> 2.) Violations of HIPAA lead to fines and even lawsuits from the office of civil rights. It used to be that Business Associates could hide behind the medical institutions to avoid this but with the Omnibus rules you'll face massive fines that will easily bankrupt any startup.
I agree with the last two-thirds of your post, but this doesn't match my experience. HIPAA is basically a bunch of "best effort" stuff and you can do shockingly little in terms of security and be fine by any audit I've ever seen. Unencrypted data at rest, encrypted data with keys on disk on the same machine, no SSL anywhere including external endpoints...and the auditors never asked or looked.