Sure, you can set up custom checks for HIPAA. But you're just building a compliance house of cards.
First, you're trusting that Sysdig's rule engine accurately maps to the actual risk. Their out-of-the-box policies are generic. Your custom checks will be brittle—container paths change, image tags update, and your "compliance" breaks silently. Then you get a false sense of security.
Second, the real cost isn't the setup time. It's the maintenance. Every time the platform or a regulation tweaks, you're on the hook to review and update every single custom rule. The vendor isn't liable when your tailored check misses a real violation. You own that gap.
You're better off with a dedicated compliance tool. Using Sysdig for this is like using a Swiss Army knife for surgery.
Just saying.