This is about three years overdue, but at least it's here.
How close does it come to making PCI-DSS Level 1 attainable on Heroku? What about HIPAA?
"This is about three years overdue."
I couldn't agree more
Recommended write-up: What is Heroku: getting started with PaaS development