Is Most Video Conferencing Software HIPAA Compliant? What Healthcare Providers Must Know

Is most video conferencing software HIPAA compliant? Learn what makes a platform safe for telehealth and how to protect patient data. ✅

Is Most Video Conferencing Software HIPAA Compliant? What Healthcare Providers Must Know

A common misconception in healthcare is that most video conferencing software is HIPAA compliant simply because it encrypts calls or is marketed as "secure." In reality, HIPAA compliance for video conferencing is far more nuanced than basic encryption. The Health Insurance Portability and Accountability Act sets strict requirements for any technology used to transmit or store protected health information (PHI), and standard consumer-grade platforms often fall short of these obligations without specific configurations or contractual agreements in place.

Telehealth has exploded in popularity since 2020, with the American Medical Association reporting that more than 60 percent of physicians used some form of video visit in recent years. This rapid adoption brought platforms like Zoom, Microsoft Teams, Google Meet, and Doxy.me into clinical workflows almost overnight. However, the speed of adoption frequently outpaced careful evaluation of each platform's HIPAA readiness, leaving many practices unknowingly exposed to significant regulatory and financial risk.

Understanding what actually makes a video conferencing solution HIPAA compliant requires looking at three interconnected factors: the platform's technical safeguards, the Business Associate Agreement (BAA) that must be signed between the covered entity and the software vendor, and the administrative policies your organization maintains around its use. Missing any one of these pillars renders even the most technically sophisticated platform non-compliant in the eyes of the Office for Civil Rights (OCR).

The Business Associate Agreement is arguably the most critical and most overlooked requirement. Under HIPAA, any vendor who handles PHI on behalf of a covered entity is classified as a business associate and must sign a BAA before any PHI is transmitted through their system. Zoom, Microsoft, and a handful of other vendors offer BAAs, but only for specific paid tiers of service — free accounts almost universally exclude BAA eligibility, making their use in clinical settings a HIPAA violation regardless of encryption quality.

Technical safeguards go beyond simple call encryption. HIPAA requires end-to-end encryption for data in transit, access controls that limit who can join a session, automatic session timeout features, and audit logging that tracks who accessed what information and when. Many popular platforms offer these features but require administrators to explicitly enable them — the default settings on consumer-focused plans are often insufficient for healthcare use without deliberate configuration adjustments.

Administrative safeguards are the organizational backbone of any HIPAA-compliant video conferencing program. Your practice must have written policies that define which platforms are approved, who is authorized to conduct telehealth visits, how patient consent for video visits is obtained and documented, and what staff training on these protocols looks like. These policies must be reviewed regularly and updated when platforms change their terms of service or feature sets. Conducting hipaa compliant video conferencing risk analyses that include your telehealth tools is a regulatory requirement, not a best practice suggestion.

This guide will walk you through the landscape of HIPAA-compliant video conferencing: which platforms qualify, what questions to ask vendors, how to configure platforms correctly, and what your organization's internal policies must address. Whether you are a solo practitioner setting up your first telehealth workflow or a compliance officer auditing an enterprise telehealth program, understanding these requirements is essential to protecting both your patients and your organization.

HIPAA-Compliant Video Conferencing by the Numbers

💰$1.9MAverage HIPAA PenaltyFor breaches involving improper telehealth disclosures
📊60%+Physicians Using TelehealthAMA survey, post-2020 adoption surge
🛡️3Required Safeguard PillarsTechnical, physical, and administrative controls
⚠️$100–$50KPenalty Per ViolationTiered based on culpability and harm
🔄AnnualRequired Policy Review FrequencyMinimum interval for HIPAA risk analysis updates
Hipaa Compliant Video Conferencing - HIPAA - Health Insurance Portability and Accountability Act certification study resource

What HIPAA Actually Requires from Video Conferencing Platforms

📋Business Associate Agreement (BAA)

A signed BAA must exist between your organization and the video platform vendor before any PHI is transmitted. This legally binding contract obligates the vendor to protect PHI and report breaches. Without it, even a technically secure platform creates a HIPAA violation.

🔒End-to-End Encryption

All video and audio data containing PHI must be encrypted in transit using AES-256 or equivalent standards. Platforms must ensure that data is encrypted from the sender's device to the recipient's device, not just at the server level, to prevent interception.

🛡️Access Controls and Authentication

HIPAA requires that only authorized individuals can access sessions containing PHI. This means waiting rooms, unique meeting IDs, password protection, and host controls that can remove unauthorized participants are all necessary platform features for clinical use.

