HIPAA20
Hosting tuned for your therapy practice. Solo private practice, group counseling office, or telehealth panel, on infrastructure built for sensitive data.
The same secure hosting infrastructure trusted by medical practices, scoped and priced for solo therapists, group counseling offices, and telehealth providers. Dedicated virtual machine isolation, dedicated IP, free SSL, on-site staff, drive chain-of-custody, audit logging, and a 45-day money-back guarantee. BAA is not included; arrange separately through your compliance counsel.
Single site · dedicated VPS isolation
Your practice website runs as its own virtual machine on hardware we own. TLS encrypts every connection, server-level firewalls block unauthorized access, and your scheduling and intake workflows route cleanly to SimplePractice, TherapyNotes, Jane App, or Counsol.
See what's included →
Your practice website runs on Dell PowerEdge Xeon servers we own outright, not leased rack space in someone else's facility. Our staff sits in the same building as the racks, and they are the only people with physical access to the drives that store your data. For a therapist concerned about where the data actually sits and who can touch it, that is the answer: chain-of-custody, in writing.
Technical, physical, and operational safeguards scoped to how a therapy practice actually runs. Policy, training, and your BAA are still your responsibility.
Your practice website runs on a dedicated virtual machine, not a shared cPanel account. The hypervisor enforces hardware-level separation between VMs, so other tenants on the underlying server cannot access your files, databases, or any client information. Dedicated CPU, RAM, storage, and IP are yours alone.
Your website lives on Ultra and links to your scheduling page, client portal, or intake form hosted on SimplePractice, TherapyNotes, Jane App, or Counsol. PHI stays in the EHR (which carries its own BAA), and the public site stays clean and fast.
Your practice gets a dedicated IP, so you are not sharing network identity with unrelated websites. For HIPAA workloads it also makes audit trails and firewall rules clearer because every connection log entry is unambiguously yours.
Even inside your dedicated VM, CloudLinux + CageFS adds a second layer of process and filesystem isolation. Belt and suspenders for a workload where the cost of a mistake is high.
Real humans, on-shore, with hosting backgrounds, including the engineers who run the HIPAA hosting fleet. Average 12-minute first-response on live chat and tickets. No outsourced ticket farm, no escalation maze.
RAID-protected storage, UPS-backed power, redundant Cisco networking, and on-site staff. Backed by a written 99.9% uptime guarantee. If a prospective client searches for you and your site is down, that's a missed referral.
One plan. No add-on fees for the safeguards that matter.
Your own virtual machine, hypervisor-isolated from neighbors.
One IP for your practice site only, no shared reputation.
Free Let's Encrypt with auto-renewal for HTTPS.
CSF + intrusion detection on every host.
Logged access + admin actions for compliance review.
Industry-standard control panel for files, DBs, email.
One-click WordPress, Joomla, and 100+ more.
Dell PowerEdge in our data center.
Unlimited @yourpractice.com mailboxes, IMAP/POP3, anti-spam.
One-click CloudFlare CDN integration.
PHP 7.4 through 8.3 selectable per domain.
Free .com / .net / .org for the first year.
You are running a private practice, a group, or a telehealth panel. The infrastructure questions still matter, just at a different scale. Your prospective-client landing page, your bio page, your contact form, your blog about coping skills and treatment approaches: all of that lives on a website. That website lives somewhere. With Ultra, it lives on hardware we own, in a facility we control, behind isolation that keeps neighboring accounts out.
For the parts of your practice that handle PHI directly (session notes, billing, secure messaging, video sessions), you almost certainly already use a HIPAA-compliant practice management platform like SimplePractice, TherapyNotes, Jane App, Counsol, or similar. Those platforms have BAAs and handle PHI inside their systems. Ultra hosts the public website that points clients to your scheduling link or intake form on those platforms. The two layers complement each other. Have questions about your specific workflow? We are happy to talk through it.
Solo therapists and counselors. Private practice LMFTs, LCSWs, LPCs, LMHCs, psychologists, and counselors building or moving their practice website to infrastructure they can trust.
