HIPAA Compliant Cloud Hosting: Requirements and How to Choose in 2026
HIPAA Compliant Hosting · https://hipaacomplianthosting.com/blog/hipaa-compliant-cloud-hosting
Last updated: September 8, 2026
HIPAA compliant cloud hosting is cloud infrastructure that stores or processes electronic protected health information (ePHI) under a signed Business Associate Agreement (BAA), with the HIPAA Security Rule safeguards in place: encryption at rest and in transit, access controls, audit logging, and tested backups. The big clouds, Amazon Web Services (AWS), Microsoft Azure, and Google Cloud, all sign a BAA and give you the building blocks. They do not hand you compliance. Under the shared responsibility model, the cloud secures the data centers and core services, and you secure how you set everything up. That gap is where HIPAA compliant cloud hosting is won or lost, and it is also where the cost lives. This guide covers five things. Which clouds sign a BAA and how. What the setup costs in 2026. Why nothing is free. What the Security Rule requires. How to choose. Every vendor fact was checked on September 8, 2026.
TL;DR: Quick answer
HIPAA compliant cloud hosting needs two things: a signed BAA under 45 CFR § 164.308(b), and the Security Rule safeguards at 45 CFR § 164.312 set up in your environment.
AWS, Azure, and Google Cloud each sign a BAA, but only for their covered services. AWS lists over 200 eligible services on its September 3, 2026 reference. Microsoft's BAA is built into the Product Terms. Google's BAA covers its whole infrastructure plus a published product list.
Cost in 2026: managed specialists run from about $249 per month (ours) to $552 per month and up (Atlantic.Net, 12-month term). Building it yourself on a raw cloud trades subscription cost for engineering hours. Nothing is free.
Encryption is "addressable" today under 45 CFR § 164.312(a)(2)(iv). The proposed Security Rule update would make it and multi-factor authentication mandatory, but it is not final; the target has slipped to July 2027.
Pick by who owns the configuration. If nobody on your team will own it, a managed host is the answer. If you have a cloud engineer, the raw clouds are cheaper and just as compliant.
What is HIPAA compliant cloud hosting?
Cloud hosting means your website or application runs on virtual servers that a cloud provider operates, instead of one physical machine you own. You rent computing power, storage, and a network, and scale them as needed. When any of those resources hold patient data, the provider becomes a Business Associate under 45 CFR § 160.103. It must sign a BAA before the data arrives.
So HIPAA compliant cloud hosting is the cloud version of the same two-part rule that governs all hosting: the contract plus the controls. For the full picture of how those two parts fit together across any setup, see our complete guide to HIPAA-compliant hosting. This article focuses on the cloud, where the scale and the flexibility are larger and so is the configuration work.
Which clouds will sign a BAA?

All three major clouds sign a BAA, and each one covers only a named set of services. Anything outside that set cannot legally hold PHI, even inside a HIPAA account. Here is how the three compare for HIPAA compliant cloud hosting, checked September 8, 2026.
Cloud | How you get the BAA | What it covers | Vendor's own words on certification |
|---|---|---|---|
AWS | Accept the Business Associate Addendum in AWS Artifact, per account | Only services on the HIPAA Eligible Services Reference, over 200 as of September 3, 2026 | "There is no HIPAA certification for a cloud service provider" |
Microsoft Azure | No separate signature; the BAA is part of the Microsoft Product Terms through the Data Protection Addendum | In-scope Azure services listed on Microsoft's audit-scope page | "No certification program approved by HHS" through which a cloud provider could demonstrate compliance |
Google Cloud | Review and accept the Google Cloud BAA through the account's privacy compliance settings, per Google's instructions | Google's entire infrastructure plus a published list of covered products | "No certification recognized by the US HHS for HIPAA compliance"; compliance is shared |
Three things stand out. All three vendors say in their own documentation that no HIPAA certification exists. Remember that when a reseller's badge says otherwise; the full story is in HIPAA certified hosting. All three leave configuration to you. And the AWS side is the best documented, which is why most managed HIPAA hosts, including us, build on it. The developer platforms that sit on top of these clouds, Heroku, Vercel, Render, Supabase, and the rest, each answer the BAA question differently, and we sort them plan by plan in our guide to HIPAA compliant app hosting. Our breakdown of AWS HIPAA eligible services walks the list service by service. Our deep dive on whether AWS is HIPAA compliant covers the platform. The database and serverless tiers have their own verdicts in is Amazon RDS HIPAA compliant and is AWS Lambda HIPAA compliant.
