If Bubble doesn’t touch or interact the data itself in any way then that would be HIPAA compliant (although technically-as some have yelled at me in other posts,-it wouldnt be HIPAA complaint as much as it would be avoding the need for HIPAA compliance ).

However in general using Bubble for front end only is not a great way to go as the utilitiy of Bubble is best when leveraging both back and front end. (Depending on your use case it may possible to use Bubble for front and back end and tokenize the PII).

Also if Bubble connects with the Xano DB in any way that it can theoretically access any PII that’s likely a violation of HIPAA.

Finally, note that if the patient is logging into the Bubble app then their email (or even username if you use that approach) is PII…

1 Like