📊Audit Logs and Activity Tracking

Covered entities must be able to track who participated in a telehealth session, when it occurred, and what information was shared. Platforms must provide access logs that can be retained and reviewed during audits or breach investigations conducted by OCR.

🗂️Data Retention and Deletion Controls

If sessions are recorded, the platform must provide controls over where recordings are stored, who can access them, and how they are eventually deleted. Retention policies must align with HIPAA's minimum-necessary principle and applicable state medical record laws.

The Business Associate Agreement sits at the heart of every HIPAA-compliant video conferencing arrangement, yet it is frequently misunderstood or simply overlooked in the rush to deploy telehealth services. A BAA is a legally binding contract that establishes what a business associate — in this case, your video platform vendor — is permitted to do with PHI, what security measures they must implement, and what happens if a breach occurs. Without this document in place, your organization is in violation of HIPAA regardless of how securely the video calls themselves are conducted.

Most major platforms that offer BAAs require healthcare organizations to use paid, enterprise-level plans. Zoom's free tier explicitly excludes BAA eligibility and lacks several required administrative controls. Zoom for Healthcare, by contrast, includes a BAA, waiting room functionality, end-to-end encryption options, and cloud recording controls that meet HIPAA standards when properly configured. The distinction between a platform's consumer and healthcare offerings is almost always where compliance or non-compliance is determined.

Microsoft Teams offers a BAA through its Microsoft 365 and Office 365 business and enterprise plans, but not through personal or family subscriptions. Microsoft's BAA covers Teams video calls, but only when the organization has configured the appropriate security and compliance settings within its Microsoft 365 tenant. This includes enabling audit logging, configuring data retention policies through the Microsoft Purview compliance center, and ensuring that guest access settings do not allow unauthorized parties into protected sessions.

Google Meet occupies a similar position. Google Workspace for Healthcare includes a BAA and offers enhanced security controls appropriate for HIPAA use. Standard Google accounts — even paid Workspace plans below the enterprise tier — may not include the same BAA provisions. Healthcare organizations must verify their specific Google Workspace agreement to confirm BAA coverage before using Meet for any telehealth purpose involving PHI, including scheduling discussions or clinical consultation calls.

Purpose-built telehealth platforms like Doxy.me, Teladoc Health, and Updox are designed from the ground up for healthcare use and offer BAAs as a standard feature of their service agreements. These platforms typically include waiting room functionality, no-download patient interfaces, session time limits, and audit logging as core features rather than add-ons. For practices that want to minimize compliance configuration burden, purpose-built solutions often provide a more straightforward path to HIPAA compliance than adapting general-purpose conferencing tools.

When evaluating any vendor's BAA, pay close attention to the breach notification provisions. HIPAA requires business associates to notify covered entities of breaches without unreasonable delay and within 60 days of discovery. Some vendor BAAs include language that narrows the definition of a reportable incident or places additional notification burdens on the covered entity. Legal review of the BAA before execution is strongly recommended, particularly for larger organizations or those operating in multiple states with their own health data privacy laws.

It is also worth noting that a BAA alone does not create compliance — it creates a legal framework within which compliance is possible. The covered entity still bears responsibility for configuring the platform according to its security policies, training staff on proper use, and conducting regular risk analyses that include the video conferencing tool. Signing a BAA and then using the platform without proper configuration or training is a compliance failure, even though the contractual obligation is technically met.

Free HIPAA Compliance Questions and Answers

Test your knowledge of HIPAA rules, BAAs, and telehealth compliance requirements

Free HIPAA Medical Information Questions and Answers

Practice questions covering PHI definitions, patient rights, and medical data protection rules

HIPAA Compliant Video Conferencing: Platform Deep Dives

Zoom for Healthcare is a HIPAA-eligible version of the standard Zoom platform available through paid business and enterprise plans. It includes a signed BAA, end-to-end encryption options, waiting room functionality, and cloud recording controls. Organizations must actively configure these features — enabling E2E encryption, requiring waiting rooms, and restricting recording permissions — because default settings do not automatically satisfy HIPAA's technical safeguard requirements without administrator intervention.

One important limitation: Zoom's end-to-end encryption mode disables certain features including cloud recording, live transcription, and some third-party integrations. Healthcare organizations must decide whether the added security of E2E encryption outweighs these feature limitations for their specific telehealth workflows. For most clinical video visits, the tradeoff favors enabling E2E encryption and using alternative documentation methods rather than relying on built-in transcription tools that require server-side processing.