What does HIPAA compliant cloud hosting cost in 2026?
This is the question most HIPAA compliant cloud hosting pages avoid, so here are published numbers, dated. Prices change; confirm on each vendor's page before you budget.
Route | Published starting price (September 8, 2026) | What the price includes | What it does not include |
|---|---|---|---|
Raw cloud (AWS, Azure, Google Cloud) | Pay per resource; the BAA itself costs nothing | Eligible services and the contract | Every setting, the monitoring, the patching, the logs, the restore tests, and the engineer who does them |
HIPAA Compliant Hosting (us) | Managed from $249 per month; $89 per month entry plan* | Single-tenant AWS environment, BAA within 24 hours, migration included on managed plans | Your application code, your risk analysis, your staff training |
Atlantic.Net | Developer plan $552.31 per month (Linux, 12-month term, $150 firewall setup fee) | Managed firewall, BAA, backups, VPN, MFA, per its plan page | Month-to-month pricing; the term is 12 months |
Liquid Web | Its own guide says to expect $600 to $1,000 or more per month | Dedicated or cloud instances with encryption, backups, monitoring | A published plan table; quotes are custom |
HIPAA Vault | Quote-based on its site; no public monthly figure | BAA for every service, per its site | A number you can budget against without a sales call |
*The $89 entry plan is a managed SFTP server; the full plan lineup is being finalized. See current plans for what each tier includes.
Two honest notes on that table. We sell HIPAA compliant cloud hosting, so weigh our row as a disclosure. The competitor figures are what their public pages said on the date shown, nothing more. And the raw-cloud row is the one people underestimate. A small practice can run a hardened environment on AWS for well under $100 per month in resources. Then it spends a week of engineer time building it, and a few hours every month keeping it that way. Whether that is cheaper than a managed plan depends entirely on who that engineer is. Our 2026 HIPAA hosting cost guide works the math line by line. Our guide to cheapest HIPAA compliant hosting covers the low end without the tradeoffs hidden.
Is there free HIPAA compliant cloud hosting?
No, and the search is worth answering straight because it is common. The BAA has no price at any of the three clouds. The eligible services still bill by use, so a "free" account becomes a paid one the moment real traffic and real storage arrive. More important, the free tiers do not include the part that makes HIPAA compliant cloud hosting compliant. That part is the configuration, the logging, the restore tests, and the documentation. Those cost either money or hours. Any host advertising free HIPAA hosting is either offering a trial, a free tier of a general product with no BAA, or a marketing page. Ask for the BAA in writing before you believe the word free.
What does the Security Rule require in the cloud?

The technical safeguards at 45 CFR § 164.312 map directly onto a cloud environment. Here is each control and what it looks like when your servers live in the cloud.
Control | CFR citation | In the cloud |
|---|---|---|
Encryption at rest | § 164.312(a)(2)(iv) | Encrypt disks, object storage, databases, and snapshots, commonly with AES-256 and managed keys |
Encryption in transit | § 164.312(e)(1), (e)(2)(ii) | TLS 1.2 or higher on every connection that carries ePHI, including between internal services |
Access control and unique IDs | § 164.312(a)(1), (a)(2)(i) | Identity and access management with named accounts, least privilege, and MFA on every login |
Automatic logoff | § 164.312(a)(2)(iii) | Idle sessions to servers and consoles time out |
Audit controls | § 164.312(b) | Platform, network, and application logs sent to tamper-resistant storage and reviewed |
Backups and recovery | § 164.308(a)(7) | Encrypted backups, copies in a second region, and a restore you have actually tested |
One point worth stating clearly, because many 2026 articles get it wrong. Encryption is still an "addressable" specification under § 164.312(a)(2)(iv). That means you use it or document an equal alternative. For hosted ePHI there is no credible alternative, so treat it as required in practice. The December 2024 proposed Security Rule update would make encryption and MFA explicitly mandatory. The rule is not final, and the target has slipped to July 2027; see our new HIPAA Security Rule tracker. Our CFR-mapped security checklist turns each of these controls into concrete settings.
