Choosing a video platform for a clinic is a procurement decision with a legal tail attached to it. The evidence base for virtual care itself is settled enough at this point: an AHRQ review of the field found that clinical outcomes hold up well against in-person care, drawing on 58 systematic reviews and more than 950 telehealth studies. What is not settled is which vendor will actually put its name on a Business Associate Agreement, on which plan, and at what price. We spent several weeks going through vendor documentation, plan pages, and compliance terms for the platforms healthcare buyers keep short-listing. Below are six that hold up, ranked on how well they fit the way clinics really work rather than on brand recognition.
What “HIPAA compliant” actually means for a video platform
There is no such thing as a HIPAA-certified video product. HIPAA compliance is a property of your organization and your configuration, not a badge a vendor earns once and keeps forever. A platform can support compliance or make it impossible, but the covered entity remains on the hook. Four terms carry most of the weight in a buying conversation.
HIPAA compliance. For a video platform, this means the vendor applies the administrative, physical, and technical safeguards the Security Rule expects to any protected health information that passes through the service, and that your own use of the product stays inside those safeguards. Turning on a public join link and recording a session to an unsecured shared drive will break compliance on a platform that is otherwise perfectly capable of supporting it.
Business Associate Agreement. A BAA is the contract that makes a vendor legally accountable for the PHI it handles on your behalf. If a vendor will not sign one, the product cannot be used for patient care involving PHI, no matter how good the encryption is. This is the first question to ask and the one that eliminates the most candidates. Several major platforms offer a BAA only on specific paid tiers, and a few cap the number of licenses the standard agreement covers.
End-to-end encryption. Encryption in transit protects a session as it crosses the network; encryption at rest protects recordings and transcripts once they land. The distinction matters because the two are often sold as one feature. Federal regulators have moved in the direction of treating encryption as non-negotiable rather than optional, and in a proposed update to the Security Rule the Department of Health and Human Services wrote that expressly requiring regulated entities to encrypt ePHI, with limited exceptions, would reflect its expectations in the current cybersecurity environment. Read any vendor’s encryption claim closely enough to know which of the two it is describing, and whether recordings are included.
Telehealth visits versus internal clinical meetings. These are two different products in practice even when they are sold as one. A patient-facing virtual visit needs to work for a 74-year-old on a hotel Wi-Fi connection with no account and no app. An internal case review needs capacity, screen sharing, and calendar integration. Medicare’s own rules point at the first use case specifically: CMS states that a provider must use an interactive system with audio and video that permits real-time communication between the distant site and the patient at home. Platforms that force a download before the patient can be seen tend to fail that requirement in practice, through no-shows rather than through technical incapacity.
Access safeguards. Virtual waiting rooms, meeting locks, unique join codes, host-only permissions, and audit trails. These are the controls that stop the wrong person from walking into a session. They are also the controls most often missing from the free tier of a platform whose paid tier has them.
How we compared these six platforms
We limited the list to platforms that will actually execute a Business Associate Agreement with a US covered entity, and we verified each claim against the vendor’s own current documentation rather than against secondary roundups. Compliance claims carry legal exposure, so anything we could not find in writing on the vendor’s site is described here as not published rather than assumed. Ratings come from Capterra and are reported as plain figures with their review counts, because a 4.6 drawn from 27 reviews and a 4.6 drawn from 14,611 reviews are not the same signal. Pricing reflects list pricing at the time of writing. We also weighted patient-side friction heavily: whether a patient can join from a browser link without installing anything or creating an account.
Comarison at a Glance
| Platform | Best for | Signed BAA | Patient joins in a browser | Starting price |
| FreeConference | Small practices running one-to-one virtual visits | Yes, included in the Healthcare Secure Plan | Yes, no download | $49.99 per month, flat |
| Doxy.me | Solo clinicians and small behavioral health practices | Yes, at no cost for individual providers | Yes | A free version; $10 day pass for premium features |
| Zoom Workplace | Practices already standardized on Zoom | Yes, online BAA covers up to nine US licenses | Browser join available, app usually prompted | $14.99 per user, per month |
| Webex Suite | Large health systems already running Cisco | Yes, initiated with Cisco | Browser join available | $0 per user per year on the entry tier; $25 per user, per month for the Suite |
| Microsoft Teams | Organizations standardized on Microsoft 365 | Yes, by default through the data protection addendum | Yes, guest browser join | $7.00 per user per month, paid yearly |
| Google Meet | Organizations already on Google Workspace | Yes, accepted by an administrator in the Admin console | Yes | $8.40 per user per month |
The Six Platforms in Detail
1. FreeConference
Flat pricing is the unusual thing here. Where nearly every other vendor on this list charges per seat and then gates the BAA behind a specific tier, the Healthcare Secure Plan is a single monthly line item that includes the signed agreement. That structure suits a two-provider practice far better than it suits a hospital, and the two-provider practice is roughly where this product sits.
