VMRacks (now hipaavault.com). I'm not affiliated, just a completely satisfied customer. As to setting up the business, I would also recommend a HIPAA auditing/hand-holding company. I use Compliancy Group (https://compliancy-group.com).
Just finished my undergrad in cis, and have been grasping at the many services in the industry. How did you find yourself in freelance within clients needing HIPAA compliant?
I am surrounded by people in the primarily private-pay Mental Health space because my (romantic) partner is a consultant in a tiny cottage industry. In my case, it's 100% "people you know". Dealing in PII suuuuuuucks because I constantly have an elevated anxiety about it. However, if it wasn't PII plus the people I know and met......then I probably wouldn't have the opportunity I have.
That said.....had I not done "this", then I probably would have done something more lucrative and "easy". I see non-PII opportunities everywhere, and (mostly) only hang around because what I do now pays the bills.
I've always wondered about how easy it would be to setup a SAAS that adheres to HIPPA.