
Key takeaways
• Mental-health apps are a $9–10B market in 2026, growing in the mid-to-high teens (Precedence Research puts 2026 at $10.06B and a 17% CAGR to $41B by 2035). Calm, Headspace, BetterHelp and Talkspace own the mainstream; postpartum, addiction recovery, veterans and employer wellness are still open.
• Pick one of five archetypes before you hire anyone. Self-help, on-demand therapy, group and community, prescription digital therapeutics (DTx), and corporate wellness each carry a different architecture, regulatory shape and unit economics from week one.
• HIPAA is table stakes; FDA is a separate build. Any app that makes a therapeutic claim is a Software-as-a-Medical-Device. The FDA authorized 1,200+ AI devices by late 2025 and zero for mental health, so plan a De Novo program, a payer and a clinical partner before you commit.
• Three states now restrict AI-delivered therapy. Illinois, Nevada and Utah passed laws in 2025. Autonomous AI “therapists” are a legal and safety dead end. Build AI around the clinician, never as the clinician.
• Crisis response is architecture, not a disclaimer. Every product needs tested suicidal-ideation detection, an in-product 988 handoff, a documented escalation path and a 24/7 clinical safety partner. Skip it and one tragedy becomes a regulatory and PR catastrophe.
Why Fora Soft wrote this playbook
We build HIPAA-grade telehealth and clinical platforms, and we have since telemental health was a niche. We built and operate CirrusMED, a US primary-care telehealth platform running a HIPAA security program with business-associate agreements across the stack, and we have shipped several NDA telemental-health products: group therapy, one-to-one sessions, employer-paid wellness, postpartum care. The architecture calls, the crisis-response patterns, the per-state licensure headaches and the AI-safety guardrails in this guide all come from products that are live today.
Fora Soft has delivered 250+ projects since 2005 with a 50-engineer in-house team. On the healthcare side that means real BAA chains, real audit logs, and a co-founder who leads our healthcare vertical, not a marketing page. Where we cite regulation here, we link the primary source: the FDA advisory record, the Federal Register, the state statutes. Where we cite our own numbers, they come from projects we shipped.
If you are a mental-health founder, a behavioral-health CMO, an employer-wellness product lead, or a therapy practice going digital, this guide hands you the archetype map, the 2026 regulatory shape, the reference architecture and the honest cost math we use with our own clients. No filler, and the parts most guides get wrong are flagged.
Building a HIPAA-grade mental-health platform?
Free 30-minute scoping call. We size the build, map the licensure, FDA and payer track if it applies, and hand you a delivery plan built on compliance patterns we already run.
The 2026 mental-health app market
The market is large, loud and uneven. Estimates for 2026 cluster between $8.6B and $10.1B: Fortune Business Insights reads $8.64B, Mordor Intelligence $9.45B, and Precedence Research $10.06B with a 17% CAGR to $41.16B by 2035. The growth rate has cooled from the pandemic spike into the mid-to-high teens, which is healthier: the money now follows retention and outcomes, not download counts.
Two 2023 collapses still set the mood. Pear Therapeutics filed for bankruptcy in April 2023 with three FDA-cleared prescription products; the science held, the payer reimbursement did not converge fast enough, and the company ran out of runway. The FTC then fined BetterHelp $7.8M in 2023 for sharing users’ health answers with ad platforms, and in 2024 ordered Cerebral to pay $7M+ for disclosing 3M+ members’ data to trackers. The lesson founders keep relearning: in this category, coverage and privacy kill more products than engineering does.
The opening in 2026 sits in three places. Underserved niches the big players ignore (postpartum, neurodivergent adults, addiction recovery, veterans, LGBTQ+ care). Employer-paid wellness, which keeps growing double digits. And AI adjuncts that help clinicians (journaling, mood tracking, between-session homework) instead of trying to replace them. The engineering primitives are mature and cheap: HIPAA-eligible clouds, telehealth video stacks, consent SDKs, retrieval and LLM tooling under a BAA. Trust is the expensive part. Win on trust, ship on the primitives.
