Thanks for the feedback

Just to clarify, the iframe is fully sandboxed and pulls content directly from a HIPAA-compliant backend. Bubble doesn’t process, log, or transmit the PHI—it only embeds the iframe

Would you still consider this “handling” PHI?

1 Like