No. As of 1 October 2026, Bubble does not sign a Business Associate Agreement, and its own documentation says that apps built on Bubble won’t achieve HIPAA compliance. That is likely to change: Bubble has said publicly that HIPAA support is in progress, will need a dedicated Enterprise plan, and is targeted for the end of 2026. Until Bubble actually signs a BAA with you, protected health information (PHI) cannot go into a Bubble app, however well you configure it. This guide covers what Bubble has and hasn’t committed to, why its SOC 2 report and AWS hosting don’t change the answer, the Bubble-specific risks to check even after a BAA exists, and your options today.
1. The Short Answer, With Sources
Search results on this question disagree, mostly because some pages describe Bubble’s plans as if they had already shipped. Here is what Bubble itself says, as of 1 October 2026:
| Question | Answer today | Source |
|---|---|---|
| Does Bubble sign a BAA? | No | Bubble’s HIPAA app builder guide (29 July 2026) |
| Can a Bubble app be HIPAA compliant? | Not today. Bubble’s documentation says apps built on Bubble “won’t achieve HIPAA compliance” and that Bubble “cannot support HIPAA compliant apps” | Bubble manual: HIPAA |
| Is HIPAA support planned? | Yes. Targeted for the second half of 2026, then “still on track for this year” | Bubble’s April and July 2026 founder AMA recaps |
| Which plan will it need? | A dedicated/Enterprise plan, arranged through Bubble’s sales team, not self-serve | April 2026 AMA recap |
| Is Bubble SOC 2 audited? | Yes, SOC 2 Type II for security; the report is available through Bubble’s sales team | Bubble security |
| Where is data hosted? | AWS. Shared plans run in a US region; dedicated Enterprise plans can choose an AWS region | Bubble security page and manual |
| Is data encrypted? | TLS in transit; AES-256 at rest through Amazon RDS | Bubble security page |
So the honest answer has two parts. Today: no, and Bubble says so itself. Soon: possibly, on an Enterprise plan, once Bubble publishes BAA terms you can read and sign. Plan around the first part, not the second.
2. Why SOC 2, AWS and Encryption Don’t Make Bubble HIPAA Compliant
Three arguments come up in almost every forum thread on this. None of them works.
“Bubble is SOC 2 Type II audited”
SOC 2 is an audit of a company’s security controls. HIPAA is a law, and one of its fixed requirements is a written contract. Under 45 CFR 164.502(e) and 164.504(e), a covered entity or business associate may let a vendor create, receive, maintain or transmit PHI on its behalf only under a business associate agreement. A strong SOC 2 report is good evidence that a vendor could protect PHI, but it is not that contract. Our SOC 2 guide for healthcare SaaS covers how the two fit together.
“Bubble runs on AWS, and AWS signs BAAs”
AWS signs a BAA with its customer, which here is Bubble. That agreement covers Bubble’s use of AWS. It does not cover your relationship with Bubble, and it gives you no contractual rights at all. You need a BAA with the company you hand PHI to, and every vendor down the chain needs one with the company above it.
“We’ll encrypt the PHI before it reaches Bubble”
HHS has addressed this directly. In its guidance on HIPAA and cloud computing, a cloud provider that stores only encrypted PHI, and does not hold the key, is still a business associate and still needs a BAA. Encryption lowers the risk; it doesn’t remove the contract requirement. And in practice, a Bubble app that can’t read its own data can’t search, sort or show it either, which defeats the reason for using Bubble.
3. Bubble’s HIPAA Roadmap, and What to Check When It Ships
Bubble’s public statements so far are short. In April 2026 it said HIPAA compliance was “in progress and targeted for the second half of 2026” and would “require a dedicated/Enterprise plan.” In July it said HIPAA was “still on track for this year.” Neither statement includes BAA terms, pricing or scope, and as of 1 October 2026 the Bubble manual still says Bubble cannot support HIPAA apps.
When Bubble announces it, read the BAA and the plan terms before you plan a launch around them. These are the questions that decide whether it works for your app:
- Which plan, and which apps? If HIPAA needs a dedicated instance, does an existing app on a shared plan have to migrate, and how?
- What does the BAA cover? The database, file storage, server logs, backups, email sending, the editor, and any AI features should all be named. Anything not named is outside it.
- Plugins and the API Connector. Are they covered at all, or only Bubble’s own components? (See section 4.)
