Every healthtech founder budgeting for AWS eventually hits the same surprise: the infrastructure bill can be predicted, and the compliance costs sitting next to it are not. HIPAA adds a quiet markup to your AWS spend, typically 15 to 25 percent, from encryption, audit logging, and network isolation you wouldn’t otherwise need.
SOC 2 adds a smaller markup on the AWS side, services like CloudTrail, GuardDuty, and Security Hub, but the real cost lives outside your cloud bill entirely: $30,000 to $150,000 in audits, pen tests, and compliance tooling in year one alone.
Why Healthtech infra budgeting is different
Most SaaS companies budget cloud spend with one number. Compute, storage, database, backups. It scales with usage, and that’s that.
Healthtech companies carry two more obligations. Founders often budget for both the same way. That’s the mistake.
HIPAA is an infrastructure cost. It lives inside your AWS bill. Encryption, access controls, audit logging, network isolation, all applied to anything touching patient data. It shows up as a markup on what you’d already pay.
SOC 2 is different. It’s a program cost, not an infrastructure cost. Most of it sits outside AWS entirely, in auditor fees, penetration tests, and compliance software. Only a small slice, tools like CloudTrail, GuardDuty, and Security Hub, lands on the cloud bill itself.
Core AWS budget by stage
| Stage | Monthly AWS spend | Infra as % of revenue | What’s typically running |
|---|---|---|---|
| Pre-seed / MVP | $500 – $2,000 | 15% – 25% | A few EC2 instances or Lambda functions, S3, a single managed database |
| Seed, early traction | $2,000 – $10,000 | 15% – 25% | Multi-AZ database, growing compute footprint, first dedicated compliance controls |
| Series A, scaling | $10,000 – $20,000 | 10% – 15% | Larger compute clusters, read replicas, more automated monitoring and logging |
| Series B and beyond | $20,000 – $100,000 | 5% – 10% | Multi-region redundancy, dedicated data pipelines, mature reserved capacity |
HIPAA’s markup on your AWS bill — what specifically drives the 15–25%
The 15 to 25 percent isn’t one fee. It’s five separate categories of cost, each doing different work.
Encryption everywhere
HIPAA requires encryption at rest and in transit for anything touching PHI. That means KMS keys on every volume, every S3 bucket, every RDS instance. KMS itself is cheap, a few dollars per key per month. But encrypted storage and the API calls to manage it add up across a growing fleet.
Audit logging and retention
CloudTrail has to run everywhere, not just on critical systems. Logs need to be kept for years, not weeks. That’s S3 and Glacier storage that never gets cheaper, plus CloudWatch charges for anything you’re actively monitoring.
Network isolation
PHI can’t sit on shared, multi-tenant services. That rules out Lightsail. It often means dedicated VPCs, private subnets, and PrivateLink endpoints instead of public internet routes. Isolation costs more than convenience.
Redundancy and backups
Multi-AZ deployments aren’t optional once patient data is involved. Backup retention windows stretch longer too, often years, not the 7 or 30 days a typical SaaS app keeps. Every extra AZ and every extra month of backups is a direct line to the bill.
Add it up, and none of these are dramatic on their own. Together, they’re where the 15 to 25 percent comes from.
Engineering costs
None of this configures itself. Someone has to set up the VPC, wire up KMS, define retention policies, and keep it all audit ready. That’s weeks of senior engineering time upfront, then ongoing work every time the infrastructure changes.
Teams without that expertise in house often lean on a healthtech AWS infrastructure partner instead. Either way, the cost is real. A misconfigured bucket or a missed BAA on the wrong service costs far more than getting it right the first time.
SOC 2’s cost

SOC 2 requires real infrastructure: centralized logging, tightened IAM, monitoring across GuardDuty, Config, CloudTrail, Security Hub. Much of it overlaps with what HIPAA already forces you to build. That AWS side runs $200 to $2,000 a month.
The bigger cost sits outside the infrastructure entirely: the audit itself, compliance automation software, penetration testing. Early stage, Type I: $30,000 to $55,000 in year one. Growth stage, Type II, the report most healthcare buyers require: $70,000 to $150,000. Full breakdown in How Much Does SOC 2 Cost on AWS?.