Cloud hosting, servers, and the types you will see
People shopping for HIPAA compliant cloud hosting run into a lot of words for the same idea. Here is a plain map.
Managed cloud hosting. A provider runs your cloud servers and the safeguards for you. This is the most common choice for healthcare teams that would rather not staff a cloud engineer. Telehealth platforms are a common case; see HIPAA compliant telehealth. Healthcare software companies have their own checklist; see HIPAA compliant hosting for healthcare SaaS. Multi-location clinics and networks do too; see HIPAA compliant hosting for multi-location clinics.
Self-managed cloud or a HIPAA compliant server you run. You rent the servers and own all the configuration: encryption, access, logging, patching, and backups. Full control, full responsibility. The machine-level checklist is in HIPAA compliant server, and the managed-versus-self-managed decision is worked through in managed vs self-managed HIPAA hosting.
Dedicated and single-tenant servers. Your environment is isolated from other customers, which lowers risk and simplifies your risk analysis. The metal-versus-cloud call is laid out in HIPAA dedicated server.
Cloud storage. Half the search results for this phrase are storage products, not hosting. A HIPAA compliant storage service holds files under a BAA; it does not run your website or application. If you need both, you need both.
The database deserves its own attention, because it holds the most records in one place. We cover that tier in HIPAA compliant database hosting. Practices that bill cards online also fall under PCI DSS, covered in PCI compliant hosting.
Who is responsible for what?

Cloud HIPAA work splits across up to three parties. Knowing the split is how you avoid the gaps that show up in audits. The model itself is defined in our glossary entry on the shared responsibility model.
Area | Cloud provider | You or your managed host |
|---|---|---|
Data centers and hardware | Secures the physical layer | Inherits it through the BAA |
Eligible services | Publishes the covered list | Keeps PHI only inside that list |
Encryption and access | Provides the tools | Turns them on and configures them |
Logging and backups | Provides the services | Enables, retains, reviews, and tests them |
Risk analysis and training | Not their job | Yours under 45 CFR § 164.308(a)(1)(ii)(A) |
The cloud provider secures the cloud. You secure what you put in it. A managed host can take that second column off your team's plate. That gap is the reason most practices buy HIPAA compliant cloud hosting instead of building it. What a managed host takes on, item by item, is spelled out in our guide to managed HIPAA hosting.
How do you choose HIPAA compliant cloud hosting?
Start with one question: who on your team will own the second column of that table? The answer picks the HIPAA compliant cloud hosting route that fits.
Your situation | Route that fits | Why |
|---|---|---|
Practice or clinic website with intake forms or a portal, no engineer on staff | Managed HIPAA host | Nobody will maintain the settings; you are buying the upkeep, not the servers |
Healthcare SaaS with a platform engineer | Raw cloud, or a managed host for the parts you do not want to run | You can own the configuration; the cost question is engineer hours versus subscription |
Multi-location group or telehealth platform | Managed single-tenant environment | Isolation and a written responsibility matrix matter more as the record count grows |
You mostly need to store and share files | HIPAA compliant storage or SFTP, not full hosting | Cheaper and simpler; do not buy a web stack to hold PDFs |
Then check any provider against six items. BAA before PHI, signed, and you have read which services it covers. Eligible services only. Encryption on by default, at rest and in transit, with managed keys. Logging you can keep and review, with retention that supports the six-year documentation rule at 45 CFR § 164.316(b)(2)(i). A tested recovery plan, not just backups that have never been restored. And a clear responsibility matrix, in writing, so you know which controls are yours. To see named vendors scored against those items, read our roundup of the best HIPAA compliant hosting providers.