Five archetypes of a mental-health product
Almost every mental-health app we have audited or shipped is one of five archetypes. They differ in who pays, how they make money, what regulator watches them, and how much software you actually build. Picking the archetype is the first and most expensive decision. Get it wrong and you rebuild from the foundation. The selector below is the exact question order we walk clients through.

Figure 1. Four questions route you to an archetype: who is the buyer, is there a therapeutic claim, is a clinician in the loop, and what job does the AI do.
Archetype 1 — Self-help and meditation
Calm, Headspace, Insight Timer, Balance. The product is a content library (guided meditations, sleep stories, breathing exercises, journaling prompts) wrapped in a subscription. No clinician, no therapeutic claim, no FDA exposure. HIPAA stays mostly out of scope unless you sell a B2B version to a covered entity, and then it walks back in.
The engineering bar is content delivery: a video-on-demand ladder, audio streaming, offline downloads, paywalls, push-notification engagement, and a recommendation surface. The hard part is producing content people finish, not writing the code. Margins are high and differentiation is brutal now that the big four have planted flags. You win on a named instructor, a specific audience, or culturally-specific content, not on features.
Reach for self-help / meditation when: you have a content edge (a named voice, a niche audience, faith-based or culturally-specific material) and enough runway to survive a 12–18-month climb to profitability.
Archetype 2 — On-demand therapy
BetterHelp, Talkspace, Cerebral. The product matches users to licensed therapists and runs sessions in-app over video, chat or async messaging. HIPAA applies fully. Per-state licensure becomes a parallel operations track that runs for months. And the insurance decision (cash-pay versus in-network) swings the unit economics by an order of magnitude, so make it before you design the billing.
The engineering surface is a full telehealth stack: identity, scheduling, video and chat, payments, a lightweight EHR, and a prescriber workflow if you carry psychiatry. On top sits a matching engine that pairs users to therapists by specialism, availability, language and identity-affirming criteria, and that verifies the clinician is licensed where the patient physically sits at session time. After the 2023–2024 FTC actions, treat privacy as a first-class feature, not a footer link.
Reach for on-demand therapy when: you already have a clinician network, an insurance partnership in flight, and a firm position on cash-pay versus in-network before day one.
Archetype 3 — Group and community
7 Cups, Wisdo, and peer-support communities. The product is a moderated community, often with group sessions led by clinicians or trained facilitators. It is cheaper to acquire users than one-to-one therapy and harder to keep them. Crisis response is harder too, because the surface area where someone can post something alarming is much larger.
Engineering: real-time chat with moderation, group video, a content-moderation pipeline (automated plus human review), abuse reporting, and a clinical-escalation path that fires when a detector flags suicidal ideation, self-harm, or danger to others. Moderation cost, not infrastructure, dominates the run rate. Budget for humans in the loop from day one, because the automated filters miss the cases that matter most.
Archetype 4 — Digital therapeutics (DTx)
Pear’s reSET and Somryst (gone after the bankruptcy), Akili’s EndeavorRx, Big Health’s Sleepio. A prescription DTx is software that treats a clinical condition with a therapeutic claim and clears an FDA pathway like any device. Reimbursement is the long pole. Payers were slow to cover Pear, and that gap, not the technology, is what ended the company.
Engineering: a CBT or CBT-i protocol delivered as a sequenced program, a real-world-evidence pipeline (anonymized outcomes piped to a warehouse for effectiveness reporting), version control on therapeutic content where each protocol revision is a regulatory event, an adverse-event reporting path, and a prescriber portal. This is the archetype where software discipline meets medical-device discipline, and the second one usually wins the argument.
Reach for prescription DTx when: you have a clinical-evidence partner, a payer signal in writing, seven figures of runway for the FDA path, and a 24–36-month timeline you can actually survive.
Archetype 5 — Corporate wellness
Lyra Health, Spring Health, Modern Health. The product sells to employers and benefits consultants, gives employees therapy, coaching, content and care navigation, and reports anonymized use back to HR. The buyer is a CHRO or benefits VP, the user is the employee, and the regulatory shape is HIPAA on the clinical sliver plus privacy law (GDPR for any EU staff) on the reporting side.
