CompyMax

Is GoTo Meeting HIPAA compliant?

Yes, with a signed agreement

Yes — GoTo's business associate addendum is published as a standing legal document that takes effect simply by using the services after its publication, and GoTo sells a dedicated Healthcare plan with recording and chat switched off.

Applies to GoTo Meeting. Last reviewed against GoTo's own documentation. Next review February 6, 2027.

Reviewed by Carlos Mendez — IT Security Manager, regional healthcare network.

What you must do

  • Buy the GoTo Meeting for Healthcare plan, which GoTo describes as 'HIPAA compatible and tailored for our customers in the healthcare industry' in conjunction with the addendum. It is currently only available in North America.
  • Understand how the addendum executes: GoTo states it is effective when a customer 'enters into an Agreement or signs an Order that has incorporated this BAA into its terms, or uses the Services after its publication to GoTo's website'. Keep a copy of the published version (July 2025, 2025.v1.1) for your file.
  • Accept the feature trade-off. The Healthcare plan's own feature chart lists recording and chat as not available — that removal is the compliant configuration, not a limitation to work around.
  • Carry your share: the addendum states the customer 'is solely responsible for its compliance with HIPAA' and for 'using the Services only in a manner that complies with HIPAA'.

Does GoTo Meeting sign a business associate agreement?

Yes. GoTo offers one. GoTo Meeting for Healthcare, North America only. The addendum itself is published as part of GoTo's standard terms. Nothing to request — GoTo's addendum is self-executing through the published terms. A countersigned sample is available through GoTo's trust resource center for practices that need a document on file.

See their documentation.

What this means in practice

GoTo took the friction out of the paperwork and moved it into the product. The addendum is published on GoTo's own site and executes when you use the services after its publication — no signature chase, no sales gate on the legal document itself. What you buy instead is the Healthcare plan, which is the compliant configuration in product form: recording is off, chat is off, and that removal is the point rather than a limitation.

This inverts the usual failure. Elsewhere, practices have the product and lack the agreement; here the agreement is easy and the trap is running patient visits on an ordinary GoTo Meeting plan where recording and chat are live. The Healthcare plan is also North America only, which multi-region organizations need to know before standardizing on it.

Read the addendum's own allocation of work: the customer is solely responsible for using the services in a way that complies with HIPAA, and GoTo reserves the right to de-identify patient information and use it for its own business purposes. Neither is unusual; both belong in your vendor file rather than discovered later.

How organizations get this wrong

The specific mistakes we see with GoTo Meeting, not generic advice.

  • Running patient visits on a standard GoTo Meeting plan because the addendum technically covers the account, when the Healthcare plan's disabled recording and chat are the compliant configuration.
  • Having nothing on file when an auditor asks, because the self-executing addendum meant nobody ever downloaded a copy.
  • Standardizing a multi-region organization on the Healthcare plan without noticing it is only sold in North America.
  • Missing the de-identification clause, which lets GoTo use de-identified patient information for its own purposes.

What the agreement does not cover

  • Meeting recordings and in-meeting chat — the Healthcare plan disables both rather than covering them.
  • Customers outside North America, where the Healthcare plan is not sold.
  • De-identified data: the addendum reserves GoTo's right to de-identify patient information and use it for GoTo's legitimate business purposes.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Zoom

    The default in this category, where the agreement rides on a paid tier rather than the published terms

  • Doxy.me

    Where the requirement is patient visits specifically rather than general-purpose meetings

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with GoTo Meeting, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from GoTo’s own published documentation, read on the date shown.

  1. Business Associate AddendumGoTo Technologies. Published July 1, 2025. Read August 30, 2026.
  2. Plan Overview: GoTo Meeting for HealthcareGoTo Support. No publication date given. Read August 30, 2026.
  3. Is GoTo Meeting HIPAA compliant?GoTo Support. Published May 28, 2026. Read August 30, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects GoTo’s published documentation as read on August 30, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.