Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Practice Operations

Is Zoom HIPAA Compliant? Yes, on Paid Plans With a BAA

Zoom can be HIPAA compliant — but only with a paid plan, a signed BAA, and the right settings. Here is what independent practices need to configure.

Patient ProtectPatient Protect Editorial Team·April 15, 2026·9 min read

Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (Certified HIPAA Consultant, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

Share
Zoom video conferencing HIPAA compliance requirements checklist

Zoom can be HIPAA compliant — but only under specific conditions. You need a paid plan, a Business Associate Agreement with Zoom, and a set of security configurations applied to your account.

Which paid plan is a smaller question than most guides make it. Zoom's own documentation names Pro, Business, Business Plus and Enterprise for healthcare customers, and adds that Zoom enters BAAs with customers subscribed to other paid plans listed on its Plans & Pricing page. So a small practice on Pro is not shut out, and there is no separate "healthcare add-on" you have to buy on top — that is a persistent misconception, and an earlier version of this page repeated it.

How you get the BAA is the part that differs by plan. A Pro purchaser selects the agreement in the checkout dropdown and accepts it there. Business, Business Plus and Enterprise customers contact Sales to execute it. If you are already subscribed, you enable it yourself from Plan Management in your account, then review and proceed.

Zoom Basic — the free tier — does not qualify. If you are conducting patient visits on it, you are operating outside compliance right now. See our full guide on HIPAA compliance for telehealth for the wider picture.

This matters because Zoom does not enable HIPAA-compliant settings by default. Purchasing the right plan is step one. Configuring it correctly is where most practices fail.

What Zoom Provides for HIPAA Compliance

Once you are on a paid plan with the BAA in place, Zoom provides several controls that support HIPAA compliance for video conferencing:

Business Associate Agreement. Zoom will sign a BAA that covers Zoom Meetings, Zoom Phone, Zoom Team Chat, and Zoom Rooms when used under a qualifying plan. The BAA defines Zoom's obligations for handling protected health information (PHI) transmitted through the platform.

AES-256 GCM encryption. Zoom encrypts meeting audio, video, and screen sharing in transit using AES-256 GCM encryption. This is the same encryption standard used by financial institutions and government agencies.

Waiting rooms and passcodes. Hosts can require participants to wait in a virtual lobby before being admitted, and meetings can require passcodes to join. Both features prevent unauthorized individuals from entering a patient session.

Host controls. The host can mute participants, remove attendees, lock meetings after all participants have joined, and control screen sharing permissions. These controls reduce the risk of unauthorized disclosure during a session.

Cloud recording with encryption. If you use cloud recording, Zoom encrypts recordings at rest. Access to recordings can be restricted by role and protected with passwords.

Admin controls for data sharing. Account administrators can disable integrations, restrict file transfers, and control which features are available to users within the organization.

What Zoom Does Not Do

Zoom handles video conferencing. It does not handle HIPAA compliance. That distinction is critical, and it is where independent practices consistently get into trouble.

Zoom does not make your practice compliant. A signed BAA with Zoom covers Zoom's obligations as a business associate. It does not cover your obligations as a covered entity. You are still responsible for the full scope of the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule.

Zoom does not encrypt chat messages end-to-end by default. In-meeting chat and persistent Team Chat messages are encrypted in transit and at rest, but they are not end-to-end encrypted unless you specifically enable Zoom's E2EE feature — which disables certain functionality like cloud recording and breakout rooms.

Zoom does not monitor who accesses recordings. Zoom stores recordings and restricts access based on your settings, but it does not audit who views them, when, or how many times. That audit trail is your responsibility.

Zoom does not handle your risk assessment. The HIPAA Security Rule requires a current, thorough risk assessment covering all systems that touch ePHI — not just video conferencing. Zoom is one tool in your stack. The risk assessment covers all of them.

Zoom does not cover other tools in your workflow. Your EHR, email, file storage, messaging apps, fax service, and patient intake forms all require their own BAAs and security configurations. The full inventory of HIPAA-compliant tools a practice needs typically runs 15 to 25 vendors. Zoom compliance is one line item, not the whole program.

Common Mistakes Practices Make with Zoom

These are the errors that come up repeatedly in practice — any one of them can create a compliance gap that is difficult to defend during an OCR investigation.

Using the free or basic plan and assuming it is compliant. Zoom Free and Zoom Basic do not support BAAs. Without a BAA, any PHI transmitted through the platform is an unmitigated HIPAA violation. There is no gray area here.

Not signing the BAA. Some practices purchase a qualifying plan but never execute the BAA. The BAA is not automatic — you must request it and sign it through Zoom's admin portal. Until that is done, Zoom has no contractual obligation to handle your data according to HIPAA standards.

Leaving cloud recordings accessible without access controls. Default sharing settings for cloud recordings may allow anyone with the link to view them. If a recording contains a patient session, that is unsecured PHI.

Not disabling file transfer and third-party integrations. Zoom supports file transfers in chat and integrations with dozens of third-party apps. Each integration that touches PHI requires its own BAA. If you have not vetted those integrations, disable them.

