Last updated: March 2026
Is Zoom HIPAA Compliant?
Quick Answer
Yes, Zoom can be HIPAA compliant with a Healthcare plan, signed Business Associate Agreement, and proper security configuration. Zoom offers HIPAA-covered Business Associate Agreements for qualifying customers. You must configure encryption, disable recording by default, manage waiting rooms, and enforce strong authentication to meet compliance requirements.
Zoom Healthcare Plan & BAA Requirements
Healthcare Plan for HIPAA Compliance
Zoom offers a dedicated Healthcare plan with built-in HIPAA compliance features and automatic Business Associate Agreement inclusion. The Healthcare plan includes HIPAA BAA coverage, enterprise-grade security, and compliance monitoring tools. All healthcare organizations must use the Healthcare plan (not standard Pro/Business plans) for HIPAA compliance.
Business Associate Agreement
Healthcare plan subscribers automatically receive HIPAA Business Associate Agreement coverage. The BAA covers all Zoom services including Zoom Meetings, Zoom Phone, Zoom Webinars, and Zoom Chat. Verify that your account is on the Healthcare plan and confirm BAA coverage is active in your account settings.
Encryption & Security Settings
| Feature |
HIPAA Configuration |
| In-Meeting Encryption |
Enforced End-to-End Encryption (E2EE) for all medical consultations |
| Encryption In Transit |
TLS 1.2+ for all connections; enforced automatically |
| Encryption at Rest |
Zoom-managed encryption for all data; customer-managed keys available |
| Recording Storage |
Encrypt in cloud or local storage; auto-delete after 30-90 days |
| Keyserver Integration |
Enterprise customers can integrate third-party key management systems |
Encryption Best Practices
- Enable End-to-End Encryption (E2EE) for all patient consultations
- Disable screen sharing by default; enable only when necessary
- Disable in-meeting file transfers that could expose PHI
- Require 256-bit AES encryption at minimum
- Store recordings on encrypted, access-controlled cloud storage
Meeting Security & Access Controls
Pre-Meeting Controls
- Waiting Room: Enable mandatory waiting room; require meeting host to admit each participant
- Authentication: Require sign-in with organization account for all participants
- Meeting ID: Use random 9+ digit IDs; disable personal meeting ID for PHI sessions
- Scheduling: Keep meeting URL private; share only via secure channels
- Password Protection: Require strong meeting passwords for all sessions
During-Meeting Controls
- Host controls: disable participant video/audio until verified
- Disable file sharing unless medically necessary
- Disable screen sharing for participants other than provider
- Use In-Meeting Chat for non-sensitive communication only
- Record only with explicit consent from all participants
Recording Storage & Retention
Recording Configuration
Set all consultations to NOT record by default. Enable recording only when participant consent is obtained and documented. Store recordings in Zoom's secure cloud storage or local encrypted storage. Configure automatic deletion to comply with healthcare data retention policies (typically 30-90 days).
| Recording Type |
HIPAA Best Practice |
| Cloud Recording |
Store in Zoom cloud with encryption; set auto-delete to 30 days |
| Local Recording |
Save to encrypted drive only; password-protect file; delete after retention period |
| Dual Recording |
Avoid if possible; if required, encrypt both copies and track access |
| Recording Consent |
Obtain written consent; document provider and patient agreement |
User Authentication & Permissions
Account-Level Controls
- Single Sign-On (SSO): Implement SAML/OAuth with your identity provider
- Two-Factor Authentication: Require 2FA for all users; enforce at account level
- Strong Password Policy: Enforce minimum 12 characters with complexity
- Session Timeout: Set automatic logout after 30 minutes of inactivity
- IP Whitelisting: Restrict access to known provider locations (optional)
Role-Based Access
- Admin role: Limited to essential administrators only
- Host role: Clinical staff with training
- Participant role: Patients and support staff
- Disable web client if video/phone only required
Zoom Phone & Chat Compliance
Zoom Phone for Telehealth
Zoom Phone calls are HIPAA compliant on the Healthcare plan. Enable encryption, disable call recording by default, and configure call retention policies. Integrate with EHR systems for secure appointment routing. Train staff on secure call handling procedures.
Zoom Chat Security
Zoom Chat supports PHI when using the Healthcare plan and BAA. However, chat messages should be minimal and non-sensitive. Configure message retention to auto-delete after 30 days. Disable external chat with non-healthcare organizations. Use chat for appointment coordination only, not clinical details.
Compliance Monitoring & Audit
Account Activity Audit
- Review Zoom Admin audit logs monthly
- Monitor user additions, removals, and permission changes
- Track all recording activities and downloads
- Alert on failed authentication attempts
- Document all compliance reviews
HIPAA Compliance Checklist
Pre-Deployment Verification
✓ Healthcare plan subscription active
✓ HIPAA BAA signed and verified
✓ End-to-End Encryption enabled by default
✓ Waiting room enabled for all meetings
✓ Sign-in required for all participants
✓ Recording disabled by default
✓ Two-factor authentication enabled
✓ SSO integrated with identity provider
✓ Audit logging enabled
✓ User training completed and documented
Frequently Asked Questions
Can we use Zoom Pro/Business plan for patient consultations?
+
No. Zoom Pro and Business plans do not include HIPAA BAAs. You must use the Zoom Healthcare plan for any patient consultations involving PHI. Even a single consultation on a Pro plan violates HIPAA. Upgrade to Healthcare immediately if you're currently using standard plans.
Does Zoom End-to-End Encryption support group meetings?
+
Yes. Zoom E2EE now supports group meetings. However, some features like virtual backgrounds, cloud recording, and screen sharing may be limited with E2EE enabled. Enable E2EE for all patient consultations. For team meetings without PHI, standard encryption is acceptable.
How long should we retain Zoom recordings of patient consultations?
+
This depends on your organization's records retention policy and the state regulations. Most healthcare providers retain recording for 3-7 years to match medical record retention. Configure automatic deletion in Zoom to enforce your retention policy consistently. Document your retention schedule.
What about Zoom Webinars for patient education?
+
Zoom Webinars are HIPAA compliant on the Healthcare plan. However, they are designed for one-way broadcast. For interactive patient education, use Zoom Meetings instead. If using Webinars, disable recording unless educational content has no patient-specific PHI.
Verify Your Zoom Telehealth Setup is HIPAA Compliant
Medcurity provides Zoom Healthcare configuration audits to ensure proper BAA coverage, encryption settings, and security controls for patient consultations.
Schedule Your Zoom Audit