HEALTHCARE AI

    Is Zoom HIPAA Compliant? What Healthcare Teams Need to Know

    Zoom can support HIPAA-regulated use, but only on an eligible paid plan with an executed Business Associate Agreement. Free and Basic accounts are not eligible, and the rest of HIPAA compliance stays your responsibility even after the BAA is signed.

    CloudNSite Team
    August 16, 2026
    9 min read

    Zoom can be used for protected health information, but only when a healthcare organization is on an eligible paid plan and has executed a Business Associate Agreement with Zoom. Free and Basic accounts are not eligible. A BAA is never automatic, and using Zoom for patient information without one leaves the data handled without the written agreement HIPAA requires. Beyond the plan and the BAA, the rest of HIPAA compliance stays your organization's responsibility.

    That is the short answer. The rest of this post covers what Zoom itself documents and what a healthcare team has to do to use it safely.

    What HIPAA compliance actually requires of a software vendor

    No video tool is "HIPAA compliant" on its own. HIPAA compliance is a property of how an organization uses a tool, not a checkbox the vendor ships. For any software that touches protected health information, three things have to be true.

    First, the vendor has to sign a Business Associate Agreement (BAA). This is the written contract HIPAA requires whenever a vendor handles PHI. A vendor that processes PHI is already a business associate with direct HIPAA liability the moment it does so. The BAA does not create that relationship. It documents the safeguards the law requires, and without it the covered entity is out of compliance. We cover the contract itself in our guide to the business associate agreement.

    Second, the product has to provide the technical safeguards HIPAA calls for. Audit controls are required. Encryption is an addressable specification, meaning you either implement it or document an equivalent measure after a risk assessment. A vendor that will sign a BAA has usually built both in.

    Third, the customer has to run the tool as part of its own HIPAA program. A BAA plus good features still fails if the account is used carelessly. Compliance is shared: the vendor supplies the capability, and the customer owns the deployment.

    Zoom meets the first two on the right plans. The third is on you.

    Zoom's stated position

    Zoom documents that it will sign a BAA. On its Health Data and HIPAA-Compliance page, Zoom states that it "helps customers enable HIPAA compliant programs by executing a Business Associate Agreement (BAA)." The same page says Zoom aligns its controls to the Healthcare Industry Trust Alliance Common Security Framework (HITRUST CSF), a recognized healthcare security standard.

    That is the honest framing to hold onto. Zoom positions itself as HIPAA-ready, meaning it provides the BAA and the safeguards required to support a compliant program. It does not claim that installing Zoom makes your practice compliant. The eligible plan and the executed BAA are what make Zoom usable for PHI. The rest is your own HIPAA program.

    Which Zoom plans can sign a BAA

    The plan tier is where most of the confusion lives, so this is the part to get right. Zoom's own Business Associate Agreement support article states that "Zoom offers Pro, Business, Business Plus, and Enterprise plans to customers in the healthcare space," and that "Zoom also enters into BAAs with customers who are subscribed to other paid plans listed on Zoom's Plans and Pricing page."

    Two practical points follow from Zoom's documentation:

    • Free and Basic accounts do not qualify. They are not listed among the plans Zoom will execute a BAA for. If you are on a free Zoom account, you cannot use it for PHI, no matter how careful your settings are.
    • A Pro plan can execute the BAA online. Zoom's article describes accepting the agreement at checkout by selecting the United States Agreement (BAA), which gives smaller practices a self-serve path. Larger organizations on a Business or Enterprise plan arrange the BAA through the standard process.

    The BAA also has to be actively executed. It is a step you take, not a default that turns on when you pay. Zoom notes that once the BAA is executed, no additional manual configuration is required to make the platform eligible. That is different from saying your use is automatically compliant. The platform becomes eligible; your HIPAA program still governs how you run it.

    Configuring Zoom for a healthcare account

    Because the platform being eligible is not the same as your use being sound, a healthcare team should still set the account up deliberately. These are standard controls any communication tool handling PHI should have in place, configured on your side rather than assumed.

    • Session encryption, so a visit cannot be intercepted in transit.
    • Waiting rooms and passcodes, so only intended participants reach a patient session.
    • Role-based access and unique logins, so only the right staff can start or manage sessions, with an audit trail of who did what.

    Recording is the setting to watch most closely. A recorded telehealth visit is PHI, so where it is stored and who can reach it becomes part of your compliance posture. Decide whether visits are recorded at all, and if they are, keep the storage and access under your control. Many practices keep recording off unless there is a documented reason to keep it.

