Is FaceTime HIPAA Compliant?
No. FaceTime is end-to-end encrypted, which is why so many practices assumed it was fine. But Apple will not sign a BAA, FaceTime has no audit logs or admin controls, and the OCR notice that tolerated it during COVID expired in August 2023. Here is the full picture, including iMessage and what to switch to.
FIG · 01No — FaceTime Is Not HIPAA Compliant
Apple does not sign a Business Associate Agreement for FaceTime, and the COVID-era OCR notice that let providers use it for telehealth expired on Aug 9, 2023. Since then, a FaceTime visit that involves PHI is an ordinary HIPAA exposure with no safe harbor.
No Apple BAA
Verified still true, Aug 2026
Enforcement discretion over
Ended 11:59 pm, Aug 9, 2023
Encrypted, not compliant
E2EE covers one Security Rule item
Apple Does Not Sign a BAA for FaceTime
HIPAA requires a Business Associate Agreement with any vendor that creates, receives, maintains, or transmits PHI on your behalf. Apple offers no BAA for FaceTime, iMessage, or iCloud, and has no healthcare-tier account that includes one. We re-checked Apple's legal and enterprise pages in August 2026: nothing has changed.
What a BAA would have to cover (and FaceTime cannot)
| BAA obligation | FaceTime reality |
|---|---|
| Report security incidents to you | No incident channel; consumer support only |
| Let you audit safeguards | No admin console, no logs to inspect |
| Return or destroy PHI at termination | No organizational account to terminate |
| Flow obligations down to subcontractors | Not offered |
The “conduit” argument
Some compliance writers argue Apple is a mere conduit: FaceTime calls are peer-to-peer, end-to-end encrypted, and Apple says it cannot decrypt them, so no BAA is needed. That is a real argument, but it only answers one question.
Why the conduit argument does not rescue you
HHS describes the conduit exception as narrow, meant for carriers like the postal service and ISPs that only pass data through. Even if Apple qualified, a conduit exception only removes the BAA requirement. It does nothing for the Security Rule controls your practice still owes: audit logs, access controls, a documented risk analysis, and workforce policy. FaceTime gives you none of those.
45 CFR §164.502(e), §164.504(e) — a covered entity may disclose PHI to a business associate only with satisfactory assurances, documented in a written contract. Who counts as a business associate?
Encryption Is Not the Same as Compliance
The usual defense of FaceTime is that it is end-to-end encrypted. True, and it matters. But encryption is one addressable specification inside a Security Rule that has dozens. Score FaceTime against five controls and the picture is clear.
Transmission security
45 CFR §164.312(e)(1)PassCalls are end-to-end encrypted with AES-256. Apple states it cannot decrypt FaceTime content. This is the one box FaceTime ticks.
Business associate contract
45 CFR §164.502(e)FailNo BAA available at any price or account tier.
Audit controls
45 CFR §164.312(b)FailNo record of who called whom, for how long, or from which device. Your call history is a consumer log on one phone.
Administrative controls
45 CFR §164.308(a)FailNo org admin, no policy enforcement, no way to disable features, no way to offboard a departing clinician.
Unique user ID and access control
45 CFR §164.312(a)PartialTied to a personal Apple ID, not a workforce identity. Device passcode is the only gate; no automatic logoff from a call log.
“A locked pipe is not a compliance program. OCR asks who was on the call, whether you had a contract with the vendor, and what your risk analysis said about it. FaceTime can answer none of those.”
The Telehealth Safe Harbor Ended in 2023
A lot of the “FaceTime is allowed” advice online is a leftover from the pandemic. For roughly three years OCR looked the other way. It no longer does. If your practice adopted FaceTime in 2020 and never revisited it, that decision has been out of date for three years.
2020-03-17
Discretion begins
OCR announces it will not penalize good-faith telehealth over non-public-facing apps. FaceTime, Zoom, and Skype are named as acceptable examples; Facebook Live and TikTok are named as not.
2023-05-11
PHE ends
The COVID-19 Public Health Emergency expires. OCR gives a 90-day transition window to move to compliant tools.
2023-08-09
Transition period ends
At 11:59 pm the notice expires. From Aug 10, 2023, full Privacy, Security, and Breach Notification Rules apply to every telehealth session.
What this means today
A FaceTime visit that discusses a diagnosis, medication, or test result is a disclosure of PHI to a vendor with no BAA. If a device is lost, a call is overheard, or a complaint is filed, you have no safe-harbor argument and no vendor contract to point to. Penalties follow the standard tiers in our HIPAA penalties guide.
88 FR 22380 (Apr 13, 2023) — Notice of Expiration of Certain Notifications of Enforcement Discretion Issued in Response to the COVID-19 Public Health Emergency. OCR's 2022 audio-only telehealth guidance remains in effect and still requires reasonable safeguards and a BAA where a vendor stores or can access PHI.
The Patient-Preference Argument and Its Limits
The Privacy Rule requires you to accommodate reasonable requests to communicate by alternative means. Practices sometimes read that as a FaceTime loophole. It is narrower than it looks. The rule governs what you may disclose to the patient and how; it does not lower your minimum-necessary or Security Rule obligations.
