Scale up as you grow — whether you're running one virtual machine or ten thousand.

From GPU-powered inference and Kubernetes to managed databases and storage, get everything you need to build, scale, and deploy intelligent applications.

This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.
So the answer is to move to our solution to AWS? I’m not ready to accept that.
I’ve gone through every line item in the security rule, that would pertain to being a SaaS provider, and I haven’t seen anything that I don’t think could be addressed with some thought and quality IT work. Has the DigitalOcean security team researched and found a deal breaker? If so, can they share their status so we can work together on this.
I realize our 8 virtual servers are pretty small right now, but I cannot believe the answer is simply “go away”.
Unfortunately, there’s a lot more to HIPAA compliance than just having solid IT and security controls. In order to sign a BAA, the company has to have policies and procedures for handling of PHI and has to train all of their staff on HIPAA regulations. There are also mandatory risk assessments and other procedures that have to be performed and documented.
There are other implications as well, such as insurance costs (breach insurance is on the rise) and the risk of stiff fines (up to $1.5M per incident) for non-compliance. For this reason, many hosting providers cannot or will not sign a BAA without significant fee increases. Even Amazon charges a penalty by forcing you to run dedicated instances, at an additional cost of $1500+ per month.
You might consider looking at one of the specialized healthcare cloud providers, such as Healthcare Blocks.