- Sub-processors. Ask for the list of services Bubble uses that would touch your PHI, each under its own BAA with Bubble.
- Breach notification. How quickly Bubble will tell you about an incident, and what it will tell you.
- Access by Bubble staff. Who at Bubble can see app data for support, and how that access is logged.
- Audit logs you can export. HIPAA expects you to be able to show who accessed which records. Check what Bubble records and whether you can get it out. Our audit logging guide lists what an auditor will look for.
4. Seven PHI Risks Specific to Bubble Apps
Even with a BAA, a Bubble app can leak PHI through parts of the platform that a BAA may not cover, or that are simply easy to misconfigure. Check each of these, today for any non-PHI healthcare app, and before go-live if Bubble’s HIPAA plan becomes available.
| # | Risk | Why it matters |
|---|---|---|
| 1 | Third-party plugins | Plugins are written by independent developers. Some run code on Bubble’s servers, some in the browser, and some send data to the plugin author’s own service. None of those authors is covered by a BAA with Bubble. |
| 2 | API Connector calls | Every external service you call with PHI (SMS, email, AI, analytics) is a separate vendor that needs its own BAA with you. |
| 3 | Privacy rules | Bubble’s access control is configured per data type through privacy rules. A data type with no rules, or a rule that is too broad, can expose records to the wrong users, and to the Data API if it is enabled. |
| 4 | File uploads | Uploaded files are stored separately from the database. Check whether they are private by default and how their URLs are protected, because an insurance card or lab PDF is PHI. |
| 5 | Logs and the editor | Server logs and the editor’s Data tab can show record contents to every collaborator on the app, including outside freelancers who aren’t part of your workforce. |
| 6 | Development data | Bubble apps have separate development and live databases. Real patient data copied into development, “just to test,” is PHI in a second place with a wider audience. |
| 7 | AI features | Any AI feature that sends app data or prompts to a model provider needs that path covered by a BAA end to end. See our HIPAA-compliant AI guide for which providers sign one. |
None of these is unique to Bubble; the same list appears in our HIPAA gap list for AI app builders. What is specific to Bubble is how much of the stack runs on the platform rather than in code you own, which makes the BAA’s exact scope matter more.
5. Your Options Today
| Option | Works when | The catch |
|---|---|---|
| A. Keep PHI out of Bubble | Your app can work with de-identified data, or handles no PHI at all: provider directories, scheduling with no clinical detail, wellness content, internal tools | Patient names, contact details and appointment data together with a health condition are PHI. Teams often discover they can’t avoid it |
| B. Bubble front end, HIPAA backend | PHI lives in a service that signs a BAA. Xano offers HIPAA and a BAA as a paid add-on; Supabase offers it as a paid add-on on its Team plan and above | If PHI passes through Bubble’s servers on the way, through server-side workflows, API Connector calls or logs, Bubble is still handling PHI without a BAA. Only data that goes straight from the browser to the HIPAA backend avoids that, and that is hard to guarantee in Bubble |
| C. Wait for Bubble’s HIPAA plan | You are not launching with real patients before 2027, and an Enterprise plan fits your budget | The date, price and BAA scope are not published. Build with synthetic data only until you have a signed BAA |
| D. Move to a stack with a BAA, or to code you own | You need PHI in production now | A rebuild. Section 6 covers how to plan it |
Option B is the most common suggestion in Bubble’s community, and it can work. But be precise about where PHI goes. “The database is HIPAA-compliant” is not the same as “PHI never touches Bubble,” and only the second one keeps you outside the need for a Bubble BAA. If you are comparing other platforms, our no-code app builder comparison and HIPAA no-code guide list which ones sign a BAA and on which plans.
6. Moving a Bubble Healthcare App to a HIPAA-Ready Stack
If you need PHI in production before Bubble’s HIPAA plan exists, this is the order that keeps the rebuild manageable:
- Inventory the data. List every Bubble data type and mark which fields are PHI. Include file fields and option sets that encode clinical meaning.
- Inventory the integrations. Every plugin and API Connector call: what data it sends, where, and whether that vendor will sign a BAA.
- Translate privacy rules into roles. Each privacy rule is an access-control decision. Write them down as role-based permissions; they become the specification for the new backend.
- Choose the backend on infrastructure covered by a BAA (for example AWS, Azure or Google Cloud under their BAAs, or a managed database with a HIPAA add-on). Add encryption, audit logging and authentication before any real data arrives.
