Is Zoom HIPAA Compliant? Telehealth Rules Since the Waiver Ended
Conditionally, and the condition is the contract rather than the product. A video platform can be used compliantly for telehealth when the vendor will sign a business associate agreement covering the plan you are actually on, and consumer tiers of any product generally do not qualify because no BAA is on offer. What changed is that the pandemic-era grace period is long gone: HHS's notice at 88 FR 22380, published April 13, 2023, expired four notifications of enforcement discretion with the COVID-19 public health emergency at 11:59 pm on May 11, 2023, and afforded covered health care providers "a 90-calendar day transition period to come into compliance with the HIPAA Rules with respect to their provision of telehealth using non-public facing remote communication technologies," a period that "will expire at 11:59 p.m. on August 9, 2023."
Since that date, telehealth has been ordinary HIPAA. No special rules, no special leniency, and no residual protection for the free tool you set up in 2020 and never revisited. The rest of this is what "ordinary HIPAA" actually demands of a telehealth workflow, and the four places we consistently find gaps.
Key takeaways
- The condition is the contract, not the product. A video platform is usable for telehealth when the vendor signs a BAA covering the plan you are actually on, and the same brand can be compliant on one tier and not on another.
- The pandemic grace period is long gone. The enforcement discretion expired at 11:59 pm on May 11, 2023 and the 90-day transition period closed at 11:59 pm on August 9, 2023, both stated at 88 FR 22380.
- There is no "post-waiver rule" to learn. The discretion was a decision not to enforce, so the position reverted to what the Security Rule and Privacy Rule always said.
- The real exposure is the artifacts: recordings, chat logs, transcripts, summaries and AI-generated notes are all PHI, and each lands in a store that has to be inside the BAA and inside your risk analysis.
- An AI notetaker connected to a patient visit is a business associate relationship nobody signed. If a model provider processes session content, it needs a BAA and a place in your inventory.
What the enforcement discretion actually was, and why it matters that it is gone
It is worth being precise, because a lot of the surviving internet content is from the period when it applied.
During the emergency, OCR announced it would exercise enforcement discretion and not impose penalties for noncompliance with the HIPAA Rules in connection with the good faith provision of telehealth using non-public facing remote communication technology. That is what let providers use consumer video tools without a BAA. It was a decision not to enforce, not a change to the rules: the underlying obligations never went away, they were simply not being penalized.
That distinction matters now for one specific reason. Because the rules never changed, there is no "post-waiver rule" to learn. When the discretion lapsed and the transition closed on August 9, 2023, the position reverted to what the Security Rule and Privacy Rule always said. Any article promising you the new telehealth rules is selling you the old ones.
The four things a compliant telehealth workflow needs
A vendor that will sign a BAA, on the plan you are on. This is the one that decides the question. A platform is not compliant or noncompliant as a product; the same brand can be both, depending on tier. Consumer and free tiers generally come with no BAA and are therefore out. Business and enterprise health care plans generally do. Check three things before you rely on one: that the agreement is executed and countersigned rather than merely available, that it covers the specific plan and features you use, and that the features outside its scope are disabled or avoided. Our BAA decision guide covers the agreement itself and the flow-down obligations behind it.
Encryption in transit, and the settings that enforce it. 45 CFR 164.312(e) makes transmission security a standard, with integrity controls and encryption as addressable implementation specifications underneath it. Addressable is not optional: you implement, or you document why it is not reasonable and appropriate and implement an equivalent alternative. For a video call carrying clinical conversation there is no such write-up. What deserves attention is that platform defaults change between releases, so the setting that was enforced when you rolled out may not be enforced now.
Access controls and audit logging, applied to the telehealth tool itself. 164.312(a) requires unique user identification and an emergency access procedure, and 164.312(b) makes audit controls a standard. Applied here that means named accounts rather than a shared clinic login, session controls, and the ability to answer who joined which visit and when. Shared credentials on a telehealth platform are one of the more common findings we see, usually because a front-desk workflow grew around a single account.
A risk analysis that actually covers the telehealth workflow. This is the requirement that gets missed, because the risk analysis was written before telehealth existed at your organization or was written about your core product and never extended. The analysis has to cover where the session data lands, which brings us to the part nobody enjoys.
Recordings, transcripts, chat and AI notetakers
This is where we find the real exposure, and it has grown considerably since 2023.
A telehealth session generates far more than a video stream. There may be a recording. There is often a chat log. Increasingly there is an automated transcript, a summary, and an AI-generated clinical note, produced either by the platform or by a third-party assistant someone connected. Every one of those artifacts is protected health information, and every one of them lands somewhere.