Hipaa Compliant Video Conferencing - HIPAA - Health Insurance Portability and Accountability Act certification study resource

General-Purpose vs. Healthcare-Specific Video Platforms: Pros and Cons

Pros
  • +General-purpose platforms (Zoom, Teams) are already familiar to most patients and staff, reducing onboarding friction
  • +Enterprise plans from major vendors often include broad compliance ecosystems covering email, storage, and video under one BAA
  • +General-purpose platforms frequently receive faster feature updates and have larger developer ecosystems for integrations
  • +Purpose-built telehealth platforms include BAAs as standard, eliminating negotiation and legal review overhead
  • +Healthcare-specific platforms are designed with clinical workflows in mind, including waiting rooms, no-download patient links, and session limits
  • +Purpose-built solutions often provide dedicated HIPAA compliance support and documentation to assist with audits and risk analyses
Cons
  • General-purpose platforms require significant configuration to meet HIPAA requirements — defaults are rarely compliant out of the box
  • BAA availability for general-purpose platforms is often restricted to expensive enterprise tiers, excluding small practices
  • Feature updates on general-purpose platforms can inadvertently change compliance-relevant settings, requiring ongoing administrator vigilance
  • Purpose-built telehealth platforms may lack integrations with non-healthcare business tools your organization also uses
  • Some healthcare-specific platforms have limited participant capacity or session length restrictions on lower-cost plans
  • Vendor lock-in risk is higher with purpose-built platforms, as migrating patient records and session histories can be complex and costly

HIPAA Administrative Safeguards 2

Practice questions on workforce training, contingency planning, and access management policies

HIPAA Administrative Safeguards 3

Deepen your understanding of HIPAA's organizational requirements and security officer roles

HIPAA-Compliant Video Conferencing Setup Checklist

  • Confirm your video platform vendor offers a Business Associate Agreement and execute it before any PHI is transmitted
  • Verify your subscription tier is eligible for the BAA — free and basic plans almost always exclude healthcare use
  • Enable end-to-end encryption in the platform's security or admin settings and document that this setting is active
  • Configure mandatory waiting rooms so patients cannot join sessions without host admission
  • Require unique meeting IDs and passwords for every clinical session rather than using recurring room links
  • Disable any features that send meeting data to third-party analytics or advertising platforms
  • Establish written policies governing which platforms are approved, who can use them, and for what clinical purposes
  • Train all staff who conduct or support telehealth visits on proper platform configuration and patient privacy protocols
  • Include your video conferencing tools in your annual HIPAA risk analysis and document any identified vulnerabilities
  • Review audit logs from your video platform at least quarterly to identify unauthorized access attempts or anomalous usage patterns

A BAA Is Necessary — But Not Sufficient for HIPAA Compliance

Many healthcare organizations sign a Business Associate Agreement with their video platform vendor and consider the compliance obligation fulfilled. This is a dangerous misconception. The BAA establishes legal accountability but does not configure the platform, train your staff, or update your policies. OCR investigations consistently find that organizations with BAAs in place still face penalties because they failed to implement the technical and administrative safeguards that the BAA was supposed to support. Treat the BAA as the starting point, not the finish line.

Even organizations that understand HIPAA's requirements for video conferencing frequently make avoidable compliance mistakes that expose them to significant regulatory risk. One of the most common errors is allowing staff to use personal devices for telehealth visits without a formal mobile device management (MDM) policy in place. When a clinician conducts a video visit from a personal smartphone or tablet, the PHI transmitted during that session may be cached, logged, or processed by apps on that device that are outside the organization's control and certainly outside the scope of any BAA the organization has executed.

Another frequent mistake involves session recording. Many platforms offer automatic or one-click recording as a convenience feature, and staff sometimes enable recording without thinking through the HIPAA implications. Recorded video sessions that include PHI are subject to all the same retention, access control, and security requirements as any other medical record. If recordings are stored in a cloud location that is not covered by the BAA — for example, a personal Dropbox account or an unsecured shared drive — the organization has created an unauthorized disclosure of PHI regardless of how securely the live session itself was conducted.

Third-party integrations present a particularly tricky compliance challenge for video conferencing platforms. Many organizations connect their video platform to scheduling software, EHR systems, payment processors, or patient communication tools. Each of these integrations potentially creates a new channel through which PHI flows, and each integration partner is a potential business associate who needs their own BAA. Organizations frequently execute a BAA with their primary video platform vendor but overlook the downstream integrations that vendor enables, creating compliance gaps that are difficult to identify without a comprehensive data flow mapping exercise.

