← All articlesTools & Vendors

Do You Need a BAA for Telehealth? What Therapists Must Know

9 min read

You picked a video platform, ran your first telehealth session, and it worked. The client showed up on screen, you talked, nobody had to drive anywhere. What almost never gets asked in that moment is the question that actually matters for HIPAA: is there a signed agreement behind that video call, and does the platform even offer one?

This is the piece that answers it plainly. When a telehealth platform counts as a business associate, when it genuinely doesn't, which specific products will sign a BAA (and which won't, no matter how secure they feel), what a real BAA has to say, and what to do when a platform flat-out refuses. Let's get it straight.

The quick answer

If a telehealth platform transmits or stores your clients' information on your behalf, you need a signed Business Associate Agreement with it — and almost every video platform does exactly that. So in practice, yes: for telemedicine you need a BAA.

The narrow exception is a service that acts as a pure "conduit" — a dumb pipe that carries data without meaningfully accessing or storing it. Very few video platforms qualify, and the ones marketed to therapists don't rely on that exception anyway; they just sign the BAA. So the honest default is: assume you need a BAA for your telehealth tool, and confirm the vendor will provide one before you run a single session with real clients.

Everything below is the detail behind that answer.

When a telehealth platform is a business associate

A business associate is any vendor that creates, receives, maintains, or transmits Protected Health Information (PHI) on your behalf. That definition lives in the HIPAA rules at 45 CFR § 160.103, and it's broader than most therapists expect.

A video platform hits that definition almost by design. Think about what actually happens in a session:

  • The client's identity is tied to your practice the moment they connect — being your client is itself PHI for a mental health provider.
  • The platform transmits the audio and video of a clinical conversation.
  • Most platforms store something: scheduling data, waiting-room entries, chat messages, session recordings, connection logs, sometimes the client's email or phone number.

Any one of those makes the platform a business associate. Storing a recording of a therapy session is the clearest case imaginable — that's PHI sitting on someone else's servers. But even a platform that stores "nothing clinical" still handles the appointment link, the client's name, and the fact that a session occurred. That's enough.

So the working rule is simple: if the platform could see, route, or hold anything that ties a specific person to their care, it's a business associate and needs a BAA. For real-world telehealth tools, that's virtually always true.

The conduit exception — and why it rarely helps

There is one genuine carve-out, and it's worth understanding precisely so you don't misuse it.

The conduit exception covers services that only transport data and don't access it except transiently, the way the postal service carries a sealed letter or an ISP carries packets. HHS has been explicit that this exception is narrow — it's meant for pure transmission couriers, not for anything that stores data. The moment a vendor maintains PHI (even temporarily, in a way that's more than fleeting), it's a business associate, not a conduit.

Here's why this almost never rescues a telehealth platform:

  • A conduit can't store your data. Video platforms store scheduling, logs, chat, and often recordings. That storage alone disqualifies them from the exception.
  • The exception is about the transmission-only role. A platform that provides a waiting room, accounts, and a portal is doing far more than transmitting.

Therapists sometimes reason, "The call is end-to-end encrypted, so the vendor can't read it — that makes them a conduit." It doesn't. Whether a vendor chooses to look at the data is irrelevant; what matters is whether they maintain it and whether they have the capacity to access it. Encryption is a safeguard, not an exemption. If a platform stores or persistently handles PHI, it needs a BAA regardless of how strong its encryption is.

Bottom line: don't build your compliance on the hope that your video tool is a "conduit." For the tools therapists actually use, it isn't.

Zoom vs Zoom for Healthcare, and other platform traps

This is where most confusion lives, because the compliant and non-compliant versions of the same product often look identical on screen. HIPAA cares about the legal relationship behind the software, not the interface. A few specifics that trip therapists up:

Regular Zoom will not sign a BAA. The standard consumer and business Zoom plans — the ones most people already have — do not come with a BAA, and Zoom won't sign one for them. Running client sessions on ordinary Zoom is not compliant, full stop.

Zoom Workplace for Healthcare will. Zoom offers a separate, paid healthcare tier built for exactly this. On that plan Zoom will execute a BAA and turns on the appropriate safeguards. Same familiar interface, completely different legal footing. If you want to use Zoom for telehealth, this is the version you need — not a setting you toggle on your existing account, but a different plan with the BAA in place.

