Is Facetime HIPAA Compliant?

FaceTime is not a HIPAA compliant telehealth platform for routine communications involving protected health information because Apple does not offer a HIPAA Business Associate Agreement for FaceTime, and HIPAA Covered Entities and Business Associates remain responsible for selecting communication tools that support required administrative oversight and contractual assurances.

Business Associate Agreement Requirement

A Business Associate Agreement is required when a vendor creates, receives, maintains, or transmits protected health information on behalf of a HIPAA Covered Entity or Business Associate in a manner that makes the vendor a Business Associate. FaceTime is not offered under a Business Associate Agreement, which prevents organizations from establishing the contractual privacy and security obligations that are standard for telehealth and collaboration platforms used with protected health information.

Conduit Classification Does Not Resolve Operational Risk

Some organizations evaluate FaceTime under the HIPAA conduit exception concept for transmission only services. FaceTime uses end to end encryption and is designed as a peer to peer communication channel, which reduces vendor access to call content. Conduit classification is fact specific and depends on whether transmission is the only service and whether any storage is transient, and it does not eliminate the need for workforce controls, permitted use and disclosure limits, and documented procedures.

A HIPAA Covered Entity or Business Associate that treats FaceTime as acceptable for a limited scenario still carries full responsibility for preventing disclosures to unauthorized recipients, confirming patient identity when applicable, and limiting content consistent with the HIPAA Minimum Necessary Rule.

Enforcement Discretion Is Not a Standing Exception

The Office for Civil Rights telehealth enforcement discretion that applied during the COVID-19 public health emergency expired after the transition period that ended on August 9, 2023. Use of consumer oriented communication tools for telehealth requires the same vendor and safeguard decisions as other electronic protected health information workflows.

Conditions That Drive Noncompliance

FaceTime use becomes noncompliant when it results in an impermissible disclosure, when users communicate protected health information with individuals who are not authorized, or when organizational controls do not support access management, monitoring, and incident response expectations. Privacy and security risk increases when calls occur in uncontrolled environments, when devices are shared, when screens or surroundings expose identifiers, or when staff use personal accounts and unmanaged devices.

Compliance Approach For Telehealth Video

Organizations that need video visits involving protected health information typically select a telehealth platform that will sign a Business Associate Agreement and supports administrative controls, authentication, and audit capabilities aligned with organizational policies. FaceTime can be reserved for scenarios where no protected health information is exchanged and where organizational policy permits its use for nonregulated communications.

Daniel Lopez

Daniel Lopez is the HIPAA expert behind HIPAA Coach. Daniel has over 10 years experience as a HIPAA trainer and has developed deep experience in teaching HIPAA to healthcare professionals. Daniel has contributed to numerous publications including expert articles on The HIPAA Guide. Daniel is currently a staff writer on HIPAA at the Healthcare IT Journal. Daniel was a subject matter expert for ComplianceJunction's online HIPAA training. Daniel's academic background in Health Information Management is the foundation of his HIPAA expertise. Daniel's primary professional interest is protecting patient privacy, which he believes is the core of the HIPAA regulations and the best route to HIPAA compliance. You can reach Daniel on the contact page of HIPAA Coach and follow him on Twitter https://twitter.com/DanielLHIPAA