Skip to main content

HIPAA Compliant CakePHP Hosting

We run CakePHP applications for healthcare teams on a single-tenant AWS environment, with the Business Associate Agreement signed within 24 hours on managed tiers. Managed tiers from $199/mo.

How your service fits together

Show who can reach the records in your CakePHP application

Which roles can read, export or bulk-download patient records?

1

Staff roles and administrators

Your users, application choices and external services determine what needs to connect.

Inside your dedicated hosting environment

2

Your CakePHP application

Confirm application maintenance, access and deployment responsibilities during scoping.

3

Record database and exports

Hosting includes encryption, audit logging and tested backups. Plan capacity follows your workload.

Illustrative operating model. Your final architecture and responsibilities are agreed during scoping. Connected applications and services need their own review; a hosting agreement does not establish their suitability.
Discuss your CakePHP architecture

Why CakePHP needs a HIPAA host, not a generic one

CakePHP is strong at the thing healthcare organisations build most often: structured records with an admin interface over them. The risk there is who can see what.

Registries and admin screens hold a lot

A CRUD application over patient records concentrates data in one place with a convenient interface. That is exactly what makes it useful and exactly what makes access control and audit logging the parts worth getting right.

Audit logging behind the application

Infrastructure and access logging runs beneath your application and is retained under the platform baseline, so there is a record of access to the environment independent of whatever your application chooses to log.

One tenant, one agreement

Every tier is an AWS account dedicated to you with the Business Associate Agreement signed within 24 hours on managed tiers. No shared database host, no neighbouring application, nothing else on the box.

Where our responsibility ends

Stated plainly, because knowing this before an incident is worth more than discovering it during one.

We run

  • The AWS account, VPC and network isolation
  • The operating system, patching and hardening
  • PHP, the web server, the database and TLS
  • CloudFront, the WAF, encryption, audit logging and backups
  • Monitoring and infrastructure incident response

You run

  • Your CakePHP application, models and templates
  • Framework and plugin updates, unless scoped with us
  • Authorisation rules and who can read or export records
  • The systems your application integrates with and the data you send them

If a problem turns out to be the server, PHP or the infrastructure, open a ticket and we take it. If it is inside your application, we tell you what we found and hand it back with recommendations.

HIPAA hosting vs standard hosting

A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.

Signed BAA before any PHI arrives
Standard Hosting
Not included
HIPAA Compliant
Included
Single-tenant isolation
Standard Hosting
Not included
HIPAA Compliant
Included
Encryption on by default, at rest and in transit
Standard Hosting
Not included
HIPAA Compliant
Included
Audit logs centralized and kept six years
Standard Hosting
Not included
HIPAA Compliant
Included
Encrypted backups with tested restores
Standard Hosting
Not included
HIPAA Compliant
Included
Written responsibility split
Standard Hosting
Not included
HIPAA Compliant
Included

CakePHP hosting tiers

Every tier is a single-tenant AWS account with a signed BAA and the same compliance baseline. What changes is capacity.

Help me choose a hosting tier

Choose capacity for your workload, rather than the size of your organization. The published tiers share the compliance baseline described above.

CPU and memory
Consider concurrent requests, background jobs, database work and your application's memory needs. Traffic alone does not tell the whole story.
Storage and backups
Allow room for your application, database, uploads and expected growth. Compare the listed live-storage and backup allocations separately.
Data transfer
Estimate outgoing data from page visits, downloads and integrations, then compare it with the included transfer.
When to size up or scope a custom setup
Review capacity when monitoring shows sustained resource pressure or you expect a workload increase. Availability and recovery goals may require architecture changes, not simply a larger server.

Unsure where to start? Share the requirements you know. An engineer can help you choose an existing tier or scope a custom configuration.

Discuss CakePHP capacity with an engineer
  • Starter

    $199/mo

    or $2,269/yr

    Compute
    1 vCPU
    Memory
    4 GB
    Storage
    50 GB
    Backups
    100 GB
    Transfer
    250 GB
    Order Starter
  • Solo

    $349/mo

    or $3,979/yr

    Compute
    2 vCPU
    Memory
    8 GB
    Storage
    100 GB
    Backups
    200 GB
    Transfer
    500 GB
    Order Solo
  • Practice

    $499/mo

    or $5,689/yr

    Compute
    4 vCPU
    Memory
    16 GB
    Storage
    200 GB
    Backups
    400 GB
    Transfer
    1,000 GB
    Order Practice
  • Clinic

    $849/mo

    or $9,679/yr

    Compute
    8 vCPU
    Memory
    32 GB
    Storage
    400 GB
    Backups
    800 GB
    Transfer
    2,000 GB
    Order Clinic
  • Group

    $1,499/mo

    or $17,089/yr

    Compute
    16 vCPU
    Memory
    64 GB
    Storage
    600 GB
    Backups
    1200 GB
    Transfer
    3,000 GB
    Order Group
  • Network

    $2,799/mo

    or $31,909/yr

    Compute
    32 vCPU
    Memory
    128 GB
    Storage
    800 GB
    Backups
    1600 GB
    Transfer
    5,000 GB
    Order Network

What every CakePHP tier includes

The same compliance baseline at Solo and at Network. Capacity is the only thing that changes.

  • Single-tenant AWS environment
  • CloudFront CDN in front of every tier
  • Web application firewall
  • EBS storage with 7-day snapshot retention
  • Encryption at rest and in transit
  • Six-year audit logging
  • Tested, encrypted backups
  • Migration included
  • BAA signed within 24 hours of signup
  • 24/7 team, monitoring and infrastructure incident response

Know who owns the next step

Clear scope matters before launch and when you need help.

Hosting operations

Our published managed-hosting baseline includes 24/7 monitoring and infrastructure incident response, patching, logging and tested backups. Application changes and third-party integrations depend on the agreed scope.

Customer support route

Before you commit

Review the BAA, responsibility split, backup and recovery requirements, migration steps and support contacts with us. Tell us which procurement documents your organization needs so we can confirm what is available.

Review scope and documentation

Planning a new service

Quotes and general inquiries use our contact process during business hours. Existing customers should use their account's support instructions for infrastructure incidents.

Contact the team

CakePHP hosting questions

We use CakePHP for an internal patient registry. Is that a fit?
That is a common shape for these tiers. The hosting side covers isolation, encryption, audit logging, backups and the Business Associate Agreement. The part that deserves your attention is authorisation. A registry makes it easy for a broad role to read more than it needs, and that is application logic, not hosting.
Does the platform log who viewed a record?
No, and no hosting platform can. We log access to the infrastructure; record-level access logging has to come from inside your application because only it knows what a record is. It is worth building if you have not, because it is usually the first thing asked for after an incident.
Can you help with data export and retention?
Backups and their retention are part of the platform. Application-level export and record retention rules are yours, since they depend on what your data means. We are happy to tell you what the platform does so your policy can be written against something accurate.

Find the right CakePHP setup

Tell us what you run, what you need to move and who manages the application. We will help you scope capacity and responsibilities before you choose a tier.