Bask Health | Blog
  • Home

  • Plans & Pricing

  • Enterprise

  • Explore

  • Bask Health - Home
  • Home

  • Plans & Pricing

  • Enterprise

  • Explore

  • Bask Health - Home
  • Home

  • Plans & Pricing

  • Enterprise

  • Explore

Bask Health - Home
Theme
    Bask Health logo
    Company
    About
    Blog
    Team
    Security
    Product
    Bask

    Telehealth Engine

    Virtual Care
    API Reference
    Solutions
    Website Builder
    Payment Processing
    Patient’s Management
    EMR & E-Prescribing
    Pharmacy Fulfillment
    Compounding
    Developers
    Integrations
    Docs
    Help Guide
    Changelog
    Legal
    Terms of Service
    Privacy Policy
    Do Not Sell My Information
    LegitScript approved

    Legit Script

    HIPAA Compliant

    Surescripts

    © 2024 Bask Health, Inc. All rights reserved.

    Is Zoom HIPAA Compliant? It Depends on the Account You Use
    HIPAA compliance
    Telehealth Software
    Video Visits

    Is Zoom HIPAA Compliant? It Depends on the Account You Use

    Zoom can be HIPAA-compliant only with a signed BAA. See what Zoom for Healthcare covers and what telehealth teams still have to own.

    Bask Health Team
    Bask Health Team
    09/30/2026
    09/30/2026

    Is Zoom HIPAA compliant? The short answer is that Zoom can be used in a HIPAA-compliant way, but not by default and not on every account. Zoom states that Zoom for Healthcare "helps enable customers' HIPAA compliance by executing a Business Associate Agreement (BAA)." Without that signed agreement, a standard or free Zoom account is not the right setup for patient visits.

    The wording matters. Zoom says it helps enable compliance. It does not say that using Zoom makes a practice compliant. HIPAA responsibility is shared: the vendor signs the BAA and protects its platform, and the provider or telehealth business configures the tool, controls access, and manages the patient information around each visit.

    This guide explains why the BAA decides the question, why the pandemic-era exception no longer applies, what your team still owns after signing, and where a video tool alone stops being enough for a telehealth business. For the full list of HIPAA requirements beyond video, see Bask's guide to HIPAA compliance in telehealth.

    Why the BAA Is the Deciding Factor

    Under HIPAA, a covered entity such as a medical practice or telehealth provider needs a Business Associate Agreement with vendors that create, receive, maintain, or transmit protected health information (PHI) on its behalf.

    The U.S. Department of Health and Human Services makes the line clear in its guidance on audio-only telehealth: a covered entity must enter into a BAA with a vendor that is "more than a mere conduit for PHI." HHS gives the example of an app that stores recordings or transcripts in the developer's cloud infrastructure. That vendor is handling PHI, so it is a business associate.

    A video platform fits that description in several ways. Depending on how it is used, it may:

    • Record sessions and store the recordings
    • Generate transcripts or captions
    • Keep in-meeting chat logs
    • Store meeting metadata that links patients to providers and times

    Any of these can put PHI in the vendor's systems. That is why the signed BAA, not the quality of the video, is what decides whether Zoom can be part of a HIPAA-compliant workflow.

    What the Conduit Exception Does and Does Not Cover

    HIPAA has a narrow exception for "conduits," such as a telephone company that only connects a call. HHS explains that a covered provider can hold an audio-only session over a regular phone line without a BAA when the telecom provider "does not create, receive, or maintain any PHI from the session and is only connecting the call."

    That exception is about transient transmission. A video platform with cloud recording, chat storage, or transcripts usually goes well beyond it, so telehealth teams should not rely on the conduit exception for video visits.

    The Pandemic Exception Is Over

    Much of the confusion about Zoom comes from 2020. During the COVID-19 public health emergency, the HHS Office for Civil Rights (OCR) announced it would not penalize providers for using "non-public facing" communication tools for telehealth in good faith, even without a BAA.

    That enforcement discretion has ended. According to HHS, it expired on May 11, 2023, and OCR's 90-day transition period ended at 11:59 p.m. on August 9, 2023.

    Many practices set up their video workflows during the emergency and never revisited them. If your team started using a standard Zoom account in 2020 and nothing has changed since, that setup was built for an exception that no longer exists.

    Regular Zoom vs. Zoom for Healthcare

    The practical difference comes down to the agreement and the account it covers.

    QuestionRegular Zoom accountZoom for Healthcare
    Does Zoom sign a BAA?NoYes, according to Zoom
    Intended for patient visits?NoYes
    Who configures settings?Your teamYour team, within the healthcare account
    Recordings and chatHandled under standard termsCovered by the BAA's terms
    Fit for telehealth with PHINot recommendedCan support HIPAA compliance when set up correctly

    Plan names, features, and pricing change over time, so confirm the current details directly with Zoom before choosing an account. The point that does not change: the BAA must be signed before PHI moves through the platform.

    What Your Team Still Has to Get Right

    A signed BAA is the starting line. The HIPAA Security Rule still expects your organization to put appropriate administrative, physical, and technical safeguards around the way you use the tool.

    Meeting Settings

    Review settings before the first patient visit:

    • Use waiting rooms or equivalent controls so patients are admitted one at a time
    • Require passcodes or unique meeting links
    • Decide who is allowed to record, if anyone
    • Confirm where recordings and transcripts are stored

    Account Access

    Most HIPAA problems come from people, not software.

