It matters because you are liable in your own right, not merely through your contract with the client. Providing IT to a healthcare organisation makes you a business associate, and a regulator investigating a breach can come to you rather than through them.
The reassuring part is that the controls it asks for are the ones a competent provider already runs — access management, encryption, audit logs, training, a disposal process for old kit. The difference is evidence. HIPAA expects you to be able to show what you do and when you last checked it, so the work is less about new tooling than about writing down what already happens.
The common misunderstanding is that compliance is a certificate. There is nothing to pass and nothing to hang on the wall. It is an operating discipline that gets assessed on whether your controls actually worked, which means the useful question is not "are we compliant" but "could we demonstrate it on a bad week".