Is Calendly HIPAA compliant?
No — Calendly's customer terms specifically forbid putting patient information into the service and Calendly does not offer a business associate agreement, so it should not be used to book patients or collect their details.
Applies to Calendly scheduling. Last reviewed against Calendly's own documentation. Next review December 6, 2026.
Reviewed by Dr. Rachel Foster, MD — Pediatrician and small practice owner.
If you keep using it anyway
- If you keep Calendly for non-patient scheduling only, delete every intake question that could reveal a health condition, reason for visit, medication, insurance or treating provider.
- Do not connect Calendly to a calendar whose event titles or descriptions pair patient names with a reason for visit.
- Do not connect Calendly to your EHR, practice management system or any patient database.
Does Calendly sign a business associate agreement?
Calendly does not offer one. Not applicable. Calendly's terms prohibit patient information rather than offering an agreement to permit it.
What this means in practice
This one is stronger than a simple absence of an agreement. Calendly's customer terms require you to warrant that your data does not contain protected health information or information subject to HIPAA. In other words, by using Calendly you are actively promising there is no patient information in it. A practice booking patients through Calendly is not merely unprotected; it is contradicting the terms it agreed to, and no plan tier, including Enterprise, changes that.
The security accreditations Calendly publishes cause a lot of the confusion. SOC 2, ISO 27001 and PCI describe how well Calendly runs its infrastructure. None of them is a statement about HIPAA, and none creates an agreement with your practice.
If you want to keep Calendly for something legitimate, such as vendor meetings or interviews, then strip it back properly: remove any question that could reveal a condition, a reason for visit, a medication, insurance or a treating provider; do not connect it to a calendar whose event titles pair patient names with why they are coming in; and keep it away from your clinical systems entirely.
How organizations get this wrong
The specific mistakes we see with Calendly, not generic advice.
- Keeping a reason-for-visit question on the booking form because the clinician finds it useful preparation before the appointment.
- Connecting Calendly to a practice calendar whose event titles already pair a patient's name with what they are being seen for.
- Buying middleware advertised as making Calendly safe for patient bookings, which creates no agreement between your practice and Calendly.
- Pointing at Calendly's SOC 2 and ISO 27001 badges as evidence of coverage when Calendly makes no HIPAA representation anywhere.
What the agreement does not cover
- Every Calendly plan, including Enterprise — no agreement is offered on any tier.
- Calendly's Customer Terms require you to warrant that your data does not contain protected health information or information subject to HIPAA.
- Calendly's security pages list SOC 2, ISO 27001 and PCI accreditations of its infrastructure but make no HIPAA representation.
- Third-party middleware marketed as making Calendly compliant does not create an agreement between your practice and Calendly.
Use instead
Listed on merit. We take no payment for placement and use no affiliate links.
Google Calendar appointment scheduling
Calendar is named on Google's Included Functionality list, so booking falls under the Workspace amendment
Purpose-built scheduling that offers an agreement on a specific plan tier
You just found one. What else is in your stack?
If Calendly was a surprise, it is rarely the only one. Most small organizations are running fifteen to thirty tools and have written agreements with a handful of them. A vendor register tracks which of yours touch patient information, which have a signed agreement, when each expires and who owns it — and exports as part of the evidence pack when a client asks.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Calendly’s own published documentation, read on the date shown.
- Customer Terms and Conditions — Calendly. Published June 1, 2026. Read July 29, 2026.
- Calendly Platform Security and Compliance — Calendly. No publication date given. Read July 29, 2026.
- Your privacy and security — Calendly. No publication date given. Read July 29, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Calendly’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.