    • Give accounts only to staff who need them
    • Turn on multi-factor authentication
    • Remove access promptly when someone leaves
    • Avoid shared logins so that activity can be traced to a person

    Recordings, Transcripts, and Chat

    The safest recording is often the one you never make. If your team does record:

    • Document why recordings are needed
    • Set a retention period and delete on schedule
    • Limit who can view or download files
    • Keep in-meeting chat free of details that belong in the medical record

    Everything Around the Call

    A BAA with Zoom covers Zoom. It does not cover the intake form a patient filled out before the visit, the notes a provider wrote afterward, the prescription that followed, or the payment link sent by email. Each of those tools needs its own review and, when it handles PHI, its own BAA. Bask's guide to HIPAA-compliant telehealth software walks through what to check for each one.

    Quick Check: Does Your Current Zoom Setup Need a Review?

    If you are not sure where your team stands, these questions usually surface the gaps in a few minutes:

    • Is there a signed BAA on file, and does it cover the account your providers actually use?
    • Did any provider start seeing patients on a personal or free account and never switch?
    • Are cloud recordings turned on, and does anyone know where they are stored?
    • Do former staff members still have active accounts?
    • Is multi-factor authentication required for every user?
    • Do providers share meeting links in a way that could let the wrong person join?
    • Are intake forms, notes, and payment links handled by tools that also have BAAs?

    A "no" or "not sure" on any of these is worth fixing before the next patient visit. None of them depends on Zoom's features. They depend on how your team sets up and maintains the account.

    Where Zoom Stops Being Enough for a Telehealth Business

    For a therapist or a small practice that already has an EHR, Zoom for Healthcare can cover the video piece well. A telehealth business has a longer chain.

    A single patient journey often includes:

    1.     A landing page and intake form

    2.     Eligibility or medical questionnaire

    3.     A video or asynchronous consultation

    4.     Clinical notes in an EMR

    5.     An e-prescription

    6.     Pharmacy fulfillment and shipping

    7.     Payment and, often, a recurring subscription

    8.     Follow-up messages and refills

    When each step runs on a different vendor, each one is another contract, another business associate relationship, another set of settings to audit, and another place data can leak. Messaging tools and CRMs are common gaps. Bask covers those in its articles on HIPAA-compliant CRMs and patient communication software. That is also why buyers increasingly look for independent assurance, such as a SOC 2 Type II report, from the platforms at the center of that chain.

    How Bask Health Handles Video Visits

    Bask Health approaches video as one step in the patient journey rather than a separate tool to bolt on.

    Bask's virtual clinic infrastructure supports synchronous care through video calls, chat, and secure online portals, plus asynchronous care for treatments that don't require a live visit. Those visits sit in the same platform as:

    •  EMR and e-prescribing
    • Pharmacy fulfillment
    • Payment processing
    • Integrated doctor networks, included on every plan
    • Customizable treatment pathways for Rx, OTC products, and medical devices

    On the security side, Bask maintains HIPAA and LegitScript compliance, SOC 2 Type II controls, multi-factor authentication, and audit logging. The Bask security page describes the safeguards behind that stack, including encryption at rest and in transit, access control, and system monitoring.

    More than 250 U.S. telehealth companies use Bask, and the platform has supported more than 10.5 million orders. For a brand that would otherwise stitch together a video tool, an EMR, a pharmacy, and a payment processor, that means fewer vendors to manage and fewer handoffs where PHI can slip through. Compare Bask plans to see which setup fits your model.

    FAQs

    Is the free version of Zoom HIPAA compliant?

    No. Zoom's BAA is tied to Zoom for Healthcare. A free or standard account without a signed BAA is not an appropriate setup for sessions that involve PHI.

    Does Zoom sign a BAA?

    Yes. Zoom states that Zoom for Healthcare "helps enable customers' HIPAA compliance by executing a Business Associate Agreement (BAA)." Confirm the current terms and eligible plans with Zoom before relying on it.

    Can therapists use Zoom for telehealth?

    Yes, when they use Zoom for Healthcare with a signed BAA and configure it properly. Therapists should also review recording settings carefully, since therapy session recordings can be especially sensitive.

    Do I need a BAA for phone-only telehealth?

    Not always. HHS explains that a regular phone company that only connects the call and does not create, receive, or maintain PHI can fall under the conduit exception. Apps that record, transcribe, or store call data are different and generally require a BAA.

    What is the difference between HIPAA compliant and HIPAA certified?

    There is no official HIPAA certification from the federal government. A vendor can support HIPAA compliance, for example by signing a BAA and maintaining safeguards, but compliance depends on how each organization uses the tool. Be cautious of any vendor that describes itself as "HIPAA certified."

    Conclusion

    So, is Zoom HIPAA compliant? It can be part of a HIPAA-compliant workflow when you use Zoom for Healthcare, sign the BAA, and configure the account with care. It isn't compliant by default, and a free or standard account isn't the right tool for patient visits.

    The bigger question for a telehealth business is what happens around the call. Every tool that touches PHI needs the same scrutiny, and every extra vendor adds another agreement to manage. The fewer places patient data has to travel, the easier it is to protect.

    References

    1.     U.S. Department of Health and Human Services. (2022). Guidance on HIPAA and audio-only telehealth. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-audio-telehealth/index.html

    2.     U.S. Department of Health and Human Services. (n.d.). HIPAA and telehealth. https://www.hhs.gov/hipaa/for-professionals/special-topics/telehealth/index.html

    3.     U.S. Department of Health and Human Services. (n.d.). Business associates. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html

    4.     Zoom. (n.d.). Zoom for Healthcare. https://www.zoom.com/en/industry/healthcare/

    This content is provided for general informational purposes only and does not constitute marketing, legal, financial, or medical advice. Always seek the guidance of a qualified professional before taking action. All information is provided “AS IS” without any representations or warranties, express or implied, regarding its accuracy, completeness, or currency.

    Schedule a Demo

    Talk to an expert about your data security needs. Discuss your requirements, learn about custom pricing, or request a product demo.

    Sales

    Speak to our sales team about plans, pricing, enterprise contracts, and more.