HIPAA here means the United States rules that bind the company running an app that holds health records for a covered entity or for one of its business associates. The patient-side questions that share the phrase, a person’s own rights over their chart, an employee’s complaint about a colleague reading one, the fee a clinic charges to copy a file, belong to a different subject and are not answered here. The question below is what a small software product gets billed once those records are already inside it.

The bill arrives in four pieces: somewhere the records are allowed to sit, a subscription that keeps the paperwork, an assessment if a customer asks for one, and the app’s own work. Three of the four have published prices. Linford and Company, an audit firm, put a HIPAA compliance audit at $8,000 to $25,000 on 3 September 2026.

Each figure below is printed as the page publishing it prints it, taken on 3 September 2026 from four sellers’ own price lists and from one rule the Department of Health and Human Services entered in the Federal Register. Nothing is averaged, nothing is folded into a range, and a page that refused to open, or that carries no figure at all, gets that said about it instead of a number. I have never audited, hosted, assessed or certified anybody’s health app. This is not legal advice, and the question of whether your own product falls inside the rule is not answered anywhere on this page.

What a HIPAA bill for a small app is actually made of

Four different companies can be involved, and each of them is selling a different thing. This section names all four and says where each one is answered in full. It carries no figures, on purpose.

Somewhere the records are allowed to sit. A hosting company or a platform that will sign a business associate agreement, and charge for a plan tier that carries it. If the app already runs on a managed database or a builder, that plan gate is the first line of the bill and often the only one the owner has met. What the plan floor and the paid add-on actually cost on Supabase is written out in one place, and what one builder’s own paperwork documents about health data in another. The map of which platforms sign that agreement, and what each one requires before they will, is drawn separately, and what one builder’s own pages say about health data today is read on another.

The paperwork and the record-keeping. A subscription to a compliance platform: policies, training records, a register of vendors, somewhere to keep the agreements you have signed. Priced per organisation, and published more openly than anything else in this market.

The assessment. An outside firm reading your controls and writing down what it found. A few publish a fee. Most do not, and that is worth knowing before the calls start.

The app’s own work. Whether one signed-in account can reach a different account’s record, what the app records about who read what, and where health records end up once they leave the database. Nobody above prices it, because none of them sells it. What actually has to move inside a product that is already holding them is a separate job from pricing it.

Those four are the bill for a small product. A number from a search result is nearly always one of them, presented as though it covered all four.

What a place to put the records costs, on two hosts’ own price lists

Two companies selling HIPAA hosting publish their prices in public. Both pages were read on 3 September 2026, with an ordinary request and a browser-shaped one, and both returned the same bytes to each.

Aptible’s pricing page sells three plans plus usage. Development carries a $0 /month base fee and is described as being for prototypes and early development. Production carries a $499 /month base fee, and the page’s own description of that plan is unusually specific: “Deploy in your own private network with high availability and 100% of HIPAA controls applied automatically.” Enterprise is priced as Custom. The same page prices a Dedicated Stack, which the Production plan includes one of, at $499/stack/month, and lists a separate LLM Gateway at $400 /mo + usage. The page describes that gateway as “One HIPAA-compliant gateway for LLM calls in your product and agentic workloads” and says it “Covers Anthropic, OpenAI, and Bedrock-hosted models under a single BAA”. If the app calls a model and the prompt carries a patient’s history, that last line is the only place on either of these two pricing pages where that problem has a price at all.

Every Aptible plan is a base fee with usage on top, and its own estimator says so in numbers. On its default settings on 3 September 2026, that estimator takes a Development plan from a $0.00 base fee to a Total $168.60/mo once app containers, endpoints, database containers, storage and thirty backups are added. That is the page’s own worked example, and it shows which half of a price is the plan and which half the machines.

Atlantic.Net’s HIPAA hosting page sells the other shape: fixed managed servers, priced monthly, each plan listing a Business Associates Agreement among its included items.

