HIPAA app cost in 2026: $17,500 to $52,500 on top of the build, and who signs a BAA
TL;DR HIPAA adds about $17,500 to $52,500 to a health app's build at US agency rates in 2026, plus hosting with vendors that sign a business associate agreement, from about $1,419 a month on Vercel and Supabase. A wellness app people download and fill in themselves is usually outside HIPAA and under the FTC's Health Breach Notification Rule instead, while an app a clinic or health plan pays you to provide is under HIPAA.
- HIPAA only applies when you work for a covered entity, like a clinic or a health plan, or for one of their vendors.
- A wellness app people use on their own is usually under the FTC's Health Breach Notification Rule instead, at up to $53,088 per violation.
- The extra build work is about 175 to 350 hours, so roughly $17,500 to $52,500, with the audit log usually the biggest line.
- Vercel signs a BAA on Pro for $350 a month and Supabase on Team from $599 plus its HIPAA add-on, while AWS and Google Cloud charge no BAA fee.
- Firebase Authentication, the Gemini API, ChatGPT's consumer plans, Resend, Postmark, SendGrid, Calendly and the AI app builders do not sign a BAA.
In this article
- Does HIPAA apply to your app?
- If HIPAA does not apply, which rules still do?
- What HIPAA adds to the build
- Which vendors sign a BAA, and on which plan?
- What a BAA-ready stack costs a month
- Is Firebase or Supabase HIPAA compliant?
- Can you send patient data to ChatGPT, Claude or Gemini?
- Can you build a HIPAA app with Lovable, Bolt or Replit?
- Did the HIPAA rules change in 2026?
- What happens if you get it wrong
- How we work on health products
- When we are not the right fit
- How to get a number for yours
HIPAA adds about $17,500 to $52,500 to the build of a health app at US agency rates in 2026, plus the monthly cost of hosting it with vendors that sign a business associate agreement, which on a Vercel and Supabase stack starts at about $1,419 a month before usage. On AWS or Google Cloud the agreement itself has no published fee, so you pay normal prices for the services it covers.
Before any of that, it is worth checking whether HIPAA applies to you at all. A wellness app that people download and fill in themselves is usually outside HIPAA and under the FTC's Health Breach Notification Rule instead, while an app a clinic or a health plan pays you to give its patients is under HIPAA, and then every vendor that touches patient data has to sign a BAA.
I run the engineering at Axtra Studios, and this guide goes through who HIPAA applies to, what it adds to the build, which hosting, database and AI vendors sign a BAA on which plan, and what that stack costs a month. It is general information and not legal advice, so your compliance lead and your counsel decide what the rule requires for your product.
Business associate agreement (BAA)The contract HIPAA requires before a vendor creates, receives, keeps or sends patient data for you. It says what the vendor may do with the data, that it will protect it and report incidents, that its own subcontractors sign the same terms, and that it returns or destroys the data at the end.
Does HIPAA apply to your app?
HIPAA only binds covered entities, which are health plans, clearinghouses and providers that bill insurers electronically, and their business associates, which are the vendors that create, receive, keep or send patient data for them. The US Department of Health and Human Services says plainly that a company that is neither does not have to comply, and it lists an app developer hired by a covered entity to give its patients an app as a business associate.
| Your app | Does HIPAA apply? | What applies |
|---|---|---|
| A wellness, habit, sleep or mood app people download and fill in themselves | Usually no | The FTC's Health Breach Notification Rule, state laws like Washington's My Health My Data Act and Apple's App Store rules |
| The same app, when a doctor recommends it or a user sends a report to their doctor | Usually no | The same rules as above |
| An app a clinic, hospital or health plan pays you to give its patients or members | Yes, you are a business associate | HIPAA's Privacy, Security and Breach Notification Rules, a BAA with your client and a BAA with each vendor |
| A wellness program run for an employer's health plan | Often yes | HIPAA, through the health plan |
| One company with a health plan edition and a consumer edition | Yes for the health plan edition, and no for the consumer one if the data stays separate | Both sets of rules, with the data kept apart |
Does HIPAA apply to your app? · Source: From HHS guidance on covered entities, business associates and health app scenarios, and the FTC's Health Breach Notification Rule, checked October 10, 2026. General information, not legal advice.
The line is who you work for, not what the app does. HHS's own scenarios say a developer is not a business associate when people download the app and enter their own readings, even if their doctor recommended it, and that one company can have a health plan edition under HIPAA and a consumer edition outside it, as long as the data stays separate.