- Export and load the data using Bubble’s data export or the Data API, then reconcile record counts and file links.
- Rebuild the workflows, starting with the ones that touch PHI.
- Cut over, then clean up. Remove PHI from the Bubble app, both databases and file storage. If real PHI was ever stored in Bubble without a BAA, talk to your privacy officer about whether it needs a breach risk assessment; our guide to HIPAA violations and penalties explains what is at stake.
The same playbook, applied to AI app builders, is in our Lovable and Base44 migration guides.
7. Where VertiComply Fits, and Where It Doesn’t
VertiComply is not a visual editor like Bubble. It generates the source code of a healthcare application from templates and your description, with HIPAA safeguards such as encryption, audit logging and role-based access built into the code. You can download the full source and deploy it to your own cloud account, under your own BAA with that cloud provider, so the code and the hosting are yours.
Two limits matter for this comparison. First, if you want to keep editing visually, Bubble is the better tool, and option A or C above may suit you. Second, apps hosted on VertiComply’s own infrastructure are currently intended for demos and staging, not PHI, until per-tenant isolation between customers is complete. For production PHI, deploy the generated code to your own BAA-covered cloud.
Not sure where your current app stands? Our free HIPAA compliance checker scores your safeguards, and if you’d rather have the migration done for you, our custom build team scopes Bubble rebuilds.
8. Frequently Asked Questions
Is Bubble HIPAA compliant in 2026?
Not as of 1 October 2026. Bubble does not sign a business associate agreement, and its documentation says apps built on Bubble won’t achieve HIPAA compliance. Bubble has said HIPAA support is in progress for a dedicated Enterprise plan, targeted for the end of 2026, but it has not published BAA terms. Until you have a signed BAA with Bubble, do not store protected health information in a Bubble app.
Does Bubble sign a BAA?
No, not yet. Bubble’s July 2026 guidance says it does not currently sign a BAA. Its founder has said HIPAA compliance is planned for 2026 on a dedicated or Enterprise plan sold through Bubble’s sales team. Check Bubble’s HIPAA documentation page for the current position, because that page will change when the plan launches.
When will Bubble be HIPAA compliant?
Bubble said in April 2026 that HIPAA compliance was targeted for the second half of 2026, and in July 2026 that it was still on track for this year. There is no confirmed launch date, price or BAA scope. Treat it as a roadmap item until Bubble updates its documentation and offers a BAA you can review.
Can I use Bubble for a healthcare app if I encrypt the PHI?
Encryption does not remove the need for a BAA. HHS guidance says a cloud provider that stores encrypted PHI is still a business associate even if it does not hold the decryption key. You can use Bubble for healthcare apps that handle no PHI, or that keep PHI entirely in a separate BAA-covered system that Bubble never stores or processes.
Can I use Bubble with Xano or Supabase for HIPAA?
It can work if PHI stays entirely in the backend and never passes through Bubble. Xano offers HIPAA and a BAA as a paid add-on, and Supabase offers a HIPAA add-on on its Team plan and above. The risk is that Bubble server-side workflows, API Connector calls and logs can carry PHI through Bubble’s servers, which would still require a BAA with Bubble.
Is Bubble SOC 2 compliant?
Yes. Bubble has a SOC 2 Type II report for security, available through its sales team, and it runs annual penetration tests. SOC 2 is a security audit, not a HIPAA contract, so it does not make Bubble usable for PHI without a business associate agreement.
What should I do if I have already stored PHI in Bubble?
Stop adding real patient data, move it to a BAA-covered system, and remove it from both of Bubble’s databases and from file storage. Then involve your privacy officer: storing PHI with a vendor that has no BAA may need a breach risk assessment under the HIPAA Breach Notification Rule. Keep a record of what was stored, for how long and who had access.
Which no-code app builders sign a HIPAA BAA?
Several do, usually only on higher-priced plans, and the terms change often. Our no-code app builder comparison lists the current options and plans. Whichever platform you choose, read the BAA itself and check that it covers the database, file storage, logs and every integration your app uses.
Last reviewed 1 October 2026. Bubble’s HIPAA plans are expected to change during late 2026, so check Bubble’s own HIPAA documentation for the current position. Third-party plan and add-on terms change often. Nothing here is legal advice on whether HIPAA applies to a specific product.