Earlier quoted context omitted.
That seems like a fairly reasonable thing given you're talking about encrypted PHI... it's some extra $ for a considerable reduction to overall attack surface when processing the most sensitive type of personal data. I don't think this meets OP's definition of "wrong".
In practical terms I don't agree that the threat of someone doing all of the following things is worth worrying about (in comparison to many other more likely failures): 1) determine what physical hardware in aws the target is running code on 2) somehow get the aws virtual machine manager to let the attacker run their malicious code on the same hardware 3) somehow pierce the protections of the virtual machine to read…
HIPPA is a very easy compliance standard to meet. If it seems difficult to meet those requirements with your standard tool configurations, you should think about what that means with respect to the integrity of your data.