Plan, as the page names itWhat the page chargesWhat the page lists in it
HIPAA Developer Linux$552.31 Per MonthManaged firewall, BAA, daily backups, vulnerability scans
HIPAA Business Linux$644.16 Per MonthThe same list with intrusion prevention added
HIPAA DR Hosting Linux$973.27 Per MonthThe Business list, aimed at disaster recovery
HIPAA DR Hosting Windows$1,026.62 Per MonthThe Windows equivalent, the highest published row

Two of the six published plans are left out above, both of them variants sitting between those rows; the page also lists a HIPAA Custom tier with no figure against it. Under the plans it sets three further terms in its own words: migration under the HIPAA Business and HIPAA Enterprise plans is “free for up to four hours and billed at $160.00 per hour after the first four hours”, pricing is “based on 12-month term”, and “A one-time $150.00 setup fee is required to configure the FortiGate firewall.”

Those are two companies’ published prices for two shapes of hosting, and neither is a market rate. One sells a deployment platform charged as a base fee plus what you run, the other a managed server on an annual term. The paperwork appears differently on each. Atlantic.Net lists a Business Associates Agreement among the included items on every HIPAA plan card. Aptible names HIPAA and SOC 2 as supported compliance frameworks from its Production plan upward, lists none against Development, and names a business associate agreement in one place on the whole page, against its LLM Gateway add-on. Neither page, read on 3 September 2026, prices the agreement as a line of its own.

What the paperwork subscription costs, on the seller’s own price list

The second line buys none of the hosting and none of the assessment. It buys somewhere to keep policies, training records, signed agreements and a register of the vendors that touch health records, so the day somebody asks, the answer is not built from memory.

Accountable publishes its whole price list. Its pricing page, read 3 September 2026, prices three plans per organisation with a seat count included in each, and prints a monthly figure and an annual figure against every plan.

PlanSeats includedPrice
Basic HIPAA15 employees, extra seats $9/mo each$199 a month, or $169 a month billed annually ($2,028/yr)
Plus15 employees, extra seats $15/mo each$299 a month, or $254 a month billed annually ($3,048/yr)
Pro20 employees, extra seats $19/mo each$799 a month, or $679 a month billed annually ($8,148/yr)

Read the seat column, because it says who the product is for. The price is built around a headcount, with fifteen or twenty people bundled in and named training courses attached, which is the shape of a clinic rather than of two people running a product. A small software company pays for a structure it does not have, and gets the parts it does need, the vendor register and the agreement store and the policy set, inside the same subscription.

Two others in the same category publish nothing. As of 3 September 2026, Total HIPAA’s pricing page does not render a figure to an automated read (a plain request and a browser-shaped request both rendered no figure), and Compliancy Group’s pricing page does not either, on the same test. Their addresses are totalhipaa.com/pricing/ and compliancy-group.com/pricing/, and both are a route to a conversation rather than a price list.

The other report enterprise customers ask for carries a bill of its own, built out of different sellers, and it is counted separately from anything on this page.

What an assessment costs, and who says so before you ask

People search for the price of getting HIPAA certified, and the sellers themselves concede what that phrase buys. Drata’s own page on the subject, at drata.com/learn/hipaa/certification-cost and read 3 September 2026, says that assessors and compliance platforms “may issue a certificate of completion or an audit report”, then adds: “While these documents can be useful for internal assurance and customer trust, regulators do not recognize them as proof of compliance.” What is actually for sale is an assessment, and one firm on this search publishes what it charges for one.

Linford and Company LLP is an audit firm rather than a software seller. On its HIPAA compliance audit services page, read 3 September 2026, it answers the question directly: “A HIPAA compliance audit costs, on average, $8,000 to $25,000, depending on a variety of factors that influence the fee associated with the audit.” The factors it names are the breadth of the audit, the services the organisation provides, how many physical locations have to be visited, and its size. The same page says what the resulting document is: a HIPAA compliance audit report issued under the attestation standards the American Institute of Certified Public Accountants sets in AT-C Section 315, Compliance Attestation, and it separates a report that may go to clients from an assessment written only for management.

KirkpatrickPrice, which ranks for the same work, publishes no fee. Its HIPAA audit services page at kirkpatrickprice.com/audit/hipaa/ was read raw on 3 September 2026, whole, including its own navigation index of every audit and every test it sells, and carries no dollar figure anywhere. That is one firm, one page, one date, not a statement about how it quotes.

An assessor may also want the running system tested, which is bought somewhere else again from somebody else again. What such a request is really asking for, and which kind of test answers it, belongs to the page on pen tests and what customers mean when they ask for one, and nothing further is said about it here.

