Skip to main content

HIPAA Compliant Slim Framework Hosting

We run Slim Framework APIs and integration services for healthcare teams on a single-tenant AWS environment, with the Business Associate Agreement signed within 24 hours on managed tiers. Managed tiers from $199/mo.

How your service fits together

Trace what your Slim integration service moves

Which systems exchange PHI through this service, and what does it log?

1

Upstream and downstream systems

Your users, application choices and external services determine what needs to connect.

Inside your dedicated hosting environment

2

Your Slim API and middleware

Confirm application maintenance, access and deployment responsibilities during scoping.

3

Request payloads, queues and logs

Hosting includes encryption, audit logging and tested backups. Plan capacity follows your workload.

Illustrative operating model. Your final architecture and responsibilities are agreed during scoping. Connected applications and services need their own review; a hosting agreement does not establish their suitability.
Discuss your Slim Framework architecture

Why Slim Framework needs a HIPAA host, not a generic one

Slim is usually chosen for APIs and integration services: the layer that moves data between systems. That makes it the layer where PHI is in motion.

An integration layer sees everything

A service that brokers between an EHR, a scheduling system and a portal handles more patient data than either endpoint. Request and response logging has to be deliberate, because the obvious way to debug an integration is also the obvious way to leak one.

Encryption in transit and at rest

TLS terminates on infrastructure dedicated to you, and anything the service persists (queues, caches and temporary payloads) sits on encrypted storage inside the same boundary, not on a shared tier somewhere adjacent.

Small surface, still single-tenant

A micro-framework API is a small thing to run and a serious thing to run carelessly. Every tier is an AWS account dedicated to you, so a lightweight service is not sharing a host with strangers.

Where our responsibility ends

Stated plainly, because knowing this before an incident is worth more than discovering it during one.

We run

  • The AWS account, VPC and network isolation
  • The operating system, patching and hardening
  • PHP, the web server, the database and TLS
  • CloudFront, the WAF, encryption, audit logging and backups
  • Monitoring and infrastructure incident response

You run

  • Your Slim application, routes and middleware
  • Framework and dependency updates, unless scoped with us
  • API authentication, rate limiting and what you log
  • The upstream and downstream systems you integrate and the data you exchange

If a problem turns out to be the server, PHP or the infrastructure, open a ticket and we take it. If it is inside your service, we tell you what we found and hand it back with recommendations.

HIPAA hosting vs standard hosting

A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.

Signed BAA before any PHI arrives
Standard Hosting
Not included
HIPAA Compliant
Included
Single-tenant isolation
Standard Hosting
Not included
HIPAA Compliant
Included
Encryption on by default, at rest and in transit
Standard Hosting
Not included
HIPAA Compliant
Included
Audit logs centralized and kept six years
Standard Hosting
Not included
HIPAA Compliant
Included
Encrypted backups with tested restores
Standard Hosting
Not included
HIPAA Compliant
Included
Written responsibility split
Standard Hosting
Not included
HIPAA Compliant
Included

Slim Framework hosting tiers

Every tier is a single-tenant AWS account with a signed BAA and the same compliance baseline. What changes is capacity.

Help me choose a hosting tier

Choose capacity for your workload, rather than the size of your organization. The published tiers share the compliance baseline described above.

CPU and memory
Consider concurrent requests, background jobs, database work and your application's memory needs. Traffic alone does not tell the whole story.
Storage and backups
Allow room for your application, database, uploads and expected growth. Compare the listed live-storage and backup allocations separately.
Data transfer
Estimate outgoing data from page visits, downloads and integrations, then compare it with the included transfer.
When to size up or scope a custom setup
Review capacity when monitoring shows sustained resource pressure or you expect a workload increase. Availability and recovery goals may require architecture changes, not simply a larger server.

Unsure where to start? Share the requirements you know. An engineer can help you choose an existing tier or scope a custom configuration.

Discuss Slim Framework capacity with an engineer
  • Starter

    $199/mo

    or $2,269/yr

    Compute
    1 vCPU
    Memory
    2 GB
    Storage
    50 GB
    Backups
    100 GB
    Transfer
    250 GB
    Order Starter
  • Solo

    $349/mo

    or $3,979/yr

    Compute
    2 vCPU
    Memory
    4 GB
    Storage
    100 GB
    Backups
    200 GB
    Transfer
    500 GB
    Order Solo
  • Practice

    $499/mo

    or $5,689/yr

    Compute
    4 vCPU
    Memory
    8 GB
    Storage
    200 GB
    Backups
    400 GB
    Transfer
    1,000 GB
    Order Practice
  • Clinic

    $849/mo

    or $9,679/yr

    Compute
    8 vCPU
    Memory
    16 GB
    Storage
    400 GB
    Backups
    800 GB
    Transfer
    2,000 GB
    Order Clinic
  • Group

    $1,499/mo

    or $17,089/yr

    Compute
    16 vCPU
    Memory
    32 GB
    Storage
    600 GB
    Backups
    1200 GB
    Transfer
    3,000 GB
    Order Group
  • Network

    $2,799/mo

    or $31,909/yr

    Compute
    32 vCPU
    Memory
    64 GB
    Storage
    800 GB
    Backups
    1600 GB
    Transfer
    5,000 GB
    Order Network

What every Slim Framework tier includes

The same compliance baseline at Solo and at Network. Capacity is the only thing that changes.

  • Single-tenant AWS environment
  • CloudFront CDN in front of every tier
  • Web application firewall
  • EBS storage with 7-day snapshot retention
  • Encryption at rest and in transit
  • Six-year audit logging
  • Tested, encrypted backups
  • Migration included
  • BAA signed within 24 hours of signup
  • 24/7 team, monitoring and infrastructure incident response

Know who owns the next step

Clear scope matters before launch and when you need help.

Hosting operations

Our published managed-hosting baseline includes 24/7 monitoring and infrastructure incident response, patching, logging and tested backups. Application changes and third-party integrations depend on the agreed scope.

Customer support route

Before you commit

Review the BAA, responsibility split, backup and recovery requirements, migration steps and support contacts with us. Tell us which procurement documents your organization needs so we can confirm what is available.

Review scope and documentation

Planning a new service

Quotes and general inquiries use our contact process during business hours. Existing customers should use their account's support instructions for infrastructure incidents.

Contact the team

Slim Framework hosting questions

Is this suitable for an HL7 or FHIR integration service?
The hosting side is: single-tenant isolation, encryption, audit logging, backups and a signed Business Associate Agreement. Whether your service implements those standards correctly is the application half and stays with you and your integration partners.
What about logging API requests?
Infrastructure and access logs are ours and are retained under the platform baseline. Application-level request logging is yours to design, and it is worth designing carefully. Full request bodies from a clinical integration are PHI, and verbose debug logging is a common way for it to end up somewhere unintended.
Do small services get the full baseline?
Yes. Isolation, encryption, WAF, audit logging, backups and monitoring are the same on every tier. A service being small changes its capacity requirements, not its obligations.

Find the right Slim Framework setup

Tell us what you run, what you need to move and who manages the application. We will help you scope capacity and responsibilities before you choose a tier.