Putting it together: a realistic all-in budget table by stage (AWS + HIPAA overhead + SOC 2 amortized monthly)
Put the three costs together and the real number looks different from a plain AWS estimate.
| Stage | Monthly AWS infra (HIPAA included) | SOC 2 program cost (year 1) | SOC 2 amortized monthly |
|---|---|---|---|
| Pre-seed / MVP | $600 – $2,500 | Usually not started yet | — |
| Seed, early traction | $2,300 – $12,500 | $30,000 – $55,000 (Type I) | +$2,500 – $4,600 |
| Series A, scaling | $11,500 – $25,000 | $70,000 – $150,000 (Type II) | +$5,800 – $12,500 |
| Series B and beyond | $23,000 – $125,000 | $40,000 – $70,000 (Type II renewal) | +$3,300 – $5,800 |
SOC 2 doesn’t bill monthly. It lands as a large chunk once a year. The amortized column just shows what it costs if you spread it evenly, so it’s easier to compare against your AWS bill.
Common mistakes that blow the budget
Budgets rarely blow up from the big numbers. They blow up from the ones nobody accounted for.
Treating SOC 2 as an AWS line item
Founders often fold SOC 2 into their cloud budget forecast. It doesn’t belong there. Most of the cost sits in audit fees and software, not infrastructure, and budgeting it as if it scales with usage leads to a nasty surprise at renewal time.
Using non-eligible AWS services for PHI
Lightsail, Amplify, Chime. None of them are HIPAA eligible, even with a signed BAA. Teams that build on these early, usually for speed, end up re-architecting under deadline pressure once an auditor or a customer’s security team flags it. Here is the full list of HIPAA eligible services.
Under-budgeting audit prep time
The audit fee is the easy number to find. The engineering hours to get ready for it aren’t. Plan on 80 to 200 hours of internal time for a Type II audit. Skip that, and the timeline slips by months.
Skipping the BAA on a subprocessor
Every vendor that touches PHI needs a signed BAA, not just AWS. Email providers, analytics tools, customer support platforms. Missing one is a common finding in HIPAA audits, and it’s usually the vendor nobody thought to check.
Over-provisioning before usage is predictable
Committing to Reserved Instances or a Savings Plan too early locks in capacity you don’t need yet. Wait until usage patterns settle, usually a few months post-launch, before making that commitment.
Savings levers once you’re past the compliance ramp

Compliance costs are mostly fixed. Infrastructure costs aren’t. Once usage patterns settle down, there’s real room to cut.
Reserved Instances and Savings Plans
Once workloads are predictable, commit to them. A one year Savings Plan can cut compute costs by up to 66 percent compared to on demand pricing. Most teams wait too long to make this switch.
Glacier and lifecycle policies for retention
HIPAA and SOC 2 both require years of log and backup retention, not months. Storing all of it on standard S3 gets expensive fast. Lifecycle policies that move older logs and backups into Glacier or Glacier Deep Archive keep you compliant at a fraction of the cost.
Right-sizing and cutting idle resources
Compliance work tends to add resources, extra logging instances, monitoring agents, redundant environments, that outlive their purpose. A regular right-sizing pass catches over-provisioned instances and orphaned volumes before they become permanent line items, which is usually where ongoing AWS management pays for itself.
Scoping security tooling to production
GuardDuty Runtime Monitoring and similar tools charge per resource monitored. Dev and CI environments rarely need the same depth of threat detection as production. Narrowing scope to where compliance actually requires it cuts the bill without cutting coverage.
Negotiating compliance software and audit renewals
Vanta, Drata, and Secureframe pricing is negotiable, especially through partners, often 15 to 25 percent off list. The same applies to auditors at renewal. Year two SOC 2 costs already drop 30 to 50 percent on their own; negotiating on top of that compounds the savings.
What to budget
Three numbers, not one. That’s the real takeaway.
Start with core AWS infrastructure for your stage. Add 15 to 25 percent for HIPAA, and build it into the architecture from day one rather than retrofitting later. Then budget SOC 2 separately, as a program cost, not a cloud cost, and plan for it landing once a year rather than spreading evenly.
A few checks before you lock in a number:
Confirm every service touching PHI is on AWS’s HIPAA eligible list, not just covered by the BAA. Get a BAA signed with every subprocessor that touches patient data, not just AWS. Budget engineering time for compliance work explicitly, it’s real cost even without an invoice. Decide on Type I or Type II early. If you’re selling to health systems or enterprise buyers, Type II is likely non negotiable, so budget for it from the start rather than treating Type I as a placeholder.
None of these numbers are exact. Account structure, existing security hygiene, and auditor choice all move them. But founders who budget for HIPAA and SOC 2 as two different kinds of cost, one infrastructure, one program, tend to avoid the surprises that catch everyone else.