Engineering: SSO into employer identity, scheduled or on-demand clinician sessions, a content library, a coaching surface, and an analytics dashboard for HR that shows usage without exposing any individual’s mental-health data. That privacy boundary is the hardest part. Aggregate by cohort, redact below a headcount threshold, and never let an employer infer who used the service. Get that wrong once and you lose the whole book of business.
Reach for corporate wellness when: you have a benefits-VP relationship or a broker partnership, and you can build the redaction-aware analytics surface as a first-class feature rather than a reporting afterthought.
Do you need FDA clearance?
Only if your product makes a therapeutic claim. The moment your marketing or clinical content says the app “treats,” “reduces symptoms of,” or “improves outcomes for” a clinical condition, you are a Software-as-a-Medical-Device (SaMD) under the FDA. Wellness, mindfulness, journaling and CBT-style scaffolding stay out of scope. The difference between a wellness app and a regulated device is sometimes a single verb, so have regulatory counsel review every claim.
Two pathways matter. De Novo is for a novel low-to-moderate-risk device with no predicate; it runs roughly 12–18 months and creates a new classification. 510(k) is for a device substantially equivalent to a predicate and is faster once evidence exists. Most novel mental-health DTx start with De Novo, and follow-on products ride 510(k) once a predicate exists.
The 2025 signal every founder should read: on November 6, 2025 the FDA’s Digital Health Advisory Committee spent a day on generative-AI mental-health devices, built around a scenario of a prescription LLM chatbot that mimics a therapy session. The committee stressed total-product-lifecycle risk management, model drift and continuous post-market monitoring. The blunt takeaway: the FDA had authorized 1,200+ AI-enabled devices by then and zero for mental health. A generative-AI “therapist” has no cleared predicate and no easy path.
Practical advice, learned the hard way from Pear: do not start the FDA path without a payer letter of intent and an academic-medical-center clinical partner. Great science with a thin payer story is how you clear the FDA and still run out of money.
HIPAA, licensure, and telehealth law
Three regulatory layers stack, and most guides get the freshest details wrong. HIPAA governs the privacy and security of protected health information for any covered entity or business associate. State licensure dictates which clinician can see which patient across state lines. Telehealth-specific law sets consent, prescribing rules and disclosures. Figure 2 shows how a single therapeutic-claim test splits your product into the wellness lane or the regulated lane, then which layers apply.

Figure 2. One claim test decides the lane; the compliance layers stack from there, with the 2025 items most guides miss flagged in orange.
HIPAA, and the rule change that is coming but not here yet. The current Security Rule still treats encryption as “addressable.” The Security Rule NPRM published January 6, 2025 would make encryption of ePHI mandatory at rest and in transit, require multi-factor authentication on every system touching ePHI, and add network segmentation and annual audits. It is not final. The comment period closed in March 2025 and OMB now targets around July 2027 for final action, so competitors who tell you it is “now in force” are wrong. Build to the proposed bar anyway, because it is good security and you will not want to retrofit MFA and encryption later. Our HIPAA and SOC 2 telehealth guide covers the platform-side scaffolding.
Per-state licensure is an engineering constraint, not a legal footnote. A therapist licensed in California cannot legally treat a client physically sitting in Texas without Texas licensure, save narrow crisis exceptions. Your matching engine has to verify patient location at session time and refuse otherwise. The interstate compacts help but partially: PSYPACT covers psychologists in roughly 42 states in 2026, while the Counseling Compact has been enacted in 40 jurisdictions but only about six were actually issuing practice privileges as of mid-2026. “Enacted” is not “you can practice there today,” so the engine verifies against live privilege data, not a static map.
Controlled-substance prescribing rides a temporary extension. If you carry psychiatry, the DEA and HHS issued a fourth temporary extension that lets clinicians prescribe Schedule II–V substances by telehealth without a prior in-person exam through December 31, 2026 (audio-only is allowed for opioid-use-disorder treatment). More than 7M such prescriptions were written in 2024, so the stakes are real, but the permanent “Special Registration” rule is still pending. Design the prescriber workflow to switch an in-person requirement back on per state and per substance, because the default law (the Ryan Haight Act) returns the moment an extension lapses.
