw me over if something happens to your company?