So I think there is some truth to what they're saying, although I don't understand how this applies to doctors receiving payments since you're not really attaching patient information to these payments AFAIK.
HIPAA tends to create a situation where you have the minimum possible compliance (e.g. the most basic encryption that hasn't been broken or just disk-based encryption rather than doing something like individual record encryption and using a a pepper) for the highest possible cost. Companies who would provide more robust protection tend not to because of the legal risk, so you have companies that fill in the space with lower quality software but are willing to put their name on a business associate agreement.
The focus then becomes the advertising of the product as HIPAA compliant rather than making it more compliant.
You do have larger companies who seemingly have better compliance, but I remember someone telling me they had to pay $700 a month for Tiger Connect for example. There is more competition in this area today, so prices have gone down, but I remember a few years back it being pretty rough on what you could get where people would stamp their product as compliant. The least expensive options seemed like there was a "messages.php" file somewhere leaking all the secure messages.
It kind of stifles innovation in a way as well. For example, there is no secure messaging product that I know of that uses the methods that Signal uses to encrypt messages. Notwithstanding the location of Signal's data, no one in compliance is going to allow use of the app without a business associate agreement. So the less-secure apps win.