Skip to main content

HIPAA Compliant App Hosting: Which Platforms Sign a BAA, and What They Charge (2026)

By Joseph Abear ·
HIPAA App Hosting

Last updated: September 11, 2026

HIPAA compliant app hosting is any platform that will sign a Business Associate Agreement (BAA) for the exact services your app uses, plus the setup you add on top. In 2026 most developer platforms will sign one. Almost every one hides it behind a paid plan, an add-on, or a separate product line. That is the trap for founders and developers. The free tier you built on is rarely the tier that signs. This guide checks ten platforms against their own pages. Each gets a HIPAA compliant app hosting verdict with a price attached, verified on September 11, 2026. Prices and terms change. Confirm with each vendor before you commit.

TL;DR: Quick answer

  • Heroku, Vercel, Netlify, Render, Railway, Fly.io, Supabase, DigitalOcean, AWS, and Google Cloud all sign a BAA in some form. None of them sign on a free plan.

  • The compliant tier costs more. Supabase Team starts at $599 per month before its HIPAA add-on. Render's HIPAA workspace starts at $250 per month plus a usage fee. Vercel's BAA is a paid add-on on Pro. Heroku requires its Shield product line.

  • On AWS, ECS, EKS, Fargate, Elastic Beanstalk, Amplify, and Lambda are on the September 3, 2026 eligible list. App Runner and Lightsail are not.

  • Firebase branding is not on Google's list. Google's covered products are what count. Firestore, Identity Platform, Cloud Run, Cloud Functions, App Engine, Cloud SQL, and Cloud Storage are on the August 28, 2026 list.

  • A signed BAA covers the platform only. Your logs, error tracker, analytics, and email still need their own BAA, or must never see PHI.

What makes app hosting HIPAA compliant?

HIPAA App Hosting Three Layers

Three layers, and all three have to hold. First, the contract. Any vendor that stores, processes, or sends protected health information (PHI) for a covered entity is a Business Associate. That is 45 CFR § 160.103. Under 45 CFR § 164.308(b), you may not hand PHI to one without a signed BAA. Second, the platform. The vendor has to run the safeguards of 45 CFR § 164.312 on its side: encryption, access control, and audit logs. Third, your setup. Every platform below leaves part of the Security Rule to you. Every one says so in its own docs. That split is why HIPAA compliant app hosting is never a single checkbox. It is a contract, a product tier, and a setup. The contract half is explained in our HIPAA business associate agreement guide. If you build software for provider customers, the full chain of duties is in HIPAA compliant hosting for healthcare SaaS.

Which app platforms sign a BAA?

HIPAA App Hosting HIPAA App Hosting H2 Who Signs

Here is the HIPAA compliant app hosting answer, platform by platform. Each row was checked against the vendor's own pages on September 11, 2026. "Signs" means the vendor offers a BAA at all. The next two columns are where the real decision lives.

Platform

Signs a BAA?

What it takes

Published cost of the compliant tier

Heroku

Yes, by support ticket

Shield product line only: Shield Private Spaces, Shield Dynos, Shield Postgres, Shield Key-Value Store

Quote only; Shield is the top tier

Vercel

Yes, self-serve

Pro team plus a paid HIPAA add-on (since September 9, 2025); redlines need Enterprise

Pro plan plus add-on; add-on price not published

Netlify

Yes

Enterprise customers only

Quote only

Render

Yes, self-serve

HIPAA-enabled workspace on Organization or Enterprise; services move to dedicated, restricted-access hosts

From $250 per month plus a percent fee on usage

Railway

Yes, through its solutions team

Add-on with a paid monthly spend threshold; Railway staff lose direct access to your workloads once it is active

Spend threshold, not a flat price

Fly.io

Yes, pre-signed

The BAA is pre-signed by Fly.io and starts when you sign it; a separate BAA covers Tigris storage

No separate fee stated

Supabase

Yes, on request in the dashboard

Team or Enterprise plan plus a paid HIPAA add-on; hosted platform only, self-hosted is out of scope; PITR, forced SSL, network restrictions, and connection logging required

Team from $599 per month plus the add-on

Firebase / Google Cloud

Yes, through the Google Cloud BAA

Only Google Cloud covered products count; Firebase-branded features are not on the list

