So I think there is some truth to what they're saying, although I don't understand how this applies to doctors receiving payments since you're not really attaching patient information to these payments AFAIK.
HIPAA tends to create a situation where you have the minimum possible compliance (e.g. the most basic encryption that hasn't been broken or just disk-based encryption rather than doing something like individual record encryption and using a a pepper) for the highest possible cost. Companies who would provide more robust protection tend not to because of the legal risk, so you have companies that fill in the space with lower quality software but are willing to put their name on a business associate agreement.
The focus then becomes the advertising of the product as HIPAA compliant rather than making it more compliant.
You do have larger companies who seemingly have better compliance, but I remember someone telling me they had to pay $700 a month for Tiger Connect for example. There is more competition in this area today, so prices have gone down, but I remember a few years back it being pretty rough on what you could get where people would stamp their product as compliant. The least expensive options seemed like there was a "messages.php" file somewhere leaking all the secure messages.
It kind of stifles innovation in a way as well. For example, there is no secure messaging product that I know of that uses the methods that Signal uses to encrypt messages. Notwithstanding the location of Signal's data, no one in compliance is going to allow use of the app without a business associate agreement. So the less-secure apps win.
It's really about who is willing to sign a business associate agreement and take the fall if something bad happens. Complexity just varies based on the implementing-companies aversion to risk. Bigger companies (appear to) have more to lose and therefore (might) implement more robust and complex solutions. A smaller company might flout more best practices than you're willing to accept - and then you can pretend to be ignorant rather than asking for an explanation about their infrastructure and hope it doesn't bite you in the ass (since you're still responsible for vetting companies even when you've initiated a business associate agreement). Both are "HIPAA-compliant", but the smaller company probably isn't HIPAA-compliant in the way one might hope.
Of course, there are people who are very afraid of what might happen if they don't take HIPAA seriously even at smaller companies. I suppose those companies turn into big expensive companies pretty quickly.
Not sure how big rsync.net is, and no I'm not advertising, but their pricing is reasonable and I trust that they really are HIPAA compliant in the way that I'm willing to accept. So this isn't a strict rule, but I do think that there are a lot of situations where you have a non-compliant product that is more compliant than the "HIPAA-compliant" product.
Not sure if I agree with the other person, but I believe the point is that it takes more time and money to comply with regulations, which makes it harder to build that software, which means that fewer will do that, which means those that do can charge more.