HIPAA Compliant Video Conferencing: Who Signs a BAA in 2026
Last updated: July 20, 2026
HIPAA compliant video conferencing is any video platform that signs a Business Associate Agreement (BAA) for your account and has the Security Rule safeguards turned on. The contract comes first in HIPAA compliant video conferencing. Under 45 CFR § 164.308(b), a platform that carries patient conversations is a Business Associate. The written agreement must exist before the first visit. Encryption alone never qualifies a tool. In 2026, five mainstream platforms have a real BAA path: Zoom, Doxy.me, Google Meet, Microsoft Teams, and Cisco Webex. Several popular apps have none. One patient call on those is a violation. This guide gives the verified plan-by-plan answer, the platforms to avoid, and the setup work after the contract.
TL;DR: Quick answer
HIPAA compliant video conferencing requires two things: a signed BAA and correct configuration. The contract decides first. Settings and training do the rest.
Five mainstream platforms offer a BAA in 2026: Zoom (qualifying paid plans, on request), Doxy.me (every plan, including free), Google Meet (through the Google Workspace BAA), Microsoft Teams (business and enterprise plans), and Cisco Webex (paid plans).
FaceTime, consumer Skype, free Zoom, and personal WhatsApp have no BAA path. They are never compliant for patient calls.
Doxy.me is the outlier worth knowing: its free plan includes a BAA for an individual provider. No other major platform matches that.
The video call is half the picture. Booking, intake forms, reminders, and your website carry PHI before the call starts. They need their own BAA-covered home.
Vendor policies change. Every claim here was verified against vendor documents in July 2026. Confirm current terms before you sign.
When is a video call PHI?
Almost always, in a care context. A telehealth session ties a named patient to their health in real time. The session, the chat, any recording, and the appointment details are all protected health information under 45 CFR § 160.103. That makes the platform a Business Associate. The BAA is the legal gate, and it is where every HIPAA compliant video conferencing decision starts. The full stack view, including recordings and state rules, is in our guide to HIPAA compliant telehealth.
Which platforms sign a BAA in 2026?

Here is the verified HIPAA compliant video conferencing list for 2026. How you get the BAA matters as much as the yes, because most of these are not automatic.
Platform | BAA available? | How you get it |
|---|---|---|
Zoom | Yes, on qualifying paid plans | Request it through Zoom's healthcare process, then enable the HIPAA settings; free and standard accounts never qualify. Full plan rules: is Zoom HIPAA compliant |
Doxy.me | Yes, on every plan including free | Included at signup for an individual provider; group practices need the Clinic BAA that covers every provider |
Google Meet | Yes, through Google Workspace | Accept the Workspace BAA in the Admin console on a paid plan; Meet is on Google's covered list. Setup detail: Google Workspace HIPAA |
Microsoft Teams | Yes, on business and enterprise plans | Covered by Microsoft's BAA in its standard product terms for commercial customers; confirm your license tier is in scope |
Cisco Webex | Yes, on paid plans | Cisco signs a BAA for paid Webex customers and publishes a HIPAA configuration whitepaper; execute the agreement before patient use |
One caution for the whole table: plan names and eligibility shift. Wix reversed its no-BAA policy in 2026. Video vendors adjust terms the same way. Treat this as the verified answer for July 2026, and confirm current terms with the vendor before you rely on it.
The platforms that never work

FaceTime, consumer Skype, free Zoom, and personal WhatsApp offer no BAA path at any price. Their encryption may be excellent. It does not matter. With no Business Associate Agreement, a single patient call on any of them violates 45 CFR § 164.308(b). The same goes for any tool that only offers personal accounts. No setting turns a consumer app into HIPAA compliant video conferencing. If a vendor cannot name its BAA process, the answer is no.
The BAA is not the finish line

