Vendor compliance profile

Is Zoom HIPAA compliant?

Zoom may support HIPAA-regulated meetings and communications only after the customer enters Zoom's BAA and verifies that the selected plan, products, account settings, AI features, recordings, chat, phone, integrations, and support paths fit the intended PHI workflow. Zoom does not provide a blanket HIPAA certification.

Reviewed by Evidence: Public first-party sourcesConfidence: High
Visit vendor site

Direct compliance answer

Zoom HIPAA, BAA, PHI, and SOC 2 snapshot

Last checked: 2026-08-28 | Confidence: High

Direct answerZoom may support HIPAA-regulated meetings and communications only after the customer enters Zoom's BAA and verifies that the selected plan, products, account settings, AI features, recordings, chat, phone, integrations, and support paths fit the intended PHI workflow. Zoom does not provide a blanket HIPAA certification.
BAA availabilityZoom says a standard BAA is available and documents activation paths for eligible paid plans. Verify that the executed BAA covers the account, plan, products, and features used by the organization.
Can it handle PHI?Meeting titles, invitations, participant names, chat, recordings, transcripts, polls, whiteboards, AI summaries, support cases, and integrations can contain PHI.
SOC 2 caveatZoom states that it makes SOC 2 + HITRUST evidence available for healthcare customer review. Obtain the current report and verify its period, systems, exceptions, and product scope.
What to verifyWhether the Zoom BAA is active for the exact account, paid plan, organization, and products used. Which meeting, phone, chat, recording, transcript, whiteboard, AI, support, and storage features are covered or restricted.

HIPAA status signal

Conditional

BAA public signal

Standard BAA available

SOC 2 evidence signal

SOC 2 + HITRUST evidence

PHI warning: Meeting titles, invitations, participant names, chat, recordings, transcripts, polls, whiteboards, AI summaries, support cases, and integrations can contain PHI.

Search query answers

Is Zoom HIPAA compliant?

Zoom can help eligible customers support HIPAA-regulated workflows under a Zoom Business Associate Agreement, but the result is conditional. Buyers still need to verify the exact paid plan, covered products, account settings, recordings, chat, phone, AI features, integrations, and user practices.

Will Zoom sign a BAA?

Zoom's current support and trust materials say it offers a standard BAA. The available activation path depends on the customer's plan and purchasing route, so confirm the agreement is effective for the exact account before PHI enters Zoom.

Can Zoom meetings contain PHI?

Potentially, but only inside an approved BAA-scoped workflow. Review meeting titles, invitations, chat, recordings, transcripts, whiteboards, polls, AI features, support access, cloud storage, and every connected calendar or application.

Does Zoom SOC 2 or HITRUST evidence prove HIPAA compliance?

No. Zoom's SOC 2 and HITRUST evidence can support security diligence, but HIPAA use still depends on the BAA, covered service scope, configuration, policies, workforce controls, and the exact PHI workflow.

HIPAA, BAA, and SOC 2 summary

HIPAAZoom says it helps customers enable HIPAA-compliant programs by executing a BAA and safeguarding PHI. This is a conditional vendor capability, not a regulatory certification or approval of every Zoom product and customer workflow.
BAAZoom says a standard BAA is available and documents activation paths for eligible paid plans. Verify that the executed BAA covers the account, plan, products, and features used by the organization.
SOC 2Zoom states that it makes SOC 2 + HITRUST evidence available for healthcare customer review. Obtain the current report and verify its period, systems, exceptions, and product scope.
PHI riskMeeting titles, invitations, participant names, chat, recordings, transcripts, polls, whiteboards, AI summaries, support cases, and integrations can contain PHI.
CategoryHIPAA-Compliant Calendar and Scheduling Software
Last checked2026-08-28
ConfidenceHigh

Public evidence and open questions

What public sources say

  • Zoom's Security and Compliance FAQ says Zoom offers a standard BAA when customers require one.
  • Zoom's BAA support article documents BAA activation paths for healthcare customers and eligible paid plans.
  • Zoom says some AI features may be unavailable to customers with a BAA, so feature-level review remains necessary.

What remains unconfirmed

  • Whether the buyer's exact Zoom plan, Meetings, Phone, Team Chat, Contact Center, recordings, transcripts, AI features, and support path are covered.
  • Whether calendar, EHR, CRM, storage, analytics, and marketplace integrations keep PHI inside separately approved systems.

What it may be used for

  • Healthcare video or communication workflows after the Zoom BAA is effective and covered products and settings are verified.
  • PHI-minimized appointment and collaboration workflows with controlled invitations, recordings, chat, AI, and integrations.
  • Vendor review when comparing Zoom with healthcare-specific telehealth or communication platforms.

What not to use it for

  • Discussing or recording PHI before the BAA and exact product scope are confirmed for the account.
  • Allowing PHI into unsupported AI features, calendar invitations, ordinary notifications, marketplace apps, or unreviewed integrations.
  • Treating a paid Zoom account, encryption, SOC 2, or HITRUST evidence as automatic HIPAA approval.

What to verify with the vendor

  • Whether the Zoom BAA is active for the exact account, paid plan, organization, and products used.
  • Which meeting, phone, chat, recording, transcript, whiteboard, AI, support, and storage features are covered or restricted.
  • Whether waiting rooms, authentication, encryption, recording, retention, access, audit, and deletion settings meet the intended workflow.
  • Whether calendars, EHRs, CRMs, cloud storage, email notifications, apps, and APIs have appropriate separate coverage.

Safer alternatives and related profiles

Safer alternatives to consider

  • A healthcare-specific telehealth platform when clinical workflows, patient intake, consent, documentation, and EHR integration need a single covered environment.
  • Microsoft Teams only after Microsoft BAA scope, tenant configuration, recordings, chat, Copilot, and connected Microsoft 365 services are reviewed.
  • A PHI-minimized Zoom workflow that keeps clinical details out of invitations, ordinary notifications, and unsupported features.

FAQ

Is Zoom HIPAA compliant?

Zoom can help eligible customers support HIPAA-regulated workflows under a Zoom Business Associate Agreement, but the result is conditional. Buyers still need to verify the exact paid plan, covered products, account settings, recordings, chat, phone, AI features, integrations, and user practices.

Will Zoom sign a BAA?

Zoom's current support and trust materials say it offers a standard BAA. The available activation path depends on the customer's plan and purchasing route, so confirm the agreement is effective for the exact account before PHI enters Zoom.

Can Zoom meetings contain PHI?

Potentially, but only inside an approved BAA-scoped workflow. Review meeting titles, invitations, chat, recordings, transcripts, whiteboards, polls, AI features, support access, cloud storage, and every connected calendar or application.

Does Zoom SOC 2 or HITRUST evidence prove HIPAA compliance?

No. Zoom's SOC 2 and HITRUST evidence can support security diligence, but HIPAA use still depends on the BAA, covered service scope, configuration, policies, workforce controls, and the exact PHI workflow.

Can Zoom be used with PHI?

Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.

Does SOC 2 mean Zoom is HIPAA compliant?

No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.

What should buyers verify before using Zoom with PHI?

Whether the Zoom BAA is active for the exact account, paid plan, organization, and products used. Which meeting, phone, chat, recording, transcript, whiteboard, AI, support, and storage features are covered or restricted. Whether waiting rooms, authentication, encryption, recording, retention, access, audit, and deletion settings meet the intended workflow. Whether calendars, EHRs, CRMs, cloud storage, email notifications, apps, and APIs have appropriate separate coverage.

Last checked and source notes

Last checked
2026-08-28
Confidence
High
Dataset rows
274 vendors