A client says "can we just FaceTime?" and it's a fair question — it's free, it's already on both your phones, and the calls are encrypted end-to-end. But for therapy sessions in 2026, the practical answer is no, FaceTime is not HIPAA-compliant — and the reason is worth understanding, because it's the same reason most consumer apps fail the test.
The problem isn't security — it's the BAA
HIPAA generally requires a signed Business Associate Agreement (BAA) with any company that transmits your clients' protected health information — and a video call carrying a therapy session qualifies. The BAA is the contract where the vendor accepts legal responsibility for protecting that data. Apple does not sign BAAs for FaceTime. There's no healthcare plan, no business tier, no paid upgrade that changes this. Without the agreement, the compliance chain is broken before the first call connects — regardless of how strong the encryption is. (This is the same test we apply to every tool in our video platform comparison.)
"But I heard FaceTime might be exempt" — the conduit argument
You may run into a technical argument that FaceTime qualifies for HIPAA's "conduit exception" — the carve-out for services that merely pass data through without storing it, like the postal service or an internet provider. Because FaceTime is end-to-end encrypted and Apple can't decrypt or store your sessions, some organizations have taken that position. It's not a fringe view — but it has never been clearly blessed by regulators for private practices, and compliance experts consistently recommend against relying on it. If your compliance position depends on winning a legal argument after a complaint is filed, it's not much of a compliance position.
Didn't this used to be allowed?
Briefly, yes — sort of. During the COVID-19 public health emergency, regulators announced they would not enforce penalties against providers using consumer video apps like FaceTime in good faith. Many therapists started using FaceTime then and simply never stopped. That enforcement discretion ended in 2023. The grace period is over, and the ordinary rules — BAA required — have been back in force for years now.
What could actually go wrong
- A complaint or audit. Using a tool with no BAA is a straightforward finding — there's no gray area to argue about, and penalties scale with how avoidable the violation was.
- Your liability insurance. Practicing outside HIPAA's requirements can complicate coverage if a privacy incident becomes a claim.
- The everyday leaks. FaceTime is tied to personal Apple IDs and phone numbers — client names and numbers end up in your personal contacts, call history, and iCloud, mingled with your personal life.
What to use instead
Any of these beat FaceTime for sessions: Zoom on an eligible healthcare plan with a signed BAA (see Does Zoom sign a BAA?), Google Meet on a paid Workspace plan with the BAA accepted (see our Google Meet guide), a purpose-built telehealth tool like Doxy.me — or a practice platform with telehealth built in. And whichever you choose, capture telehealth consent at intake.
The simpler path
The appeal of FaceTime was always "one tap, no setup." You can keep that convenience without the compliance risk: Theraflow attaches a secure video link to each appointment automatically — the client taps the link from a PHI-free reminder, you both join, and the session, notes, and consent all live in one place under one BAA, included in the flat $29.99/month plan.
Bottom line
Is FaceTime HIPAA-compliant for therapy? No. Apple won't sign a BAA, the pandemic-era leniency that made it tolerable ended in 2023, and the conduit-exception argument is a gamble no solo practice needs to take — especially when compliant alternatives cost little or nothing more.
Related reading: Is Zoom HIPAA-compliant for therapy?, HIPAA-compliant phone service for therapists and HIPAA-compliant telehealth for therapists.