    What happens if a team uses Zoom for PHI without a BAA

    If a healthcare team runs telehealth visits or discusses patient information over a Zoom account with no executed BAA, the PHI shared in those sessions is handled without the written agreement HIPAA requires. That is a compliance gap, and depending on what was disclosed it can rise to a reportable breach, which is a determination your breach-assessment process has to make rather than an automatic conclusion.

    The exposure is easy to create by accident. A clinician uses a personal free Zoom account for a quick patient call. A practice pays for Pro but never selects the BAA at checkout. A team turns on cloud recording of visits before the agreement is in place. Each of these puts patient data on the platform without the contract HIPAA requires. The fix is always the same: get the BAA executed first, then use the tool.

    How to use Zoom in a HIPAA-aligned way

    Once you are on an eligible plan with a signed BAA, treat Zoom as one controlled tool inside your HIPAA program rather than a finished compliance solution. A short routine keeps the everyday use sound.

    • Execute the BAA before any PHI touches the platform. This is step one, not step ten.
    • Confirm the account controls above are configured and that staff know to use them.
    • Keep meeting access tight, so links and passcodes are not shared beyond the intended participants.
    • Govern recordings on purpose, with a clear rule for whether and where visits are stored.
    • Review access periodically, removing people who no longer need it and checking the audit trail.

    None of this is exotic, but all of it is the customer's responsibility. The BAA commits Zoom to its safeguards for the platform. It does not make Zoom accountable for how your team configures and runs it.

    If you have already used Zoom for PHI without a BAA

    If patient information has already gone through a Zoom account with no BAA in place, treat it as a potential incident rather than something to quietly move past. Get an eligible plan and execute the BAA now so future sessions are covered. Then work with your compliance lead or counsel to assess what was disclosed and follow your breach-assessment process. Document the timeline and the remediation steps you take. Acting early and on the record is far better than discovering the gap during an audit.

    How CloudNSite builds HIPAA-ready systems for healthcare teams

    Zoom is a video platform, and getting it right is one piece of a larger picture. The harder problem for most practices is everything around the visit, from intake and records to the AI tools a team wants to run on patient data without sending PHI somewhere it should not go.

    That is the work we do. CloudNSite builds AI systems for healthcare teams on infrastructure that keeps PHI inside a boundary you control, with the BAAs and access controls in place before anything goes live. If you are evaluating where AI can fit in a regulated practice, start with our HIPAA-compliant AI solution and our healthcare AI consulting. For the wider tool question, our guide to HIPAA compliant AI tools covers what to check before you trust any vendor with patient data.

    FAQs

    Is the free version of Zoom HIPAA compliant? No. Zoom's documentation lists paid plans for healthcare customers, and free and Basic accounts are not among them. You cannot use a free Zoom account for protected health information.

    Does Zoom sign a BAA? Yes, on eligible paid plans. Zoom states that it executes a Business Associate Agreement to help customers enable HIPAA compliant programs. On a Pro plan the BAA can be accepted online at checkout; a Business or Enterprise plan arranges it through the standard process. It is never automatic.

    Is Zoom for telehealth HIPAA compliant? It can support telehealth. Visits are HIPAA-aligned when they run on an eligible paid plan with an executed BAA and your organization runs the account inside its own HIPAA program. The plan and the BAA come first, and the rest of your safeguards still apply.

    Can you record a telehealth visit on Zoom? Yes, but a recording of a visit is PHI. On an eligible plan with a BAA you can record, and you are responsible for where the recording is stored and who can reach it. Many practices keep recording off unless there is a documented reason to keep it.

    Does Zoom encrypt healthcare meetings? Zoom provides meeting encryption and, per its own documentation, aligns its controls to the HITRUST CSF healthcare security framework. Under HIPAA, encryption is an addressable specification rather than a flat requirement, so it protects the session while your risk assessment and the BAA cover the rest of what HIPAA expects.

    Is Claude AI HIPAA compliant? Claude can be used with PHI only under a BAA, which Anthropic offers for its commercial HIPAA-eligible services such as Claude Enterprise (with HIPAA activated) and the HIPAA-Ready API. The consumer plans (Free, Pro, Max) are not covered. Even under the BAA some endpoints are excluded, including the Batch API and Web Fetch. As with Zoom, the BAA and the correct configuration are what make it usable for patient data.

    Who is responsible if PHI is exposed on Zoom? Responsibility is shared. Zoom is committed under the BAA to the platform safeguards, and the covered entity is accountable for how the account is configured and used. A signed BAA does not move deployment mistakes onto Zoom.

    Related HIPAA vendor checks

    See these vendor checks for BAA and HIPAA details:

    Sources

    LET'S BUILD

    Need Help with Healthcare AI?

    Our team can help you implement the strategies discussed in this article.