Skip to main content

Ready to Publish?

Important: The preview environment is not HIPAA-compliant. Do not use real patient data during testing or previews. Only test with synthetic or sample data.

Ready to go live?

Publishing requires a Pro plan ($1,000/month) or higher. You’ll need:
  • HIPAA-ready production infrastructure
  • Signed BAAs with all services that handle PHI
  • Security review
Backend hosting BAA included: On the Pro plan, the backend hosting BAA is included for production deployments, so you don’t need a separate hosting account or separate BAA negotiation.
Optional penetration test: We offer an optional in-house penetration test for $3,000. Teams typically request this when they need a pen test report for procurement, security review, or enterprise onboarding.
If your app integrates with third-party services (telehealth video, messaging, eRx, analytics, etc.), those vendors may have their own fees and agreements, including BAAs where applicable.
Press Publish in the top right corner. Before your app goes live, our team will review it to ensure everything is secure and HIPAA compliant. This typically takes 1–2 business days. We’ll notify you by email once your app is deployed.
Contact our team to begin your HIPAA-compliant deployment process.

What You’ll Need to Set Up

Before your app can go live, there are a few accounts and configurations you’ll need to handle on your end. Our team will guide you through each step.
1

GitHub

Create a GitHub account (if you don’t have one), create a repository for your project, and invite the Specode team as collaborators. This is where your production code will live.
2

Vercel

Create a Vercel account, link it to your GitHub repository, and invite the Specode team. Vercel hosts your app’s frontend.
3

Email Service (Mailgun)

Set up a Mailgun account for transactional emails (password resets, notifications, etc.). You’ll need to:
  • Get your API key
  • Configure your sending domain
  • Set up DNS records for email deliverability
4

Custom Domain

If you’re using a custom domain (e.g., app.yourcompany.com), you’ll need to configure DNS records with your domain provider:
  • Point your domain to Vercel (frontend)
  • Add DNS records for Mailgun (email)
5

BAAs (Business Associate Agreements)

For HIPAA compliance, you’ll need signed BAAs with each service that handles protected health information (PHI). Your Specode team will help identify which BAAs are needed based on your app’s integrations.
The backend hosting BAA is included with your Pro plan - no separate negotiation needed.
Not sure where to start? Our team walks you through this entire process once you’re ready to publish. Just click Publish or reach out to support.