Why the numbers on this search disagree by more than ten times

Five pages that rank for this question were read raw on 3 September 2026, whole, each tested with an ordinary request and a browser-shaped one. All five price the same object, and that object is a healthcare organisation.

Secureframe’s cost article breaks a programme into line items and totals it at “$25k-100k+”, with an “Onsite HIPAA compliance audit (if necessary): $40k+” and annual staff training at “$30-50 per user”. Compliancy Group’s cost article totals a multi-location organisation’s consulting bill at “$78,000+”, built from “$20,000+ for Risk Analysis and Management Plan”, “$40,000+ for Onsite Audit” and four smaller rows, and gives a single-location organisation a total of $4,000 to $12,000. Thoropass’s guide puts auditor fees at “$15,000 to $200,000+” and prices remediation from a thousand dollars up to architectural changes it says can exceed $200,000. The HIPAA Journal, a publisher rather than a seller, opens a piece dated 13 March 2025 by saying that mid-range estimates “fall into the range of between $80,000 and $120,000”. Drata’s page, which refused an ordinary request that day and answered a browser-shaped one, puts onsite HIPAA audits at “$40,000+” at the foot of a seven-row list of the same kind. The five were read at secureframe.com/hub/hipaa/costs, compliancy-group.com/cost-of-hipaa-compliance/, thoropass.com/blog/hipaa-audit-cost-a-guide, hipaajournal.com/how-much-does-hipaa-compliance-cost/ and drata.com/learn/hipaa/certification-cost. Four of the five sell in this market, so their addresses are text here and carry no link.

Now the counted part. Across those five pages, read whole and including their navigation, the count of BAA-covered hosting plan prices is zero, the count of builder or database plan gates is zero, and the count of priced subprocessors is zero. Aptible, Atlantic.Net, Supabase and Firebase are named as vendors on none of the five. Drata’s page mentions “cloud storage and hosting providers” once, as a category of business associate, with no figure attached.

There is a second tell. Two of the five reproduce the same thirteen-year-old government table: Secureframe’s page and Drata’s page both list a notice of privacy practices, breach notification requirements, business associate agreements and Security Rule compliance for business associates, with identical figures against each, totalling $1,210, both attributing it to the estimate HHS published with the 2013 Final Rule. That thirteen-year-old $1,210 sits a few paragraphs from Secureframe’s own “$25k-100k+” total, and each page qualifies it in the sentence that follows. Secureframe writes that “[f]or most organizations $283 for compliance with these requirements is not a realistic number”; Drata writes that “those figures represent minimal administrative obligations, not the full cost of building a secure, scalable HIPAA compliance program”. Each then goes on to the larger programme figures quoted above.

That is what the factor of ten is made of. These pages price a healthcare organisation: an office, staff who need annual training, physical locations an auditor visits, a notice of privacy practices to give patients. If you are two people and an app, most of the object being priced does not exist in your case, and the parts of your bill that do exist are absent from theirs. The question underneath the search, how much it costs to build a HIPAA compliant app, has no answer here because none of these pages is pricing software at all.

What a HIPAA violation costs, in the amounts the rule sets today

The one set of HIPAA numbers a government publishes is the penalty schedule, and it moved this year. The Department of Health and Human Services published its current adjusted amounts in a final rule in the Federal Register on 28 January 2026, at 91 FR 3665, document number 2026-01688, which revises table 1 to 45 CFR 102.3. The rows below cite 45 CFR 160.404, the regulation that sets HIPAA penalties, and the amounts are the ones in the column the table labels “2025 Maximum adjusted penalty ($)”.

The rule states its own reach in one sentence: “The adjusted civil monetary penalty amounts apply to penalties assessed on or after the date of publication to the Federal Register, if the violation occurred on or after November 2, 2015.” It also gives the arithmetic: a cost-of-living multiplier for 2025 of 1.02598, applied to the previous year’s amounts and rounded to the nearest dollar.

The four tiers are separated in the rule by what the organisation knew, in the table’s own terms: a violation the covered entity or business associate did not know about and would not have known about by exercising reasonable diligence; one due to reasonable cause and not to willful neglect; one due to willful neglect but corrected inside the thirty-day period the rule describes; and one due to willful neglect and not corrected in it.