Free accounts and consumer-grade plans are a persistent source of compliance violations, particularly in smaller practices and among individual practitioners. The appeal is obvious — these tools are free, familiar, and functional. However, using FaceTime, WhatsApp Video, standard Skype, or the free tier of virtually any major platform for clinical telehealth visits is a HIPAA violation because none of these options include BAA availability, adequate audit logging, or the access controls HIPAA requires. The OCR has issued guidance specifically cautioning against the use of these tools for telehealth involving PHI.

It is worth noting that during the COVID-19 public health emergency, the OCR exercised enforcement discretion for telehealth, temporarily allowing covered entities to use non-HIPAA-compliant platforms for good-faith provision of telehealth services. This enforcement discretion period has ended. As of 2023, the OCR returned to standard enforcement, meaning that any previously tolerated use of non-compliant platforms must now be corrected or it represents an active compliance violation subject to full penalty exposure.

Geographic and jurisdictional complexity adds another layer to the compliance challenge. Several states — including California, New York, and Texas — have enacted their own health data privacy laws that impose requirements beyond HIPAA's federal floor. California's CMIA and New York's SHIELD Act, for example, include provisions that can affect video conferencing compliance even when federal HIPAA requirements are met. Multi-state telehealth providers must ensure their video conferencing policies account for the most restrictive applicable state law in addition to the federal HIPAA framework.

Staff turnover creates ongoing compliance risk that is often underestimated. When employees who administered or used a video conferencing platform leave the organization, their access credentials must be deactivated promptly, any personal devices used for telehealth must be wiped of organizational data, and any session recordings they had access to must be reviewed for appropriate retention. Workforce exit procedures should explicitly include telehealth tool access revocation as a standard checklist item to prevent former employees from retaining access to systems that may contain PHI.

Hipaa Compliant Video Conferencing - HIPAA - Health Insurance Portability and Accountability Act certification study resource

Building a comprehensive, durable telehealth compliance policy requires more than selecting the right platform and signing a BAA. It demands a systematic approach to policy development, staff training, technical configuration, and ongoing monitoring that treats video conferencing as a core component of your organization's HIPAA compliance program rather than a standalone technology decision. The foundation of this approach is a formal telehealth risk analysis that maps every point at which PHI enters or exits the video conferencing workflow.

Start by documenting your complete telehealth data flow: from the moment a patient schedules a telehealth visit, through the video session itself, to the post-visit documentation and any recordings or transcripts generated. For each step in this flow, identify what PHI is involved, who has access to it, what systems process or store it, and what safeguards are in place. This mapping exercise will reveal integration points, access control gaps, and data retention issues that are not visible when evaluating the video platform in isolation from the broader workflow it supports.

Staff training for telehealth compliance must be specific and practical, not a generic HIPAA refresher. Clinicians and administrative staff need to know exactly which platforms are approved, precisely how to configure a compliant session (including enabling encryption, setting up waiting rooms, and restricting recording), and what to do if a technical problem occurs during a visit that might expose PHI. Training should include scenario-based exercises — for example, what should a clinician do if a patient is accidentally placed in the wrong waiting room, or if a session is inadvertently recorded without patient consent?

Patient consent for telehealth is both an ethical and regulatory consideration. While HIPAA does not require a separate informed consent for telehealth specifically, many state laws do, and best practice strongly favors obtaining and documenting patient agreement to participate in video visits. This consent should include an explanation of the platform being used, the security measures in place, the risks inherent to internet-based communication, and the patient's right to choose an in-person visit instead. Consent documentation should be stored in the patient's medical record in the same manner as other consent forms.

Incident response planning must explicitly address telehealth-specific breach scenarios. What is your organization's protocol if the video platform vendor reports a data breach? What steps will you take if an unauthorized individual joins a telehealth session? Who is responsible for notifying affected patients if PHI is compromised during a telehealth interaction? These questions should be answered in your incident response plan before a breach occurs, not during one. Tabletop exercises that simulate telehealth breach scenarios are an effective way to test and strengthen these protocols.

Vendor management is an ongoing responsibility, not a one-time task. Video platform vendors update their terms of service, privacy policies, feature sets, and security configurations on a regular basis. Any change to a vendor's data processing practices could affect the scope or validity of your BAA. Assign a designated staff member to monitor vendor communications and flag any changes that require legal review or policy updates. Many organizations add telehealth vendor review as a standing agenda item in their quarterly compliance committee meetings to ensure this responsibility receives consistent attention.

Finally, document everything. HIPAA's administrative safeguards explicitly require covered entities to maintain written documentation of their security policies and procedures, retain that documentation for six years, and make it available for review during OCR investigations. Your telehealth compliance documentation should include your vendor evaluation criteria, executed BAAs, configuration screenshots showing security settings, training completion records, risk analysis results, and any corrective actions taken in response to identified gaps. Thorough documentation is both a compliance requirement and your most important defense if your telehealth program is ever scrutinized by regulators.