Ask, for each: where is it stored, for how long, who can retrieve it, is that store inside the BAA's scope, and is it inside the scope of your risk analysis. In our experience the honest answers are frequently "a cloud drive nobody inventoried," "forever," "anyone in the workspace," "no," and "no."
The AI notetaker case deserves its own sentence, because it is the newest and the most likely to have been adopted without procurement. If a model provider processes session content, that provider is handling PHI on your behalf, and the analysis is the same as for any other subprocessor: it needs a BAA, and it needs to be in your inventory. A clinician connecting a personal assistant tool to a patient visit is a business associate relationship nobody signed.
Patient consent for recording is a separate question from HIPAA, governed largely by state law, and it varies enough that it needs local advice rather than a national rule of thumb.
Audio-only and the platforms people actually use
Two practical points that come up in every telehealth assessment.
Ordinary telephone calls are not the problem people assume. HHS has published guidance on audio-only telehealth, and the analysis differs from video precisely because a traditional telephone call over a public switched network involves a carrier acting as a conduit rather than a business associate. That changes once you route audio through an application, a VoIP platform that stores content, or a service that transcribes the call: at that point you are back to needing a BAA with whoever holds the data.
Consumer messaging and video apps remain unsuitable for scheduled clinical encounters, not because of the encryption, which is often excellent, but because there is no agreement, no audit trail you control, and no scope statement. Encryption is a control. Compliance is a control plus a contract plus evidence.
The honest caveat
If you are a small practice running a handful of virtual visits a week on a platform whose BAA you have executed, with recording turned off and no transcription, you are close to done. Confirm the BAA scope, write two paragraphs adding telehealth to your risk analysis, replace any shared login, and move on. You do not need a consultancy for that, and a firm that quotes you a large assessment for it is selling you an artifact you will never use.
The work becomes real when telehealth is a product rather than a tool: when you are building the platform, integrating it with an EHR, recording at scale, or letting a model touch session content. That is a different engagement and it should be scoped as one.
Where Top Floor fits
We do the telehealth workflow mapping, the subprocessor and BAA review, and the risk-analysis extension under our HIPAA practice, and the ongoing evidence and vendor management under Compliance as a Service. If a session artifact has already gone somewhere it should not have, that is a breach analysis rather than a compliance project, and breach notification deadlines is the clock you are working against.
How to decide this week
Name every tool a clinician can start a patient conversation in, including the ones nobody approved. Then find the executed BAA for each, with a date on it. The tools with no agreement are the decision.
For each remaining tool, list the artifacts a session produces: recording, chat, transcript, summary, notes. Follow each one to the system it lands in and ask whether that system is inside the agreement.
Then open the risk analysis and search it for the word telehealth. If it is not there, add the workflow, date the update, and keep the previous version. That single edit closes the gap that most enforcement narratives in this space begin with.
Frequently asked questions
Is Zoom HIPAA compliant for telehealth?
It depends entirely on the plan and the agreement, not on the software. A video platform can be used compliantly when the vendor signs a business associate agreement covering the plan and features you actually use, and consumer or free tiers generally offer no such agreement. Confirm three things before relying on any platform: that the BAA is executed and countersigned rather than merely offered, that it covers your specific plan and the features you have enabled, and that anything outside its scope is disabled. The same brand can be compliant on one tier and not on another.
When did the COVID-19 telehealth HIPAA waiver end?
The enforcement discretion expired with the COVID-19 public health emergency at 11:59 pm on May 11, 2023. HHS then afforded covered health care providers a 90-calendar day transition period to come into compliance with the HIPAA Rules for telehealth using non-public facing remote communication technologies, and that period expired at 11:59 pm on August 9, 2023. Both dates are stated in the HHS notice published at 88 FR 22380 on April 13, 2023. Since then telehealth has been subject to the ordinary HIPAA Rules with no special treatment.
Are telehealth recordings and transcripts protected health information?
Yes. A session recording, a chat log, an automated transcript, a summary and an AI-generated clinical note are all protected health information, and each one lands in a storage system that has to be inside your business associate agreement and inside your risk analysis. This is where we find the most exposure, because the artifacts are generated automatically and stored somewhere nobody inventoried. If a third-party assistant or model provider processes session content, that provider is handling PHI on your behalf and needs a BAA of its own.
Do ordinary phone calls need a BAA for telehealth?
Generally not for the call itself. HHS has published guidance on audio-only telehealth, and a traditional telephone call over a public switched network involves a carrier acting as a conduit rather than a business associate, so the conduit exception applies to the transmission. The analysis changes as soon as content is retained: routing audio through an application, using a VoIP platform that stores recordings, or adding transcription puts a vendor in the position of maintaining protected health information on your behalf, and at that point a business associate agreement is required.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.