Tier, in shortMinimum per violationMaximum per violationCalendar-year cap
Did not know$145$73,011$2,190,294
Reasonable cause$1,461$73,011$2,190,294
Willful neglect, corrected$14,602$73,011$2,190,294
Willful neglect, not corrected$73,011$2,190,294$2,190,294

One more row covers violations before 18 February 2009, at a single amount of $198 with a calendar-year cap of $49,848. All of it comes from the Government Publishing Office’s copy of the rule, read 3 September 2026.

Two notes on where those figures came from, because the obvious sources would not open. As of 3 September 2026, HHS’s own enforcement pages refused an automated read (a plain request and a browser-shaped request both returned a refusal), so the penalty amounts here are taken from the rule HHS published in the Federal Register, read from the Government Publishing Office copy. The refused address was hhs.gov/hipaa/for-professionals/compliance-enforcement/index.html, and its enforcement rule page beneath it did the same. The Federal Register’s own copy of the same document, at federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment, answered both request shapes with an access notice in place of the document, so it corroborates nothing on its own and is recorded here as the address of the same rule rather than as a source that was read.

One thing is worth checking against whatever you read next. On 3 September 2026, several pages ranking on this search, and one seller’s own pricing page, still printed penalty ceilings the current table does not carry. Secureframe’s cost article says fines “can reach $1.5 million per year”. Drata’s page says “Civil penalties can range from $100 to $1.5 million per year” and, further down, that fines “can reach $1.5 million per year for willful neglect”. Accountable’s pricing page, the same one that publishes the plan figures above, prints a tier block ending at “$2.07M/yr” whose lowest tier opens at $100. The rule published on 28 January 2026 puts the lowest minimum at $145, the maximum in three of the four tiers at $73,011, and the calendar-year cap at $2,190,294. That is a comparison between what those pages printed on that date and what the rule states, and nothing more.

What none of those prices covers

Pay all three published lines and you have bought a place to put the records, a filing cabinet for the paperwork, and somebody to come and look. None of it touches the code.

Three questions decide whether the app is doing what the paperwork says it does, and no seller above prices any of them. Whether one signed-in account can reach a different account’s record, settled by trying it with two real accounts rather than by reading the policy that says it cannot happen. What the app records about who read what, which is a different thing from an error log and is usually missing in a product nobody wrote by hand. And where health records go once they leave the database: into a model provider’s prompt, a logging service, an email, an export somebody built in an afternoon. The hosting agreement covers the host and the subscription covers the documents. Nothing on either bill reaches what the code does, and the way to settle it is for somebody who can read the thing to go and look. What a review of an app’s own code covers is written out separately, and it is sold by companies in a different line of work again.

None of that is sold here either. It is not an auditor, an assessor, a compliance platform, a host or a law firm, it writes no policies and negotiates no agreements, and it never decides whether an app meets the rule.

Common questions about HIPAA compliance cost

How much does HIPAA compliance cost for a small app?

There is no single figure, because four sellers are involved and only three publish anything. The prices published on 3 September 2026: HIPAA hosting from Aptible at a $499 per month base fee plus usage on its Production plan, or managed servers from Atlantic.Net between $552.31 and $1,026.62 per month on a twelve-month term; a compliance subscription from Accountable at $199, $299 or $799 per month by plan; and a HIPAA compliance audit from Linford and Company at, in its own words, “on average, $8,000 to $25,000”. The fourth line, the app’s own work, is priced by nobody here.

Those are four companies’ prices for four different things, not a total. Adding them would produce a number nobody has quoted you.

How much does it cost to get HIPAA certified?

Nothing, in the sense the question means, because the certificate is not the thing being sold. Drata’s own page on HIPAA certification cost, read 3 September 2026, states that assessors and compliance platforms “may issue a certificate of completion or an audit report” and then says of those documents that “regulators do not recognize them as proof of compliance”. What has a price is the assessment behind the document, and the one audit firm on this search that publishes a figure puts it at $8,000 to $25,000.

If a quote arrives for HIPAA certification specifically, the useful next question is which of the four lines above it covers.

What does a HIPAA risk assessment cost?

