BetterHelp made the demand undeniable: a lot of people want therapy that fits around their life, from their phone, without a waiting room. So founders keep asking how to build something similar, and here is the mistake most of them make first. They treat it as a normal marketplace app and plan to sort out privacy and safety later. In a mental health product, later is too late. An online therapy app is a normal app wrapped around three genuinely hard problems, matching people to the right clinician, running private real-time sessions, and handling health data lawfully, and two of those three are safety and privacy problems that have to be designed in from the first commit. Get that sensitive core right and the rest is familiar product work. This guide walks the whole build, including a straight take on HIPAA and safety, and what it should cost in 2026.
What an online therapy app actually is
Strip away the branding and a therapy platform is a two-sided product connecting clients and licensed therapists, with a session at its heart and a strict privacy layer underneath everything. Clients arrive, get matched, book, meet by video or message, and pay on a recurring plan. Therapists manage availability, run sessions and keep notes. Everything both sides do reads and writes to a data core that has to be treated as sensitive by default. I call this the sensitive-core rule, and it is the lens I judge every feature by: the protected data core is the real product, and each screen earns its place by how safely it reads and writes to that core. Picture the pieces around it before deciding what version one includes.
Therapist-client matching, the feature that defines the product
Matching is what makes a therapy app feel personal rather than like a directory, and you can start simple. Collect a structured intake from the client, needs, preferences, language, availability and, critically, their location, then filter therapists by specialisation, open slots and the state they are licensed in. In the US, therapists are licensed per state, so a client in one state generally cannot be matched to a therapist licensed only in another. That single rule shapes your data model more than almost anything else.
Rule-based filtering is a perfectly good version one. It is transparent, easy to explain to clients, and easy to tune when a match goes wrong. Save smarter ranking, weighting soft fit and outcomes, for later, once you have real matches to learn from. Resist the urge to build a clever recommendation engine before you have any users, because an empty system has nothing to be clever with.
Sessions: video, chat and the calm in between
Do not build real-time video yourself. Use a specialised video infrastructure provider that offers encryption and will sign a business associate agreement, and spend your engineering on the experience around it. Your app owns the waiting room, the join flow, session notes and the messaging that carries the relationship between appointments. The provider owns the hard media plumbing. This split lets a small team ship a reliable, private session without becoming a video company by accident.
Messaging matters as much as video in this category, because a lot of subscription therapy happens asynchronously through chat. Treat those messages as clinical records: encrypted, access-controlled and retained per your policy and the law. Client and therapist should communicate only inside the app, never through personal phone numbers or email, so the relationship stays masked, contained and auditable. Notifications need care too, a push alert should never reveal the content of a message on a lock screen. Small privacy choices like that are what make a health app trustworthy.
Scheduling and payments
Scheduling and billing are where a therapy app becomes a business, and both should lean on proven services rather than custom code. Scheduling means therapist calendars, client booking, timezone handling, reminders and cancellations, and it is worth getting the reminder flow right because missed sessions hurt both sides. For payments, most online therapy runs on subscriptions, weekly or monthly plans handled by a payment provider that manages recurring billing and stores cards so you never do. Some platforms also allow one-off sessions or generate superbills clients submit to their own insurer.
Keep card data entirely inside the payment provider so numbers never touch your servers. That one decision removes a large category of risk and compliance burden from your build, which is exactly the kind of trade-off we recommend when scoping any first version in our guide to building an MVP.
Privacy and HIPAA, told straight
If you serve US users and handle protected health information, HIPAA applies, and it is an ongoing legal and operational commitment rather than something a vendor certifies for you. Nobody can hand you a HIPAA certificate, and any partner who claims to make you compliant with a checkbox is misleading you. What compliance actually looks like in a build is concrete and buildable, but it is work you carry for the life of the product.
| Requirement area | What it means in practice |
|---|---|
| Business associate agreements | Signed BAAs with every provider that touches patient data: video, hosting, messaging, analytics |
| Encryption | Data encrypted in transit and at rest, with sensible key management |
| Access control | Role-based access so people see only what their role needs, with unique logins |
| Audit logging | A record of who accessed what and when, retained and reviewable |
| Breach response | A written plan for detecting, containing and reporting a data breach |
Two honest points. First, HIPAA is only the US frame; if you serve the UK or EU you also face GDPR and its own rules for health data, so decide your markets early because they change the build. Second, compliance is not a one-time task. It lives on in your vendor choices, your access reviews and your incident drills. Bring in a healthcare lawyer at the start, not after launch. The same reality shapes any medical build, which is why our companion guide on building a telehealth app like Teladoc spends real time on it too.
