I would not put a definitive “Yes” here until your legal/security position has been formally established.
For launch, I'd use:
Amy is designed with healthcare privacy and security requirements in mind. Our approach to HIPAA and other applicable requirements depends on the services, data and organizations using Amy.
For detailed information about Amy's security and compliance approach, see our HIPAA Compliance and Security pages.
Once your actual HIPAA position is formally established, we can make this answer much more specific.