Is FaceTime HIPAA compliant?
No — Apple publishes no business associate agreement for FaceTime, and the COVID-era enforcement discretion that once let providers use it for telehealth expired on August 9, 2023.
Applies to FaceTime. Last reviewed against Apple's own documentation. Next review February 26, 2027.
Reviewed by Carlos Mendez — IT Security Manager, regional healthcare network.
If you keep using it anyway
- If FaceTime is ever used, treat it as an emergency fallback and document why — the regulatory permission that made it defensible ended in 2023, and nothing has replaced it.
- Do not rely on the end-to-end encryption argument. Apple's own privacy disclosure describes a consumer service; encryption in transit does not create the agreement HIPAA requires with a vendor that is more than a conduit.
- Move scheduled visits to a vendor that will sign — the current HHS position is that providers must use vendors that 'will enter into HIPAA business associate agreements in connection with the provision of their video communication products'.
Does FaceTime sign a business associate agreement?
Apple does not offer one. Not applicable. Apple publishes no agreement for FaceTime; its only published HIPAA agreement covers the Health Records Share with Provider program.
What this means in practice
FaceTime's reputation as acceptable for telehealth is a leftover from an emergency that ended. During COVID, OCR published an enforcement discretion naming FaceTime among consumer video apps it would tolerate for telehealth; that discretion expired on August 9, 2023, and nothing has replaced it. Since then FaceTime has been what it always was underneath: a consumer service with no agreement available, from a vendor whose FaceTime privacy disclosure never mentions HIPAA at all.
The encryption argument deserves a direct answer because it is the one clinicians actually make. FaceTime is end-to-end encrypted and Apple says it never stores call content — and none of that substitutes for the agreement HIPAA requires. Encryption is one factor in a risk analysis; the missing agreement is the missing thing, and Apple offers none for FaceTime on any tier. The only HIPAA agreement Apple publishes anywhere is scoped to the Health app's Share with Provider program.
The practical shape of the problem is the unscheduled call: a patient FaceTimes the clinician's personal iPhone, or a visit is running late and FaceTime is the path of least resistance. The fix is having the covered fallback already installed — a doxy.me room link or a Doximity dialer call costs the same thirty seconds.
How organizations get this wrong
The specific mistakes we see with FaceTime, not generic advice.
- Citing the COVID-era flexibility as if it were current, when OCR's discretion expired on August 9, 2023.
- Treating end-to-end encryption as the compliance answer, when the missing business associate agreement is the actual gap.
- Accepting inbound patient FaceTime calls on personal devices because declining feels rude, instead of redirecting to the covered channel.
- Assuming Apple's healthcare work implies coverage — its only published agreement is scoped to Health Records sharing, not FaceTime.
What the agreement does not cover
- Everything. Apple's FaceTime privacy disclosure makes no HIPAA representation and offers no agreement on any Apple product tier.
- The one agreement Apple does publish — for the Health app's Share with Provider program — is scoped to that program and does not extend to FaceTime.
- The old safe harbor: OCR's enforcement discretion named FaceTime among consumer video apps tolerated 'during the COVID-19 nationwide public health emergency', and HHS states that discretion expired at 11:59 p.m. on August 9, 2023.
Use instead
Listed on merit. We take no payment for placement and use no affiliate links.
The closest like-for-like replacement: a browser link the patient clicks, with a free self-serve agreement
Where the practice wants one meetings product for both staff and patient visits
For clinicians who reach patients from a personal device and need the practice number shown instead
You just found one. What else is in your stack?
If FaceTime was a surprise, it is rarely the only one. Most small organizations are running fifteen to thirty tools and have written agreements with a handful of them. A vendor register tracks which of yours touch patient information, which have a signed agreement, when each expires and who owns it — and exports as part of the evidence pack when a client asks.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Apple’s own published documentation, read on the date shown.
- FaceTime & Privacy — Apple. Published December 12, 2025. Read August 30, 2026.
- Notification of Enforcement Discretion for Telehealth Remote Communications During the COVID-19 Nationwide Public Health Emergency — HHS Office for Civil Rights. No publication date given. Read August 30, 2026.
- HIPAA and Telehealth — HHS Office for Civil Rights. Published April 12, 2023. Read August 30, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Apple’s published documentation as read on August 30, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.