Vendor compliance profile
Is Zoom HIPAA compliant?
Zoom may support HIPAA-regulated meetings and communications only after the customer enters Zoom's BAA and verifies that the selected plan, products, account settings, AI features, recordings, chat, phone, integrations, and support paths fit the intended PHI workflow. Zoom does not provide a blanket HIPAA certification.
Direct compliance answer
Zoom HIPAA, BAA, PHI, and SOC 2 snapshot
Last checked: 2026-08-28 | Confidence: High
| Direct answer | Zoom may support HIPAA-regulated meetings and communications only after the customer enters Zoom's BAA and verifies that the selected plan, products, account settings, AI features, recordings, chat, phone, integrations, and support paths fit the intended PHI workflow. Zoom does not provide a blanket HIPAA certification. |
|---|---|
| BAA availability | Zoom says a standard BAA is available and documents activation paths for eligible paid plans. Verify that the executed BAA covers the account, plan, products, and features used by the organization. |
| Can it handle PHI? | Meeting titles, invitations, participant names, chat, recordings, transcripts, polls, whiteboards, AI summaries, support cases, and integrations can contain PHI. |
| SOC 2 caveat | Zoom states that it makes SOC 2 + HITRUST evidence available for healthcare customer review. Obtain the current report and verify its period, systems, exceptions, and product scope. |
| What to verify | Whether the Zoom BAA is active for the exact account, paid plan, organization, and products used. Which meeting, phone, chat, recording, transcript, whiteboard, AI, support, and storage features are covered or restricted. |
HIPAA status signal
Conditional
BAA public signal
Standard BAA available
SOC 2 evidence signal
SOC 2 + HITRUST evidence
PHI warning: Meeting titles, invitations, participant names, chat, recordings, transcripts, polls, whiteboards, AI summaries, support cases, and integrations can contain PHI.
Search query answers
Is Zoom HIPAA compliant?
Zoom can help eligible customers support HIPAA-regulated workflows under a Zoom Business Associate Agreement, but the result is conditional. Buyers still need to verify the exact paid plan, covered products, account settings, recordings, chat, phone, AI features, integrations, and user practices.
Will Zoom sign a BAA?
Zoom's current support and trust materials say it offers a standard BAA. The available activation path depends on the customer's plan and purchasing route, so confirm the agreement is effective for the exact account before PHI enters Zoom.
Can Zoom meetings contain PHI?
Potentially, but only inside an approved BAA-scoped workflow. Review meeting titles, invitations, chat, recordings, transcripts, whiteboards, polls, AI features, support access, cloud storage, and every connected calendar or application.
Does Zoom SOC 2 or HITRUST evidence prove HIPAA compliance?
No. Zoom's SOC 2 and HITRUST evidence can support security diligence, but HIPAA use still depends on the BAA, covered service scope, configuration, policies, workforce controls, and the exact PHI workflow.
HIPAA, BAA, and SOC 2 summary
| HIPAA | Zoom says it helps customers enable HIPAA-compliant programs by executing a BAA and safeguarding PHI. This is a conditional vendor capability, not a regulatory certification or approval of every Zoom product and customer workflow. |
|---|---|
| BAA | Zoom says a standard BAA is available and documents activation paths for eligible paid plans. Verify that the executed BAA covers the account, plan, products, and features used by the organization. |
| SOC 2 | Zoom states that it makes SOC 2 + HITRUST evidence available for healthcare customer review. Obtain the current report and verify its period, systems, exceptions, and product scope. |
| PHI risk | Meeting titles, invitations, participant names, chat, recordings, transcripts, polls, whiteboards, AI summaries, support cases, and integrations can contain PHI. |
| Category | HIPAA-Compliant Calendar and Scheduling Software |
| Last checked | 2026-08-28 |
| Confidence | High |
Public evidence and open questions
What public sources say
- Zoom's Security and Compliance FAQ says Zoom offers a standard BAA when customers require one.
- Zoom's BAA support article documents BAA activation paths for healthcare customers and eligible paid plans.
- Zoom says some AI features may be unavailable to customers with a BAA, so feature-level review remains necessary.