Doxy.me signs a BAA even on its free tier. This is a genuinely useful fact for a solo therapist on a budget: Doxy.me is a browser-based, telehealth-specific platform, and it will provide a BAA at no cost. That makes it one of the few ways to run compliant video without a paid subscription. (Read the BAA and enable the account properly — free doesn't mean zero-configuration — but the agreement itself is available.)

Google Meet needs Google Workspace plus the signed BAA. Meet inside free consumer Google is not compliant, for the same reason free Gmail isn't. On a paid Google Workspace plan you can accept Google's BAA in the Admin Console, and Meet is one of the covered services — but only once that BAA is signed and only on the paid plan.

FaceTime, Skype, and consumer messaging apps don't offer BAAs at all. They're built for personal use, and there's no compliant version to upgrade to. Convenient, but off the table for PHI.

If you want a fuller side-by-side of the options, see our roundup of HIPAA-compliant telehealth platforms. The test across all of them is the same one: will this specific product, on this specific plan, sign a BAA?

What a compliant BAA actually has to contain

Getting a document called a "BAA" isn't the finish line — it has to contain the right provisions. The required elements are set out at 45 CFR § 164.504(e), and a proper telehealth BAA should cover all of them. Our full BAA guide walks through each in depth, but here's what to confirm is present:

Permitted uses and disclosures. Exactly what the platform is allowed to do with your clients' information — and it should be narrow, limited to running the service. A vendor that reserves the right to use PHI for its own marketing or analytics is a red flag.

Appropriate safeguards. The platform must commit to administrative, physical, and technical safeguards to protect PHI from unauthorized use or disclosure — encryption in transit and at rest being the obvious technical ones for video.

Breach notification. The vendor must agree to report any breach of unsecured PHI to you, within a defined timeframe. Look for a concrete number. "Promptly" is not a timeframe; 30 days or fewer is reasonable.

Subcontractor flow-down. Telehealth platforms run on cloud infrastructure (AWS, Google Cloud, and the like) and other subprocessors. The BAA must require that any subcontractor touching PHI is bound by the same protections. If subcontractors aren't mentioned at all, that's a gap.

Return or destruction of PHI. When you stop using the platform, it must return or destroy the PHI it holds — including any session recordings — or explain why that isn't feasible. This matters more with telehealth than with almost any other vendor, precisely because recordings can linger.

A "BAA" that's really just the standard Terms of Service with a HIPAA sentence bolted on does not meet this bar. A BAA is a specific contract with specific required terms; a ToS is not a substitute.

What to do if a platform won't sign one

Sometimes you fall in love with a tool and then discover it won't offer a BAA. The answer here is short and non-negotiable.

If a platform that would handle PHI won't sign a BAA, don't use it for PHI. Period. There's no configuration, no encryption setting, and no privacy toggle that closes this gap. Using a vendor without a required BAA is a HIPAA violation even if their security is excellent — the missing agreement is itself the problem.

Your realistic options:

  1. Switch to a platform that will sign. For every non-compliant tool there's a compliant path: regular Zoom → Zoom Workplace for Healthcare; consumer Google → Google Workspace with the BAA; or a purpose-built option like Doxy.me. You rarely have to give up the workflow, just the specific plan.

  2. Keep the tool, but never put PHI through it. If there's a genuinely non-clinical use — a general webinar with no identified clients, an internal team call with no patient data — a non-BAA tool can live there. The discipline has to be absolute: the day one client session runs through it, the gap is back.

  3. "Accept the risk." Not a real option. Running client telehealth on a platform that won't sign a required BAA is simply out of compliance, and it's the kind of gap that's obvious in hindsight after an incident.

Where this leaves you

For telehealth the chain of reasoning is short and reliable. Your video platform transmits and usually stores your clients' information, which makes it a business associate. The conduit exception is too narrow to rescue the tools therapists actually use. So you need a signed BAA — one that spells out permitted uses, safeguards, breach notification, subcontractor flow-down, and return or destruction of PHI. Pick a product on a plan that will sign it (Zoom Workplace for Healthcare, Doxy.me, Google Meet on Workspace, and other healthcare-specific platforms all qualify), sign the BAA, store it with your other vendor agreements, and document it.

Your telehealth platform is one vendor relationship among several — your EHR, email, scheduler, cloud backup, and billing service each need the same treatment. Getting the video tool right is real progress. It's one line on a longer list, and every line deserves the same simple question: will they sign a BAA, and does it say the right things?

Not sure if your vendors are HIPAA compliant?

Our assessment checks your EHR, email, telehealth, and cloud storage against HIPAA requirements. Free, 25 minutes, results are instant.

Free · See your score instantly