Thanks for the advice. Yeah, my other option it seemed was to go with Rackspace dedicated managed hosting at over $1,000 per month, which is a little bit high for a startup's budget.
Is it possible to just prototype the service with non-sensitive data during development period and migrate to HIPAA compatible servers when you have customers?
If you already have customers, bake the hosting in to the price. They're almost certainly used to paying for things like that already, and I assume that if your app has to be HIPAA compliant, that it probably already has a $xx,000 price at a minimum anyway, so that should work out just fine.
That's a good point. I just wanted to have something lined up from the get-go, but I see what you mean. Enterprise and health care customers are accustomed to paying large fees for compliant environments, so baking it into the price shouldn't be much of an issue. Thanks.