If HIPAA does not apply, which rules still do?
A health app outside HIPAA still has rules, and the main one is the FTC's Health Breach Notification Rule. Since its 2024 update it reaches apps that track fitness, sleep, mental health or fertility, and a breach under it includes sharing data without the user's permission, not just a hack, which is how GoodRx came to pay a $1.5 million penalty in 2023.
The rule gives you 60 days to tell the people affected, and the FTC at the same time if 500 or more are involved, and the penalty is up to $53,088 per violation, which the FTC kept at the 2025 level for all of 2026.
State laws go further in places, so Washington's My Health My Data Act covers health data outside HIPAA and lets people sue, and Apple's App Store rules bar using health data for advertising and storing it in iCloud whether HIPAA applies or not.
What HIPAA adds to the build
If HIPAA does apply, the extra work is in a few specific places, and most of it is engineering you would want in any serious health product anyway. The hours below are how I would scope each part on top of a normal build, and the dollar column prices them at what US agencies charge, which Clutch puts at $100 to $149 an hour for web development.
| Line item | What it covers | Hours | At US agency rates |
|---|---|---|---|
| Data map and risk analysis support | Where patient data lives, who touches it and which vendors need a BAA, with your compliance lead | 20 to 40 | $2,000 to $6,000 |
| Access control | Roles, a unique login for every user, multi-factor sign-in and automatic logoff | 30 to 60 | $3,000 to $9,000 |
| Audit log | A record of every read and change to patient data, with a screen to review it | 40 to 80 | $4,000 to $12,000 |
| Encryption and the side channels | Encryption in transit and at rest, and no patient data in logs, emails, push text or analytics | 30 to 60 | $3,000 to $9,000 |
| Backups and a tested restore | Point-in-time recovery and a restore drill before launch | 15 to 30 | $1,500 to $4,500 |
| Security review before launch | An internal review of the app and its settings, with a third-party test priced separately | 20 to 40 | $2,000 to $6,000 |
| Documentation | The evidence your compliance lead keeps for six years | 20 to 40 | $2,000 to $6,000 |
What HIPAA adds to the build of a health app · Source: Hours are how Axtra Studios scopes this work on top of a normal build, totalling 175 to 350. Rates from Clutch's web development pricing guide (US agencies, $100 to $149 an hour). Checked October 10, 2026.
The audit log is usually the biggest line, because the rule expects a record of who looked at patient data and not only who changed it, and someone on your team needs a screen to review it.
Keeping patient data out of the side channels is the one most teams miss, so the error logs, the emails, the push notification text and the analytics events all need checking, because each of those services needs its own BAA if patient data reaches it.
The base build sits underneath all of this, and our guides to web app and SaaS cost, mobile app cost and MVP cost and timeline cover that part. A third-party penetration test is extra, and one security firm, Lorikeet, publishes $7,500 to $35,000 for a web app depending on its size, while HHS offers a free security risk assessment tool for small and medium providers.
Which vendors sign a BAA, and on which plan?
Every vendor that creates, receives, keeps or sends patient data for you needs to sign a BAA with you, and HHS says that holds even for a cloud host that only stores encrypted data it cannot read. Here is who signs, on which plan and at what published price, as of October 10, 2026.
