The verdict in three sentences
A secure patient portal (access to results, documents, bookings, messaging) costs 30,000 to 90,000 EUR excl. VAT as a custom build, certified hosting included. Data-protection compliance — encryption, access logging, consent, data minimization — represents 15 to 25 % of the budget and is non-negotiable. The return shows up in patient satisfaction, fewer calls and reduced legal risk in the event of a breach.
European GDPR/HDS vs US HIPAA
Both frameworks protect health data but differ on hosting and penalties. Here are the key points for a decision maker.
| Requirement | GDPR + HDS (Europe) | HIPAA (United States) |
|---|---|---|
| Certified hosting | Mandatory (HDS) | BAA with compliant host |
| Encryption at rest | Strongly recommended | Required (addressable) |
| Access logging | Mandatory | Mandatory |
| Explicit consent | Yes | Privacy notice |
| Breach notification window | 72 h to authority | 60 days |
| Maximum penalty | 20 M EUR or 4 % of revenue | 1.9 M USD/year per category |
| Access / portability right | Yes, within 1 month | Access within 30 days |
The cost of compliance, item by item
Securing a patient portal is not just development: it is architecture, auditing and continuous documentation.
| Compliance item | Order of magnitude | Frequency |
|---|---|---|
| Certified health hosting | 400 to 1,500 EUR/month | Recurring |
| End-to-end encryption & keys | 6,000 to 15,000 EUR | Setup |
| Access logging & audit | 5,000 to 12,000 EUR | Setup |
| Impact assessment (DPIA) | 4,000 to 10,000 EUR | Per project |
| Annual pentest | 5,000 to 15,000 EUR | Annual |
| Outsourced DPO | 500 to 2,000 EUR/month | Recurring |
Mini case study
Sarah, COO of a clinic group in New York, deploys a patient portal at 70,000 EUR excl. VAT for 40,000 active patients. Previously, the call center handled 6,000 requests/month (results, documents, bookings) at an average cost of 3.50 EUR per call, i.e. 21,000 EUR/month. The portal absorbs 60 % of these in self-service, saving 12,600 EUR/month, over 151,000 EUR/year. The portal pays for itself in under six months, before even counting the reduced penalty risk in the event of an incident.
FAQ
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Must a patient portal be on certified health hosting?
In Europe, yes, as soon as it stores identifying health data. In the US, the host must sign a BAA and meet HIPAA technical rules. In both cases, standard consumer hosting is excluded.
Is end-to-end encryption mandatory?
It is not always named explicitly, but it is the best defense in a breach: stolen encrypted data is often treated as not compromised, which eases notification obligations.
How long to build a compliant portal?
Expect 4 to 7 months depending on features (secure messaging, payment, record integration) and the level of audit required.
Do we need a DPO?
For a healthcare organization processing data at scale, yes, a data protection officer is mandatory in Europe. It can be outsourced for 500 to 2,000 EUR/month.
What is the risk of an undeclared breach?
In Europe, up to 20 M EUR or 4 % of global revenue, plus reputational damage. Access logs and an up-to-date impact assessment are your best legal protections.
Let's scope your project. Describe your patient volume, target features and regulatory framework (GDPR/HDS or HIPAA) and we will frame a compliant portal with an indicative budget. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

