Is WhatsApp HIPAA Compliant?

What WhatsApp's end-to-end encryption does — and does not — mean for healthcare messaging compliance.

Get started for free
No

No. Meta explicitly states that WhatsApp is not HIPAA compliant and will not sign a Business Associate Agreement. Using WhatsApp for protected health information violates HIPAA regardless of its end-to-end encryption.

Why?

Meta will not sign a BAA

Meta's Cloud API Hosting Terms state that Meta is not a Business Associate and that WhatsApp is not HIPAA compliant. Without a BAA, any transmission of PHI through WhatsApp violates HIPAA.

Source: Meta Cloud API Hosting Terms (HIPAA disclaimer)

No audit trail

HIPAA requires that covered entities maintain logs of who accessed PHI and when. WhatsApp provides no admin-accessible audit trail for organizational messaging.

Source: HHS HIPAA Security Rule

Encryption alone does not satisfy HIPAA

WhatsApp uses the Signal Protocol for end-to-end encryption. But the HIPAA Security Rule requires administrative safeguards, access controls, audit logging, and breach notification procedures in addition to encryption. Penalties for HIPAA violations range from $141 to $2,134,831 per violation.

Source: HHS HIPAA Enforcement and Penalties

Metadata is not encrypted

WhatsApp encrypts message content but not metadata — who messaged whom, when, and how often. WhatsApp can use and share this metadata under its Terms of Service.

Source: Meta Cloud API Hosting Terms (HIPAA disclaimer)

What WhatsApp says

Meta's Cloud API Hosting Terms state that Meta is not a Business Associate and that the WhatsApp Business Platform is not HIPAA compliant. The WhatsApp Business Terms also disclaim suitability for entities with heightened confidentiality requirements.
Source: Meta Cloud API Hosting Terms (HIPAA disclaimer)

HIPAA-compliant alternatives

BloomText

Purpose-built HIPAA messaging with a signed BAA on every plan, including the free plan. Patients reply via SMS without downloading an app.

TigerConnect

Enterprise clinical messaging platform used by hospitals and health systems. Includes role-based routing and EHR integrations.

OhMD

Patient texting platform with EHR integrations, call-to-text, and website chat for practices that need broader patient communication tools.

Frequently Asked Questions

Is WhatsApp HIPAA compliant?

No. Meta explicitly states in its Cloud API Hosting Terms that WhatsApp is not HIPAA compliant and will not act as a Business Associate. Using WhatsApp for protected health information violates HIPAA regardless of its encryption.

Does Meta sign a BAA for WhatsApp?

No. Meta will not enter into a Business Associate Agreement for WhatsApp or WhatsApp Business. A signed BAA is required under HIPAA before transmitting PHI through any third-party service.

Can I use WhatsApp if a patient texts me first?

HIPAA allows patients to request communication through a specific channel. If a patient initiates and you document the request, responding on WhatsApp may be permissible — but best practice is to redirect the conversation to a HIPAA-compliant platform.

What happens if I send PHI on WhatsApp?

Sending PHI through WhatsApp without a BAA is a HIPAA violation. Penalties range from $141 to $2,134,831 per violation depending on the level of negligence, and criminal penalties can apply for knowing violations.

Sources

Last verified May 26, 2026.

  1. BloomText pricing
  2. Meta Cloud API Hosting Terms (HIPAA disclaimer)
  3. HHS HIPAA Security Rule
  4. HHS HIPAA Enforcement and Penalties

Need HIPAA-compliant messaging?

Get started for free

Trusted by today's leading healthcare professionals

Streamlined appointment schedulingWith BloomText Broadcast SMS Messaging, I literally took the job of 20 employees and I can do it by myself in three and a half hours.Chief Administrative Officer, Radiology
Best HIPAA app on the marketBloomText has brought our clinic into the modern age, and our patients love being able to communicate with us via text or through our website.Office Administrator, Family Medicine
Excellent for acute careBloomText is the nervous system for my business. It helps us differentiate ourselves in terms of our communication and our quality of care.Clinical Director, Acute Care