Pay per use on covered products

DigitalOcean

Yes, via Sales or Support

Covered products only (Droplets, Kubernetes, Spaces, Load Balancers among them) plus a Standard or Premium support plan

Resource pricing plus the support plan

AWS

Yes, in AWS Artifact

Eligible services only: ECS, EKS, Fargate, Elastic Beanstalk, Amplify, Lambda are listed; App Runner and Lightsail are not

Pay per use; you build the safeguards

Read the middle column twice. Every "yes" in the first column comes with a condition in the second: a product line, a plan, or a list of covered services. A Heroku app on standard dynos is outside the BAA. So is a Vercel hobby project, a Supabase Pro project, or a Firebase app that leans on Crashlytics. The vendor's security page does not change that. That is the first rule of HIPAA compliant app hosting: the tier decides, not the brand. The same list logic applies on every cloud. Our glossary entry on HIPAA-eligible services explains why.

The platforms, one at a time

HIPAA App Hosting Platform Notes

Heroku: Shield or nothing

Heroku's compliance page tells customers building HIPAA apps to open a ticket. That ticket completes a Business Associate Addendum. Every product it lists under HIPAA is in the Shield line. That means Shield Private Spaces, Shield Dynos, Shield Postgres, Shield Connect, Kafka on Shield, and the Shield Key-Value Store. Standard dynos and standard Postgres are not on that list. So HIPAA compliant app hosting on Heroku means moving the whole app into a Shield Private Space. That product is priced by quote. It sits at the top of Heroku's range.

Vercel: the BAA came to Pro in 2025

Vercel's changelog of September 9, 2025 says Pro teams can enter a BAA to support HIPAA workloads. It is sold as a paid add-on. It is self-serve, with no Enterprise contract. On Vercel, HIPAA compliant app hosting starts at Pro, not Hobby. Two limits apply. Any redline to the standard agreement requires Enterprise. And Vercel points its most sensitive workloads at Secure Compute, an Enterprise feature. Say your PHI lives in a covered database elsewhere, and Vercel only serves the frontend or Next.js app. Then the Pro path is the cheapest BAA on this list to get.

Netlify: Enterprise only

Netlify announced a HIPAA offering. It says Enterprise customers that handle PHI can execute a BAA. There is no self-serve path and no published price. HIPAA compliant app hosting on Netlify starts with a sales call.

Render: a workspace switch with a price tag

Render added HIPAA-enabled workspaces on June 9, 2025. On an Organization or Enterprise plan, you sign the BAA from the dashboard. The workspace then moves your services to dedicated, restricted-access hosts. Disks and snapshots are encrypted at rest. For a full-stack app, Render is the simplest HIPAA compliant app hosting switch on this list. The published starting price is $250 per month plus a percent fee on your existing usage.

Railway: a spend threshold, and staff lose access

Railway's compliance page describes the HIPAA BAA as an add-on with a paid monthly spend threshold. You arrange it through the solutions team. One detail worth liking: once a BAA is active, Railway staff can no longer directly access your running workloads. The HIPAA compliant app hosting cost here is the committed spend, not a flat fee.

Fly.io: pre-signed

Fly.io's compliance page says its BAA is pre-signed. It becomes active when you sign it. A separate BAA covers Tigris object storage. That is the lowest-friction contract on this list. The HIPAA compliant app hosting setup is still yours, because Fly gives you machines and volumes, not a hardened stack.

Supabase: Team plan, add-on, and four required settings

Supabase offers its BAA on Team and Enterprise plans as a paid HIPAA add-on. Team starts at $599 per month. The docs are clear that the hosted platform has the controls and self-hosted Supabase does not. A project marked for HIPAA must turn on point-in-time recovery, forced SSL, network restrictions, and Postgres connection logging. The security advisor adds checks over time. Supabase is the database half of many HIPAA compliant app hosting stacks. Confirm the add-on price before you design around it.

Firebase: the brand is not on the list

Firebase's own terms say Google makes no claim that Firebase services meet HIPAA. What counts is Google Cloud's covered products list, dated August 28, 2026, under the Google Cloud BAA. Firestore, Identity Platform, Cloud Run, Cloud Run functions, Cloud Functions, App Engine, Cloud SQL, and Cloud Storage are on it. Firebase-branded tools such as Google Analytics for Firebase and Crashlytics are not. A Firebase app can be built inside the BAA. HIPAA compliant app hosting on Firebase means staying on the covered products and keeping the rest away from PHI.

