Earlier quoted context omitted.
How is the government restricting the supply of HIPAA-compliant software?
I suspect HIPAA-compliant software is needlessly complex, such that only a few large companies can afford to supply it. Like the tax code.
Of course, there are people who are very afraid of what might happen if they don't take HIPAA seriously even at smaller companies. I suppose those companies turn into big expensive companies pretty quickly.
Not sure how big rsync.net is, and no I'm not advertising, but their pricing is reasonable and I trust that they really are HIPAA compliant in the way that I'm willing to accept. So this isn't a strict rule, but I do think that there are a lot of situations where you have a non-compliant product that is more compliant than the "HIPAA-compliant" product.