Even though your not responding directly to me, I would be very interested to know what other companies are doing to beef of security on the iphone. (not sarcasm, I just like to see what they implemented)
Things that would have to be available to IT
1: Remote wipe, and not through MobileMe
2: Hardware encryption where the encryption keys on the device are in encrypted. (I read that the encryption key on the iphone may not itself be encrypted.)
3: Policy control, where an individual company can control what applications are allowed on the device
4: Better password security for the entire device, 4 pin passcode does not cut.
I don't know anything about what is required of Doctors, nor did you mention what they doing on the iphone or what kind of data they have stored there.
If you want to see what security is take a look at Options/Security options on a Blackberry.
This is what BB security is about:
http://docs.blackberry.com/en/admin/deliverables/7127/BB_Ent_Soln_Security_5_0_0_STO.pdf
How HSBC is using iPhone for corporate email is truly remarkable. I wonder how they match the security of BES server. Not to say anything is fool proof, but iphone with corporate bank email seems foolhardy.