Crowdsourced transparency for healthtech

The HIPAA (BAA) Tax

A hidden cost that hits healthtech founders when they least expect it.

TL;DR: Many SaaS vendors offer affordable "Pro" plans at $20–50/mo, but lock the Business Associate Agreement (BAA), a legal requirement for handling patient data under HIPAA, behind "Enterprise" plans that cost $20k–50k/year. This is the HIPAA Tax.

🔒

Enterprise Barrier

Vendors that require an enterprise upgrade to sign a BAA.

VendorBase PriceBAA RequirementSourceUpdated
HubSpotPro: $800/moEnterprise: $3,600/mo + $3k–7k onboardinghubspot.com2025-12-02
TypeformPlus: $50/moEnterprise Plan (Contact Sales)typeform.com2025-12-02
Monday.comPro: $16/seat/moEnterprise Plan (Contact Sales)monday.com2025-12-02
NotionPlus: $10/user/moEnterprise Plan (Contact Sales)notion.com2025-12-02
BoxBusiness: $15/user/moEnterprise, Enterprise Plus, or Enterprise Advancedbox.com2025-12-02
NetlifyPro: $20/user/moEnterprise (Contact Sales)netlify.com2025-12-02
SnowflakeStandard: $2/creditBusiness Critical: starts at $10,000snowflake.com2025-12-02
💳

Compliance Premium

Vendors that charge a published add-on fee for BAA access.

VendorBase PriceBAA RequirementSourceUpdated
RenderProfessional: $19/user/moOrganization: $29/user/mo + 20% usage fee + $250/mo minimumrender.com2025-12-02
Railway$5/mo minimum$1,000/mo spend thresholdrailway.com2025-12-02
DigitalOceanDroplets: $4/moStandard Support Plan: $99/modigitalocean.com2025-12-02
Fly.ioPay-as-you-goCompliance Support: $99/mofly.io2025-12-02
VercelPro: $20/moPro Add-on: $350/movercel.com2025-12-02
IntercomEssential: $29/seat/moExpert: $132/seat/mointercom.com2025-12-02
SupabasePro: $25/moTeam: $599/mo + HIPAA Add-On (Contact Sales)supabase.com2025-12-02

FAQ

What is the HIPAA (BAA) Tax?

The HIPAA (BAA) Tax is a hidden cost that hits healthtech founders when SaaS vendors lock Business Associate Agreements (BAAs), a legal requirement for handling patient data under HIPAA, behind enterprise plans that cost $20k-50k/year while base plans are only $20-50/month.

What is a Business Associate Agreement (BAA)?

A BAA is a legal contract required under HIPAA between a healthcare provider (covered entity) and a vendor (business associate) that handles Protected Health Information (PHI). Without a signed BAA, healthcare companies cannot legally use a SaaS product to process patient data.

I'm a vendor and I'd like to update this information.

Please feel free to submit a PR to this page, or reach out at hipaa@keygraph.io.

Acknowledgments

Inspired by the original SSO Tax, which brought transparency to enterprise SSO pricing. Building on the precedent set by BAA Tax, an earlier effort that never quite took off. And finally, sparked by a Bookface comment from a YC founder who got hit by the HIPAA BAA tax while building their healthtech startup.