These suggestions are very sound, and I'd suggest the same, but they are overly pedantic for a contract value at a maximum of $2.4k/year. I've seen a number of healthcare providers bound by HIPAA who don't have any of these features (and way less) and are still very competitive in the market. It's not to say you shouldn't do these things, but they are not what will win you contracts for your suggested pricing tiers. More importantly they will probably burden your business from a cost perspective (assuming you're still relatively new to the market).
TL;DR - Put them on the list, but don't let them burden you from making money.