# Is Bubble HIPAA compliant? No — and Bubble's own docs say so

- Tool: Compliance
- Last updated: August 2026

## TL;DR

No. Bubble's own documentation states that apps built on Bubble do not achieve HIPAA compliance, and Bubble offers no Business Associate Agreement on any plan as of August 2026. In July 2026 Bubble said it is working on HIPAA support, targeting a separate Enterprise plan by the end of 2026. Until that ships, there is no signed agreement covering patient data held in Bubble.

## Frequently asked questions

### Can I just ask Bubble for a BAA?

You can ask, but as of August 2026 there is nothing to sign. Bubble does not offer a Business Associate Agreement on any plan, and its own documentation says apps built on Bubble won't achieve HIPAA compliance. Bubble never states "we don't sign BAAs" — the agreement simply does not appear in its docs, its pricing pages or its Trust Center.

### I read that Bubble is HIPAA compliant on Enterprise. Who's right?

Bubble is. Its documentation and its own July 2026 blog post both say the platform does not meet HIPAA standards today. The Enterprise plan on Bubble's pricing page offers custom workload units, choice of hosting location and customization — HIPAA is not among them. The blogs saying otherwise were early rather than invented: Bubble has said it is working on HIPAA support, targeting Enterprise by the end of 2026.

### Bubble has SOC 2. Isn't that good enough?

They are different instruments. SOC 2 is an independent audit of the controls a company says it operates. A BAA is a contract in which a vendor accepts obligations for handling protected health information. A company can hold SOC 2 and still have no BAA to offer, which is exactly Bubble's position today. One does not substitute for the other.

### Should I just wait for Bubble's HIPAA plan at the end of 2026?

That is a real option, and we say so in our "when not to hire us" section. Bubble has said it is working on it and named end of 2026 for an Enterprise plan. It is a target, not a commitment, and we cannot tell you what will ship or what it will cost. If your launch is before that date, or real patient records are already in the database, waiting is not the same as doing nothing — the data sits in Bubble the whole time.

### Do I have to throw away my Bubble app and rebuild it?

No, and that is usually the wrong move. What we do is move the patient data out: Bubble keeps the interface, the workflows and the non-patient logic, and patient records move to a backend covered by a signed BAA that Bubble talks to. Founders brace for "rebuild it" and mostly do not need to hear it. The work typically runs 6–10 weeks.

### We already launched and there are real patients in the database. What do we do first?

Two tracks at once. Talk to a healthcare attorney about what your obligations are — that question is theirs, not ours. On the technical side, stop new patient data flowing into surfaces you have not checked, then run the inventory: which fields, which files, which third-party calls, and whether the development database holds a copy. You cannot fix what you have not listed.

### Does choosing a hosting location or a dedicated instance solve it?

No. Where the servers physically sit is a separate question from whether a vendor has agreed in writing to handle protected health information. Bubble lists choice of hosting location under Enterprise, and separately states that the platform does not meet HIPAA standards. The second statement is not undone by the first.

---

Source: https://www.rapidevelopers.com/compliance/is-bubble-hipaa-compliant
© RapidDev — https://www.rapidevelopers.com/compliance/is-bubble-hipaa-compliant