What remains unconfirmed
- Whether the buyer's exact Zoom plan, Meetings, Phone, Team Chat, Contact Center, recordings, transcripts, AI features, and support path are covered.
- Whether calendar, EHR, CRM, storage, analytics, and marketplace integrations keep PHI inside separately approved systems.
What it may be used for
- Healthcare video or communication workflows after the Zoom BAA is effective and covered products and settings are verified.
- PHI-minimized appointment and collaboration workflows with controlled invitations, recordings, chat, AI, and integrations.
- Vendor review when comparing Zoom with healthcare-specific telehealth or communication platforms.
What not to use it for
- Discussing or recording PHI before the BAA and exact product scope are confirmed for the account.
- Allowing PHI into unsupported AI features, calendar invitations, ordinary notifications, marketplace apps, or unreviewed integrations.
- Treating a paid Zoom account, encryption, SOC 2, or HITRUST evidence as automatic HIPAA approval.
What to verify with the vendor
- Whether the Zoom BAA is active for the exact account, paid plan, organization, and products used.
- Which meeting, phone, chat, recording, transcript, whiteboard, AI, support, and storage features are covered or restricted.
- Whether waiting rooms, authentication, encryption, recording, retention, access, audit, and deletion settings meet the intended workflow.
- Whether calendars, EHRs, CRMs, cloud storage, email notifications, apps, and APIs have appropriate separate coverage.
Safer alternatives and related profiles
Safer alternatives to consider
- A healthcare-specific telehealth platform when clinical workflows, patient intake, consent, documentation, and EHR integration need a single covered environment.
- Microsoft Teams only after Microsoft BAA scope, tenant configuration, recordings, chat, Copilot, and connected Microsoft 365 services are reviewed.
- A PHI-minimized Zoom workflow that keeps clinical details out of invitations, ordinary notifications, and unsupported features.
FAQ
Is Zoom HIPAA compliant?
Zoom can help eligible customers support HIPAA-regulated workflows under a Zoom Business Associate Agreement, but the result is conditional. Buyers still need to verify the exact paid plan, covered products, account settings, recordings, chat, phone, AI features, integrations, and user practices.
Will Zoom sign a BAA?
Zoom's current support and trust materials say it offers a standard BAA. The available activation path depends on the customer's plan and purchasing route, so confirm the agreement is effective for the exact account before PHI enters Zoom.
Can Zoom meetings contain PHI?
Potentially, but only inside an approved BAA-scoped workflow. Review meeting titles, invitations, chat, recordings, transcripts, whiteboards, polls, AI features, support access, cloud storage, and every connected calendar or application.
Does Zoom SOC 2 or HITRUST evidence prove HIPAA compliance?
No. Zoom's SOC 2 and HITRUST evidence can support security diligence, but HIPAA use still depends on the BAA, covered service scope, configuration, policies, workforce controls, and the exact PHI workflow.
Can Zoom be used with PHI?
Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.
Does SOC 2 mean Zoom is HIPAA compliant?
No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.
What should buyers verify before using Zoom with PHI?
Whether the Zoom BAA is active for the exact account, paid plan, organization, and products used. Which meeting, phone, chat, recording, transcript, whiteboard, AI, support, and storage features are covered or restricted. Whether waiting rooms, authentication, encryption, recording, retention, access, audit, and deletion settings meet the intended workflow. Whether calendars, EHRs, CRMs, cloud storage, email notifications, apps, and APIs have appropriate separate coverage.
Last checked and source notes
- Last checked
- 2026-08-28
- Confidence
- High
- Dataset rows
- 274 vendors
- Reviewed Zoom's current Security and Compliance FAQ, HIPAA readiness page, and BAA support article on 2026-08-28.
- Zoom's public BAA article describes plan and activation paths but does not approve a customer's configuration or workflow.
- ComplySaaS did not inspect a private Zoom agreement, account configuration, or current non-public audit report.
- Zoom: HIPAA Business Associate Agreement
- Zoom Security and Compliance FAQ
- Zoom: Health data and HIPAA readiness