Is Zoom HIPAA compliant in 2026? What telehealth operators must verify before scaling
Zoom is HIPAA compliant, but only when two conditions are both met: you are on an eligible paid plan and you have a signed Business Associate Agreement (BAA) with Zoom. Without both, any patient session transmitted over Zoom is unprotected under HIPAA, regardless of how the meeting is configured. The free tier cannot qualify at all. Upgrading to a paid plan without completing the BAA process still leaves your clinical sessions fully exposed.
Short answer: yes, but only under specific conditions
Zoom can support HIPAA-compliant telehealth sessions. Two gates must both be open: an eligible paid plan and a signed BAA naming Zoom as your business associate.
Most operators assume that paying for Zoom closes the compliance gap. It does not. The BAA is a separate legal agreement that establishes Zoom's obligations for handling protected health information (PHI). Until that agreement is signed and confirmed active, Zoom processes your session data as a general-purpose video platform, and the HIPAA protections simply do not apply.
There is a second layer most guides skip. Signing the BAA only makes you eligible for HIPAA-mode operation. You must then configure specific admin settings, or the agreement has no practical effect on your actual sessions.

Which Zoom plans are HIPAA compliant?
Plan-level eligibility determines your compliance starting point. The question "is Zoom HIPAA compliant" has a different answer depending on which tier you are running.
| Plan | BAA Available | E2EE Default | Cloud Recording Controls | Compliance-Ready |
|---|---|---|---|---|
| Free (Basic) | No | No | No | No |
| Pro | Yes (on request) | Optional | Limited | Conditional |
| Workplace | Yes (on request) | Optional | Yes | Conditional |
| Workplace for Healthcare | Yes (included) | Yes | Enhanced | Yes (with config) |
For current per-seat pricing on each tier, see Zoom's healthcare pricing page.
Is Zoom Free HIPAA compliant?
No. The free tier does not support BAA agreements, which makes any clinical use non-compliant by definition. There is no configuration path that changes this. PHI transmitted through a Zoom Free account is unprotected under the HIPAA Privacy Rule and Security Rule, regardless of any other meeting settings in place.
If any member of your clinical team is using Zoom's free tier for patient sessions, that is an active compliance violation. The platform simply lacks the legal framework required for covered entities.
Is Zoom Pro HIPAA compliant?
Zoom Pro is BAA-eligible, but it is not HIPAA compliant out of the box. You must manually request a BAA through the Zoom Admin portal and then enable the required admin settings before any HIPAA protections take effect. Many small practices ask whether Zoom Pro is HIPAA compliant because Pro is the entry-level paid tier, and operators assume upgrading from free resolves the compliance gap. It does not.
Pro gives you access to the admin dashboard, where you can manage encryption settings, recording controls, and waiting room configurations. Access to those controls matters. But without a signed BAA, those controls exist in a non-HIPAA context.
Is Zoom Workplace HIPAA compliant?
Zoom Workplace is BAA-eligible and is the practical compliance tier for most mid-size telehealth operations. The common mistake is treating plan eligibility as actual compliance. They are not the same thing.
After upgrading to Workplace, you still need to submit the BAA request through the admin portal, confirm the agreement is active, and then configure the mandatory admin settings. Skipping any of those steps leaves you exposed. An active Workplace subscription with no signed BAA is legally equivalent to running on the free plan from a PHI-protection standpoint.
Zoom Workplace for Healthcare vs. standard Workplace
Zoom Workplace for Healthcare is a dedicated clinical tier. E2EE is on by default, the BAA is part of the onboarding process rather than a separate request, and audit logging is more granular. These defaults reduce configuration risk in meaningful ways.
Standard Workplace places the full configuration burden on your admin team. The Healthcare tier builds more of the compliance baseline into the default state. For a telehealth operator running high session volume with limited IT support, that difference compounds quickly. The per-seat cost is higher, but compliance-related setup time and ongoing audit overhead are substantially lower.
Is Zoom HIPAA compliant across all plan tiers?
The common search "is zoom workplace pro hipaa compliant" points to a confusion that spans every tier: operators assume plan eligibility equals compliance. It does not. Whether you are on Pro, Workplace, or the Healthcare tier, a signed BAA and correct admin configuration remain required steps regardless of the plan name on your invoice.
How to sign a BAA with Zoom (step-by-step)
Here is how it works:
- Confirm plan eligibility. Log into Zoom Admin. You must be on Pro, Workplace, or Workplace for Healthcare. Free accounts cannot request a BAA.
- Locate the BAA request. Navigate to Admin > Account Management > Account Profile. Scroll to the "HIPAA Business Associate Agreement" section. This option is not visible on free accounts.
- Submit the request. Click "Request BAA" and complete the form. Zoom reviews and countersigns the agreement. Zoom does not publish a guaranteed turnaround for countersigning, so build the BAA step into your launch timeline rather than assuming same-day approval.