If you would rather have it built and run for you
The hardest part of HIPAA compliant cloud hosting is not the idea. It is the steady configuration and upkeep that the safeguards demand. If your team would rather serve patients and ship product than tune cloud security, a managed host can own that layer. At HIPAA Compliant Hosting, our managed HIPAA cloud hosting provisions single-tenant environments on AWS. They arrive with encryption, a web application firewall, monitoring, six-year audit logging, and tested encrypted backups. The BAA is signed within 24 hours. Managed plans start from $249 per month with migration included. We sell this service, so treat that as a disclosure, not a neutral verdict. The honest inverse: if you have a cloud engineer who will own the second column and keep the evidence, you do not need us. The raw clouds are cheaper for you and just as compliant, and we will say so. If you want a straight read on your setup, tell us what you are building. For a figure tied to your workload, request a quote.
Frequently asked questions
Is cloud hosting HIPAA compliant?
Cloud hosting can be HIPAA compliant when it runs under a signed BAA, keeps PHI inside the provider's covered services, and implements the Security Rule safeguards. Those are encryption, access control, audit logging, and tested backups. The cloud is not compliant on its own.
Which cloud is best for HIPAA compliant cloud hosting?
AWS, Azure, and Google Cloud all sign a BAA and can host PHI well. AWS publishes the largest eligible list, over 200 services as of September 3, 2026, and is the best documented. The best choice depends on your stack and your team's skills, because each one leaves configuration and logging to you.
How much does HIPAA compliant cloud hosting cost?
As of September 8, 2026, managed specialists publish starting prices from $249 per month (ours) to $552.31 per month on a 12-month term (Atlantic.Net). Liquid Web's own guide cites $600 to $1,000 or more. Building on a raw cloud costs less in resources and more in engineer time. Confirm current prices with each vendor.
Is there free HIPAA compliant cloud hosting?
No. The BAA is free at AWS, Azure, and Google Cloud, but the eligible services bill by use. The configuration, logging, and restore tests that make the setup compliant cost money or hours. A host advertising free HIPAA hosting is offering a trial or a product with no BAA.
Does AWS, Azure, or Google Cloud make my app HIPAA compliant automatically?
No. A signed BAA and covered services are necessary, not sufficient. Your configuration, access decisions, and documented risk analysis determine whether the system is compliant, and all three vendors say so in their own documentation.
Do I need a managed host for HIPAA compliant cloud hosting?
No, but many teams choose one. You can configure the cloud yourself if you have the skills and time. A managed host exists to run the encryption, logging, patching, and backups so your staff does not have to.
Recap: HIPAA compliant cloud hosting
To recap, HIPAA compliant cloud hosting is cloud infrastructure that holds ePHI under a signed BAA with the Security Rule safeguards in place. AWS, Azure, and Google Cloud all sign a BAA, each in its own way, but only for their covered services. Only you can configure and document the controls that make the system compliant. Nothing is free, and the real cost is whoever owns the configuration. Build it yourself if you have that person. Hand it to a managed host if you do not. Either way, get the BAA first, keep PHI inside covered services, and encrypt, log, and test everything.
This article is general information, not legal advice. Cloud provider service lists, BAA terms, and competitor prices change. The figures here reflect each vendor's public pages as read on September 8, 2026, and the AWS HIPAA Eligible Services Reference dated September 3, 2026. The December 2024 Security Rule proposal is not final (final action now targeted for July 2027). Confirm current terms with your provider, consult qualified counsel, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting and compliance reviews. Reviewed September 2026.
Sources
45 CFR § 164.312 (technical safeguards): ecfr.gov
45 CFR § 164.308 (administrative safeguards, BAA requirement): ecfr.gov
AWS: HIPAA Eligible Services Reference (updated September 3, 2026) and HIPAA Compliance and the BAA
Microsoft: HIPAA and the Azure compliance offering (BAA via the Product Terms)
Google Cloud: HIPAA compliance on Google Cloud (updated August 28, 2026)
Atlantic.Net: HIPAA-compliant hosting plans and pricing (read September 8, 2026)
Liquid Web: HIPAA compliant hosting guide (read September 8, 2026)
HIPAA Vault: HIPAA Vault home page (read September 8, 2026)