Can AI legally deliver therapy in 2026?
In a growing number of states, no. Three states passed laws in 2025 that restrict or ban AI from delivering mental-health care directly to patients, and this is the single fastest-moving part of the regulatory picture. If your roadmap has an autonomous AI “therapist” on it, delete that line now.
Illinois signed the Wellness and Oversight for Psychological Resources (WOPR) Act in August 2025, the first state law to bar AI from providing therapy or making therapeutic decisions directly to patients. Enforcement sits with the state regulator (IDFPR), with civil penalties up to $10,000 per violation. AI for scheduling and administrative support is fine; AI as the clinician is not.
Nevada signed AB 406 in June 2025 (effective July 1), which blocks AI systems from providing mental or behavioral health care and from claiming they can, with penalties up to $15,000. Utah took a lighter touch with HB 452 (effective May 2025): not a ban, but mandatory disclosure that the user is talking to AI and hard limits on selling or sharing their health data. Ohio and others are moving too.
Read together with the FDA’s November 2025 signal, the direction is unmistakable: regulators want a human clinician accountable for care, and they want AI in a supporting role. That is not a constraint to fight. It matches the safety evidence, and it is exactly how we architect these products.
Crisis-response architecture
A crisis-response path is mandatory for any product touching mental health, and the shape is the same regardless of archetype. The US 988 Suicide & Crisis Lifeline has handled more than 25 million contacts since its 2022 launch, which tells you how often people in distress reach for the nearest surface. If your app is that surface, it has to route them, not just log them. Figure 3 is the pipeline we ship.

Figure 3. Detection feeds a human handoff and clinical escalation; every trigger is logged immutably and disclosed to the user up front.
1. Detection. Run a classifier over every user-generated text segment (chat, journal entries, AI conversation turns, community posts) for suicidal ideation, self-harm, eating-disorder distress or danger to others. What we ship in production: a small fine-tuned classifier on an open-weight model with a thresholded score, plus an LLM confirmer for borderline cases to hold false positives down without missing the real ones.
2. In-product handoff. When it triggers, surface a non-dismissible interstitial with the local crisis line (988 in the US, 116 123 across much of Europe, region-specific elsewhere) and an offer to start a call or chat. Test the handoff on a schedule. A crisis path that silently rotted after a dependency update is worse than none.
3. Clinical escalation. If the user has a clinician on the platform, route a notification into that clinician’s queue within an SLA and with the right consent posture. If they do not, route to a 24/7 clinical safety partner. We have shipped these vendor contracts, and the SLA is the part you negotiate hardest.
4. Documentation and audit. Log every triggered case immutably, attribute it to the classifier version that fired, and review it in a weekly clinical-safety meeting. The audit trail protects the user, the platform and the clinician, in that order.
5. Disclosure. The user must know up front that automated detection runs and what happens when it fires. That belongs in the consent flow, not buried on page nine of a privacy policy. Utah now requires this kind of disclosure by law; treat it as the floor everywhere.
Where AI helps and where it harms
AI in mental health helps people or hurts them, and the line is sharper here than in most domains. We deploy it in three patterns that work and one we refuse to build. The rule underneath all of them: AI organizes and supports care, a licensed human is accountable for the care itself.
Works: AI as scaffolding. Journaling prompts, mood tracking with structured reflection, CBT-style thought-record templates, between-session homework reminders. The AI helps the user organize their own thinking. It does not hand out advice.
Works: AI as clinician helper. Ambient documentation (see our AI scribe architecture playbook), session summaries, check-in nudges, treatment-plan adherence reminders. The clinician stays in the loop and signs off.
Works: AI as crisis classifier. Detecting distress in user-generated text, as in Figure 3. The classifier triggers a human handoff. It never answers the user with therapy.
Refuse to build: unsupervised AI giving therapy. The 2024–2025 reports of chatbot-induced harm in vulnerable users, and now three state laws, put this out of bounds for us. The risk and ethics math does not close, and the legal ground is closing under it. If you want the technical discipline for keeping any AI honest in production, our LLM evaluation guide is the companion piece, and for real-time voice specifically, the LiveKit AI-agents guide covers the streaming stack with BAA caveats.
