most requirements overlap with PCI (having built both banking and healthcare systems, PCI is much more demanding if still superficial)
the hardest part is paperwork and staff procedures
the most expensive part, amd i am not sure if this solution addresses this, is every single hospital customer i have insists on a totally independent 3rd part audit. what that entails is totally arbitrary but it costs ~25-50k per year. they would not, for example, take the internal audit of the vendor providng hipaa compliance as sufficient. however, if the vendor also provided an audit by an external party, i suspect that would work
be sure this or any other vendor is willing to sign a BAA with you specific to each customer
Just to add a few more points. On the technology side you want to make sure you have data encrypted "at rest" and "in transit". i.e. At rest means things like running AES encrypted drives for your DB data storage. AWS has docs & case studies on this and is HIPAA compliant. Just don't use RDS, it isn't HIPAA compliant yet.
and Emr/ehr vendors fall into a different kettle of fish for becoming meaningful use certified which is orthogonal to hipaa. i suspect most consumer health apps can ignore that, though