Skip to main content

HIPAA Compliant Symfony Hosting

We run Symfony applications for healthcare organisations on a single-tenant AWS environment, with the Business Associate Agreement signed within 24 hours on managed tiers. Managed tiers from $199/mo.

How your service fits together

Map a Symfony system that has to outlive its build team

Which Messenger transports carry patient data, and how long is it retained?

1

Users, roles and connected systems

Your users, application choices and external services determine what needs to connect.

Inside your dedicated hosting environment

2

Your Symfony application and workers

Confirm application maintenance, access and deployment responsibilities during scoping.

3

Application database and message transports

Hosting includes encryption, audit logging and tested backups. Plan capacity follows your workload.

Illustrative operating model. Your final architecture and responsibilities are agreed during scoping. Connected applications and services need their own review; a hosting agreement does not establish their suitability.
Discuss your Symfony architecture

Why Symfony needs a HIPAA host, not a generic one

Symfony is chosen for systems meant to last: long support windows, explicit architecture, and a codebase a new team can still read in five years.

Built to outlive the build team

Healthcare systems are replaced far less often than they are handed over. Symfony long-term-support releases pair with a platform that is patched and monitored continuously, so age does not quietly become exposure.

Messenger and workers handle real records

Symfony Messenger moves work off the request. Those transports and their payloads sit inside the same isolated environment, under the same encryption, retention and audit-logging baseline as the database they came from.

Isolation you can describe to an auditor

Every tier is an AWS account dedicated to you. Being able to name the account, VPC and agreement turns an architecture diagram into something that survives an assessment.

Where our responsibility ends

Stated plainly, because knowing this before an incident is worth more than discovering it during one.

We run

  • The AWS account, VPC and network isolation
  • The operating system, patching and hardening
  • PHP, the web server, the database and TLS
  • CloudFront, the WAF, encryption, audit logging and backups
  • Monitoring and infrastructure incident response

You run

  • Your Symfony application, bundles and configuration
  • Framework and dependency updates, unless scoped with us
  • Security voters, roles and what your code does with PHI
  • The systems your application integrates with and the data you send them

If a problem turns out to be the server, PHP or the infrastructure, open a ticket and we take it. If it is inside your application, we tell you what we found and hand it back with recommendations.

HIPAA hosting vs standard hosting

A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.

Signed BAA before any PHI arrives
Standard Hosting
Not included
HIPAA Compliant
Included
Single-tenant isolation
Standard Hosting
Not included
HIPAA Compliant
Included
Encryption on by default, at rest and in transit
Standard Hosting
Not included
HIPAA Compliant
Included
Audit logs centralized and kept six years
Standard Hosting
Not included
HIPAA Compliant
Included
Encrypted backups with tested restores
Standard Hosting
Not included
HIPAA Compliant
Included
Written responsibility split
Standard Hosting
Not included
HIPAA Compliant
Included

Symfony hosting tiers

Every tier is a single-tenant AWS account with a signed BAA and the same compliance baseline. What changes is capacity.

Help me choose a hosting tier

Choose capacity for your workload, rather than the size of your organization. The published tiers share the compliance baseline described above.

CPU and memory
Consider concurrent requests, background jobs, database work and your application's memory needs. Traffic alone does not tell the whole story.
Storage and backups
Allow room for your application, database, uploads and expected growth. Compare the listed live-storage and backup allocations separately.
Data transfer
Estimate outgoing data from page visits, downloads and integrations, then compare it with the included transfer.
When to size up or scope a custom setup
Review capacity when monitoring shows sustained resource pressure or you expect a workload increase. Availability and recovery goals may require architecture changes, not simply a larger server.

Unsure where to start? Share the requirements you know. An engineer can help you choose an existing tier or scope a custom configuration.

Discuss Symfony capacity with an engineer
  • Starter

    $199/mo

    or $2,269/yr

    Compute
    1 vCPU
    Memory
    4 GB
    Storage
    50 GB
    Backups
    100 GB
    Transfer
    250 GB
    Order Starter
  • Solo

    $349/mo

    or $3,979/yr

    Compute
    2 vCPU
    Memory
    8 GB
    Storage
    100 GB
    Backups
    200 GB
    Transfer
    500 GB
    Order Solo
  • Practice

    $499/mo

    or $5,689/yr

    Compute
    4 vCPU
    Memory
    16 GB
    Storage
    200 GB
    Backups
    400 GB
    Transfer
    1,000 GB
    Order Practice
  • Clinic

    $849/mo

    or $9,679/yr

    Compute
    8 vCPU
    Memory
    32 GB
    Storage
    400 GB
    Backups
    800 GB
    Transfer
    2,000 GB
    Order Clinic
  • Group

    $1,499/mo

    or $17,089/yr

    Compute
    16 vCPU
    Memory
    64 GB
    Storage
    600 GB
    Backups
    1200 GB
    Transfer
    3,000 GB
    Order Group
  • Network

    $2,799/mo

    or $31,909/yr

    Compute
    32 vCPU
    Memory
    128 GB
    Storage
    800 GB
    Backups
    1600 GB
    Transfer
    5,000 GB
    Order Network

What every Symfony tier includes

The same compliance baseline at Solo and at Network. Capacity is the only thing that changes.

  • Single-tenant AWS environment
  • CloudFront CDN in front of every tier
  • Web application firewall
  • EBS storage with 7-day snapshot retention
  • Encryption at rest and in transit
  • Six-year audit logging
  • Tested, encrypted backups
  • Migration included
  • BAA signed within 24 hours of signup
  • 24/7 team, monitoring and infrastructure incident response

Know who owns the next step

Clear scope matters before launch and when you need help.

Hosting operations

Our published managed-hosting baseline includes 24/7 monitoring and infrastructure incident response, patching, logging and tested backups. Application changes and third-party integrations depend on the agreed scope.

Customer support route

Before you commit

Review the BAA, responsibility split, backup and recovery requirements, migration steps and support contacts with us. Tell us which procurement documents your organization needs so we can confirm what is available.

Review scope and documentation

Planning a new service

Quotes and general inquiries use our contact process during business hours. Existing customers should use their account's support instructions for infrastructure incidents.

Contact the team

Symfony hosting questions

Is Symfony a good fit for healthcare systems?
It is a common choice where a system has to be maintained for a long time by people who did not write it: explicit configuration, long-term-support releases and a strong convention for structure. None of that makes it compliant by itself, but it does make the application half easier to audit and hand over.
Do you support Symfony long-term-support versions?
The platform provides a supported PHP runtime, and which Symfony release you run on it is your decision. We will tell you when the PHP version underneath is approaching end of life, because that is ours to manage.
Where do Messenger transports run?
Inside the same single-tenant environment as the application and database, under the same encryption and audit-logging baseline. Message payloads routinely contain patient data, so they should not be sitting on infrastructure outside the boundary you documented.

Find the right Symfony setup

Tell us what you run, what you need to move and who manages the application. We will help you scope capacity and responsibilities before you choose a tier.