Reach for AI when: it scaffolds the user’s own thinking, assists a named clinician, or flags a crisis for a human. Draw the line the moment AI becomes the one giving care.
Not sure where your AI feature crosses the line?
Send us the feature list. We map each one to wellness, SaMD or a state-law risk, and tell you what stays and what has to change before you ship.
What a mental-health app costs to build
A compliant MVP costs less than most 2026 agency guides claim. The market consensus lands a HIPAA-grade MVP at $70k–$140k over four to six months, inside a wider $40k–$400k range. We use Agent Engineering (AI handling boilerplate under senior review), so our estimates sit at or below the MVP end, not above it. The table below is MVP-to-first-scale by archetype. It excludes the FDA program for DTx, which is a separate order of magnitude.
| Archetype | MVP build | Time to MVP | Year-1 run | Regulatory load |
|---|---|---|---|---|
| Self-help / meditation | $40k–$80k | 8–12 wks | $60k–$180k | Light |
| On-demand therapy | $110k–$160k | 14–20 wks | $200k–$600k | HIPAA + state licensure |
| Group / community | $80k–$140k | 12–18 wks | $180k–$500k (moderation-heavy) | Moderation + HIPAA-lite |
| Prescription DTx | $130k–$240k engineering + $1M–$3M FDA | 12–24 mo | $300k–$1M+ | FDA + HIPAA + QMS |
| Corporate wellness | $100k–$180k | 14–22 wks | $220k–$700k | HIPAA + privacy (GDPR) |
A worked example, arithmetic shown. Take a HIPAA-grade on-demand therapy MVP. The scope is roughly 14 build-weeks: consent and identity (2), scheduling (2), HIPAA video and chat (4), payments and billing (1.5), the clinician and patient apps (3), the licensure-aware matching engine (1.5). Staff it with a four-engineer pod plus part-time design and DevOps. Agent Engineering handles the CRUD, the SDK wiring and the test scaffolds, so the pod ships noticeably more scope per week than a hand-coded team.
Four engineers across 14 weeks is 56 engineer-weeks. At a conservative blended delivery rate of about $2,000 per engineer-week, that is 56 × $2,000 = $112,000. Add the crisis-response path and a light security review and you land near $120k–$135k, inside the $70k–$140k market band for a compliant MVP and below the $180k–$250k a hand-built equivalent usually runs. Figure 4 plots the MVP bands across all five archetypes.

Figure 4. MVP build cost by archetype. The solid bar is the floor, the lighter extension reaches the top of the band. DTx excludes the separate FDA program.
Where roadmaps actually slip is not the engineering line. On-demand and DTx budgets balloon on per-state licensure operations and the clinician-supply chain. Plan those as parallel multi-quarter tracks with their own owner, or the compliant MVP you shipped on time sits idle waiting for clinicians it cannot legally deploy.
Mini case — corporate-wellness app at scale
A corporate-wellness operator we worked with served roughly 240,000 covered employees across 18 large employers. Their legacy product was a content library bolted to a third-party therapy-marketplace SDK. Engagement sat at 8% monthly active users per covered life, and the CHRO reporting was assembled by hand in spreadsheets, which meant it was always a week stale and occasionally wrong.
We re-architected over 22 weeks. Identity moved to a multi-tenant SSO surface honoring per-employer SAML and OIDC with a hard privacy boundary between tenants. The therapy surface became a first-party product (clinician portal, scheduling, video and chat under a HIPAA program) instead of a rented SDK. A retrieval layer served the operator’s own evidence-based content, AI scaffolding drove journaling and mood tracking, and a 24/7 clinical safety partner backed the crisis path. HR reporting shipped cohort-aggregated with hard redaction below a five-employee threshold, so no manager could ever infer an individual. The multi-tenant discipline came straight from platforms like BrainCert, which we scaled to 100K+ customers.
Two quarters after launch: monthly active users reached 19% of covered lives (a 2.4× lift), therapy bookings rose 5.1×, content completion 3.2×, and the CHRO reporting that used to take an analyst a week now shipped overnight, with zero privacy incidents. Figure 5 shows the before-and-after. Want a similar assessment of your stack? Book a 30-minute call and we will walk your metrics.

