Zoom can support HIPAA compliance, but only under specific conditions: your organization is on an eligible paid plan, Zoom has signed a business associate agreement (BAA) with you, and the account is configured with the right security settings. The free consumer version of Zoom does not come with a BAA and is not appropriate for protected health information (PHI). That distinction is the whole answer in miniature: no software product is HIPAA compliant by itself; compliance depends on the BAA, the safeguards, and how your team actually uses the tool. This article is general information, not legal advice.

Key takeaways:

  • Zoom offers a BAA to healthcare customers on qualifying paid plans, which is the non-negotiable starting point for using it with PHI.
  • The free consumer version of Zoom has no BAA and should never be used for patient care conversations.
  • A signed BAA covers Zoom's obligations, not yours: meeting settings, authentication, recording policies, and staff behavior remain your responsibility.
  • Configuration matters as much as the contract: waiting rooms, passcodes, and disciplined use of chat and recording are what keep sessions defensible.
  • Video visits work best alongside a compliant SMS channel for reminders, intake, and follow-up, since most telehealth no-shows and drop-offs happen around the visit, not during it.

The direct answer, unpacked

The question "is Zoom HIPAA compliant" assumes compliance is a property a product either has or lacks. HIPAA does not work that way. The law, administered by the Department of Health and Human Services and published at HHS.gov, places obligations on covered entities and their business associates. A vendor becomes part of your compliance picture when it signs a BAA and provides safeguards; your organization completes the picture through configuration, policy, and training.

Applied to Zoom, the conditions look like this:

  1. Eligible plan. Zoom makes its BAA available to organizations on qualifying paid offerings, including its healthcare-oriented plans. Consumer and free accounts are excluded.
  2. Signed BAA. The agreement must actually be executed between your organization and Zoom before PHI is discussed on the platform, not merely available somewhere in the terms.
  3. Correct configuration. Zoom exposes security controls; it is on your organization to turn them on and use them consistently.

Meet all three and Zoom can be a legitimate part of a HIPAA-supported telehealth program. Miss any one and every video visit is exposure.

What Zoom offers healthcare organizations

Described factually, per Zoom's public documentation, the platform provides healthcare customers on qualifying plans with a set of capabilities relevant to HIPAA's Security Rule:

  • BAA availability. Zoom will execute a business associate agreement with qualifying accounts, accepting the business associate obligations HIPAA defines.
  • Encryption. Zoom encrypts meeting traffic in transit and offers additional encryption options for meetings on eligible plans. Your compliance review should confirm the current specifics for the plan you buy, since offerings evolve.
  • Access and meeting controls. Passcodes, waiting rooms, authentication requirements, locked meetings, and host controls over screen sharing and participants.
  • Administrative controls. Account-level policies that let an administrator enforce settings across all users rather than trusting each clinician to configure their own meetings.
  • Audit and reporting features. Account activity reporting that supports the kind of oversight the Security Rule expects.

None of this is unusual among major vendors, and that is the point: Zoom is a capable, widely used platform that can be operated in a HIPAA-supported way. The work is in operating it that way.

What a BAA does and does not cover

The BAA is necessary and widely misunderstood, so it is worth being precise.

What it does:

  • Obligates Zoom to implement safeguards for the PHI it handles on your behalf.
  • Requires breach notification to your organization when incidents occur on their side.
  • Limits Zoom's permitted uses of PHI and flows obligations to subcontractors.

What it does not do:

  • It does not configure your account. A signed BAA with waiting rooms disabled and recordings syncing to a personal laptop is a false sense of security.
  • It does not cover behavior. A clinician taking a video visit from a coffee shop on speaker, or pasting clinical details into a group chat, is outside anything the contract can fix.
  • It does not extend to unapproved uses or personal accounts. A provider who falls back to a free personal account when the corporate one glitches has left the BAA's coverage entirely.
  • It does not make you compliant. It is one leg of the stool: contract, safeguards, and usage together support compliance.

Configuration responsibilities that fall on the practice

If your organization signs the BAA and stops there, the riskiest part of the job is still undone. A defensible Zoom deployment for care conversations typically includes:

  • Waiting rooms on, always. The host admits each participant deliberately, which prevents the wrong patient from joining early and hearing another patient's session.
  • Unique meetings and passcodes. No reused personal meeting rooms for patient visits; every appointment gets its own protected session.
  • Authentication and access control. Clinician accounts protected with strong authentication, centrally managed, and deprovisioned the day someone leaves.
  • Recording discipline. Decide whether visits are recorded at all; if they are, recordings must land in controlled, encrypted storage with access limits, never on personal devices. Many practices simply disable recording for clinical visits.
  • Minimal PHI in chat. In-meeting chat is easy to overlook. Keep clinical substance out of it, and clear or disable chat saving for patient sessions.
  • Screen sharing hygiene. Hosts control sharing, and clinicians close records and inboxes before sharing anything.
  • Account-level enforcement. Set these policies at the admin level so they are defaults, not suggestions.

