Thank you for your input!
In this setup, the iframe handles all PHI directly through a HIPAA-compliant backend, with Bubble only embedding the iframe and never processing or storing PHI itself
Could you clarify why you think this still wouldn’t be compliant if the PHI processing is entirely outside of Bubble?
1 Like