- Q01Has Bubble ever offered HITRUST inheritance?
- No. Bubble has been silent on HITRUST throughout. The underlying reason is structural — HITRUST CSF assumes the platform underneath has signed the right contracts and exposes inheritable infrastructure controls. Bubble does neither, so even if the team wanted to offer an inheritance package there would be nothing to inherit from at the application tier.
- Q02Can a plugin or wrapper bring Bubble inside the assessment boundary?
- No. HITRUST assessors evaluate the platform and its operating controls, not a JavaScript shim on top of it. Plugins run inside Bubble's browser runtime and Bubble's server runtime. Neither can be brought into a controlled boundary you have authority to operate, which is what r2 expects.
- Q03What does a hybrid look like in practice?
- You stand up a small Next.js service on AWS HIPAA-eligible infrastructure, point your PHI-bearing forms and APIs at it, and define a clean boundary that the assessor can walk. The Bubble app keeps non-PHI surfaces and stays out of scope. The boundary is the entire selling point — the moment PHI leaks back into Bubble, the boundary is gone.
- Q04How long does an end-to-end HITRUST programme actually take?
- e1 is the fastest, typically around 10 weeks once the stack is in place. i1 runs 4–9 months. r2 runs 6–18 months including readiness, validated assessment, remediation, and HITRUST quality assurance. Most teams sequence them: e1 first to get a signal in market, then i1 or r2 when a specific deal demands it.
- Q05Does HITRUST replace HIPAA, SOC 2, or ISO 27001?
- It overlaps with all three but doesn't replace them. The HITRUST control library maps to HIPAA, NIST 800-53, PCI DSS, and ISO 27001, which is why large buyers like it — one assessment, many frameworks. You will still hold a separate BAA chain for HIPAA, and you may still want SOC 2 or ISO 27001 for sales outside healthcare.
- Q06Can you sign a BAA with us?
- Bubble will not. AWS, Azure, GCP, and Vercel Enterprise / Pro will. As the engineering partner we sign a BAA covering our access during the build and warranty period; the production BAA chain lands with whichever hyperscaler hosts the regulated surfaces.