Figure 5. Corporate-wellness rebuild, before versus after two quarters. Every bar is anchored to zero and labeled with the real number.
A decision framework in five questions
Five questions decide the archetype and where the bottleneck will sit. Answer them honestly before you write a product spec.
1. Who is the buyer? Consumer (D2C subscription, self-help fits), employer (corporate wellness), payer (DTx with reimbursement), or clinic and health system (clinician-first). The buyer sets monetization and regulatory shape more than any other variable.
2. Is there a therapeutic claim? If yes, you are SaMD under the FDA; plan the De Novo path, a payer and a clinical partner. If no, you stay in wellness and coaching territory and the regulatory load drops sharply.
3. Is a clinician in the loop? This flips HIPAA scope, per-state licensure, prescriber workflow, malpractice insurance and the engineering surface all at once. Adding a clinician roughly triples the build compared with a pure self-help app.
4. What is the AI’s job? Scaffolding is safe, clinician-helper is safe, crisis-classifier-with-handoff is safe. Therapy substitute is a do-not-build, and in Illinois and Nevada it is now illegal. Write the specific job into the roadmap; “AI-powered” is not a spec.
5. Have you stress-tested the crisis path? Run a tabletop: what happens when a user types a suicide note, when someone describes self-harm in a community thread, when a clinician’s safety check goes unanswered for six hours? If you cannot answer all three, you are not ready to ship, whatever the archetype.
Five pitfalls (and when not to build)
1. Treating crisis response as a feature you add later. The first time you need it, it is already too late. Build detection, handoff, escalation, documentation and disclosure into version 1.0, even if the product is “just” a journaling app.
2. Privacy as a footer link. The BetterHelp and Cerebral orders were about pixel tracking and ad-platform data sharing. Privacy is now a purchase driver in mental health. Build it as a feature, document it, and keep it auditable so a procurement team can verify it.
3. Underestimating per-state licensure. Legal will quote six weeks. The real operations work to onboard a clinician in a new state averages three to four months once you include credentialing, malpractice coverage and CAQH attestation. Staff it as a standing track, not a one-off task.
4. Starting the FDA path without a payer. Pear’s lesson, once more: clearance takes 12–24 months and millions, and reimbursement takes longer and is harder to control. No payer letter of intent and no clinical-evidence partner means no FDA program.
5. Shipping AI as the therapist. When not to build at all: if your only differentiator is an autonomous AI that gives therapy, stop. It is unsafe on the evidence and illegal in a growing list of states. Reshape the idea around a clinician plus AI scaffolding, or pick a different problem.
KPIs to measure
Quality KPIs. Crisis-response activation within the target SLA above 99.5%, classifier precision above 0.85 and recall above 0.92 on a clinician-labeled validation set, content-moderation false-negative rate under 0.5%, and a clinical-outcome measure (PHQ-9, GAD-7) moving the right way for at least 70% of active users. Recall matters more than precision here; a missed crisis costs more than a false alarm.
Business KPIs. 90-day retention above 35% for self-help, 6-month retention above 55% for therapy, monthly active users above 15% of covered lives for corporate wellness, NPS above +40 for users and +30 for clinicians, and CAC payback under 9 months for D2C and 12 for B2B2C.
Reliability KPIs. Platform uptime above 99.95%, video-session p99 connect time under 4 seconds, payment success above 98%, a clean BAA-chain audit every quarter, deletion requests fulfilled under 7 days, and zero S0 or S1 privacy incidents for the year.
FAQ
How much does it cost to build a mental-health app?
A compliant MVP runs $40k–$80k for self-help, $110k–$160k for on-demand therapy, and $100k–$180k for corporate wellness, typically over 8 to 22 weeks. Prescription DTx adds a separate $1M–$3M FDA program on top of engineering. The market consensus for a HIPAA-grade MVP is $70k–$140k; our estimates sit at or below that with Agent Engineering.
Do I need FDA clearance for a mental-health app?