What you get
- A signed Business Associate Agreement included with the plan, described by the vendor as formalizing your HIPAA compliance
- End-to-end encryption applied to video, audio, screen shares, and chat
- Telehealth-specific access controls: virtual waiting rooms, meeting locks, unique codes, participant limits, and host permissions
- Audit trails showing who joined, when, and from where, plus secure recording and transcription
BAA status: Offered and included in the Healthcare Secure Plan, per the vendor’s own healthcare page.
Rating: 4.6 out of 5 on Capterra, from 27 reviews.
Pricing: $49.99 per month for the Healthcare Secure Plan, with capacity for up to 100 call participants and up to 5 web participants.
Where it falls short: That 5-web-participant ceiling is a hard limit, and it is the reason this belongs in the patient-visit column rather than the internal-meetings column. A department running a weekly case conference with a dozen clinicians on video will hit the wall immediately. The review base is also thin. Twenty-seven reviews tell you much less than eleven thousand do, and buyers who weight social proof heavily should factor that in.
2. Doxy.me
Built for telehealth first, with almost nothing else bolted on. The patient experience is a link, a browser, and a waiting room, which is the shortest path from appointment reminder to visit that anyone on this list offers. The trade-off is that everything outside the visit itself, including scheduling and documentation, has to live somewhere else.
What you get
- A virtual waiting room and patient queue as the core workflow rather than an add-on
- Unlimited calls, chat, screen sharing, and file transfer on the paid tier
- Group calls for up to 25 participants
- A usable free version aimed at providers who see occasional virtual patients
BAA status: Offered at no cost. The vendor’s help documentation states that all doxy.me users get a free Business Associate Agreement, generated from the account settings. Note the limit: the standard agreement covers individual providers, and organizations with multiple providers are directed to request a clinic BAA through support.
Rating: 4.6 out of 5 on Capterra, from 1,227 reviews.
Pricing: A free version is available. The premium tier is billed per user per month with annual billing, but the figure is not published on the pricing page. A $10 day pass unlocks premium features for 24 hours, which is a genuinely useful way to test it.
Where it falls short: Unpublished pricing is a real friction point for a practice manager building a budget, and the individual-provider default on the BAA catches multi-clinician groups out. The 25-participant cap also rules it out for anything resembling a departmental meeting.
3. Zoom Workplace
Most practices that end up on Zoom did not choose it for telehealth. They already had it, a clinician started using it for visits, and compliance caught up afterward. That is a common and mostly workable path, provided somebody actually executes the agreement, because the free Basic tier does not carry one.
What you get
- Meetings of up to 30 hours on paid plans, with 100 participants on Pro and 300 on Business
- Browser-based join as an option, though the client is prompted first in most flows
- Recording, transcription, and a large integration catalog including major EHR vendors
- An online BAA process that a small practice can complete without a sales call
BAA status: Offered. Zoom states that it helps customers enable HIPAA-compliant programs by executing a Business Associate Agreement and safeguarding protected health information. The self-serve route has a documented ceiling: the online BAA covers up to nine licenses in the US, on a paid plan, and larger deployments go through the sales team.
Rating: 4.6 out of 5 on Capterra, from 14,611 reviews.
Pricing: $14.99 per user, per month for Pro. The free Basic tier caps group meetings at 40 minutes and does not support a BAA.
Where it falls short: The patient-side experience is the weak point. Zoom pushes the installed client hard, and every extra step between a text-message link and a visible patient face costs you appointments. The nine-license ceiling on the self-serve agreement also arrives sooner than most growing practices expect.
4. Webex Suite
Cisco’s position in this category comes from the network side rather than the telehealth side. If your health system already runs Cisco infrastructure and has a security team that speaks in terms of TLS and SRTP, Webex fits into an existing review process with very little argument.
What you get
- Media encryption using Secure Real-Time Transport Protocol, with client-to-cloud traffic protected by Transport Layer Security
- A HIPAA self-assessment that Cisco has conducted across Webex Meetings, Webex Teams, Control Hub, and Webex for Developers
- Up to 1,000 attendees on the enterprise tier
- Administrative depth: Control Hub gives security teams the logging and policy controls they usually ask for
BAA status: Offered. Cisco documents a BAA process for healthcare customers and publishes its HIPAA self-assessment scope, and organizations initiate their own agreement with Cisco.