Group counseling practices. Multi-clinician offices, group practices, and partnerships hosting a shared practice website with bios, services, and intake routing.
Telehealth therapy providers. Virtual-first practices and telehealth panels whose public website routes clients to a HIPAA-compliant video platform like Doxy.me, SimplePractice Telehealth, Zoom for Healthcare, or VSee.
Psychologists and psychiatrists. Doctoral-level clinicians, neuropsychologists, and prescribing psychiatrists running a private or group practice website.
Every account ships with a free SSL certificate from Let's Encrypt with auto-renewal. TLS encrypts data in transit between your site and visitors, meeting the encryption-in-transit requirements outlined in the HIPAA Security Rule for transmitting ePHI. The cPanel control panel itself is TLS-only.
Server access and administrative actions are logged for audit purposes. Login activity, file changes, and configuration changes are recorded. Detailed logs are available on request for compliance reviews if your consultant or auditor needs to verify infrastructure-level controls. Server-level intrusion detection watches for unauthorized access attempts and blocks suspicious traffic automatically.
If your practice site is already hosted somewhere, our technicians will migrate it to Ultra HIPAA Hosting free of charge on annual plans. After signup, open a support ticket with your current host's cPanel login (or FTP / database credentials if it's not cPanel) and our team handles the file copy, database export and import, email accounts, DNS records, and SSL provisioning.
We take extra care with credentials and data during the transfer. Credentials are handled inside our ticket system, not in email. Database dumps are removed from the staging area after import. The new copy stages under a temporary URL for testing, and we coordinate the DNS cutover to minimize downtime so prospective clients always reach a working site.
23 years of hosting. Therapy-practice infrastructure on hardware we own.
Your practice website needs hosting that takes client confidentiality as seriously as you do. Whether you are a solo therapist running a private practice, a group counseling office, or a telehealth provider, the website where prospective clients first find you should rest on infrastructure built for sensitive data. Ultra's HIPAA-ready plan runs on a dedicated virtual machine with a dedicated IP, free TLS encryption, server-level firewall and intrusion detection, audit logging, and full hardware chain-of-custody over the drives that store your data.
Most therapists do not need their public website to store PHI. The actual PHI lives inside your practice management system: SimplePractice, TherapyNotes, Jane App, Counsol, or similar. Those platforms carry BAAs and handle session notes, billing, secure messaging, and video sessions. Ultra hosts the public-facing website that links out to your EHR's scheduling page, client portal, or intake form. The two systems integrate at the link/redirect level. This is the clean separation of responsibilities most therapists land on once they have talked it through with a compliance consultant.
This plan does not include a Business Associate Agreement (BAA). Ultra provides the server infrastructure and physical safeguards that support HIPAA compliance, but a BAA is a separate legal agreement that must be arranged independently. Most therapists work with a compliance consultant or healthcare attorney to establish BAAs with the vendors that actually handle PHI in their practice (typically the EHR or practice management system, not the public-facing website). The plan also does not cover your written HIPAA policies, workforce training, risk analyses, or breach response procedures. Contact us if you have questions about exactly what our infrastructure covers.
For a therapist evaluating hosting, the real question is not whether a host has encryption and firewalls (every host does). The question is who controls the physical infrastructure and whether you can verify it. Most "HIPAA compliant" providers rent rack space in third-party facilities and have no answer to "who has physical access to my drives?" We do: our staff, in our building, with documented chain-of-custody from rack-in to drive-destruction. For solo practitioners who carry every client relationship personally, that level of clarity is worth something.
The questions our sales team gets from solo practitioners and group practices. If yours isn't here, drop us a line.
If your website collects, transmits, or stores protected health information (PHI) and you are a HIPAA covered entity, you generally need a Business Associate Agreement with any vendor that touches that PHI, including your web host. Ultra does not currently offer a BAA. Most solo therapists work with a compliance consultant or healthcare attorney to determine which of their vendors need BAAs and to draft the agreements. We focus on providing the secure infrastructure layer; the BAA itself is a separate legal arrangement, and most therapists land it with their EHR rather than their web host because that's where PHI actually lives.
