Violation of what specifically?
Because HIPAA does not say you cant store data with third parties. That would be every cloud EMR out there.
That's my point though. Is HIPAA says nothing technical about who can store data, just who's responsible for it getting out.