I am building a patient registration and appointment scheduling app for a healthcare clinic based in Dallas. I am part of the team at Software Orca working through the discovery phase, and the technical requirements keep shifting in ways that make accurate cost estimation difficult.
The specific problem is around HIPAA compliance. Things like encrypted local storage, session management, audit trail logging, and role-based access control all add meaningful development time, but exactly how much depends on decisions we have not locked yet, like whether we go native or cross-platform, and how the backend authentication layer gets structured.
Dallas has a strong healthcare market with clinics and smaller provider networks actively going through digital transformation. Most of them come in with a budget figure that does not account for the compliance layer at all.
How do other developers handle this gap with clients? I have tried breaking estimates into phases and presenting ranges rather than fixed numbers, but clients almost always anchor to the lower figure and expect that to hold.
Do you treat compliance requirements as a separate line item, or fold them into each feature as an overhead buffer? And when scope shifts mid-discovery, how do you communicate that without the client feeling like the original quote was not honest?