DigitalOcean: covered products plus a support plan

DigitalOcean signs a BAA. New customers request it through Sales, and existing customers through Support. It requires a Standard or Premium support plan. Its covered products include Droplets, Kubernetes, Spaces object storage, and Load Balancers. Anything outside the covered list stays off limits for PHI. That makes DigitalOcean a low-cost HIPAA compliant app hosting base, if you do the hardening.

AWS containers and serverless: read the list

AWS signs its BAA self-serve in AWS Artifact. The September 3, 2026 eligible services reference lists Amazon ECS, Amazon EKS, AWS Fargate for the ECS and EKS engines, Elastic Beanstalk, Amplify Console, and Lambda. AWS App Runner and Amazon Lightsail are absent as of that date. An app deployed on either is outside the BAA. Eligible is not compliant. HIPAA compliant app hosting on AWS is the setup you add on top. The database and serverless halves are worked through in is Amazon RDS HIPAA compliant and is AWS Lambda HIPAA compliant. The platform verdict is in is AWS HIPAA compliant.

Where app stacks leak PHI after the BAA is signed

HIPAA App Hosting H2 Where Stacks Leak

Signing the platform's BAA fixes one vendor. A modern app stack has six or eight. The HIPAA compliant app hosting leaks we find in reviews sit in the tools around the app, not in the app.

  • Error and crash tracking. A stack trace that includes a request body can carry a patient record straight to a vendor with no BAA. Scrub payloads, or use a vendor that signs.

  • Product analytics. Google Analytics for Firebase is off Google's covered list. Event names and user properties become PHI once they identify a person and a health context. The rules are in HIPAA tracking technologies.

  • Logs. Platform logs shipped to a third-party log service are a transfer of whatever your app printed. Log identifiers, not records. Keep the log vendor inside the BAA chain.

  • Transactional email and SMS. Appointment reminders and portal alerts are PHI surfaces. The email provider needs its own BAA.

  • The database. A managed database from a different vendor than the app host needs its own BAA and its own settings. See HIPAA compliant database hosting.

A patient-facing portal pulls every one of these together. That is why the build order in HIPAA compliant patient portal starts with the vendor chain rather than the code.

What HIPAA compliant app hosting costs in 2026

HIPAA App Hosting What it Costs

The honest comparison is the compliant tier, not the tier you started on. That is the only HIPAA compliant app hosting price that matters. Published figures as of September 11, 2026:

Route

Published starting point

What you still own

Supabase Team plus HIPAA add-on

$599 per month plus the add-on

The app host, the four required settings, every other vendor

Render HIPAA workspace

$250 per month plus a usage percent

Your database vendor, logs, analytics, email

Vercel Pro plus BAA add-on

Pro plan plus an unpublished add-on price

Everything behind the frontend

Raw AWS, Google Cloud, or DigitalOcean

Pay per resource, often under $100 per month for a small app

All setup, hardening, logging, backups, and the engineer's hours

Managed HIPAA compliant app hosting from us, single-tenant

From $249 per month; Docker from $249; n8n and Strapi from $299

Your app code, your risk analysis, your third-party vendors

We sell the last row, so weigh it as a disclosure. Two things the table makes plain. The cheap developer tiers are not in it, because none of them sign. And the raw-cloud row is only cheap if you already employ the person who will do the hardening every month. That is the same math as HIPAA compliant cloud hosting in general.

Which route fits your app?

HIPAA App Hosting Which Route Fits

Match the route to the app. HIPAA compliant app hosting is not one product.

