HIPAA compliance costs most digital-health startups roughly $15,000–$50,000 — there’s no certificate to buy, so the cost is policies, a risk assessment, technical controls, Business Associate Agreements, tooling and engineering time. With Folksoft’s managed HIPAA gap assessment, most healthtech teams reach HIPAA-ready in weeks for a few thousand dollars plus minimal internal effort — a real GRC analyst end to end, not a dashboard.
What most healthtech startups pay across risk analysis, policy work, tooling and internal time — for a team of 11–25 on simple infrastructure.
Those are open-market figures. Leave your name and work email and someone from our team will come back to you with your price for this exact scope, or book a call and talk it through.
Indicative ranges based on what early-stage startups typically pay in the US market — your figure depends on scope, cloud footprint and how many vendors need a Business Associate Agreement.
There is no certificate and no mandatory auditor, so every dollar in a HIPAA budget buys work rather than a badge.
The Security Rule risk analysis, the policies that come out of it, and the remediation work in between — plus inventorying which vendors touch PHI and getting a Business Associate Agreement signed with each one. It prices on how much infrastructure handles PHI, not on headcount, and it is the one line HIPAA genuinely requires.
An annual licence to hold the policies, the risk register, the training records and the evidence an enterprise security review will ask for. Most vendors price per employee, so it grows every time you hire — and it renews every year, HIPAA being a standing obligation rather than a one-off project.
The line nobody budgets for. Engineers pulled off the roadmap to encrypt what holds PHI, wire up audit logging, tighten access controls, chase BAAs out of vendors and write down what they did. It scales on headcount and on how many environments carry PHI at once.
An independent firm reviewing your HIPAA posture and writing it up. Nothing in the law asks for one, and it is not a certificate — but a hospital, payer or enterprise buyer occasionally names it in a security review. It is the only part of a HIPAA budget that behaves like a SOC 2 audit fee.
There is no HIPAA certificate, so what you are choosing is whether anyone outside your company reviews the work.
The standard route, and what Folksoft delivers. The Security Rule risk analysis is run, the policies are written, the gaps are closed, and you get a Gap Assessment Report you can put in front of a customer.
An outside firm reviews the same controls and attests to them. Buy one when a hospital, payer or enterprise customer asks for it by name — never by default.
There is no such thing as HIPAA certification. A vendor selling you a “HIPAA certified” badge is selling their own logo, not a legal status — what regulators and enterprise buyers ask to see is a documented risk analysis and the controls behind it. See the full HIPAA programme.
Most of the savings are in scoping the PHI, not in shopping for a cheaper consultant.
Only the systems that create, receive, store or transmit protected health information are in scope. Push PHI out of the ones that do not need it and the risk analysis, the controls and the bill all shrink together.
HIPAA has none to sell. Money spent on a badge is money not spent on the risk analysis and the controls that an OCR investigation — or an enterprise security questionnaire — will actually ask you to produce.
AWS, Google Cloud, Azure and most healthtech SaaS offer a standard Business Associate Agreement you can execute at no charge. Paying to draft one per vendor is the most avoidable line on the bill.
SOC 2, ISO 27001 and GDPR share most of their controls with the HIPAA Security Rule. Running them through one programme costs far less than three separate projects — toggle them in the calculator above to see the difference.
Most healthtech startups spend $15,000–$50,000 all-in during year one. There is no certificate to buy, so the money goes on a Security Rule risk analysis and the readiness work around it ($8,000–$20,000), a GRC platform to hold the evidence ($6,000–$12,000 a year), and your own engineering and security time ($2,000–$21,500, depending on headcount and how much of your infrastructure touches PHI). An optional third-party assessment adds $5,000–$15,000 on top. Folksoft covers the same scope for less. What that comes to depends on your environment, so we price it properly rather than guessing at it here — leave your details on the calculator above and we’ll come back with your price.
No. There is no such thing as HIPAA certification — the Department of Health and Human Services does not certify anyone, and no other body has the standing to. What exists is evidence: a documented risk analysis, written policies, implemented technical controls, workforce training and signed Business Associate Agreements. A vendor selling a “HIPAA certified” badge is selling their own logo, which costs real money and carries no legal weight. If a customer wants outside validation, an optional third-party assessment runs $5,000–$15,000 — and produces a report, not a certificate.
A gap assessment is internal: a consultant — or Folksoft — runs the risk analysis, writes the policies, closes the gaps and hands you a Gap Assessment Report. All-in, that year lands at $16,000–$53,500 depending on headcount and how much of your infrastructure handles PHI. A third-party assessment adds an independent firm’s review on top at $5,000–$15,000, taking the same year to $21,000–$68,500. Nothing in HIPAA requires the third party, so buy one when a hospital, payer or enterprise customer asks for it by name.
The agreements themselves usually do not. Every vendor that creates, receives, stores or transmits PHI on your behalf needs a BAA, and the major ones — AWS, Google Cloud, Azure and most healthtech SaaS — publish a standard agreement you can execute at no charge. The cost is the work around them: inventorying which vendors actually touch PHI, chasing signatures, and replacing or re-architecting around the ones that will not sign. That sits inside the risk analysis and readiness line ($8,000–$20,000), and it is the step that most often turns up a vendor you have to swap out.
Two to four months on the open market, from the risk analysis through to controls being in place and evidenced. Almost all of that is readiness work rather than review — there is no observation window as there is for SOC 2 Type 2, and no audit to schedule. Folksoft gets healthtech startups HIPAA-ready in weeks, and an optional third-party assessment, if a customer asks for one, runs after that.
Fifteen minutes on a call and we’ll scope the PHI, name the price and give you a date for your Gap Assessment Report.