BAA Generator
HomeResourcesDoes Zoom Sign a HIPAA BAA?
Vendor BAA Guide

Does Zoom Sign a HIPAA Business Associate Agreement?

By BAA Generator Research Team  ·  Published Apr 19, 2026  ·  Last reviewed Apr 28, 2026  ·  3 min read

Need a BAA right now?

Generate my BAA → See pricing →
Family resources. If you're still working out whether your practice is a HIPAA covered entity (and therefore needs a BAA at all), see ComplyCreate's guide to covered entities. Also need to issue a Notice of Privacy Practices to patients? Generate one at NPP Generator.

Key Takeaways

Direct answer: Yes — Zoom offers a HIPAA Business Associate Agreement for healthcare customers on Zoom for Healthcare and eligible Business/Enterprise plans. The BAA is not automatic — you must request it through Zoom's healthcare compliance process and enable HIPAA mode in your account settings. Free Zoom accounts cannot be used for telehealth involving PHI.

Telehealth has made Zoom one of the most important platforms in modern healthcare delivery. But Zoom's default configuration is not HIPAA compliant — specific steps are required to bring it into compliance for PHI handling. Here's exactly what you need to know.

Which Zoom Plans Support HIPAA Compliance?

Zoom's HIPAA BAA is available for:

Not supported: Zoom Basic (free), Zoom Pro (individual paid plan). These plans do not qualify for HIPAA compliance and should never be used for telehealth sessions involving PHI.

How to Get Zoom's HIPAA BAA

Zoom does not automatically provide a BAA when you sign up for an eligible plan. You must:

  1. Purchase a qualifying Zoom plan (Zoom for Healthcare, Business, or Enterprise)
  2. Contact Zoom through their HIPAA BAA request process (available in Zoom's Trust Center or through your account representative)
  3. Sign the BAA — Zoom will provide the document for your signature
  4. Enable HIPAA mode in your Zoom Admin Portal under Account Management > Account Settings > Security

HIPAA mode is not active by default, even on qualifying plans. Both the BAA and HIPAA mode configuration are required for compliant use.

What HIPAA Mode Disables on Zoom

When HIPAA mode is activated, Zoom disables features that could expose PHI to third-party AI processing or unauthorized storage:

These trade-offs are important to understand before switching to HIPAA mode — some productivity features your staff relies on will be unavailable.

What Zoom's BAA Covers

Zoom's HIPAA BAA governs how Zoom handles PHI transmitted or stored through Zoom's systems. It covers:

Zoom's BAA covers Zoom's platform. Your organization still needs BAAs with any other vendors that access PHI stored or transmitted through Zoom.

More vendor BAA guides

Generate a compliant BAA in 5 minutes

HHS model BAA provisions · 45 CFR § 164.504(e) compliant · clean PDF + editable Word

No subscription · PDF + Word · Free watermarked preview

Related: Communications & messaging

Frequently Asked Questions

Does Zoom sign a HIPAA BAA?
Yes — Zoom offers a HIPAA Business Associate Agreement for healthcare customers, but it requires a paid Zoom for Healthcare plan or an eligible Business or Enterprise plan with HIPAA features enabled. Free Zoom accounts are not covered and cannot be used for telehealth sessions involving PHI.
Is standard Zoom HIPAA compliant for telehealth?
Standard Zoom plans (free or basic paid) are not HIPAA compliant for telehealth. HIPAA compliance requires Zoom for Healthcare or an eligible Business/Enterprise plan with HIPAA mode enabled, which turns off certain AI features (like Zoom AI Companion) and requires a signed BAA. The free Zoom plan should never be used for telehealth sessions involving PHI.
What features are disabled in HIPAA mode on Zoom?
When HIPAA mode is enabled on Zoom, features that could expose PHI to third parties are disabled, including: Zoom AI Companion (meeting transcription and summaries), meeting recording storage in Zoom's cloud (unless you have Zoom for Healthcare), smart summaries, and certain third-party app integrations. Local recording to your own systems remains available.