- Enable required settings. After confirmation, go to Admin > Account Settings and activate: end-to-end encryption, Waiting Room for all meetings, disable cloud recording auto-start, disable auto-transcription, and restrict third-party app access for meeting participants.
- Verify BAA status. Return to Account Profile and confirm the agreement status shows as "Active." A pending status means Zoom has not yet processed the request.
- Document the activation date. Record the BAA execution date in your compliance files. You will need this for any HIPAA audit or incident response.
- Re-verify after any plan change. If you upgrade or downgrade your Zoom plan, the BAA may require reconfirmation. Treat every plan change as a trigger to check BAA status.
With the BAA signed and settings locked, you have reached the compliance floor, not the growth engine. Every step above is the legal prerequisite for operating; it does not drive patient acquisition on its own.

Is Zoom HIPAA compliant for telehealth?
Yes, but telehealth creates PHI vectors that a standard meeting configuration does not automatically address. A telehealth session generates PHI beyond the video itself: chat messages, session metadata, cloud recordings, intake data, and post-visit summaries all qualify as PHI when they contain identifiable health information. Each data type requires its own control. The question "is zoom hipaa compliant telehealth" points to exactly this gap: the BAA covers the video session itself, but the PHI generated around that session requires additional controls that must be configured separately.
Waiting room and access controls
The Waiting Room must be enabled for every patient session. This is not a default on most plans. Without it, patients can join before the provider is present, and a host can accidentally admit the wrong participant. Both scenarios expose PHI.
Mandatory settings include requiring a password for every meeting, disabling the ability for participants to join before the host, and disabling any browser-based join options that bypass the Waiting Room. Meeting links reused across multiple patients are also a compliance risk, because a prior patient could rejoin using a saved link from an earlier session.
Cloud recording and PHI storage
Cloud recordings of patient sessions are PHI under the HIPAA Privacy Rule. If cloud recording is enabled by default on your account, every session is automatically stored in Zoom's cloud environment without any host action. Under a signed BAA, Zoom bears contractual responsibility for protecting those recordings. But your organization, as the covered entity, remains accountable for what is recorded, how long it is retained, and when it is deleted.
Disable cloud recording by default in Admin settings. If your clinical workflow requires recordings, enable it selectively at the host level and establish a documented retention and deletion policy. Local recordings move data custody to your own storage environment, which may simplify your audit trail but creates its own security obligations.
Intake forms and patient consent
Collecting PHI through native Zoom features creates compliance exposure the BAA alone does not resolve. Zoom's in-session chat, pre-meeting registration forms, and polling features are not purpose-built for clinical data. Data entered through those channels may not be handled under the same controls that govern the session video itself.
Written patient consent is required before recording any session. That consent must be documented in your clinical records system, not just captured verbally during the call. For building compliant pre-visit flows, the design of your telehealth platform's intake and booking experience matters as much as the session configuration itself.
5 configuration settings that determine compliance
Each setting below carries a specific compliance risk at its platform default. Verify all five in Admin > Account Settings after your BAA is confirmed active.
- End-to-end encryption (E2EE): Default is off on most plans. Without E2EE, Zoom's servers can technically decrypt session content in transit. Enable E2EE for all clinical meetings.
- Cloud recording auto-start: Default is on for many account types. Every session records automatically without any host action. Disable auto-start and restrict recording permissions to host-only.
- Auto-transcription: Default is enabled on Workplace plans. Transcripts of clinical sessions are PHI and can be emailed automatically to participants through an unencrypted channel. Disable auto-transcription unless your workflow specifically requires it and you have a compliant retention policy in place.
- Third-party app integrations: Marketplace apps can access meeting data, including session content. Each app requires its own BAA if it will handle PHI. Audit every connected app after the initial BAA signing.
- Meeting link reuse (Personal Meeting ID): Reused links allow prior session participants to rejoin future meetings. Disable the Personal Meeting ID for clinical sessions and generate a unique link per appointment.

HIPAA-compliant marketing on Zoom: what telehealth clinics must know
Every top-10 competitor skips this angle entirely. Using Zoom for telehealth creates a data environment that intersects directly with your paid media operations. That intersection is a compliance exposure most operators have not mapped.
Zoom session attendance data is PHI in a telehealth context. A patient who attended a virtual consultation has disclosed a health-seeking behavior. Feeding that attendance data into a Meta custom audience or a Google Customer Match list to retarget the patient is a HIPAA violation. The fact that the patient provided an email address for appointment scheduling does not constitute authorization to use that data for advertising purposes.
