Yes, Zoom Workplace Pro can be HIPAA compliant, but only once your organization signs a Business Associate Agreement (BAA) with Zoom. Paying for a Pro plan alone does not make any meeting on it compliant with HIPAA.
Zoom lists Pro alongside Business, Business Plus, and Enterprise as eligible plans for a BAA, according to Zoom's own support documentation. The HIPAA Journal notes that Zoom has been adopted by more than 150,000 businesses. Signing the agreement, though, is only step one of using the platform compliantly.
📋 Which Zoom plans qualify for a BAA
🖱️ The exact steps to turn on HIPAA coverage in your account
⚠️ Why a signed BAA still does not guarantee a compliant meeting
💰 A worked example weighing the cost of skipping this step
🤖 Which AI features change once your BAA is active
This article reflects Zoom's published policies and general HIPAA guidance current as of 2026. Vendor features, plan names, and BAA terms change. Confirm current details on Zoom's compliance page and with your organization's privacy or compliance officer before you rely on them. It is educational, not legal advice or a substitute for counsel on your specific obligations.
What Makes a Video Platform HIPAA Compliant in the First Place
HIPAA is a federal law that protects the privacy and security of a patient's protected health information (PHI). It applies directly to covered entities, meaning health care providers, health plans, and health care clearinghouses. It also reaches business associates. These are the vendors covered entities hire to help handle PHI, and Zoom falls into that second group.
A covered entity cannot simply start using a vendor to discuss patient information and call itself compliant. HIPAA requires a signed contract, the Business Associate Agreement. It must exist between the covered entity and the vendor before any PHI passes through that vendor's platform. The agreement spells out each side's duties for keeping that information safe.
Signing the agreement is a legal step, not a technical one, and it does not reconfigure the software on its own. Zoom still expects the account holder to use the platform's controls correctly. Staff must verify who is on a call before sharing details, and share only the minimum necessary information for the task at hand. A signed BAA without those habits still leaves a practice exposed to a HIPAA violation.
HIPAA splits its rules into two related parts, and both matter here. The Security Rule covers the technical and admin safeguards a platform and its users must follow, like encryption and access controls. The Privacy Rule covers who gets to see PHI at all. A signed BAA alone cannot enforce that part on its own.
Zoom encrypts calls end to end with AES-256-bit encryption. It also aligns its controls to the HITRUST CSF, a widely used healthcare security framework. Those technical safeguards satisfy much of the Security Rule's expectations for a vendor.
They do nothing, though, to stop a staff member from sharing a patient's diagnosis with the wrong person on a call. That is a Privacy Rule problem the technology cannot solve by itself. Only staff training and clear habits close that particular gap.
Which Situation Applies to You?
The right next step depends on where your organization stands with Zoom right now. Three common starting points cover most readers searching this question. Each one leads to a different first action, so identifying the right one first saves a step later.
The Solo Provider Buying Zoom Pro for the First Time
A therapist, a dietitian, or a small telehealth practice can request the BAA during checkout, the first time they buy Zoom Pro. The option appears as a dropdown choice before payment, so no separate contract negotiation or sales call is required. This path is the fastest of the three, since the agreement takes effect the moment checkout finishes.
A solo provider in this situation should treat the BAA step as part of buying the software, not an optional add-on to consider later. Delaying it even by a few weeks means each session held in that window sits outside the agreement's protection. The dropdown choice at checkout costs nothing extra, so there is little reason to put it off.
A provider switching from an older video tool to Zoom Pro for the first time should confirm the BAA before the first patient call, not after. That single checkout step removes the entire gap the next persona below fell into. Waiting until after the first session, even by one day, creates the exact exposure this article's mistakes section warns against.
The Existing Pro Subscriber Who Has Not Signed Yet
Many practices pay for Zoom Pro for ordinary scheduling and meetings long before anyone asks whether it is HIPAA compliant. That existing subscription can add the BAA later through the account's billing settings. Switching plans is not required, and no past meeting history gets lost. Skipping this step is the single most common gap this article's mistakes section covers.
A practice manager who inherited an existing Zoom account from a predecessor is especially likely to fall into this gap. Nobody actively decided to skip the BAA. It simply never came up until an insurer, auditor, or new compliance hire asked to see it.
