The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of protected health information (PHI).
AWS will sign a BAA, but they only cover the Physical Safeguards (e.g. facility access controls, etc.). TrueVault handles both the Technical and Physical Safeguards.
With AWS you still need to build your own HIPAA compliant application stack. The technical requirements include: -encryption and decryption -key management -key rotation -access control -unique user identification -emergency access -automatic logoff -audit controls -mechanism to authenticate electronic PHI -person or entity authentication -transmission security -integrity controls