Tell us what you have in mind. We turn AI prototypes and fresh ideas into shipped, scalable products, from India, for the US and UK.
Safety is a feature, not a disclaimer
A mental health product carries a duty of care, and safety design has to be deliberate and clinician-led. Show crisis resources and hotline numbers prominently and make them easy to reach at any moment. State plainly what the service is and is not, because most subscription therapy is not built for emergencies, and saying so protects your users and your business. Give therapists clear tools and protocols to escalate when they judge a client to be at risk.
These are not choices engineers should make alone. Build them with licensed clinicians who understand risk and duty of care, and revisit them as you grow. On the AI question, the same caution applies: supporting features like intake triage or note summaries are reasonable, but an AI must never pose as a therapist or make clinical calls. Be transparent about where AI is used, and keep any patient data it touches inside your compliance boundary.
What everyone gets wrong: letting AI play therapist
Every few months a founder pitches me an app where an AI does the therapy and humans are optional. It is the wrong lesson from a real capability. AI is genuinely useful here, for intake triage, matching suggestions, scheduling, summarising a clinician's notes, the administrative weight that steals a therapist's time. What it must not do is pose as the clinician or make a clinical decision, because that is where the safety and regulatory risk becomes serious and, frankly, where the product stops being therapy. My honest view, after building both AI systems and health products, is that code does not make a mental health business succeed. Clinical quality, trust, safety design and the human relationship do, and AI's job is to let good clinicians do more of that, not to replace them. Treat AI as amplification for licensed humans, be transparent with users about where it sits, and keep every byte it touches inside your compliance boundary.
The tech stack that holds it together
There is a sensible default here that many health apps use, and the goal is mature, well-supported tools rather than anything clever. Cross-platform mobile with React Native or Flutter lets you ship iOS and Android from one codebase. A backend in Node.js or a similar runtime handles the logic, with PostgreSQL for the structured, related records a therapy platform holds. Add a specialised video provider that will sign a BAA, a payment provider for subscriptions, and a mainstream cloud that also offers a BAA and the controls HIPAA expects. Layer encryption, access control and audit logging across all of it from day one, because these are far harder to add later.
How we build it, phase by phase
A therapy app rewards getting the sensitive parts right early, so we build it in a way that front-loads clinical and privacy decisions. Appico's method is AI-amplified: we use AI to move quickly where speed is safe, and put senior human engineering where health data and safety demand it.
- Clinical and compliance mapping. Before code, we map the client and therapist journeys with clinical input and set the privacy boundary, so HIPAA and safety shape the design rather than patch it.
- AI-drafted flows. We use AI to generate working prototypes of intake, matching and the session experience quickly, so you and early clinicians react to something real in days.
- Engineering and safety hardening. Senior engineers build the data model, encryption, access control, audit logging, video and payment integrations to the standard a health product requires.
- Mock runs, then supervised launch. Before real clients, we run internal mock sessions end to end (book, consent, join the encrypted call, message, take a subscription payment) to confirm every integration syncs and every field lands in the right format, a discipline we adopted after a near-miss where third-party integrations looked connected but had never been exercised. Then we launch to a small cohort with clinicians involved, watch real use, fix what it exposes, and widen carefully.
Notice the phase labels are specific to a health build. The general shape of taking a concept to a shipped product is the same one we describe for any first version, but here the hardening phase carries extra weight.
What it costs and how long it takes
Every figure here is an estimate and a range, because honest cost tracks scope, seniority and how much is bespoke. The compliance, video and payment pieces add real work beyond a standard app, which is why a therapy MVP sits above a simple app in both time and cost.
| Tier | Typical cost (offshore) | What you get |
|---|---|---|
| Therapy MVP | $40,000 to $90,000 | Matching, secure video and chat, scheduling, subscriptions, HIPAA-aware build |
| Growth platform | $90,000 to $160,000 | Group sessions, clinician dashboards, richer matching, superbills, analytics |
| Scaled service | $160,000+ | Insurance integrations, multi-market compliance, advanced tooling and reporting |
A well-scoped MVP is realistic in about four to six months with a focused team. The same scope from a US or UK studio comfortably costs two to three times these numbers, mostly because of hourly rates rather than any difference in the code, a gap we break down in our guide to what it costs to build a mobile app. Building with a senior team in India keeps the number sensible without trading away the engineering discipline a health app needs, which we cover in our guide to outsourcing to India.