Use it as a documented exception, never as a default
If you rely on patient preference, the file should show the request, the warning you gave, and the date. If OCR asks, that note is the difference between a reasonable accommodation and an undocumented habit.
Defensible
- Patient requests FaceTime in writing or you note a verbal request
- You explain FaceTime is not a HIPAA-covered tool and the patient still prefers it
- Session content is limited to what that patient needs
- Clinician uses a practice-managed device, not a personal phone
- Your risk analysis names the exception and its controls
Not defensible
- Offering FaceTime as a standard telehealth option on your website
- Group FaceTime with family members or other patients present
- Clinician-to-clinician consults about a patient over FaceTime
- Screen-sharing charts, images, or lab results on a call
- Recording the session with a third-party app
Common situations
45 CFR §164.522(b)(1) — a covered health care provider must accommodate reasonable requests by individuals to receive communications of PHI by alternative means or at alternative locations.
Is iMessage HIPAA Compliant?
No, for the same reasons and two extra ones. iMessage shares FaceTime's missing BAA and missing controls, and adds a storage problem and a fallback problem that FaceTime does not have.
Blue bubble (iMessage)
End-to-end encrypted between Apple devices. Still no BAA, no audit trail, and the message sits in Messages in iCloud and device backups.
Green bubble (SMS / RCS)
Sent when the other person is not on iMessage or data is unavailable. Carrier SMS is not encrypted at all. Your phone decides which one to use, not your policy.
Messages persist in iCloud and backups
Unlike a FaceTime call, a text is stored. With Apple's standard data protection and iCloud Backup on, the backup carries a copy of the Messages in iCloud key so Apple can help recover the account. Advanced Data Protection closes that gap, but it is a per-user setting on a personal Apple ID, which you cannot enforce or audit across staff.
Personal-device sprawl
Messages sync to every device signed into the Apple ID: a home iPad, a family Mac, a spouse's shared laptop. Lost or stolen unencrypted devices are one of the most common HIPAA violations, and a texted lab result multiplies that surface.
No retention or retrieval control
Either party can delete a thread. You cannot produce a conversation for a records request, a complaint investigation, or a breach assessment unless someone kept a screenshot.
Practical rule: appointment reminders with no clinical content can go by plain text if the patient agreed to it. Anything with a result, a diagnosis, or a medication name goes through a platform with a BAA. Compare HIPAA-compliant texting platforms
What to Use Instead of FaceTime
The replacement needs to be as easy for the patient as tapping a FaceTime call, or clinicians will drift back. Every option below signs a BAA, keeps audit logs, and gives you an admin console to offboard staff.
Zoom for Healthcare
Best for: Practices that already live in Zoom and want a BAA plus admin controls, waiting rooms, and EHR integrations.
BAA on the Healthcare plan only; the free and standard Pro tiers do not qualify.
Zoom HIPAA setup guidedoxy.me
Best for: Solo and small practices. Browser-based, no app for the patient, free tier includes a BAA.
Patients click a link, so it replaces the FaceTime habit with the least friction.
Full video platform comparisonMicrosoft Teams (Microsoft 365)
Best for: Groups already on Microsoft 365 for email and files. The BAA is part of the Microsoft enterprise terms.
Needs specific tenant settings before it is compliant; not compliant out of the box.
Teams configuration stepsSwitching checklist
- 1Sign the vendor BAA before the first patient session and file it with your other agreements.
- 2Add the new platform to your risk analysis and retire FaceTime in the same update.
- 3Write a one-paragraph telehealth policy: approved tools, device rules, what to do when a patient FaceTimes you.
- 4Cover the change in staff training and log attendance.
- 5Update your Notice of Privacy Practices if it names telehealth channels.
Tools for each step: BAA template, policy template, training log, Notice of Privacy Practices.
Quick Reference: FaceTime, iMessage & HIPAA
FaceTime is not HIPAA compliant
Apple signs no BAA (still true Aug 2026). No audit logs, no admin controls, no org account.
The safe harbor ended Aug 9, 2023
OCR's COVID telehealth enforcement discretion is over. Pandemic-era advice no longer applies.
Patient preference is a logged exception
Document the request and warning under 45 CFR §164.522(b). It does not waive your Security Rule duties.
iMessage fails too, with extra storage risk
Messages persist in iCloud and backups, sync to every device, and fall back to unencrypted SMS.
Related Tools & Guides
Best HIPAA Video Conferencing
Zoom for Healthcare, doxy.me, VSee, Teams, and more compared.
Is Zoom HIPAA Compliant?
Which Zoom plan includes a BAA and the settings to lock down.
Best HIPAA Compliant Texting
Patient texting platforms that sign a BAA, side by side.
Is WhatsApp HIPAA Compliant?
Another encrypted consumer app that fails the BAA test.
BAA Template Generator
Draft a Business Associate Agreement for your telehealth vendor.