Only if your product makes a therapeutic claim, such as “treats depression” or “reduces PTSD symptoms.” Wellness, mindfulness, journaling and CBT-style scaffolding do not require FDA clearance. Prescription digital therapeutics do, via a De Novo or 510(k) pathway. Have regulatory counsel review every claim, because the line between a wellness app and a device is sometimes a single verb.
Is it legal to use AI for therapy in the US?
Not as an autonomous therapist in a growing number of states. Illinois (WOPR Act, 2025) and Nevada (AB 406, 2025) bar AI from delivering mental-health care directly to patients, with penalties up to $10,000 and $15,000 per violation. Utah (HB 452) requires disclosure and data limits rather than a ban. AI for scheduling, scaffolding, documentation and crisis triage with a human handoff remains fine everywhere.
What is the smallest viable mental-health app?
A self-help library with paywalls, push-notification engagement, mood tracking, and a properly shipped crisis-response interstitial. Roughly $40k–$80k and 8 to 12 weeks. The trap is calling it “small” and skipping the crisis path. That is the one part you can never defer, whatever the size.
How do I handle prescribing controlled substances by telehealth?
A DEA and HHS extension lets clinicians prescribe Schedule II–V substances by telehealth without a prior in-person exam through December 31, 2026, with audio-only allowed for opioid-use-disorder treatment. Build a real prescriber workflow with a full audit trail, and design it to re-enable an in-person requirement per state and per substance, because the Ryan Haight Act default returns if the extension lapses.
How do I evaluate an AI tool that claims therapeutic outcomes?
Ask for a peer-reviewed study with a real comparator and a pre-registered protocol, the FDA correspondence, and two reference customers who ran the tool for at least six months. Ignore press releases. Given the FDA has cleared zero generative-AI mental-health devices as of late 2025, treat any “FDA-approved AI therapist” claim as a red flag until you see the letter.
How long until a mental-health app breaks even?
Self-help: 18–24 months at meaningful MRR. On-demand therapy: 24–36 months once clinician supply and per-state licensure stabilize. Corporate wellness: 18–30 months once you cross the third or fourth large employer. DTx: 36–60 months from the start of clearance to reimbursement at scale. Capitalize to the archetype, not to the optimistic case.
Can I run a mental-health app outside the US?
Yes. The UK (MHRA), EU (MDR for DTx), Australia (TGA) and Canada (Health Canada) all have workable regimes. The shape differs from the FDA, the GDPR and UK GDPR posture is stricter than HIPAA on consent, and per-country clinician licensure dictates per-country clinician supply. Launch one country at a time and localize the crisis lines for each.
What to read next
Sister guide
Telemedicine platform development 2026
The full telehealth surface a mental-health platform inherits: visits, scheduling, EHR-lite, billing.
Compliance
HIPAA & SOC 2 telehealth video platform
The BAA chains, encryption and audit logging a mental-health product lives inside.
Adjacent
AI scribe architecture for ambient documentation
The clinician-helper AI pattern that pairs with mental-health platforms.
LLM ops
LLM app evaluation in production
How to keep AI scaffolding honest in production before it ever touches a user.
Work with us
Telemedicine & healthcare development
How we scope and ship HIPAA-grade telehealth and mental-health platforms.
Ready to ship a mental-health app worth trusting?
A 2026 mental-health app is a regulated, ethically loaded product where good engineering is necessary and not sufficient. Pick the right archetype, ship a working crisis-response path, treat HIPAA and per-state licensure as engineering constraints, keep AI on the clinician’s side of the line the new state laws just drew, and build privacy as a promise a procurement team can audit. Get those five right and you build something that survives the regulator, the FTC, the press cycle and, most of all, the user.
We have shipped this surface inside AI-assisted healthcare products, on CirrusMED’s HIPAA stack, and on top of TransLinguist’s NHS-grade interpretation platform, and the patterns are battle-tested in production. Send your brief and we will size, scope and plan a build for your archetype, your buyer and your regulatory shape, grounded in telemedicine engineering we run every day.
Send your brief, get a delivery plan
Free 30-minute consult. We size the build, draft the licensure, FDA and payer track, and hand you a plan built on HIPAA-grade patterns we already operate.