Before you start, a short checklist
Run through this before committing a budget. If you cannot answer most of it, you are not ready to build yet, and knowing that is valuable.
- Which markets are you serving, and therefore which laws apply (HIPAA, GDPR)?
- Have you engaged a healthcare lawyer on compliance and terms?
- Do you have licensed clinicians shaping matching and safety?
- Have you confirmed a video provider that will sign a business associate agreement?
- Is your subscription model and payment provider decided?
- Is code, hosting, data and account ownership written into the contract in your name?
Where to go from here
An online therapy app is buildable by a focused team, but it is not a place to cut corners on privacy or safety. Start with the core session loop, design compliance and safety in from day one, and lean on proven providers for video and payments so your team can focus on the experience and the data. If you want a real number for your own scope, our app development and AI development teams scope health builds feature by feature, so you approve the plan, the privacy boundary and the price before anyone writes a line of code. Two neighbouring guides are worth a read while you plan, because they share the compliance-and-payments discipline a health app needs: our walk-through of building an insurance app like Lemonade and our guide to building an event ticketing app like Eventbrite. Build the version that helps one client meet one therapist safely and privately. That is the version that proves the whole idea.
Frequently asked questions
How much does it cost to build an online therapy app like BetterHelp?
A focused MVP with matching, secure video and chat, scheduling and subscription billing is roughly $40,000 to $90,000 built with a senior offshore team, and two to three times that in the US or UK. A larger platform with group sessions, insurance handling, clinician dashboards and analytics runs from $100,000 upward. Every figure here is an estimate that moves with scope, seniority and how much you cut for version one.
Is an online therapy app required to be HIPAA compliant?
If you serve US users and handle protected health information, you are subject to HIPAA, and there is no shortcut around that. HIPAA is a legal and operational obligation you take on, not a certificate a vendor stamps on your app. In practice it means signed business associate agreements with every provider that touches patient data, encryption in transit and at rest, strict access controls, audit logging, and a breach response plan. A development partner can build to these requirements, but compliance is an ongoing responsibility that stays with you as the operator. Get a healthcare lawyer involved early.
How does therapist-client matching work in a therapy app?
Most platforms collect a structured intake from the client covering needs, preferences and availability, then match against therapist attributes such as specialisation, licence state, language and open slots. Early versions can use straightforward rule-based filtering, which is transparent and easy to tune. You can layer smarter ranking on top later once you have real usage data. The important constraint in the US is that therapists are licensed per state, so matching must respect where the client is located.
What technology should I use for video therapy sessions?
Building real-time video from scratch is rarely worth it. Most teams use a specialised video infrastructure provider that offers encryption and will sign a business associate agreement, which keeps you inside your compliance boundary. The app handles scheduling, waiting rooms and session notes around that video layer. This lets you ship a reliable, private session experience without owning the hardest parts of real-time media yourself.
How do payments and subscriptions work for a therapy app?
Most online therapy runs on subscriptions, often weekly or monthly plans that bundle a number of sessions or messaging access, handled through a payment provider that manages recurring billing, cards and receipts. Some platforms also support one-off session payments or superbills clients submit to their own insurer. Handle card data through the payment provider so card numbers never touch your servers, which keeps that part of the build far simpler and safer.
How do you handle safety and crisis situations in a therapy app?
Safety design is not optional in a mental health product. At minimum, show clear crisis resources and hotline numbers prominently, state plainly what the service is and is not (most subscription therapy is not for emergencies), and give therapists tools and protocols for escalating risk. These decisions should be made with licensed clinicians, not engineers alone. Being honest that the app is not an emergency service protects both your users and your business.
Can I use AI in an online therapy app?
You can use AI carefully for supporting features such as intake triage, matching suggestions, scheduling, therapist note summaries and administrative work. What you should not do is let an AI pose as a therapist or make clinical decisions, which raises serious safety and regulatory issues. Treat AI as a tool that helps licensed humans work better, be transparent with users about where it is used, and keep any patient data flowing through AI inside your compliance boundary.
Do I own the code and data if I outsource the build?
You should, from day one. Insist that source code, repositories, hosting and all provider accounts are created in your name, with intellectual property assignment written into the contract. This matters even more for a health product, where patient data ownership and the business associate agreements sit with you as the operator. A reputable partner offers this as standard.
“Disciplined, committed, over-delivers. Three years in, I would re-hire any day.”
“A factory of ideas.”
“A fantastic-looking and performing website.”
Talk to the team, we reply within 24 hours, and the first consultation is free.
Start a conversation →