| Vendor | Signs a BAA, and on which plan | Published price | Watch out for |
|---|---|---|---|
| AWS | Yes, on any account, accepted in AWS Artifact | No BAA fee published | Only its HIPAA-eligible services may hold patient data |
| Google Cloud | Yes, on any account | The same prices as everyone else | Check the list of covered products |
| Firebase | Partly, through the Google Cloud BAA | The same as Google Cloud | Firebase Authentication is not covered, so use Identity Platform, and keep patient data out of Crashlytics, messaging and Analytics |
| Microsoft Azure | Yes, automatically in its product terms | No separate fee stated | Check which services are in scope |
| Vercel | Yes, on Pro as an add-on or on Enterprise | Pro $20 a month plus $350 a month for the BAA | Not on the free Hobby plan |
| Supabase | Yes, on Team or Enterprise | Team from $599 a month, a HIPAA add-on a Supabase team member quoted at $350, and point-in-time recovery from $100 | Several security settings must be on, and no patient data in public storage |
| Neon | Yes, on Scale | No extra cost today, with a 15% surcharge announced | Some features, like its Data API, are not covered |
| Render | Yes, on Scale or Enterprise | $499 a month plus compute, and 20% on all usage | The switch cannot be undone |
| Fly.io | Yes, with the BAA pre-signed | $99 a month for its HIPAA package | Check that each service you use is in the contract |
| Cloudflare | Yes, on Enterprise only | Not published | Sign before any patient data flows |
| OpenAI API | Yes, for accounts set up for modified data retention | No BAA fee stated | Live web search is not covered, and ChatGPT Free, Plus, Pro and Business are not eligible |
| Anthropic API | Yes, once the primary owner signs and sales turns it on | Not published | Batch, Files, code execution and some other features are excluded |
| Gemini | Yes on Google Cloud | The same as Google Cloud | Not through the Gemini API or AI Studio |
| Twilio | Yes, with its Security or Enterprise Edition | Not published | SendGrid email is not covered |
| Amazon SES | Yes, under the AWS BAA | $0.10 per 1,000 emails | Set it up inside a covered AWS account |
| Paubox | Yes, on every plan | Free for 300 emails a month, paid plans from $104 a month billed yearly | Check the plan's email limit |
| SendGrid, Postmark and Resend | No | Not applicable | Do not send patient data through them |
| Clerk, Auth0 and Stytch | Yes, on Enterprise only | Not published | Or use the platform's own sign-in under its BAA |
| Sentry | Yes, on Business and up | $80 a month billed yearly | Remove patient data before it is sent |
| PostHog | Yes, on Boost, Scale or Enterprise | Boost listed at $250 a month | The managed reverse proxy is not covered |
| Stripe | No, and none is needed for card payments | Not applicable | Its terms bar patient data, so keep diagnoses out of payment descriptions |
| Zoom | Yes, on any paid plan | Pro from $14.16 per user a month billed yearly | Turn on the BAA before the first visit |
| Calendly | No | Not applicable | Do not collect patient data through it |
| Lovable, Bolt and Replit | No | Not applicable | Prototype with fake data only |
Who signs a BAA, on which plan, at what published price · Source: From each vendor's own HIPAA, pricing or terms page, checked October 10, 2026. Supabase does not print its HIPAA add-on price, and the $350 figure is a Supabase team member's answer on its GitHub discussions.
Two rows catch people out. Stripe does not sign a BAA, and it does not need to for card payments, because HIPAA has an exception for payment processing, but its terms still forbid sending it patient data, so diagnoses and visit details stay out of payment descriptions. And the AI app builders do not sign at all, which our guide to taking an AI-built prototype to production covers from the other side.
What a BAA-ready stack costs a month
The fixed monthly cost depends a lot on the stack, so here are the usual ones from published prices only. These are the fees before any usage, and the email, error tracking and seats still come on top.
| Stack | What signs the BAA | Fixed monthly cost | Still to add |
|---|---|---|---|
| Next.js on Vercel with Supabase | Vercel and Supabase | About $1,419: $20 and $350 on Vercel, $599 and $350 on Supabase and $100 for recovery | Usage, seats, an email service that signs and error tracking |
| Render with Neon | Render and Neon | $499 plus 20% of usage on Render, and no extra cost on Neon today | Usage on both, email and error tracking |
| Fly.io | Fly.io | $99 for the HIPAA package on a paid plan | Check that the database you use is covered, then email and error tracking |
| AWS | AWS | No BAA fee, so you pay for the services you use | The engineering time to set it up well |
| Google Cloud with Firebase | Google Cloud | No HIPAA premium | Identity Platform in place of Firebase Authentication |
| Heroku Shield | Heroku | Up to about $3,500 for the space, a dyno and Postgres | The BAA fee itself is not published |
What a BAA-ready stack costs a month, before usage · Source: From Vercel, Supabase, Render, Neon, Fly.io, AWS, Google Cloud and Heroku pricing pages, checked October 10, 2026.
The big clouds look cheapest on paper, because AWS and Google Cloud charge nothing extra for the agreement, but setting them up properly takes more engineering time than a managed platform. Vercel with Supabase costs more each month and much less to set up, which is usually the better trade for an early product, and it is a stack we build on often.
Is Firebase or Supabase HIPAA compliant?
Supabase signs a BAA on its Team plan, from $599 a month, with a paid HIPAA add-on that it does not print on its pricing page, and a Supabase team member quoted it at $350 a month. It also requires point-in-time recovery, from $100 a month, along with settings like enforced SSL and network restrictions, and patient data cannot go in a public storage bucket.