Your app

Route that fits

Why

Next.js or static frontend, PHI only in the API and database

Vercel Pro with the BAA add-on, database on a covered service

Cheapest BAA to get; the frontend rarely stores PHI

Full-stack Node, Python, or Laravel app with its own database

Render, Fly.io, or a managed single-tenant host

One vendor for compute and disks keeps the BAA chain short

Containerized app, Docker Compose or Kubernetes

AWS ECS or EKS, DigitalOcean Kubernetes, or managed Docker hosting

All three are covered; the difference is who hardens the hosts

Headless CMS or automation tool (Strapi, n8n) that touches PHI

Self-hosted on a BAA-covered single-tenant server

The vendors' own clouds are not the covered path; the server under them is

Mobile backend on Firebase

Google Cloud covered products only, under the Google Cloud BAA

Firestore and Identity Platform are covered; Firebase analytics tools are not

If you would rather not assemble the chain yourself

HIPAA App Hosting Rather Not Assemble

The pattern in every row above is the same. The platform signs for its slice. You own the rest of the chain and all of the setup. For a founder with a product to ship, that chain is the work. Our managed single-tenant servers cover 17 platforms. That includes HIPAA compliant Docker hosting for container apps, HIPAA compliant n8n hosting for automations that touch PHI, and HIPAA compliant Strapi hosting for headless CMS builds. Laravel and the other PHP frameworks run on managed HIPAA cloud hosting. Each arrives on dedicated AWS with encryption, a web application firewall, audit logging, and tested backups. The BAA is signed within 24 hours. Managed plans start from $249 per month with migration included. The memory-heavy platforms (n8n, Strapi, Drupal) start from $299. We sell HIPAA compliant app hosting, so weigh this section as a disclosure. The honest inverse: say your stack is a frontend on Vercel and a database on Supabase, and an engineer owns the settings and the vendor chain. Then you do not need us. That pairing under two BAAs is a valid path and cheaper. Either way, the HIPAA compliant hosting plans are public. You can request a quote or tell us what you are building for a straight answer.

Frequently asked questions

Is Heroku HIPAA compliant?

Heroku will complete a Business Associate Addendum by support ticket. Only its Shield product line is listed for HIPAA: Shield Private Spaces, Shield Dynos, Shield Postgres, and the Shield Key-Value Store. Standard dynos are not on the list. A PHI app must live in a Shield Private Space.

Is Vercel HIPAA compliant?

Vercel signs a BAA for Pro teams as a paid add-on. It has been self-serve since September 9, 2025, with no Enterprise contract required. Redlines to the agreement need Enterprise. Vercel recommends its Enterprise-only Secure Compute for the most sensitive workloads. HIPAA compliant app hosting on Vercel is still shared work: Vercel signs, and you set up the rest.

Is Firebase HIPAA compliant?

Not as a brand. Firebase's terms say Google makes no HIPAA claim for Firebase services. What is covered is Google Cloud's covered products list under the Google Cloud BAA. That list includes Firestore, Identity Platform, Cloud Run, Cloud Functions, App Engine, Cloud SQL, and Cloud Storage as of August 28, 2026. Firebase analytics and crash tools are not on it.

Can I host a HIPAA app on a free or hobby plan?

No. None of the ten platforms reviewed here sign a BAA on a free tier. Heroku needs Shield. Vercel needs Pro plus an add-on. Supabase needs Team or Enterprise. Render needs Organization or Enterprise. Netlify needs Enterprise. The free tier is where the app is built, not where PHI can live. HIPAA compliant app hosting always starts at a paid tier.

Do I need a BAA for my healthcare app?

If your app creates, receives, stores, or sends PHI for a covered entity such as a clinic or health plan, yes. Every vendor in the data path needs one: the app host, the database, the email provider, and the log or error tool. If your app sells directly to consumers with no covered entity in the loop, HIPAA usually does not apply. State health-privacy laws and the FTC still do.

Recap: HIPAA compliant app hosting

To recap, HIPAA compliant app hosting means a platform that signs a BAA for the services you actually use. Your own setup sits on top. As of September 11, 2026, Heroku, Vercel, Netlify, Render, Railway, Fly.io, Supabase, DigitalOcean, AWS, and Google Cloud all sign. Every one attaches a condition: a product line, a paid plan, an add-on, or a covered-products list. Price the compliant tier, not the starter tier. Keep analytics, crash tools, logs, and email inside the chain or away from PHI. Then decide who owns the setup. That person is the real cost of HIPAA compliant app hosting.

This article is general information, not legal advice. Vendor plans, prices, BAA terms, and covered-service lists change often. The details here reflect each vendor's public pages as read on September 11, 2026. They also reflect the AWS HIPAA Eligible Services Reference dated September 3, 2026, and Google Cloud's covered products page dated August 28, 2026. Confirm current terms with each vendor. Consult qualified counsel. Base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting and compliance reviews. Reviewed September 2026.

Sources

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.

Email me occasional updates about HIPAA hosting and compliance. No more than a few times a month, and you can unsubscribe at any time.