Is Zoom HIPAA Compliant for Group Therapy Sessions? Requirements and How to Stay Compliant
Zoom HIPAA Compliance Overview
Whether Zoom is HIPAA compliant for group therapy sessions depends on your plan, contracting, and configuration—not the app alone. To handle Protected Health Information (PHI), you must use Zoom under a signed Business Associate Agreement (BAA), apply appropriate security settings, and follow your organization’s privacy and security policies.
HIPAA compliance spans administrative, physical, and technical safeguards. The HIPAA Privacy Rule allows uses and disclosures of PHI for treatment without patient authorization, which includes group therapy. Still, you must implement reasonable safeguards to prevent unauthorized access or disclosures and uphold Telehealth Compliance obligations under federal and applicable state law.
In practice, you combine the right Zoom plan, Encryption Standards, and Access Controls with disciplined workflows: unique user accounts, least-privilege permissions, staff training, and documented procedures for session setup, verification, and incident response.
Required Zoom Plans for Compliance
Standard consumer or business plans without a BAA are not appropriate for PHI. You need a Zoom offering that provides and signs a Business Associate Agreement (BAA)—commonly a healthcare-designated plan or an enterprise contract with a healthcare addendum. Confirm in writing that the BAA is executed before enabling any clinical use.
Verify the scope of services covered by the BAA and restrict your team to in-scope products and features only. Ensure each workforce member who will host or manage sessions is provisioned under the covered account, not personal profiles.
- Obtain an executed BAA from Zoom (and any integrated vendors) before use with PHI.
- Confirm which features (e.g., meetings, chat, recording, transcription) are in scope.
- Disable or block features not covered by the BAA for all clinical users.
Business Associate Agreement Importance
The Business Associate Agreement establishes how Zoom may create, receive, maintain, or transmit PHI on your behalf and the safeguards it must maintain. It defines permitted uses, breach notification duties, and requirements for subcontractors and data retention or deletion.
A BAA also clarifies what is out of scope. If a feature is excluded—such as certain app integrations, storage locations, or AI-enabled services—you should treat it as off-limits for PHI. Your internal policies should reflect these limits, and technical controls should enforce them wherever possible.
Remember: a BAA does not replace your obligations. You must still conduct a Security Risk Analysis, implement role-based Access Controls, and train your workforce on proper Zoom usage for group sessions.
Zoom for Healthcare Features
Healthcare-designated Zoom offerings support HIPAA-aligned safeguards when properly configured. Meetings use strong transport security and modern Encryption Standards (e.g., AES-256-GCM). Optional end-to-end encryption (E2EE) can add protection but may limit certain features; evaluate tradeoffs during your risk analysis.
Access Controls help you manage who gets in and what they can do: Waiting Room, meeting passcodes, meeting lock, host-only screen sharing, and host suspension of participant activities. Administrative controls—SSO, two-factor authentication, granular roles, and audit logs—support governance and accountability.
Clinical teams also benefit from telehealth-friendly workflows: structured waiting, identity verification at entry, and consistent host controls. When combined with policy and training, these features create a reliable foundation for group therapy sessions.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Security Settings Configuration
Configure security at the account level and enforce it for all clinical users to reduce room for error. The following settings are commonly used to safeguard PHI in group sessions:
- Require a passcode and Waiting Room for all meetings; disable “Join before host.”
- Lock the meeting after all participants arrive; admit only expected individuals.
- Restrict screen sharing to the host by default; enable per participant only as needed.
- Disable participant annotation, file transfer, and the ability to save chat unless clinically necessary.
- Disable private chat for group therapy to prevent unmonitored disclosures.
- Prevent participants from renaming themselves to maintain verified identities.
- Set recording to off by default; restrict who can record and where recordings are stored.
- Enable SSO and require multi-factor authentication for admins and hosts.
- Use role-based privileges; limit access to settings, reports, and recordings on a need-to-know basis.
- Review data routing/storage options and choose locations consistent with your policies.
- Disable third-party apps and experimental or AI features unless they are explicitly in scope under your BAA and risk review.
Recording and Consent Considerations
Default to no recording for group therapy. If recording is clinically necessary, obtain explicit written consent that explains the purpose, who can access the recording, where it will be stored, and how long it will be retained. Follow state consent laws for audiovisual recording and wiretap requirements.
Treat recordings, transcripts, and chat logs as PHI. Store them only in covered environments, apply encryption at rest, enforce strict Access Controls, and set automated retention/deletion consistent with your policy and the BAA. Disable auto-saving of chats unless required and justified.
Authorization under the HIPAA Privacy Rule is generally not required for treatment activities like group therapy. However, you should set clear group confidentiality expectations, notify participants of residual privacy risks inherent to group settings, and prohibit external recording by participants.
Compliance Responsibilities for Providers
Conduct and document a Security Risk Analysis specific to telehealth and group therapy, then implement a risk management plan. Map Zoom-related risks—identity verification, admission controls, misdirected invites, chat disclosures, and recording—along with controls and monitoring.
Establish written policies and procedures: session setup checklists, participant verification steps, escalation for disruptions, minimum necessary guidance, and incident response. Train staff and maintain sanctions for noncompliance. Periodically audit settings, logs, and access to recordings.
Execute BAAs with all relevant vendors, not just Zoom. Maintain a current inventory of in-scope features, disable out-of-scope tools, and document your rationales. Align your practices with the HIPAA Privacy Rule and Security Rule, and integrate Telehealth Compliance requirements from applicable state laws and professional guidance.
Bottom line: with the right plan, a signed BAA, disciplined configuration, and strong administrative safeguards, you can run secure, confidential group therapy sessions on Zoom while protecting PHI.
FAQs
What Zoom plans are HIPAA compliant?
Only plans that include a signed BAA with Zoom are appropriate for PHI. Typically, this means a healthcare-designated offering or an enterprise agreement with a healthcare addendum. Free tiers and standard business plans without a BAA should not be used for clinical services.
How does a BAA affect Zoom usage?
The BAA defines permitted uses of PHI, required safeguards, breach notifications, and which products and features are covered. You must limit use to in-scope features, disable excluded tools (such as certain app integrations or AI functions), and enforce policies and technical controls to protect PHI.
Can group therapy sessions be held without individual authorization?
Yes. Under the HIPAA Privacy Rule, disclosures for treatment generally do not require patient authorization, and group therapy is a treatment activity. You should still obtain informed consent for telehealth, set confidentiality expectations, and comply with stricter state laws where applicable.
What security measures must be enabled to maintain HIPAA compliance on Zoom?
Require passcodes and the Waiting Room, lock meetings, restrict screen sharing, disable private chat and file transfer, turn off recording by default, enforce SSO and multi-factor authentication, apply role-based Access Controls, and store any necessary recordings only in covered, encrypted locations with defined retention and access reviews.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.