Skip to main content

HIPAA Compliant Laravel Hosting

We run custom Laravel applications for healthcare teams on a single-tenant AWS environment, with the Business Associate Agreement signed within 24 hours on managed tiers. Managed tiers from $199/mo.

How your service fits together

Draw the line around your custom Laravel application

Where does your application write patient data, including queue payloads and logs?

1

Patients, staff and API clients

Your users, application choices and external services determine what needs to connect.

Inside your dedicated hosting environment

2

Your Laravel application and queues

Confirm application maintenance, access and deployment responsibilities during scoping.

3

Application database, jobs and logs

Hosting includes encryption, audit logging and tested backups. Plan capacity follows your workload.

Illustrative operating model. Your final architecture and responsibilities are agreed during scoping. Connected applications and services need their own review; a hosting agreement does not establish their suitability.
Discuss your Laravel architecture

Why Laravel needs a HIPAA host, not a generic one

Laravel is where custom healthcare software usually gets built: patient portals, intake, scheduling, internal tooling. Custom means nobody has audited it but you.

Custom code, no shared assumptions

An off-the-shelf CMS has thousands of eyes on it. Your Laravel application has yours. That makes the platform underneath the part that should be a known quantity: patched, isolated, logged and backed up without you having to think about it.

Queues, jobs and logs carry PHI too

A queued job payload, a failed-job row and an application log line can each contain patient data. They live in the same environment, under the same encryption and retention baseline as the database, rather than somewhere nobody thought to look.

A BAA before the first deploy

The Business Associate Agreement is signed within 24 hours on managed tiers, before your application handles anything real. Getting the paperwork done first is considerably easier than retrofitting it around a system already in production.

Where our responsibility ends

Stated plainly, because knowing this before an incident is worth more than discovering it during one.

We run

  • The AWS account, VPC and network isolation
  • The operating system, patching and hardening
  • PHP, the web server, the database and TLS
  • CloudFront, the WAF, encryption, audit logging and backups
  • Monitoring and infrastructure incident response

You run

  • Your Laravel application, its packages and its migrations
  • Framework and dependency updates, unless scoped with us
  • Authentication, authorisation and what your code does with PHI
  • The APIs and services your application integrates with

If a problem turns out to be the server, PHP or the infrastructure, open a ticket and we take it. If it is inside your application, we tell you what we found and hand it back with recommendations.

HIPAA hosting vs standard hosting

A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.

Signed BAA before any PHI arrives
Standard Hosting
Not included
HIPAA Compliant
Included
Single-tenant isolation
Standard Hosting
Not included
HIPAA Compliant
Included
Encryption on by default, at rest and in transit
Standard Hosting
Not included
HIPAA Compliant
Included
Audit logs centralized and kept six years
Standard Hosting
Not included
HIPAA Compliant
Included
Encrypted backups with tested restores
Standard Hosting
Not included
HIPAA Compliant
Included
Written responsibility split
Standard Hosting
Not included
HIPAA Compliant
Included

Laravel hosting tiers

Every tier is a single-tenant AWS account with a signed BAA and the same compliance baseline. What changes is capacity.

Help me choose a hosting tier

Choose capacity for your workload, rather than the size of your organization. The published tiers share the compliance baseline described above.

CPU and memory
Consider concurrent requests, background jobs, database work and your application's memory needs. Traffic alone does not tell the whole story.
Storage and backups
Allow room for your application, database, uploads and expected growth. Compare the listed live-storage and backup allocations separately.
Data transfer
Estimate outgoing data from page visits, downloads and integrations, then compare it with the included transfer.
When to size up or scope a custom setup
Review capacity when monitoring shows sustained resource pressure or you expect a workload increase. Availability and recovery goals may require architecture changes, not simply a larger server.

Unsure where to start? Share the requirements you know. An engineer can help you choose an existing tier or scope a custom configuration.

Discuss Laravel capacity with an engineer
  • Starter

    $199/mo

    or $2,269/yr

    Compute
    1 vCPU
    Memory
    4 GB
    Storage
    50 GB
    Backups
    100 GB
    Transfer
    250 GB
    Order Starter
  • Solo

    $349/mo

    or $3,979/yr

    Compute
    2 vCPU
    Memory
    8 GB
    Storage
    100 GB
    Backups
    200 GB
    Transfer
    500 GB
    Order Solo
  • Practice

    $499/mo

    or $5,689/yr

    Compute
    4 vCPU
    Memory
    16 GB
    Storage
    200 GB
    Backups
    400 GB
    Transfer
    1,000 GB
    Order Practice
  • Clinic

    $849/mo

    or $9,679/yr

    Compute
    8 vCPU
    Memory
    32 GB
    Storage
    400 GB
    Backups
    800 GB
    Transfer
    2,000 GB
    Order Clinic
  • Group

    $1,499/mo

    or $17,089/yr

    Compute
    16 vCPU
    Memory
    64 GB
    Storage
    600 GB
    Backups
    1200 GB
    Transfer
    3,000 GB
    Order Group
  • Network

    $2,799/mo

    or $31,909/yr

    Compute
    32 vCPU
    Memory
    128 GB
    Storage
    800 GB
    Backups
    1600 GB
    Transfer
    5,000 GB
    Order Network

What every Laravel tier includes

The same compliance baseline at Solo and at Network. Capacity is the only thing that changes.

  • Single-tenant AWS environment
  • CloudFront CDN in front of every tier
  • Web application firewall
  • EBS storage with 7-day snapshot retention
  • Encryption at rest and in transit
  • Six-year audit logging
  • Tested, encrypted backups
  • Migration included
  • BAA signed within 24 hours of signup
  • 24/7 team, monitoring and infrastructure incident response

Know who owns the next step

Clear scope matters before launch and when you need help.

Hosting operations

Our published managed-hosting baseline includes 24/7 monitoring and infrastructure incident response, patching, logging and tested backups. Application changes and third-party integrations depend on the agreed scope.

Customer support route

Before you commit

Review the BAA, responsibility split, backup and recovery requirements, migration steps and support contacts with us. Tell us which procurement documents your organization needs so we can confirm what is available.

Review scope and documentation

Planning a new service

Quotes and general inquiries use our contact process during business hours. Existing customers should use their account's support instructions for infrastructure incidents.

Contact the team

Laravel hosting questions

Does hosting with you make our Laravel app HIPAA compliant?
It makes the hosting layer compliant and gives you a signed Business Associate Agreement covering it. Your application still has to do its part: authenticate users properly, authorise access to records, avoid logging PHI where it should not, and handle data you send to third parties. We can tell you what we see, but the code is yours.
Can you deploy our application for us?
Deployment beyond the platform baseline is scoped separately rather than assumed. The managed tiers cover the server, runtime, database, TLS, WAF, encryption, logging, backups and monitoring; how your code gets onto it is a conversation, not a fixed part of the plan.
What about Laravel queues and scheduled jobs?
They run in the same single-tenant environment, so job payloads and failed-job records fall under the same encryption, logging and backup baseline as everything else. That matters because queue payloads are an easy place for patient data to end up unnoticed.

Find the right Laravel setup

Tell us what you run, what you need to move and who manages the application. We will help you scope capacity and responsibilities before you choose a tier.