Rating: 4.4 out of 5 on Capterra, from 7,410 reviews.
Pricing: The entry tier is listed at $0 per user per year with a 40-minute meeting limit and up to 100 attendees. The Suite is listed from $25 per user per month. Enterprise pricing is quoted by the sales team.
Where it falls short: It is the heaviest product here, and reviewers consistently flag performance on older hardware, which is exactly the hardware sitting in a lot of exam rooms. For a solo therapist seeing patients from a laptop, this is far more platform than the job requires.
5. Microsoft Teams
The interesting fact about Teams in a healthcare context is contractual rather than technical. Microsoft extends its HIPAA Business Associate Agreement through the Online Services Data Protection Addendum by default to all customers who are covered entities or business associates, and Teams sits inside the in-scope service list. So for an organization already paying for Microsoft 365, the agreement is generally already in place.
What you get
- Coverage under the Microsoft HIPAA BAA as an in-scope service, alongside Exchange Online, SharePoint, and OneDrive
- Guest access that lets an external participant join from a browser without a Microsoft account
- Native integration with the Microsoft 365 identity, device, and data-loss-prevention stack
- Meeting lobbies, recording controls, and retention policies managed centrally
BAA status: Offered and included by default rather than requested. Microsoft’s compliance documentation states that the BAA is available through the Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA.
Rating: 4.5 out of 5 on Capterra, from 11,055 reviews.
Pricing: From $7.00 per user per month, paid yearly, on Microsoft 365 Business Basic. Higher tiers run to $23.50 and $32.00 per user per month with Copilot included.
Where it falls short: Teams was designed for employees, not patients. The guest join path works, but it presents an interface built around a corporate meeting, and it assumes a level of comfort with software that a lot of patients do not have. Practices also inherit the full Microsoft 365 administrative surface, which is a great deal of configuration to get right when all you wanted was a video visit.
6. Google Meet
Meet earns its place through the browser. There is no client to install, the join flow is a link, and it works on almost anything with a camera. The compliance side is well documented rather than merely implied: Google Meet appears by name on Google’s HIPAA Included Functionality list, most recently updated in May 2026.
What you get
- Browser-first join with no download, on desktop and mobile
- Meeting capacity that scales by edition: 100 participants on Business Starter, 150 on Standard, 500 on Plus
- Host controls, recording on higher editions, and central administration through the Admin console
- Coverage under Google’s BAA alongside Gmail, Drive, Calendar, and Chat
BAA status: Offered. Google requires customers subject to HIPAA who want to use covered services to enter a Business Associate Agreement, which a super administrator reviews and accepts in the Admin console under Account settings, then Legal and compliance. Administrators must accept it before any PHI goes into Google services.
Rating: 4.5 out of 5 on Capterra, from 12,155 reviews.
Pricing: $8.40 per user per month for Business Starter, $16.80 for Business Standard, and $26.40 for Business Plus.
Where it falls short: The BAA is an administrative action that somebody has to actually take, and in smaller organizations it is routinely assumed to be handled when nobody has opened the Admin console. Recording is also absent from the entry edition, which matters for practices that document sessions. Meet is a strong general-purpose tool with no telehealth-specific workflow, so waiting rooms and patient queues have to be improvised.
Matching the platform to the visit type
The mistake we see most often is buying one platform for two jobs that pull in opposite directions.
For patient-facing visits, the deciding factor is rarely the feature list. It is whether the patient arrives. A link that opens in whatever browser the patient already has, with no account creation and no app store detour, converts a scheduled appointment into a completed one far more reliably than any amount of functionality behind an install prompt. FreeConference, Doxy.me, and Google Meet are the three here that treat browser join as the default rather than the fallback. Add a virtual waiting room and a meeting lock, and you have covered the realistic risk of someone joining a session they should not be in.
Internal clinical meetings pull the other way. Case reviews, tumor boards, and multidisciplinary rounds need capacity, dependable screen sharing for imaging, calendar integration, and recording with a retention policy attached. Teams and Webex are built for this and are usually already paid for. Google Meet handles it competently once you are past the entry edition. FreeConference is not the right tool for it, and its own capacity numbers say so.
