The Direct Answer
A video conferencing platform is HIPAA compliant for telehealth only when the vendor will sign a business associate agreement (BAA) covering the video service, the platform encrypts video and audio in transit, and your practice configures the account correctly, meaning waiting rooms, unique logins, and session logging are turned on. General-purpose apps like standard Zoom, FaceTime, or Skype do not meet this bar on their own unless you are using the specific paid, BAA-eligible tier the vendor designates for healthcare use.
The Health Insurance Portability and Accountability Act (HIPAA) is the 1996 federal law that sets privacy and security standards for protected health information (PHI), and its Security Rule at 45 CFR Part 164, Subpart C requires covered entities to safeguard electronic PHI (ePHI) wherever it is created, transmitted, or stored, including during a video visit.
Quick Answer
A HIPAA-compliant video conferencing platform for telehealth requires a signed business associate agreement (BAA) with the vendor, encryption for video and audio in transit, access controls such as waiting rooms and unique logins, and audit logs you can produce if HHS asks for them. Consumer versions of Zoom, FaceTime, Skype, and Google Meet do not meet this standard unless you upgrade to the vendor's specific healthcare or BAA-eligible plan. The COVID-19 enforcement discretion that let providers use ordinary video apps for telehealth ended on August 9, 2023, according to the U.S. Department of Health and Human Services. Purpose-built telehealth tools and healthcare add-ons to platforms like Zoom, Microsoft Teams, and Google Workspace are commonly used, but confirm current BAA terms and pricing directly with each vendor before you rely on marketing claims.
What a Business Associate Agreement Actually Covers
A business associate agreement (BAA) is a contract required under HIPAA between a covered entity, such as your practice, and any vendor that creates, receives, maintains, or transmits PHI on your behalf, and it obligates the vendor to safeguard that data and report breaches. Video conferencing counts as a business associate function whenever a patient's image, voice, or clinical information passes through the platform during a visit. The U.S. Department of Health and Human Services Office for Civil Rights (OCR), the agency that enforces HIPAA, ended its COVID-era Notification of Enforcement Discretion for telehealth on August 9, 2023, closing a 90-day transition window after the COVID-19 Public Health Emergency expired. Since that date, using a non-BAA-eligible consumer app for a clinical video visit can create a documentation gap during an OCR audit or breach investigation, even when the visit itself goes smoothly.
The HIPAA Security Rule does not name specific products. It requires administrative, physical, and technical safeguards, and NIST Special Publication 800-66, the National Institute of Standards and Technology's implementation guide for the HIPAA Security Rule, recommends encryption for ePHI in transit, unique user authentication, and audit controls as baseline technical safeguards. That means the compliance burden sits on how you configure and use a platform, not just on which logo is on the login screen.
What Makes a Video Platform HIPAA Compliant
- The vendor will sign a written BAA specifically covering the video conferencing product, not just other services in its suite
- Video and audio are encrypted in transit for every session
- The account supports unique logins per provider, not one shared password for the whole office
- Waiting rooms or an equivalent control prevent uninvited participants from joining a session
- Session and access logs are retained and exportable if you need to produce them for an OCR investigation
- Recording, screen sharing, and chat transcripts are covered by the same BAA and retention policy as the live video feed
What HIPAA-Compliant Video Conferencing Costs
Pricing for BAA-eligible video conferencing generally falls into three tiers. General-purpose platforms such as Zoom, Microsoft Teams, and Google Meet offer a healthcare or business-plan add-on that unlocks BAA eligibility, typically priced as a per-user monthly subscription on top of the standard plan, and you must sign the vendor's specific healthcare BAA rider rather than accept the standard terms of service. Purpose-built telehealth platforms, such as doxy.me and VSee, offer a limited free tier with a signed BAA plus paid tiers that add scheduling, waiting-room branding, and EHR integration. EHR-embedded video visits fold the video cost into the electronic health record subscription instead of billing it separately.
Because list pricing changes and varies by seat count and contract term, confirm current numbers directly with each vendor's sales team and get the BAA terms in writing before you commit, rather than relying on marketing pages alone. If you're deciding whether to manage this vendor evaluation in-house or bring in outside help, our guide to a cybersecurity company vs MSP explains the difference in scope and when each makes sense.