For practices seeking external validation of their telehealth compliance posture, third-party HIPAA compliance audits conducted by qualified health information privacy consultants can identify gaps that internal reviews miss. These audits typically evaluate not only your video conferencing tools but your entire HIPAA compliance program, providing a comprehensive view of organizational risk. Some liability insurance carriers specializing in healthcare also offer compliance assessment services as part of their risk management support, making external review accessible even for smaller practices with limited compliance budgets.

For clinicians and compliance professionals preparing for HIPAA certification exams or workforce training assessments, understanding video conferencing compliance is increasingly a tested domain. The shift to telehealth has made questions about electronic PHI transmission, business associate obligations, and technical safeguards more prevalent in HIPAA knowledge assessments. Being able to distinguish between what makes a platform HIPAA-eligible versus HIPAA-compliant — and understanding that the difference lies in configuration and policy, not just vendor agreement — is a conceptual distinction that frequently appears in exam scenarios.

When studying HIPAA's Security Rule as it applies to video conferencing, focus on the three categories of implementation specifications: required and addressable. Required specifications — like access controls and audit controls — must be implemented. Addressable specifications — like automatic logoff — must either be implemented or the covered entity must document why an equivalent alternative was chosen instead. Many video conferencing compliance configurations fall into addressable categories, meaning your organization has flexibility in how it achieves compliance but cannot simply ignore the requirement without written justification in your risk analysis documentation.

The minimum necessary standard is another frequently tested concept with direct telehealth implications. When conducting a video visit, clinicians should disclose only the PHI necessary for the specific consultation at hand. This means avoiding unnecessarily sharing screens containing full patient records when only a specific lab result or medication list is relevant to the current visit. Screen sharing during telehealth visits should be intentional and limited to the minimum information required, with a specific policy governing what types of information may be shared via screen share and under what circumstances.

Patient rights under the Privacy Rule also apply in the telehealth context. Patients have the right to request a copy of their telehealth visit records, including any written notes generated during or after the visit. If sessions are recorded with patient consent, patients have the right to request access to those recordings under the same access provisions that govern physical medical records. Your organization's telehealth policy should address how patient access requests for telehealth records are handled, including the timeline for response and any applicable fees for copies.

Understanding the difference between a covered entity and a business associate is foundational for any HIPAA exam and highly relevant to video conferencing compliance. Your healthcare organization is the covered entity; your video platform vendor is the business associate. If your organization also provides telehealth services to another covered entity — for example, a hospital system that contracts with an independent telehealth provider — your organization occupies both roles simultaneously and must have BAAs in place on both sides of each relationship. These complex arrangements require careful legal mapping to ensure all PHI flows are covered by appropriate agreements.

The concept of minimum necessary also applies to the staff members who have access to telehealth session records and recordings. Not every employee who has a credential on your video platform needs access to all session recordings or audit logs. Implementing role-based access controls that limit recording access to treating clinicians and designated compliance staff reduces the risk of internal unauthorized disclosure and demonstrates that your organization is applying the minimum necessary standard throughout its telehealth operations.

Finally, remember that HIPAA compliance is not a destination — it is a continuous process. The technology landscape for video conferencing changes rapidly, and the regulatory guidance around telehealth is evolving as OCR gains more experience enforcing HIPAA in the post-pandemic telehealth environment. Healthcare organizations that treat their telehealth compliance program as a living document — regularly reviewed, tested, updated, and trained — are far better positioned to adapt to regulatory changes and avoid enforcement actions than those who implement compliance measures once and consider the matter settled.

HIPAA Administrative Safeguards 4

Challenge yourself with advanced questions on HIPAA security management and risk assessment

HIPAA Administrative Safeguards 5

Master complex HIPAA administrative safeguard scenarios with this advanced practice set

HIPAA Questions and Answers

About the Author

Brian Henderson
Brian HendersonCIA, CISA, CFE, MBA

Certified Internal Auditor & Compliance Certification Expert

University of Illinois Gies College of Business

Brian Henderson is a Certified Internal Auditor, Certified Information Systems Auditor, and Certified Fraud Examiner with an MBA from the University of Illinois. He has 19 years of internal audit and regulatory compliance experience across financial services and healthcare industries, and coaches professionals through CIA, CISA, CFE, and SOX compliance certification programs.

Join the Discussion

Connect with other students preparing for this exam. Share tips, ask questions, and get advice from people who have been there.

View discussion (6 replies)