You cannot copy content of this website, your IP is being recorded.

What is Secure Bubble from PatientGain

What is Secure Bubble from PatientGain?

PatientGain’s “Secure Bubble” is a server-side privacy architecture that isolates website tracking, chat interactions, and form submissions within an encrypted, HIPAA-compliant cloud environment. It is referred as the “HipaaServer”. It is the at the heart of the PatientGain secure architecture, with restricted access. It acts as a protective buffer between your clinic’s web traffic and external networks, ensuring Protected Health Information (PHI) is never exposed to non-compliant advertising or analytics tools.

How the Secure Bubble Functions

  • Isolated Ingestion: When a patient visits your website, submits a form, or uses an AI chatbot, raw tracking data routes directly to PatientGain’s secure server network (hosted on HIPAA-compliant AWS and Google Cloud infrastructure) covered by a Business Associate Agreement (BAA).
  • Server-Side Scrubbing & Obfuscation: Inside the bubble, native software automatically strips away user IP addresses, masks browser fingerprints, and redacts URL query parameters containing sensitive medical search terms.
  • Sanitized Data Output: The scrubbed, anonymized conversion metrics are forwarded to native dashboards as obfuscated data. Your staff, front-desk, then click on “Un-Obfuscate” to see the actual patient data. As the staff “clicks” the action is captured for auditing.

Secure Infrastructure and Hosting

PatientGain’s platform and applications are hosted on secure cloud infrastructure, primarily Amazon Web Services (AWS), which is designed to be compliant with HIPAA and HITECH standards.  A BAA-backed, SOC 2 Type II certified platform that allows healthcare practices to run performance marketing. PatientGain’s HIPAA server is hosted on AWS Cloud (with BAA). PatientGain also uses Google’s GCP cloud (With BAA). Any app level access is logged, and managed based on roles. Practice users are segregated into different levels and roles, per HIPAA guidelines. Even PatientGain’s internal staff have roles and every staff cannot see every account, it is strictly based on need-to-know basis. Internal staff’s activity is logged also, for internal auditing. All internal staff members are background checked.

  • Data Encryption: ePHI is protected using encryption both “at rest” (when stored) and “in transit” (when transmitted, e.g., via HTTPS/SSL).
  • Secure Storage: Patient data collected through PatientGain apps, such as their CRM, is stored on secure, HIPAA-compliant servers, not in less secure locations like standard website database tables (e.g., in WordPress itself). 

Key Operational Advantages

  • Bypasses Ad Network Restrictions: Because platforms like Google and Meta refuse to sign BAAs for standard client-side tracking, the bubble prevents accidental ePHI transmission at the root server level.
  • Eliminates Costly Middleware: Practices avoid spending thousands of dollars on standalone data-scrubbing middleware or custom server proxy builds because the privacy proxy is natively integrated into the platform.
  • Unified Legal Protection: Web hosting, intake forms, scheduling apps, AI chatbots, and analytics are all contained within the same secure bubble under a single, comprehensive BAA.