Three Ways to Get HIPAA-Compliant Video Visits
General-purpose platform plus healthcare add-on (Zoom, Microsoft Teams)
- Typical cost model
- Per-user monthly add-on to an existing subscription
- Good fit for
- Practices already standardized on that platform for internal meetings
Purpose-built telehealth platform (doxy.me, VSee)
- Typical cost model
- Free BAA-eligible tier or a low per-provider monthly fee
- Good fit for
- Solo and small practices wanting a dedicated patient-facing link
EHR-embedded video visit
- Typical cost model
- Bundled into the EHR subscription
- Good fit for
- Practices wanting scheduling, notes, and video under one login
| Feature | Typical cost model | Good fit for |
|---|---|---|
| General-purpose platform plus healthcare add-on (Zoom, Microsoft Teams) | Per-user monthly add-on to an existing subscription | Practices already standardized on that platform for internal meetings |
| Purpose-built telehealth platform (doxy.me, VSee) | Free BAA-eligible tier or a low per-provider monthly fee | Solo and small practices wanting a dedicated patient-facing link |
| EHR-embedded video visit | Bundled into the EHR subscription | Practices wanting scheduling, notes, and video under one login |
Using Your Existing Platform's Healthcare Add-On
- Staff already know the interface, which cuts training time
- One vendor relationship and one invoice to manage
- Often integrates with the calendar and scheduling tools you already use
Considerations
- The BAA may not cover every feature, such as recording, transcription, or AI-generated notes, by default, so you have to check
- Healthcare-tier pricing can cost more per seat than a purpose-built telehealth app
- Patients may need to download desktop software rather than clicking a browser link
What to Ask a Vendor Before You Sign
- Will you sign a BAA specifically for the video conferencing product, and can I see the template before purchase?
- Does the BAA cover recordings, chat transcripts, and any AI-generated visit notes, or only the live video feed?
- Where is video and session data stored, and for how long after the session ends?
- What encryption standard is used for video and audio in transit?
- Can I get an audit log of who joined each session and when?
- What is the documented breach notification timeline under the BAA?
The Video Platform Is Only One Layer
A signed BAA and an encrypted video stream protect the session itself, but they do not protect the laptop, tablet, or front-desk computer a provider uses to join that session. If that device is infected with malware, running outdated software, or accessible to anyone who walks up to it, a HIPAA-compliant video platform will not stop PHI from leaking through the endpoint. Reviewing healthcare cybersecurity threats for 2026 alongside your telehealth rollout helps you see the video vendor's BAA as one control among several, not the whole picture.
Practices that skip staff training on phishing and credential theft often see that gap show up first in email or remote access, not in the video tool itself, which is why pairing a compliant platform with HIPAA security awareness training and a documented ransomware prevention plan matters as much as picking the right vendor. Behavioral health telehealth carries its own nuances around consent and session notes; see our guide to HIPAA compliance for mental health practices for specifics. If your practice also routes billing through a third party, the same BAA logic applies; our guide to medical billing company HIPAA compliance requirements covers how that vendor relationship should be documented.
Common Mistake
Signing a BAA with your video conferencing vendor does not automatically cover every feature you turn on. Providers sometimes enable AI-generated visit summaries or cloud recording without confirming those specific features are included in the BAA, which can leave that data outside the vendor's contracted safeguards.
Secure the Devices Behind Your Telehealth Visits
A HIPAA-compliant video platform protects the session, but the computers and laptops your staff use to join it need their own defenses. Bellator Shield and Bellator Core add managed endpoint detection and response starting at $19 per computer per month, so you can compare coverage on our protection plans page.
Frequently Asked Questions
Standard consumer Zoom is not automatically HIPAA compliant. Zoom offers a healthcare plan that includes a signed BAA and additional security configurations; you must be on that specific plan with an executed BAA before using it for clinical video visits.
Google Meet can be used for telehealth if your practice is on a qualifying Google Workspace plan and has signed Google's BAA, which covers specific Workspace services including Meet. Free personal Gmail accounts are not covered by a BAA.
The COVID-19 enforcement discretion that allowed non-BAA-eligible apps like FaceTime and Skype for telehealth ended on August 9, 2023, according to HHS. Using them now without a BAA falls outside HIPAA's standard requirements for transmitting electronic PHI.
HHS OCR investigates HIPAA complaints and reported breaches, and the absence of a BAA with a vendor handling ePHI can complicate that review and may expose the practice to corrective action. This is a compliance risk description, not legal advice; consult qualified counsel about your specific situation.
Only if the recording feature is explicitly included in the vendor's BAA and the recordings are stored under the same safeguards as live video. Confirm this in writing rather than assuming a general BAA extends automatically to every add-on feature.
From requirement to defensible practice
Turn HIPAA requirements into safeguards that fit patient care
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring HIPAA security
Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.
- Common question: HIPAA cybersecurity requirementsUse the plain-language HIPAA guideUnderstand administrative, physical, and technical safeguards without sorting through legal language.
- Common question: HIPAA security risk assessmentPrepare for a HIPAA risk assessmentIdentify vulnerabilities, document risk, and prioritize the gaps that matter most.
- Common question: HIPAA Security Rule explainedReview the HIPAA Security RuleSee how the standards and implementation specifications fit together.
- Common question: healthcare ransomware protectionReduce healthcare ransomware riskProtect patient data and keep clinical operations recoverable after an attack.
- Common question: HIPAA endpoint securityProtect practice workstations and devicesApply managed endpoint detection to the devices that access protected health information.