Most firms that perform this work publish no fee, and the figures circulating on this search come from companies selling software rather than from the firms doing the assessing. On 3 September 2026, Compliancy Group’s cost article priced a risk analysis and management plan at “$2,000” for a single-location organisation and “$20,000+” for a multi-location one, and Secureframe’s article gave “$2k-20k, depending on organization size and complexity” for the same line item. Both describe a healthcare organisation, not a software product.

Two named firms that actually run these audits sit either side of the question: Linford and Company publishes an $8,000 to $25,000 range on its own service page, read 3 September 2026, and KirkpatrickPrice’s HIPAA audit services page carried no figure at all on the same date.

Do I have to pay for HIPAA compliant hosting, or can I stay on my current plan?

That turns on what your current provider’s own pages say, and it is a contract question before it is a price question. On the two pages read here on 3 September 2026, Atlantic.Net lists a Business Associates Agreement among the included items on every HIPAA plan card, while Aptible’s own comparison table names no supported compliance framework against its Development plan and names HIPAA and SOC 2 from Production upward. Either way the answer sits on a tier rather than on a change of technology.

Which platforms sign that agreement, and what each of them wants in place first, is mapped across the whole set elsewhere, and the two platforms most AI-built apps already sit on have their own answers written out in full.

How much does it cost to build a HIPAA compliant app?

Nobody ranking on this search is answering it, which is the finding rather than a dodge. All five pages read on 3 September 2026 price a healthcare organisation’s programme: staff training per user, an onsite audit, a notice of privacy practices, a consultant. None names a hosting plan price, a builder or database plan gate, or a subprocessor’s fee, and none quotes what building or hosting a small app costs; the closest is Thoropass’s remediation range, from about a thousand dollars up to architectural changes it says can exceed $200,000, which is priced for an existing organisation’s programme rather than for a small app.

What a whole build is priced at, before any of this, is counted separately, and the running bill for the tools that built it is counted somewhere else again. Both are questions about the app, and neither one moves any of the four lines here.

What is the maximum fine for a HIPAA violation?

Under the rule the Department of Health and Human Services published on 28 January 2026, at 91 FR 3665, the maximum per violation is $73,011 in three of the four tiers, and $2,190,294 in the tier for willful neglect that was not corrected in the thirty-day period the rule describes. The calendar-year cap is $2,190,294 across all four. Those amounts sit in the column labelled “2025 Maximum adjusted penalty ($)” in table 1 to 45 CFR 102.3, in the rows citing 45 CFR 160.404.

The rule states that the adjusted amounts apply to penalties assessed on or after its publication date where the violation occurred on or after 2 November 2015. Several pages ranking on this search still print an annual ceiling of $1.5 million instead.

Does signing a BAA reduce what I have to spend?

It changes which of the four lines you are paying, and the total moves with it; whether it moves down depends on what the plan with the agreement costs against what you would otherwise have bought, and nobody in this article publishes that comparison. On Atlantic.Net’s page a Business Associates Agreement is an included item on every HIPAA plan card rather than a charge of its own, and the one place Aptible’s pricing page names a business associate agreement is its LLM Gateway add-on. What neither page answers for is the code above it: every vendor page in this article draws its line at its own service.

Is a compliance platform subscription the same as an audit?

No. A subscription of the kind priced above keeps policies, training records, agreements and a vendor register, and produces documents. An audit is an outside firm examining what is in place and writing a report about it. Linford and Company’s own service page describes what it issues as a HIPAA compliance audit report under the American Institute of Certified Public Accountants’ attestation standard AT-C Section 315, which is not a thing a subscription generates.

They come from different companies, on different price pages, and paying for either leaves the other unpaid.

What is the cheapest way to hold health data in an app that already works?

On the prices read on 3 September 2026 for this page, the lowest recurring figure on a plan card that lists a Business Associates Agreement is Atlantic.Net’s HIPAA Developer Linux plan at $552.31 per month on a twelve-month term, and the lowest hosting entry point of any kind is Aptible’s Production plan at a $499 per month base fee before usage. Neither is a recommendation, and neither includes the paperwork subscription or the assessment.

For most owners the cheaper move is finding out which health records the app is actually holding, and where they are already travelling to, before paying anybody to protect a set of data nobody has mapped.