Skip to main content

HIPAA Compliant Payload CMS Hosting

We run Payload CMS for healthcare teams building patient-facing content and intake on a single-tenant AWS environment, with the Business Associate Agreement signed within 24 hours on managed tiers. Managed tiers from $199/mo.

How your service fits together

See where PHI enters your Payload collections

Which collections receive patient information, and who can read or export them?

1

Front ends and form submissions

Your users, application choices and external services determine what needs to connect.

Inside your dedicated hosting environment

2

Payload CMS and its collections

Confirm application maintenance, access and deployment responsibilities during scoping.

3

Content database and uploaded media

Hosting includes encryption, audit logging and tested backups. Plan capacity follows your workload.

Illustrative operating model. Your final architecture and responsibilities are agreed during scoping. Connected applications and services need their own review; a hosting agreement does not establish their suitability.
Discuss your Payload CMS architecture

Why Payload CMS needs a HIPAA host, not a generic one

A headless CMS moves patient-facing content into an API. That is a good architecture, and it means the data boundary is now something you have to run deliberately.

Collections hold more than content

Payload collections are a database schema with an admin UI on top. The moment a form writes an appointment request or an intake answer into one, that collection holds PHI and needs the same controls a clinical system does.

Self-hosted, under a BAA

Payload Cloud is a managed multi-tenant service. Running Payload on infrastructure dedicated to you, under a signed Business Associate Agreement, is what makes the arrangement documentable for a covered entity.

Media uploads leave the page

Payload writes uploads to disk or object storage. Scans, photographs and attached documents are PHI as surely as a database row, so the storage behind them is encrypted, access-logged and backed up.

Where our responsibility ends

Stated plainly, because knowing this before an incident is worth more than discovering it during one.

We run

  • The AWS account, VPC and network isolation
  • The operating system, patching and hardening
  • Node.js, the process manager, the database and TLS
  • CloudFront, the WAF, encryption, audit logging and backups
  • Monitoring and infrastructure incident response

You run

  • Your Payload application, collections and access control rules
  • Payload and dependency updates, unless scoped with us
  • Content, editors, roles and API keys
  • The front end that consumes the API and anything you send it to

If a problem turns out to be the server, the Node runtime or the infrastructure, open a ticket and we take it. If it is inside your Payload application, we tell you what we found and hand it back with recommendations.

HIPAA hosting vs standard hosting

A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.

Signed BAA before any PHI arrives
Standard Hosting
Not included
HIPAA Compliant
Included
Single-tenant isolation
Standard Hosting
Not included
HIPAA Compliant
Included
Encryption on by default, at rest and in transit
Standard Hosting
Not included
HIPAA Compliant
Included
Audit logs centralized and kept six years
Standard Hosting
Not included
HIPAA Compliant
Included
Encrypted backups with tested restores
Standard Hosting
Not included
HIPAA Compliant
Included
Written responsibility split
Standard Hosting
Not included
HIPAA Compliant
Included

Payload CMS hosting tiers

Every tier is a single-tenant AWS account with a signed BAA and the same compliance baseline. What changes is capacity.

Help me choose a hosting tier

Choose capacity for your workload, rather than the size of your organization. The published tiers share the compliance baseline described above.

CPU and memory
Consider concurrent requests, background jobs, database work and your application's memory needs. Traffic alone does not tell the whole story.
Storage and backups
Allow room for your application, database, uploads and expected growth. Compare the listed live-storage and backup allocations separately.
Data transfer
Estimate outgoing data from page visits, downloads and integrations, then compare it with the included transfer.
When to size up or scope a custom setup
Review capacity when monitoring shows sustained resource pressure or you expect a workload increase. Availability and recovery goals may require architecture changes, not simply a larger server.

Unsure where to start? Share the requirements you know. An engineer can help you choose an existing tier or scope a custom configuration.

Discuss Payload CMS capacity with an engineer
  • Starter

    $199/mo

    or $2,269/yr

    Compute
    1 vCPU
    Memory
    4 GB
    Storage
    50 GB
    Backups
    100 GB
    Transfer
    250 GB
    Order Starter
  • Solo

    $349/mo

    or $3,979/yr

    Compute
    2 vCPU
    Memory
    8 GB
    Storage
    100 GB
    Backups
    200 GB
    Transfer
    500 GB
    Order Solo
  • Practice

    $499/mo

    or $5,689/yr

    Compute
    4 vCPU
    Memory
    16 GB
    Storage
    200 GB
    Backups
    400 GB
    Transfer
    1,000 GB
    Order Practice
  • Clinic

    $849/mo

    or $9,679/yr

    Compute
    8 vCPU
    Memory
    32 GB
    Storage
    400 GB
    Backups
    800 GB
    Transfer
    2,000 GB
    Order Clinic
  • Group

    $1,499/mo

    or $17,089/yr

    Compute
    16 vCPU
    Memory
    64 GB
    Storage
    600 GB
    Backups
    1200 GB
    Transfer
    3,000 GB
    Order Group
  • Network

    $2,799/mo

    or $31,909/yr

    Compute
    32 vCPU
    Memory
    128 GB
    Storage
    800 GB
    Backups
    1600 GB
    Transfer
    5,000 GB
    Order Network

What every Payload CMS tier includes

The same compliance baseline at Solo and at Network. Capacity is the only thing that changes.

  • Single-tenant AWS environment
  • CloudFront CDN in front of every tier
  • Web application firewall
  • EBS storage with 7-day snapshot retention
  • Encryption at rest and in transit
  • Six-year audit logging
  • Tested, encrypted backups
  • Migration included
  • BAA signed within 24 hours of signup
  • 24/7 team, monitoring and infrastructure incident response

Know who owns the next step

Clear scope matters before launch and when you need help.

Hosting operations

Our published managed-hosting baseline includes 24/7 monitoring and infrastructure incident response, patching, logging and tested backups. Application changes and third-party integrations depend on the agreed scope.

Customer support route

Before you commit

Review the BAA, responsibility split, backup and recovery requirements, migration steps and support contacts with us. Tell us which procurement documents your organization needs so we can confirm what is available.

Review scope and documentation

Planning a new service

Quotes and general inquiries use our contact process during business hours. Existing customers should use their account's support instructions for infrastructure incidents.

Contact the team

Payload CMS hosting questions

Is Payload CMS HIPAA compliant?
Payload itself is neither compliant nor non-compliant; software is neutral and compliance is a property of how it is hosted, configured and operated. What we provide is the hosting half: a single-tenant environment, a signed Business Associate Agreement, encryption, audit logging and backups. The application half stays yours: access rules, what you collect, and who can read it.
Can we use Payload Cloud instead?
Payload Cloud is a multi-tenant managed service. If you are handling PHI you need a Business Associate Agreement with whoever operates the infrastructure, and you need to be able to describe the isolation boundary to an auditor. Self-hosting on a dedicated environment under our BAA is what makes that describable.
Where do Payload media uploads live?
On storage inside the environment dedicated to you, encrypted at rest and covered by the same backup and audit-logging baseline as the database. Uploaded documents and images are treated as PHI, because in a healthcare context they usually are.

Find the right Payload CMS setup

Tell us what you run, what you need to move and who manages the application. We will help you scope capacity and responsibilities before you choose a tier.