Before scaling paid acquisition alongside Zoom-based visits, verify that no clinical session data flows into your ad platforms. A compliant consent flow separates clinical data from marketing data at the point of collection and uses a consent management platform to govern what can move where. Whether your analytics stack is HIPAA compliant is a question that needs an answer before you connect any session data to your tracking infrastructure.
If your GA4 instance passes session identifiers to your CRM, and your CRM contains Zoom attendance data, the downstream audience logic may inadvertently build PHI-linked segments. This is where compliance breaks down in practice. Your compliant telehealth advertising strategies and your Zoom configuration must be designed together, not audited separately after a complaint.
Telehealth operators building paid acquisition alongside Zoom sessions need compliant tracking infrastructure in place before scaling spend. The tracking-first patient acquisition infrastructure that connects your Zoom compliance layer to your growth operations is what makes scaling sustainable rather than a series of retroactive fixes.
Common mistakes that break HIPAA compliance on Zoom
These are operator-level errors more specific than any "pitfalls" section in the current top-10:
- Cloud recording left on by default. The admin setting controls the default for all hosts. If you configured this during initial setup and changed plans since, the setting may have reverted. Re-verify after every plan change.
- Auto-transcription enabled account-wide. Transcripts can be emailed automatically to participants through an unencrypted channel. That creates a separate PHI exposure beyond the recording itself.
- Free plan in use by any clinical staff member. Individual providers on a team account may be on different plan tiers. Audit every seat that touches patient sessions.
- BAA not re-verified after a plan upgrade. Moving from Pro to Workplace, or adding seats, can interrupt BAA status on some accounts. The agreement does not transfer automatically.
- Third-party apps added without BAA review. Scheduling integrations, CRM connectors, and productivity tools in the Zoom marketplace access meeting data. Each app added after the initial BAA signing may not be covered by the original agreement.
Your telehealth stack is compliant. Is it built to acquire patients at scale?
Compliance is the floor, not the growth engine. Most telehealth operators spend weeks getting the Zoom BAA signed, settings configured, and clinical workflows documented. Then they activate paid media and discover that the compliance work and the growth infrastructure were never designed to connect.
The pattern that appears across telehealth audits is consistent: a compliant session platform, a pixel sending uncontrolled signals, a CRM receiving data from three sources with no reconciliation, and a reporting dashboard that cannot answer why CAC changed last month. Valhalla Vitality resolved this by building the acquisition system around the compliance layer from the start. The result was a 287% increase in monthly revenue and a 45% reduction in CAC.
Getting there starts with understanding where your current tracking, funnel, and PHI data flows have gaps. An end-to-end audit covers your Zoom configuration, pixel setup, CRM data flows, and paid media consent model as one connected system. Start an end-to-end acquisition audit to see what that process looks like for a telehealth operation at your scale.
FAQ
Does Zoom automatically sign a BAA with all paid accounts?
No. The BAA is a separate agreement that you must actively request through the Zoom Admin portal. Upgrading to a paid plan makes you eligible to request a BAA, but the agreement is not automatically executed. You must complete the request and confirm the status shows "Active" on your account before any HIPAA protections apply.
Is the free version of Zoom ever HIPAA compliant?
No. Zoom's free tier does not support BAA agreements, which means it cannot be used in any HIPAA-compliant configuration. There is no setting, add-on, or workaround that changes this. Using the free tier for patient sessions is an active HIPAA violation regardless of any other meeting settings in place.
Can Zoom recordings contain protected health information?
Yes. A cloud recording of a telehealth session is PHI under the HIPAA Privacy Rule because it captures identifiable health information. This applies to video recordings, audio recordings, and auto-generated transcripts. Under a signed BAA, Zoom bears contractual responsibility for securing those recordings, but your organization remains accountable for recording consent, retention periods, and deletion procedures.
Is Zoom HIPAA compliant for therapy sessions?
Yes, under the same two conditions that apply to all telehealth use: an eligible paid plan and a signed BAA. Therapy sessions introduce heightened sensitivity because the session content itself is highly specific PHI. Auto-transcription must be disabled, cloud recording requires documented patient consent before each session, and the Waiting Room must be enabled to prevent any unauthorized access to an active session.
What happens if you use Zoom without a signed BAA?
Using Zoom for patient sessions without a signed BAA means Zoom is processing PHI without the required business associate agreement. That is a direct HIPAA violation, and your organization bears the compliance liability. Penalties under HIPAA range from $100 to $50,000 per violation category, depending on the level of negligence and whether the violation was identified and corrected promptly after discovery.
Is Zoom HIPAA compliant? A summary for operators who need a definitive answer
When clinics and telehealth operators ask "is zoom hipaa compliant?" they are usually looking for a yes or no. The honest answer is conditional: Zoom supports HIPAA-compliant operation, but compliance is not a property of the platform, it is a property of your configuration. A signed BAA, an eligible paid plan, and verified admin settings are all required simultaneously.