The fix takes only a few minutes inside Plan Management, but finding the moment to check for it is the real obstacle. Setting a single calendar reminder to review vendor agreements once a year would have caught this gap long before an outside party did. A practice that reviews its vendor agreements on a fixed schedule rarely discovers a gap like this at all.
The Growing Practice Outgrowing a Self-Service Plan
A clinic adding several providers, an EHR integration, or advanced admin controls often outgrows Pro's self-service BAA option. Business, Business Plus, and Enterprise plans still support a BAA. Larger organizations typically work with Zoom's sales team for this, though, instead of a checkout dropdown. This path takes longer, but it also opens features like centralized account management across many providers.
A clinic at this stage should start the sales conversation before its provider count forces the issue. Waiting until the self-service plan visibly breaks down under a growing staff list tends to create a gap. It is the same kind of gap the second persona above fell into. Talking to sales early also gives the clinic time to compare Business and Enterprise features before staff come to depend on Pro.
How to Turn On HIPAA Coverage on Zoom Workplace Pro
The exact click path differs depending on whether you are buying Pro for the first time or subscribed to it now. For a first-time purchase, go to Zoom's healthcare pricing page and select the Pro plan, then click Buy Now. On the checkout page, choose United States Agreement (BAA) from the Select Business Country menu. Read and accept the agreement, then complete payment.
For an existing Pro subscription, sign in to the Zoom web portal and open Plans and Billing, then Plan Management. Scroll to the Discover our other popular products section, open it, and find the Business Associate Agreement (US only) tile. Click Enable, then review and accept the agreement to activate it on the existing account.

Once either path is complete, Zoom states that no further manual configuration is needed to activate the agreement itself. That claim covers the contract, not the practice's day-to-day habits. A signed BAA still sits alongside separate responsibilities for how staff use the platform during a patient call.
Zoom's Plan Management page also lets an admin view the BAA's effective date. An admin can review its terms again later, or disable it if the organization's status changes. Checking that effective date matters, since coverage starts on that date rather than on the date the Pro subscription itself began.
A practice that signs late in the year should treat any PHI shared before that date as a gap. That gap is worth a review with its compliance officer. Documenting the review itself, not only fixing the gap, is what an auditor typically wants to see.
A Canadian practice sees a near-identical flow, with one difference in the paperwork. Zoom offers a Personal Health Information Annex, not a BAA, for organizations with a Canadian billing address. It covers similar ground under Canada's PIPEDA and PHIPA rules instead of the US HIPAA statute. The click path through Plan Management stays the same in both cases, since Zoom's system detects the billing country and offers the matching agreement.
Worked Example: Weighing the Cost of Skipping the BAA
Consider a solo physical therapy practice paying for Zoom Pro today. The license runs roughly $16 a month, and the practice uses it for video visits with patients. Adding the BAA costs nothing extra on top of that subscription.
Zoom does not charge separately for the agreement itself on the Pro plan. The only real cost is the few minutes it takes to complete the checkout step or the Plan Management flow described above. Compared to the subscription's existing monthly cost, that one-time step barely registers.
Skipping that step carries a very different kind of cost. HIPAA civil penalties are set in tiers tied to the covered entity's level of awareness and correction, under rules the HHS Office for Civil Rights enforces. The exact dollar figures adjust over time. The tiers still reward a practice that acted in good faith, and punish one that ignored a known gap.
A single unresolved gap, like never signing a BAA at all, can turn an otherwise ordinary practice into evidence that it ignored a known requirement rather than an honest oversight. That distinction is what pushes a penalty toward the higher end of the range. The risk grows the moment the gap surfaces during an audit or a patient complaint. A compliance officer or attorney is worth consulting on the current penalty structure before it ever gets that far.
The math here is not close. A few minutes spent enabling the BAA is effectively free. Set against a potential penalty range that starts in the hundreds of dollars and climbs sharply from there, the choice is easy.
The bigger practical risk is not the dollar amount at all, though. It is the disruption of an investigation landing on a small practice that assumed its video platform was covered without ever checking. Staff time spent gathering records and answering questions during that review often costs more than the fix itself would have.