You can host the form on Ultra's hosting with SSL/TLS encryption protecting data in transit. For HIPAA-compliant intake forms that store PHI, most therapists either keep the public-website form simple (basic contact info only) and direct sensitive intake to a HIPAA-compliant practice management system like SimplePractice, TherapyNotes, Jane App, or Counsol that already has BAAs in place, OR work with a compliance consultant to ensure the full intake workflow including the BAA chain is covered. The hosting infrastructure supports it; the workflow design is a separate decision based on your practice setup.
For the marketing, scheduling-link, and informational pages of a telehealth therapy practice, yes. The actual video session platform is typically a separate HIPAA-compliant service like Doxy.me, SimplePractice Telehealth, Zoom for Healthcare, or VSee, each of which provides its own BAA. Ultra hosts your practice website that links out to the video platform; we do not provide the video conferencing layer itself.
Yes. Ultra's hosting plays well alongside any practice management or EHR platform. Your website lives on Ultra and links to your scheduling page, client portal, or intake form hosted on your EHR vendor's domain. The two systems integrate at the link/redirect level. Most therapists run their public-facing website on Ultra and route confidential workflows (notes, billing, secure messaging) through their EHR provider, which is a clean separation of responsibilities and the workflow most compliance consultants recommend.
Standard shared hosting plans run as cPanel accounts on multi-tenant servers (with CloudLinux CageFS separating accounts at the filesystem level), share IP addresses with potentially dozens or hundreds of other websites, and are often hosted on cloud infrastructure where the provider has no physical control over the hardware. For a therapy practice handling client information, that is a poor fit. This plan is a dedicated virtual machine (VPS): your own VM with its own dedicated CPU, RAM, storage allocation, kernel, and IP address. The hypervisor enforces hardware-level separation between VMs, and we physically own and operate the underlying server in our own facility. Our staff are the only people with access.
No. Ultra does not currently offer a BAA. We are transparent about this because we believe it is important for therapists to understand exactly what they are getting. Our plan provides the server-level infrastructure and physical safeguards that support compliance, but a BAA is a separate legal agreement. Most therapists work with a compliance consultant or healthcare attorney to establish BAAs with the vendors that actually handle PHI in their practice, which is typically the EHR rather than the public-facing website.
Yes. Ultra offers free website migration with annual or longer plans. Our migration team handles cPanel transfers, WordPress sites, database moves, and email setup with extra care taken on credentials and data handling during the transfer. Just submit a support ticket after signing up with your current host's login details inside the ticket system (not email).
For appointment scheduling that involves PHI, route clients to your EHR's scheduling page (SimplePractice, TherapyNotes, Jane App, etc.) which carries its own BAA. For general contact forms on your hosted website, encrypted form submission over HTTPS is included by default via the free SSL certificate. If a prospective client sends sensitive information through a basic contact form, your standard practice should be to respond by directing them to a secure intake method through your EHR rather than continuing the conversation by email.
Ultra's HIPAA hosting for therapists starts at $49.95 per month when billed annually. That includes a dedicated IP address, 25 GB of SSD storage, unlimited @yourpractice.com email accounts, free SSL certificate, VPS-level isolation (dedicated virtual machine), on-site hardware with drive chain-of-custody, cPanel control panel, and 24/7 on-site support. The regular month-to-month price is $79.95. Use coupon code HIPAA20 for 20% off your first order.
When a solo practice scales into a group or you start running multiple sites (a main practice site plus a specialty-area landing page or two), our VPS plans (root access, guaranteed CPU/RAM) and dedicated server plans (full hardware control) are the upgrade path. Our support team handles the migration with no downtime, and the same on-site physical safeguards apply at every tier.
20% off your first order with code HIPAA20. 45-day money-back guarantee. Free secure migration included.