Sharing meeting links without passcodes. A meeting link without a passcode can be accessed by anyone who obtains the URL — whether through email forwarding, accidental sharing, or a compromised inbox.

Not training staff on proper use. A provider who understands the settings is not enough. Every staff member who uses Zoom for patient communication needs to know the correct procedures — how to enable waiting rooms, how to lock meetings, what not to share in chat.

Settings to Configure for HIPAA Compliance

Once you have a qualifying plan and a signed BAA, apply these settings in your Zoom admin dashboard:

  • Enable waiting room — require all participants to be admitted by the host before entering the meeting. This prevents unauthorized access.
  • Require meeting passcodes — set this as a default for all meetings, not just ad hoc ones. Applies to scheduled meetings, instant meetings, and meetings accessed via phone.
  • Disable cloud recording unless operationally required — if you do not need recordings, turn them off. If you do, restrict access to account administrators and set recordings to require a password for viewing.
  • Disable file transfer in meetings — unless you have a documented business need and the transfer mechanism is covered under your compliance program, turn this off.
  • Lock meetings after all participants join — prevents additional attendees from entering once the session is underway. Particularly important for one-on-one patient visits.
  • Disable third-party integrations without BAAs — review every app connected to your Zoom account. If an integration has access to meeting data, chat content, or recordings and you do not have a BAA with that vendor, disable it.
  • Restrict screen sharing to host only — unless clinically necessary, prevent participants from sharing their screens to reduce the risk of accidental PHI exposure.
  • Enable the "Require encryption for 3rd party endpoints" setting — ensures that SIP/H.323 room systems connecting to your meetings use encryption.

These settings should be applied at the account level by an administrator, not left to individual users.

Where Zoom Fits in Your Compliance Program

Zoom is a video conferencing tool. It handles one function in your practice's technology stack — real-time audio and video communication with patients.

HIPAA compliance is not a single tool. It is a program that covers every system, process, and person that touches protected health information. The HIPAA compliance checklist maps out the full scope of what your practice needs. A compliant Zoom configuration addresses video conferencing. You still need:

  • A current security risk assessment covering all ePHI systems — your EHR, email, file storage, messaging, and every connected device
  • Written policies and procedures addressing the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule
  • Workforce training that is documented, current, and covers role-specific risks
  • BAA tracking for every vendor that handles PHI on your behalf — not just Zoom
  • An incident response plan that your team can actually execute when something goes wrong

Zoom being properly configured is one checkbox. The compliance program is the full checklist.

Patient Protect monitors your complete compliance state — including whether tools like Zoom are accounted for in your data flow, whether BAAs are current, and whether your risk assessment reflects your actual environment.

Frequently Asked Questions

Is Zoom Free HIPAA compliant?

No. Zoom Free does not support a Business Associate Agreement, which is a mandatory requirement under HIPAA for any vendor that handles PHI. Using Zoom Free for patient visits is a compliance violation regardless of what settings you configure.

Does Zoom sign a BAA?

Yes. Zoom's documentation names Pro, Business, Business Plus and Enterprise for healthcare customers, and states that Zoom also enters BAAs with customers on other paid plans listed on its Plans & Pricing page. It is not applied automatically on purchase. On Pro you accept it in the checkout dropdown; on Business and above you contact Sales; if you are already subscribed, you enable it from Plan Management in your account.

Can I use Zoom for telehealth visits?

Yes, if you are on a paid plan with the BAA executed and you have configured the security settings outlined above. Zoom markets a healthcare-oriented offering with features tailored to clinical workflows, but the BAA itself is not confined to it.

Is Zoom end-to-end encrypted?

Zoom offers an optional end-to-end encryption (E2EE) feature, but it is not enabled by default. Standard Zoom meetings use AES-256 GCM encryption between the client and Zoom's servers. E2EE encrypts the session so that even Zoom cannot access the content, but it disables cloud recording, live transcription, and breakout rooms. For most practices, AES-256 GCM with a signed BAA satisfies the HIPAA encryption requirement.

What Zoom plan do I need for HIPAA compliance?

Zoom's documentation names Pro, Business, Business Plus and Enterprise for healthcare customers, and adds that it enters BAAs with customers on other paid plans listed on its Plans & Pricing page. Free and Basic do not qualify. Every path requires the executed BAA to be in place before PHI is discussed on the platform; higher tiers add administrative controls that matter more as the workforce grows.


Patient Protect tracks your full compliance state, including vendor BAAs and tool configurations, starting at $39/month.

Was this useful? Share it.

Share

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Next step

What would an OCR investigator find on your website?

Free 30-second scan — tracking pixels, security gaps, missing policies. See what’s visible before they do.

Stay informed

Subscribe to HIPAA Pulse.

Breach alerts, enforcement updates, and compliance intelligence — every two weeks.

© 2026 Patient Protect LLC. All rights reserved. Content may not be reproduced, scraped, or used to train AI models without written permission. Terms · DMCA