Medcurity Get Started
Last updated: March 2026

Is Zoom HIPAA Compliant?

Quick Answer

Yes, Zoom can be HIPAA compliant with a Healthcare plan, signed Business Associate Agreement, and proper security configuration. Zoom offers HIPAA-covered Business Associate Agreements for qualifying customers. You must configure encryption, disable recording by default, manage waiting rooms, and enforce strong authentication to meet compliance requirements.

Zoom Healthcare Plan & BAA Requirements

Healthcare Plan for HIPAA Compliance

Zoom offers a dedicated Healthcare plan with built-in HIPAA compliance features and automatic Business Associate Agreement inclusion. The Healthcare plan includes HIPAA BAA coverage, enterprise-grade security, and compliance monitoring tools. All healthcare organizations must use the Healthcare plan (not standard Pro/Business plans) for HIPAA compliance.

Business Associate Agreement

Healthcare plan subscribers automatically receive HIPAA Business Associate Agreement coverage. The BAA covers all Zoom services including Zoom Meetings, Zoom Phone, Zoom Webinars, and Zoom Chat. Verify that your account is on the Healthcare plan and confirm BAA coverage is active in your account settings.

Encryption & Security Settings

Feature HIPAA Configuration
In-Meeting Encryption Enforced End-to-End Encryption (E2EE) for all medical consultations
Encryption In Transit TLS 1.2+ for all connections; enforced automatically
Encryption at Rest Zoom-managed encryption for all data; customer-managed keys available
Recording Storage Encrypt in cloud or local storage; auto-delete after 30-90 days
Keyserver Integration Enterprise customers can integrate third-party key management systems

Encryption Best Practices

Meeting Security & Access Controls

Pre-Meeting Controls

During-Meeting Controls

Recording Storage & Retention

Recording Configuration

Set all consultations to NOT record by default. Enable recording only when participant consent is obtained and documented. Store recordings in Zoom's secure cloud storage or local encrypted storage. Configure automatic deletion to comply with healthcare data retention policies (typically 30-90 days).

Recording Type HIPAA Best Practice
Cloud Recording Store in Zoom cloud with encryption; set auto-delete to 30 days
Local Recording Save to encrypted drive only; password-protect file; delete after retention period
Dual Recording Avoid if possible; if required, encrypt both copies and track access
Recording Consent Obtain written consent; document provider and patient agreement

User Authentication & Permissions

Account-Level Controls

Role-Based Access

Zoom Phone & Chat Compliance

Zoom Phone for Telehealth

Zoom Phone calls are HIPAA compliant on the Healthcare plan. Enable encryption, disable call recording by default, and configure call retention policies. Integrate with EHR systems for secure appointment routing. Train staff on secure call handling procedures.

Zoom Chat Security

Zoom Chat supports PHI when using the Healthcare plan and BAA. However, chat messages should be minimal and non-sensitive. Configure message retention to auto-delete after 30 days. Disable external chat with non-healthcare organizations. Use chat for appointment coordination only, not clinical details.

Compliance Monitoring & Audit

Account Activity Audit

HIPAA Compliance Checklist

Pre-Deployment Verification

✓ Healthcare plan subscription active
✓ HIPAA BAA signed and verified
✓ End-to-End Encryption enabled by default
✓ Waiting room enabled for all meetings
✓ Sign-in required for all participants
✓ Recording disabled by default
✓ Two-factor authentication enabled
✓ SSO integrated with identity provider
✓ Audit logging enabled
✓ User training completed and documented

Frequently Asked Questions

Can we use Zoom Pro/Business plan for patient consultations? +
No. Zoom Pro and Business plans do not include HIPAA BAAs. You must use the Zoom Healthcare plan for any patient consultations involving PHI. Even a single consultation on a Pro plan violates HIPAA. Upgrade to Healthcare immediately if you're currently using standard plans.
Does Zoom End-to-End Encryption support group meetings? +
Yes. Zoom E2EE now supports group meetings. However, some features like virtual backgrounds, cloud recording, and screen sharing may be limited with E2EE enabled. Enable E2EE for all patient consultations. For team meetings without PHI, standard encryption is acceptable.
How long should we retain Zoom recordings of patient consultations? +
This depends on your organization's records retention policy and the state regulations. Most healthcare providers retain recording for 3-7 years to match medical record retention. Configure automatic deletion in Zoom to enforce your retention policy consistently. Document your retention schedule.
What about Zoom Webinars for patient education? +
Zoom Webinars are HIPAA compliant on the Healthcare plan. However, they are designed for one-way broadcast. For interactive patient education, use Zoom Meetings instead. If using Webinars, disable recording unless educational content has no patient-specific PHI.

Verify Your Zoom Telehealth Setup is HIPAA Compliant

Medcurity provides Zoom Healthcare configuration audits to ensure proper BAA coverage, encryption settings, and security controls for patient consultations.

Schedule Your Zoom Audit