There is a third pattern worth naming, because it does not look like either of the first two. In conversations with buying teams over the past year, a recurring inquiry came from an organization that was not a clinic at all: a pharmacy program running 340B patient onboarding, which needed to hand a patient off into a video conversation with a telehealth provider partway through an intake flow. That buyer is not comparing meeting features. They are asking whether the video piece can be dropped into an existing workflow without asking the patient to install anything, and whether the vendor will sign. If that describes your situation, weight the BAA terms and the browser-join behavior above everything else on the spec sheet, and treat capacity as almost irrelevant.
A short compliance checklist before you sign
Work through these before the contract, not after the pilot.
- Get the BAA in writing, and read which plan it applies to. Several vendors here offer it only on paid tiers, and at least one caps the number of licenses the self-serve agreement covers. Confirm the tier you are actually buying is the tier the agreement names.
- Ask what happens to recordings and transcripts. Encryption in transit is common. Encryption at rest, retention periods, and deletion on request vary widely, and recordings are where PHI accumulates fastest.
- Check the access safeguards individually. Waiting room, meeting lock, unique join code, host-only screen share, and an audit log. Many platforms have four of the five, and the missing one is usually the audit log.
- Test the patient path on a phone, on cellular data, with a fresh browser. Not on your own laptop with the app already installed. The gap between those two experiences is where no-shows come from.
- Ask where the data lives. Data residency commitments differ by vendor and by plan, and this is the question most likely to be answered vaguely on a first sales call.
- Confirm who is responsible for configuration. A compliant platform that is misconfigured is a non-compliant deployment, and the covered entity carries that risk, not the vendor.
One more piece of practical advice from watching these purchases: ask the vendor what happens if you downgrade. Buying teams ask about capacity and about downgrade behavior more often than they ask about anything else, and the answers are frequently missing from public documentation. If a practice drops from a paid plan to a free one, does the BAA survive, do recordings remain accessible, and does the waiting room disappear? Get that in writing too.
Frequently asked questions
Is Zoom HIPAA compliant?
Zoom can support HIPAA compliance, but only on a paid plan with an executed Business Associate Agreement, and only if configured correctly. The free Basic tier is not covered. Zoom’s self-serve online BAA covers up to nine licenses in the US; larger deployments go through the sales team. No video platform is HIPAA-compliant by itself.
Which of these platforms will sign a BAA?
All six. The differences are in terms and cost. Microsoft includes it by default through its Data Protection Addendum. Google requires an administrator to accept a Business Associate Amendment in the Admin console. Doxy.me provides one at no cost, though the standard version covers individual providers rather than organizations. FreeConference includes it in the Healthcare Secure Plan. Zoom offers a self-serve agreement up to nine licenses. Cisco documents a BAA process for Webex customers.
Can patients join a secure video visit without downloading an app or creating an account?
Yes, on several of these. FreeConference, Doxy.me, and Google Meet all support browser-based joining with no install. Microsoft Teams supports guest browser join. Zoom and Webex both offer a browser path, but each pushes the installed client first, which adds friction for older or less technical patients.
Is end-to-end encryption required by HIPAA?
The Security Rule has historically treated encryption as an addressable implementation specification rather than a flat requirement, which means a covered entity has to implement it or document why an equivalent alternative is reasonable. That posture is tightening. The proposed Security Rule update from the Department of Health and Human Services would expressly require encryption of ePHI with limited exceptions. Treat encryption as expected rather than optional.
Does a signed BAA make my practice compliant?
No. A BAA is necessary but not sufficient. Compliance is a function of the agreement plus your configuration plus your staff behavior. Public join links, recordings saved to personal drives, and shared host credentials will create a violation on a fully capable platform.
The Bottom Line
There is no single correct answer here, and any roundup that gives you one is selling something. If your organization already pays for Microsoft 365 or Google Workspace, the agreement is likely already available to you and the cheapest correct answer is probably the platform you own. If you run a large system on Cisco, Webex will clear your security review with the least friction. If you are a solo clinician who sees a handful of virtual patients a week, the free version of a purpose-built telehealth tool is genuinely enough.
The gap in the market sits with the small practice that has outgrown a free tool but has no interest in per-seat enterprise licensing and no IT department to configure it. If secure video conferencing for healthcare with a signed BAA, browser-based patient access, and flat monthly pricing is what you are shortlisting for a small clinic, FreeConference is built around that exact buyer, with the waiting rooms, meeting locks, and audit trails included rather than sold as an upgrade. Just check the capacity numbers against how you actually meet before you sign.
Whichever way you go, verify the compliance claim against the vendor’s current documentation yourself, on the day you buy. Terms change, plans get renamed, and the version of the truth in a comparison article is only ever as fresh as the day it was written.