Bubble & Hipaa...Where do complications arise?

We landed a good size deal with a client to build our a medical app, now we ran into issues…HIPAA & GDPR…

We’ve read every single post on bubble pertaining to these 2 compliances and we seem to not understand why we keep reading you can’t build HIPAA compliant on Bubble nor why GDPR will be a journey.

Everything that seems to be required is possible with bubble.

CHECKMARK2 resized 600 Access Authorization

CHECKMARK2 resized 600Log In Monitoring

CHECKMARK2 resized 600 Password Management

CHECKMARK2 resized 600 Data Backup Plan

CHECKMARK2 resized 600 Disaster Recovery Plan

CHECKMARK2 resized 600 Emergency Mode Operation Plan

PHYSICAL SAFEGUARDS [142.308 (b)]

CHECKMARK2 resized 600 Facility Security Plan

CHECKMARK2 resized 600 Data Backup and Storage

ACCESS CONTROL [142.308 ©]

CHECKMARK2 resized 600 Unique user identification

CHECKMARK2 resized 600 Automatic Log off

CHECKMARK2 resized 600 Encryption / Decryption

If we just use bubble for front & AWS for all backend will we be able to comply then?

@emmanuel @eve

2 Likes

Hi Chris, I am in the same boat. Did you get a clear answer on this? I have a client in the medical field and I am exploring using bubble for this. Please let me know if you were successful with this.

@eazycode

1 Like

Hey All, unfortunately Bubble can’t sign BAA - so it’s not possible to handle all HIPAA requirements for the moment