Signing the contract starts the work. HIPAA compliant video conferencing still fails when the settings and habits are wrong. Four things close the gap:
Enable the compliance settings. Zoom's HIPAA configuration restricts features. Workspace and Teams need admin-enforced access controls and MFA. Defaults are not compliance.
Decide your recording policy. A recorded session is stored PHI. It needs BAA-covered, encrypted storage with access logging, never a personal drive.
Keep every patient call on the covered account. The most common violation we see is drift: a clinician using a personal account "just this once."
Put it in your risk analysis. 45 CFR § 164.308(a)(1)(ii)(A) expects the whole video workflow documented, from booking to storage.
How do you choose between them?
Match the platform to what your practice already runs. The cheapest compliant option is usually the BAA you can activate today. A solo therapist gets the fastest start with Doxy.me, because the free plan carries an individual BAA. A practice on paid Google Workspace can cover Meet by accepting the BAA in the Admin console. A Microsoft 365 shop should look at Teams first for the same reason. Telehealth-first groups tend to land on Zoom's healthcare offering. Enterprises with Cisco contracts pick Webex. There is no single best HIPAA compliant video conferencing platform. There is the platform whose BAA, settings, and price fit your stack.
The other half: everything around the call
The platform covers the call. It does not cover how the patient got there. The appointment was booked somewhere, and schedulers have their own BAA rules; see is Calendly HIPAA compliant. The intake form collected health details somewhere; the standards are in HIPAA compliant forms. The confirmation email, the join page, and any stored records live on your website. That infrastructure needs its own HIPAA compliant hosting under a BAA. A perfect video setup feeding an uncovered intake form is still a violation. The leak just happens before the call.
If you would rather have the whole path handled
Tell us how your telehealth visits run: how patients book, what the intake asks, where the site lives, and which video platform you use. If your video setup is already right, we will say so. We sell the other half: BAA-covered hosting for the booking, intake, and site, plus a client-side compliance review that documents what the current flow leaks. Weigh that as a disclosure.
Frequently asked questions
Which video conferencing platforms are HIPAA compliant?
Zoom (qualifying paid plans), Doxy.me (all plans), Google Meet (under the Workspace BAA), Microsoft Teams (business and enterprise), and Cisco Webex (paid plans) all offer a BAA in 2026. Each becomes HIPAA compliant video conferencing only after the BAA is signed and the settings are configured.
Is FaceTime HIPAA compliant for telehealth?
No. Apple offers no BAA for FaceTime, so it cannot be used for patient calls regardless of its encryption. The same applies to consumer Skype, free Zoom, and personal WhatsApp.
Is there free HIPAA compliant video conferencing?
Yes, one real option. Doxy.me includes a BAA on its free plan for an individual provider. That makes it the only free HIPAA compliant video conferencing choice among the major platforms. Free tiers elsewhere, including Zoom, carry no BAA.
Is a BAA enough to make video visits compliant?
No. The BAA is the legal gate. You still need the platform's compliance settings enabled, a deliberate recording policy, staff who keep every patient call on the covered account, and the workflow documented in your risk analysis.
Does the video platform cover my booking and intake forms?
No. The platform's BAA covers the call. Scheduling tools, intake forms, reminder emails, and your website each need their own BAA-covered handling, because PHI flows through them before the visit starts.
Recap: HIPAA compliant video conferencing
To recap, HIPAA compliant video conferencing is a signed BAA plus correct configuration, in that order. Five mainstream platforms qualify in 2026: Zoom, Doxy.me, Google Meet, Microsoft Teams, and Webex. FaceTime and consumer apps never do. Pick the platform whose BAA fits the stack you already run. Enable its compliance settings and keep recordings in covered storage. And remember the call is only half the path: booking, intake, and your site need BAA-covered hosting of their own.
This article is general information, not legal advice. Platform plans, BAA eligibility, and covered-service lists are as publicly described in July 2026 and change; confirm current terms with each vendor, consult qualified counsel, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting and compliance reviews. Reviewed July 2026.
Sources
Doxy.me Help Center: How do I get a BAA with doxy.me?
Google Workspace: HIPAA Included Functionality
Microsoft: HIPAA and the HITECH Act compliance offering
45 CFR § 164.308 (BAA requirement): ecfr.gov