No. Loom’s own help center says Loom “currently is not able to sign Business Associate Agreements” and asks customers not to send it personal health information if that would break their HIPAA obligations. Atlassian, which owns Loom, offers a BAA for some of its cloud products. Loom isn’t one of them.
Here’s what that means if your team records screens that might show patient data, and what to check before you choose a replacement.
Quick answer: Loom doesn’t support HIPAA workloads
The sources, and the dates we checked them, are at the end of this article.
- Loom can’t sign a Business Associate Agreement (BAA). Its own help article says so.
- Without a BAA, a covered entity can’t let a vendor create, receive, maintain or transmit protected health information (PHI) on its behalf.
- Atlassian’s BAA covers Jira, Confluence Cloud, Jira Service Management, Rovo and Jira Product Discovery. Loom isn’t on the list.
- Encryption and security certifications don’t replace the agreement. HIPAA asks for the BAA itself.
Why the BAA decides it
Under the HIPAA Privacy Rule, a covered entity may let a business associate “create, receive, maintain, or transmit protected health information on its behalf” only after getting satisfactory assurance that the information will be safeguarded (45 CFR 164.502(e)(1)). Those assurances “must be documented through a written contract or other written agreement” (45 CFR 164.502(e)(2)). That written agreement is the BAA.
A video platform that stores screen recordings becomes a business associate as soon as a recording shows PHI: a chart in the EHR, a scheduling screen, a lab result, an insurance form. If the vendor won’t sign a BAA, that recording can’t be stored there.
Does Atlassian’s BAA cover Loom?
No. Atlassian’s HIPAA compliance page lists the products its BAA covers: Jira, Confluence Cloud, Jira Service Management, Rovo and Jira Product Discovery, on Standard, Premium or Enterprise plans. Loom isn’t among them, and Loom’s own article still says it can’t sign a BAA.
A BAA covers the products it names. Having one for Jira or Confluence doesn’t extend it to Loom, even when the same Atlassian organization pays for both.
What it means for a healthcare team using Loom today
This isn’t legal advice. Your privacy officer decides what counts as PHI in your workflows and which vendors may hold it.
- Don’t record screens that show PHI: EHR charts, patient portals, scheduling, billing or claims screens.
- Plan for what a screen recording catches by accident: a notification, a second monitor, a browser tab with a patient’s name. A “no PHI” rule has to cover those too.
- Review existing libraries for recordings that already contain PHI, and agree with your privacy or compliance owner how to handle them.
- If your policy allows Loom for content with no PHI, write that line down so recorders know where it is.
What to check in a HIPAA-ready screen recorder
| Check | Why it matters | What to ask the vendor |
|---|---|---|
| A signed BAA | Required before the tool can hold PHI | Which plan includes it, and who signs it? |
| Access control on every link | Sharing a link is a disclosure | Can links be limited to named people or your organization, and revoked? |
| Retention and deletion | PHI shouldn’t sit in a video library forever | Can admins set retention, and what does deletion remove? |
| Redaction before sharing | Recordings capture more than you meant to show | Can recorders blur a region before the link goes out? |
| Admin control | Offboarding has to remove access everywhere | Is there SSO, SCIM provisioning and group-based permissions? |
| Storage | Your security review will ask where recordings live | Where is data stored, and can you bring your own storage? |
Where Zight fits
Zight is HIPAA compliant on the Scale plan, with a signed BAA available. Scale also adds SSO and SCIM with group-based permissions, and custom data retention with S3 storage. Compare plans.
Recorders can blur regions before sharing, and viewers watch in a browser without a Zight account. With request links, a colleague or customer can record their own screen and send it back without installing anything.
A BAA doesn’t make every recording compliant. Your configuration and policy still decide what may be captured and who can see it. See how healthcare teams use Zight, or compare healthcare screen recorders.
Moving recordings off Loom
If you’re leaving Loom, save what you need before you change plans. Our guide to cancelling a Loom subscription covers ownership, download eligibility and links. For a side-by-side view, see Zight vs Loom.
Don’t move a recording that contains PHI into any tool until that tool’s BAA is signed and the workflow is approved.
Frequently asked questions
Is Loom HIPAA compliant in 2026?
No. When we checked on October 6, 2026, Loom’s help article said it can’t sign Business Associate Agreements, and it asks customers not to send it PHI where that would break their HIPAA obligations.
Does Atlassian’s BAA cover Loom?
No. Atlassian’s BAA covers Jira, Confluence Cloud, Jira Service Management, Rovo and Jira Product Discovery. Loom isn’t listed.
Can I use Loom if I blur patient information?
Blurring reduces what a recording shows, but the raw recording still passed through Loom before you edited it. Without a BAA, the safe policy is to keep PHI out of Loom entirely. Your privacy officer makes the call.
Which Zight plan includes a BAA?
Scale. Zight is HIPAA compliant on the Scale plan, with a signed BAA available.
Sources
Atlassian Support, “Is Loom HIPAA Compliant?”, checked October 6, 2026.
Atlassian Trust Center, HIPAA compliance, checked October 6, 2026.
45 CFR 164.502(e), disclosures to business associates, via Cornell Law School’s Legal Information Institute, checked October 6, 2026.