Is Zoom HIPAA compliant? The short answer is that Zoom can be used in a HIPAA-compliant way, but not by default and not on every account. Zoom states that Zoom for Healthcare "helps enable customers' HIPAA compliance by executing a Business Associate Agreement (BAA)." Without that signed agreement, a standard or free Zoom account is not the right setup for patient visits.
The wording matters. Zoom says it helps enable compliance. It does not say that using Zoom makes a practice compliant. HIPAA responsibility is shared: the vendor signs the BAA and protects its platform, and the provider or telehealth business configures the tool, controls access, and manages the patient information around each visit.
This guide explains why the BAA decides the question, why the pandemic-era exception no longer applies, what your team still owns after signing, and where a video tool alone stops being enough for a telehealth business. For the full list of HIPAA requirements beyond video, see Bask's guide to HIPAA compliance in telehealth.
Why the BAA Is the Deciding Factor
Under HIPAA, a covered entity such as a medical practice or telehealth provider needs a Business Associate Agreement with vendors that create, receive, maintain, or transmit protected health information (PHI) on its behalf.
The U.S. Department of Health and Human Services makes the line clear in its guidance on audio-only telehealth: a covered entity must enter into a BAA with a vendor that is "more than a mere conduit for PHI." HHS gives the example of an app that stores recordings or transcripts in the developer's cloud infrastructure. That vendor is handling PHI, so it is a business associate.
A video platform fits that description in several ways. Depending on how it is used, it may:
- Record sessions and store the recordings
- Generate transcripts or captions
- Keep in-meeting chat logs
- Store meeting metadata that links patients to providers and times
Any of these can put PHI in the vendor's systems. That is why the signed BAA, not the quality of the video, is what decides whether Zoom can be part of a HIPAA-compliant workflow.
What the Conduit Exception Does and Does Not Cover
HIPAA has a narrow exception for "conduits," such as a telephone company that only connects a call. HHS explains that a covered provider can hold an audio-only session over a regular phone line without a BAA when the telecom provider "does not create, receive, or maintain any PHI from the session and is only connecting the call."
That exception is about transient transmission. A video platform with cloud recording, chat storage, or transcripts usually goes well beyond it, so telehealth teams should not rely on the conduit exception for video visits.
The Pandemic Exception Is Over
Much of the confusion about Zoom comes from 2020. During the COVID-19 public health emergency, the HHS Office for Civil Rights (OCR) announced it would not penalize providers for using "non-public facing" communication tools for telehealth in good faith, even without a BAA.
That enforcement discretion has ended. According to HHS, it expired on May 11, 2023, and OCR's 90-day transition period ended at 11:59 p.m. on August 9, 2023.
Many practices set up their video workflows during the emergency and never revisited them. If your team started using a standard Zoom account in 2020 and nothing has changed since, that setup was built for an exception that no longer exists.
Regular Zoom vs. Zoom for Healthcare
The practical difference comes down to the agreement and the account it covers.
| Question | Regular Zoom account | Zoom for Healthcare |
|---|
| Does Zoom sign a BAA? | No | Yes, according to Zoom |
| Intended for patient visits? | No | Yes |
| Who configures settings? | Your team | Your team, within the healthcare account |
| Recordings and chat | Handled under standard terms | Covered by the BAA's terms |
| Fit for telehealth with PHI | Not recommended | Can support HIPAA compliance when set up correctly |
Plan names, features, and pricing change over time, so confirm the current details directly with Zoom before choosing an account. The point that does not change: the BAA must be signed before PHI moves through the platform.

What Your Team Still Has to Get Right
A signed BAA is the starting line. The HIPAA Security Rule still expects your organization to put appropriate administrative, physical, and technical safeguards around the way you use the tool.
Meeting Settings
Review settings before the first patient visit:
- Use waiting rooms or equivalent controls so patients are admitted one at a time
- Require passcodes or unique meeting links
- Decide who is allowed to record, if anyone
- Confirm where recordings and transcripts are stored
Account Access
Most HIPAA problems come from people, not software.
- Give accounts only to staff who need them
- Turn on multi-factor authentication
- Remove access promptly when someone leaves
- Avoid shared logins so that activity can be traced to a person
Recordings, Transcripts, and Chat
The safest recording is often the one you never make. If your team does record:
- Document why recordings are needed
- Set a retention period and delete on schedule
- Limit who can view or download files
- Keep in-meeting chat free of details that belong in the medical record
Everything Around the Call
A BAA with Zoom covers Zoom. It does not cover the intake form a patient filled out before the visit, the notes a provider wrote afterward, the prescription that followed, or the payment link sent by email. Each of those tools needs its own review and, when it handles PHI, its own BAA. Bask's guide to HIPAA-compliant telehealth software walks through what to check for each one.