Then write it down: a telehealth policy covering approved accounts, prohibited personal-account use, environment expectations (private rooms, headphones), and incident reporting. Training closes the loop. If you are still comparing vendors, our overview of HIPAA-compliant telehealth platforms walks through how to evaluate the field, and the same BAA-plus-configuration test applies to every product on it.

Where SMS fits alongside telehealth video

A video platform handles the visit itself. Almost everything around the visit (scheduling, reminders, intake, technical instructions, follow-up) happens best over text, because text is the channel patients reliably read.

A practical division of labor:

  • Before the visit: text confirmations and reminders with the date, time, and join link; a reply-to-reschedule option; and a short tech check ("find a quiet spot, and use headphones if you can"). This is where telehealth programs win or lose their no-show battle.
  • Around intake: a text link to forms and consent documents so the visit starts on time instead of with paperwork.
  • After the visit: a follow-up check-in, care instructions delivered through a secure link where needed, and a prompt to schedule the next appointment.
  • Ongoing: two-way texting for logistics questions, with routine confirmations handled automatically. On FRANSiS, the AI Powered Helper answers the routine "how do I join" and "can I move my appointment" messages and hands anything clinical to staff.

The same compliance logic governs the texting side: a platform with a signed BAA, encryption in transit (TLS 1.3) and at rest (256-bit AES), audit logs, and minimal-necessary message content. That is exactly what FRANSiS provides for care teams; the details are on our HIPAA-compliant text messaging page. Video and SMS are not competitors; a telehealth program without a compliant text layer is a program with an attendance problem.

A decision checklist for your organization

Before running patient visits on Zoom (or any video platform), confirm:

  1. We are on a plan eligible for a BAA, and the BAA is signed and on file.
  2. No clinician uses a free or personal account for anything patient-related.
  3. Waiting rooms, passcodes, and unique meeting links are enforced at the account level.
  4. Recording is disabled for clinical visits, or recordings flow only to controlled, encrypted storage.
  5. Chat use in patient sessions is restricted and understood by staff.
  6. Access is centrally managed, with strong authentication and same-day deprovisioning.
  7. A written telehealth policy exists and every clinician has been trained on it.
  8. Patient communication around visits (reminders, intake, follow-up) runs through a channel with the same compliance posture, including a signed BAA.
  9. We have documented patient consent for telehealth and for text communications, and we honor opt-outs immediately.
  10. We periodically re-review vendor documentation, since plans and features change.

If any item is unchecked, that item is your next project, and most of them cost configuration time rather than money.

Frequently asked questions

Is the free version of Zoom HIPAA compliant?

No. The free consumer version does not include a BAA, so it cannot be used for PHI regardless of how carefully meetings are configured. Only qualifying paid plans with an executed BAA, correctly configured, can support HIPAA compliance for patient care.

Does signing a BAA make Zoom HIPAA compliant for my practice?

The BAA is necessary but not sufficient. It covers Zoom's obligations for the PHI it handles; your practice remains responsible for meeting settings, authentication, recording policies, staff training, and appropriate use. Compliance is the combination of contract, configuration, and behavior.

Can I use Zoom for therapy or behavioral health sessions?

Yes, under the same conditions: an eligible paid plan, a signed BAA, and strict configuration. Behavioral health raises the stakes on privacy, so waiting rooms, private clinician environments, disabled recording, and neutral calendar and reminder language (avoiding sender names or wording that implies a diagnosis) deserve extra attention.

Is Zoom's chat feature safe for patient information?

Treat in-meeting chat cautiously. Even on a BAA-covered account, chat is easy to save, forward, or leave behind on a shared device, so keep clinical substance out of it and manage chat-saving settings centrally. Use the visit itself for clinical discussion and a compliant messaging platform for anything that must be written down.

What should we use for patient reminders and follow-up around Zoom visits?

Use a texting platform with the same compliance posture as your video tool: signed BAA, encryption in transit and at rest, audit logs, and consent management. Text reminders with join links reduce telehealth no-shows, and post-visit texts keep follow-up on track without pulling staff onto the phones.

Conclusion

Zoom can absolutely be part of a HIPAA-supported telehealth program: get on an eligible paid plan, execute the BAA, lock down the configuration, and train the people. What it cannot be is compliant out of the box, and the free version cannot be part of patient care at all. Judge Zoom (and every vendor) by the same three-part test: contract, safeguards, and how your team actually uses it. Then finish the job by giving the visit a compliant communication layer around it, because the visit is only as good as the patient's odds of showing up.

Building a telehealth program patients actually attend? FRANSiS adds the HIPAA-supported SMS layer, with a signed BAA included, for reminders, intake, and follow-up around your video visits. Talk to the FRANSiS team to see how it fits your workflow.