Firebase is the one founders get wrong. Google's BAA covers Firestore, Cloud Storage, Cloud Run functions and Identity Platform, but Google's own comparison table marks Firebase Authentication as not covered, and Firebase Hosting, the Realtime Database, Crashlytics, Cloud Messaging and Analytics are not on the covered list, so a HIPAA app on Firebase signs in through Identity Platform and keeps patient data out of those products.
Can you send patient data to ChatGPT, Claude or Gemini?
Not through the consumer apps. OpenAI signs a BAA for its API when the account is set up for one of its modified data retention options, live web search is not covered, and its HIPAA guide from July 2026 says ChatGPT Free, Plus, Pro and Business are not eligible.
Anthropic signs a BAA for its API once the organization's primary owner signs and its sales team turns it on, with features like Batch, Files and code execution excluded.
Gemini is covered when you use it on Google Cloud, but not through the Gemini API or AI Studio, and HHS's own list of business associates now includes an AI chatbot vendor on a provider's patient portal, so the AI layer needs the same paperwork as the database. Our guide to AI chatbot and agent cost covers the build and the monthly bill, and our AI solutions page has more on how we build that layer.
Can you build a HIPAA app with Lovable, Bolt or Replit?
Not on their hosting. Lovable says it does not sign BAAs and its terms forbid patient data, Replit tells you to deploy a medical site on a host that offers one, and Bolt calls itself "HIPAA ready" without naming a BAA anywhere we could find. A prototype built with fake data is fine, and the code then moves to a stack where every vendor has signed.
Did the HIPAA rules change in 2026?
Not yet. HHS proposed a large update to the Security Rule in January 2025, and the 2026 regulatory agenda moved it to long-term actions with a target of July 2027, so the current rule still applies. It is still worth building so that multi-factor sign-in, an inventory of your systems and yearly testing are easy to add, since those are in the proposal.
The penalties did not rise either. HIPAA fines run from $145 to $2,190,294 per violation depending on how much the company knew and how fast it fixed things, with a yearly cap of $2,190,294 for the same violation, and the FTC kept its own penalty at the 2025 level after the 2026 inflation adjustment was cancelled.
What happens if you get it wrong
The cases are usually ordinary mistakes. Health Fitness Corporation, which runs wellness programs for employers, paid $227,816 to HHS in 2025 after a misconfigured server left patient data open to web crawlers, and it had not done an accurate risk analysis, which is the first thing the rule asks for.
And there is no official HIPAA certification to buy your way out of it. HHS says it does not recognize private certifications, so a vendor's badge tells you about the vendor and not about your product.
How we work on health products
We have not taken a product through a HIPAA audit, and we would not claim to. Where a product handles patient data, we scope the hosting, access and audit requirements with your compliance lead at the start, choose providers who will sign a business associate agreement and build to that plan, and your counsel decides whether it meets the rule. Our health and wellness expertise page has more on the work behind this guide.
When we are not the right fit
If you need deep integration with a hospital's records system like Epic or Cerner, software regulated as a medical device or a HITRUST certification by a deadline, a specialist health technology firm is the better choice. And if your budget is under about ten thousand dollars, a no-code platform with a published HIPAA plan, like Knack from $499 a month, is honestly a cheaper first step.
Where we fit is a health or wellness product on a modern stack, so a patient-facing web app or mobile app with the access control, the audit log and the vendor agreements planned from the first sprint, as part of our web development and mobile app development work.
How to get a number for yours
The tables will tell you whether HIPAA applies and which stack fits, and a short call will turn that into a number. We can go through who your customers are, what data the app holds and which vendors it needs, and send you a written scope priced in milestones with the monthly hosting cost next to it.
Our HIPAA stack and BAA checklist is a plain spreadsheet with every vendor above, the plan each one needs and a column to record when its BAA was signed, and it is really worth filling in before any real patient data arrives.
The rules in this guide come from HHS's pages on covered entities, business associates, cloud computing and its health app scenarios, the FTC's Health Breach Notification Rule and its 2026 penalty notice, the Security Rule agenda entry, the HIPAA penalty table and Washington's My Health My Data Act.
Vendor terms and prices come from AWS, Google Cloud, Vercel, Supabase, Neon, Render, Fly.io, OpenAI, Anthropic, Twilio, Paubox, Sentry, PostHog, Stripe and Lovable, with the penetration test price from Lorikeet Security, all checked on October 10, 2026. Rates come from Clutch's web development pricing guide, and everything here follows our editorial policy.