A larger clinic on a Business or Enterprise plan faces the same math at a bigger scale. More providers means more patient calls each month, so a missing BAA multiplies the number of unprotected sessions an audit could point to. The fix costs the same handful of minutes in either case; only the size of the gap it closes changes with the size of the practice.
Lessons From Practices That Got This Wrong
Three patterns repeat across real accounts of Zoom and HIPAA compliance. Each teaches a different lesson, and none of them is fully about the software itself. Together, they cover the gap between signing an agreement and using it correctly day to day.
Renata Never Signed a BAA in the First Place
Renata ran a small counseling practice and had used Zoom Pro for two years. A routine audit then asked for proof of a signed BAA with each video vendor. She had assumed a paid Zoom subscription included HIPAA coverage on its own, much like many small practice owners do.
There was no agreement on file. Her practice had to treat each prior video session as a potential gap while it retroactively signed the BAA and documented the fix. The audit itself took less time than the two years of uncertainty that preceded it.
| What Renata Assumed | What the Audit Found |
|---|---|
| "Paying for Zoom Pro means it's already HIPAA compliant" | No Business Associate Agreement on file at all |
| No review of Zoom's compliance settings | Two years of sessions with no documented coverage |
Marcus Signed the BAA but Skipped the Habits Around It
Marcus ran a telehealth practice and signed the BAA on his Zoom Pro account the day it launched. He followed each step in the checkout flow correctly. His front-desk staff still routinely used the in-meeting chat to send full patient names alongside diagnosis codes to coordinate scheduling.
That habit predated the BAA and never got revisited. The signed agreement covered Zoom's side of the relationship, but the chat habit violated HIPAA's minimum-necessary standard on the practice's own side. A short training session on what belongs in a scheduling chat, versus a clinical note, would have closed this gap early.
| What Marcus Had | What Was Still Missing |
|---|---|
| A signed, active BAA with Zoom | Staff training on minimum-necessary PHI sharing |
| Compliant platform-level settings | A chat habit that shared more detail than needed |
Priya Caught the AI Feature Gap Before It Became a Problem
Priya ran a multi-provider clinic and signed the BAA when the practice upgraded from Pro to Business Plus for its growing staff. During onboarding, her office manager noticed that a meeting-summary AI feature the front desk liked had been disabled once the BAA activated. Priya's team confirmed with Zoom which AI features stay available under a BAA.
They then built a manual note-taking habit for the features that would not be. That step avoided a compliance question no one on staff had thought to ask in advance. Her lesson is the simplest of the three: checking a vendor's current feature list before staff depend on it beats discovering the gap during a live patient call. That five-minute check saved her office manager an awkward moment in front of a waiting patient.
Mistakes to Avoid
- Assuming a paid Zoom plan already includes a BAA. Zoom requires the agreement to be requested and signed separately, even on plans that qualify for one.
- Never checking the BAA's effective date. Coverage starts on that date, not on the date the subscription itself began, leaving earlier sessions outside the agreement.
- Treating the signed BAA as the end of the compliance work. Staff habits, like sharing more PHI than necessary in chat, can violate HIPAA even under an active agreement.
- Using a personal or free Zoom account for any patient communication. Free accounts sit outside Zoom's list of plans eligible for a BAA.
- Skipping staff training on the minimum-necessary standard. Employees who do not know the rule tend to over-share patient details out of habit, not malice.
- Assuming each AI feature still works the same after signing. Some AI features are automatically disabled once a BAA is active, and a practice caught off guard may lose a workflow it depended on.
- Failing to document who verified the patient's identity on a call. A HIPAA review often asks for evidence of that step, not only an assumption that it happened.
- Forgetting to review the BAA again after a plan change. Moving from Pro to Business Plus or Enterprise can change which team handles the agreement going forward.
Setting Up Zoom Workplace Pro Correctly
Do
- Request or enable the BAA before any patient call happens, not after a practice realizes it should have one.
- Document the BAA's effective date somewhere your compliance officer can find it during an audit.
- Train staff on the minimum-necessary standard for what to share by chat, email, or voice during a patient call.
- Verify a patient's identity at the start of each video visit, especially for a first-time telehealth appointment.
- Recheck your AI feature list after signing the BAA, since some tools may be disabled automatically.
