Is Whereby HIPAA compliant?
Yes, but only on the Whereby Embedded platform with a signed agreement and the documented configuration — the compliance offering is aimed at products that embed video, not at teams looking for a meeting app.
Applies to Whereby Embedded. Last reviewed against Whereby's own documentation. Next review February 13, 2027.
Reviewed by Carlos Mendez — IT Security Manager, regional healthcare network.
What you must do
- Use Whereby Embedded, not the ordinary meeting product. HIPAA compliance is included at no additional cost on the Embedded Enterprise plan and sold as a paid add-on on the self-serve Build plan; the free Explore tier has no route to it.
- Sign the agreement before launch. Whereby's own line is 'in order to be fully HIPAA compliant you must sign a BAA with us' — reach out to your Whereby contact for the ready-to-sign document, or have Whereby's legal team review yours.
- Apply the documented room configuration: rooms locked at creation, room names generated as UUIDs so URLs cannot leak who is meeting whom, and streaming and room integrations disabled.
- Store recordings in your own S3 bucket. Whereby's setup guide requires recordings to land in storage your organization manages, not Whereby's.
Does Whereby sign a business associate agreement?
Yes. Whereby offers one. Embedded Enterprise (included), or the Build plan with the HIPAA compliance add-on. Not available on the free tier. Through your Whereby contact, who provides the ready-to-sign agreement; Whereby will alternatively review a customer-supplied agreement.
What this means in practice
Whereby's compliance offering is aimed at builders, not at practices looking for a meeting app. It lives on the Embedded platform — the API product teams use to put video inside their own telehealth application — where it is included on Enterprise and available as a paid add-on on the self-serve Build plan. If you came here comparing meeting tools, the honest answer is that this is the wrong shelf.
For builders, the documentation is unusually prescriptive, and following it is the compliance work: rooms created locked, room names generated as UUIDs so a URL never encodes who is meeting whom, streaming and integrations disabled, and cloud recordings written to an S3 bucket your organization controls. The storage rule is the sharpest line any vendor in this category draws — any feature using Whereby's own storage is stated not to be HIPAA compliant, full stop.
The agreement itself is signed through your Whereby contact, and Whereby will review a customer-supplied version — rare flexibility. But signing without the room configuration is a false comfort: a telehealth product minting guessable room names has a disclosure problem no agreement fixes.
How organizations get this wrong
The specific mistakes we see with Whereby, not generic advice.
- Choosing Whereby as a practice meeting tool, when the compliance capability exists on the Embedded developer platform rather than the meeting product.
- Letting recordings default to Whereby-provided storage, which Whereby states is not HIPAA compliant for any feature that uses it.
- Minting readable room names like drsmith-jones-followup, which leak who is meeting whom in every URL and calendar entry.
- Signing the agreement on the Build plan but skipping the add-on, or skipping the documented room configuration, and treating the signature as the whole job.
What the agreement does not cover
- Any feature that uses Whereby-provided storage — Whereby states flatly that none of it is considered HIPAA compliant.
- Live streaming over RTMP and third-party room integrations such as Miro and YouTube.
- The free Explore plan, and local recordings, which remain your own responsibility wherever they end up.
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with Whereby, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Whereby’s own published documentation, read on the date shown.
- HIPAA compliant setup — Whereby. Published May 1, 2023. Read August 30, 2026.
- Whereby Embedded Pricing — Whereby. Published August 13, 2026. Read August 30, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Whereby’s published documentation as read on August 30, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.