Quick Check: Does Your Current Zoom Setup Need a Review?
If you are not sure where your team stands, these questions usually surface the gaps in a few minutes:
- Is there a signed BAA on file, and does it cover the account your providers actually use?
- Did any provider start seeing patients on a personal or free account and never switch?
- Are cloud recordings turned on, and does anyone know where they are stored?
- Do former staff members still have active accounts?
- Is multi-factor authentication required for every user?
- Do providers share meeting links in a way that could let the wrong person join?
- Are intake forms, notes, and payment links handled by tools that also have BAAs?
A "no" or "not sure" on any of these is worth fixing before the next patient visit. None of them depends on Zoom's features. They depend on how your team sets up and maintains the account.
Where Zoom Stops Being Enough for a Telehealth Business
For a therapist or a small practice that already has an EHR, Zoom for Healthcare can cover the video piece well. A telehealth business has a longer chain.
A single patient journey often includes:
-
A landing page and intake form
-
Eligibility or medical questionnaire
-
A video or asynchronous consultation
-
Clinical notes in an EMR
-
An e-prescription
-
Pharmacy fulfillment and shipping
-
Payment and, often, a recurring subscription
-
Follow-up messages and refills
When each step runs on a different vendor, each one is another contract, another business associate relationship, another set of settings to audit, and another place data can leak. Messaging tools and CRMs are common gaps. Bask covers those in its articles on HIPAA-compliant CRMs and patient communication software. That is also why buyers increasingly look for independent assurance, such as a SOC 2 Type II report, from the platforms at the center of that chain.
How Bask Health Handles Video Visits
Bask Health approaches video as one step in the patient journey rather than a separate tool to bolt on.
Bask's virtual clinic infrastructure supports synchronous care through video calls, chat, and secure online portals, plus asynchronous care for treatments that don't require a live visit. Those visits sit in the same platform as:
- EMR and e-prescribing
- Pharmacy fulfillment
- Payment processing
- Integrated doctor networks, included on every plan
- Customizable treatment pathways for Rx, OTC products, and medical devices
On the security side, Bask maintains HIPAA and LegitScript compliance, SOC 2 Type II controls, multi-factor authentication, and audit logging. The Bask security page describes the safeguards behind that stack, including encryption at rest and in transit, access control, and system monitoring.
More than 250 U.S. telehealth companies use Bask, and the platform has supported more than 10.5 million orders. For a brand that would otherwise stitch together a video tool, an EMR, a pharmacy, and a payment processor, that means fewer vendors to manage and fewer handoffs where PHI can slip through. Compare Bask plans to see which setup fits your model.
FAQs
Is the free version of Zoom HIPAA compliant?
No. Zoom's BAA is tied to Zoom for Healthcare. A free or standard account without a signed BAA is not an appropriate setup for sessions that involve PHI.
Does Zoom sign a BAA?
Yes. Zoom states that Zoom for Healthcare "helps enable customers' HIPAA compliance by executing a Business Associate Agreement (BAA)." Confirm the current terms and eligible plans with Zoom before relying on it.
Can therapists use Zoom for telehealth?
Yes, when they use Zoom for Healthcare with a signed BAA and configure it properly. Therapists should also review recording settings carefully, since therapy session recordings can be especially sensitive.
Do I need a BAA for phone-only telehealth?
Not always. HHS explains that a regular phone company that only connects the call and does not create, receive, or maintain PHI can fall under the conduit exception. Apps that record, transcribe, or store call data are different and generally require a BAA.
What is the difference between HIPAA compliant and HIPAA certified?
There is no official HIPAA certification from the federal government. A vendor can support HIPAA compliance, for example by signing a BAA and maintaining safeguards, but compliance depends on how each organization uses the tool. Be cautious of any vendor that describes itself as "HIPAA certified."
Conclusion
So, is Zoom HIPAA compliant? It can be part of a HIPAA-compliant workflow when you use Zoom for Healthcare, sign the BAA, and configure the account with care. It isn't compliant by default, and a free or standard account isn't the right tool for patient visits.
The bigger question for a telehealth business is what happens around the call. Every tool that touches PHI needs the same scrutiny, and every extra vendor adds another agreement to manage. The fewer places patient data has to travel, the easier it is to protect.
References
1. U.S. Department of Health and Human Services. (2022). Guidance on HIPAA and audio-only telehealth. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-audio-telehealth/index.html
2. U.S. Department of Health and Human Services. (n.d.). HIPAA and telehealth. https://www.hhs.gov/hipaa/for-professionals/special-topics/telehealth/index.html
3. U.S. Department of Health and Human Services. (n.d.). Business associates. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
4. Zoom. (n.d.). Zoom for Healthcare. https://www.zoom.com/en/industry/healthcare/