Don't
- Don't assume payment alone equals compliance. A Pro subscription and a signed BAA are two separate steps.
- Don't use a free or personal Zoom account for any PHI-related call. Free accounts are not on Zoom's HIPAA-eligible plan list.
- Don't let front-desk habits go untrained after the BAA is signed. The agreement covers Zoom's obligations, not your staff's.
- Don't ignore Zoom's own disclaimer that this is not legal advice. Treat the vendor's compliance page as a starting point, not a final answer.
- Don't delay a plan upgrade once your provider count outgrows Pro's self-service tools. Business and Enterprise plans exist for exactly that stage.
Weighing Zoom Workplace Pro Against a Dedicated Telehealth Platform
Pros
- Most staff already know how to use Zoom, cutting training time compared to an unfamiliar dedicated telehealth tool.
- The BAA is free to add on Pro, with no separate compliance fee stacked on top of the subscription.
- Zoom's HITRUST-aligned controls and encryption meet a security bar many smaller telehealth vendors have not yet matched.
- The self-service checkout path is fast, letting a solo provider get covered in minutes rather than weeks.
- Growing into Business or Enterprise stays on the same platform, avoiding a full re-training when the practice scales up.
Cons
- Some AI features disappear once the BAA activates, which can disrupt a workflow staff had grown used to.
- The BAA only covers Zoom's obligations, leaving staff training and habits entirely up to the practice.
- General-purpose video tools lack built-in patient intake or scheduling that some dedicated telehealth platforms bundle in.
- A missed effective-date review can leave a coverage gap that only surfaces during an audit or complaint.
- Sales-assisted plans (Business and up) move slower than the instant Pro checkout flow, which matters for a practice that needs coverage right away.
What to Do Next
- Check whether your organization has an active, signed BAA with Zoom, and note its effective date.
- If you do not have one, request it at checkout for a new Pro purchase or through Plan Management for an existing subscription.
- Confirm which AI features are disabled once the BAA is active, and build a manual workaround for any your team relies on.
- Train front-desk and clinical staff on the minimum-necessary standard for sharing PHI over chat, email, or voice.
- Review your provider count and features against Pro's limits, and talk to Zoom's sales team if your practice has outgrown a self-service plan.
Frequently Asked Questions
Is Zoom Workplace Pro HIPAA compliant by default?
No. A Pro subscription alone does not include a Business Associate Agreement. The agreement has to be requested separately at checkout or through account settings.
Which Zoom plans qualify for a HIPAA Business Associate Agreement?
Pro, Business, Business Plus, and Enterprise. Zoom's own support documentation lists these as the plans eligible for a BAA. Free accounts are not included.
How do I add a BAA to an existing Zoom Pro account?
Through Plan Management. Sign in to the Zoom web portal and open Plans and Billing, then Plan Management. Enable the Business Associate Agreement tile listed there.
Does signing a BAA with Zoom cost extra money?
No, not on Pro. Zoom does not charge a separate fee for the agreement itself on the Pro plan, only the existing subscription cost.
Can I still use Zoom's AI features after signing a BAA?
Only some of them. Certain AI features are automatically disabled once a covered entity signs a BAA. A practice should confirm which ones stay available.
Does a signed BAA guarantee my Zoom meetings are HIPAA compliant?
No. The agreement covers Zoom's responsibilities, but staff still have to follow HIPAA's minimum-necessary standard and verify patient identity during each call.
What happens if I never sign a BAA and use Zoom for patient calls anyway?
The practice is out of compliance. An audit or complaint can treat each prior session as an unaddressed gap. That is more serious than a late but documented fix.
Is a free Zoom account ever appropriate for talking with patients?
No. Free accounts sit outside Zoom's list of HIPAA-eligible plans, so any patient communication should move to a paid, BAA-covered plan first.
Who is responsible for making sure Zoom is used correctly under HIPAA?
Both a security officer and a privacy officer. One typically owns the platform's technical configuration. The other ensures staff follow the privacy rules during actual use.
Should a growing practice move from Zoom Pro to Zoom Business?
Often, yes. Once a practice adds more providers or needs centralized account management, growth becomes the deciding factor. Business or Enterprise plans support that scale better than Pro's self-service tools.