Super admins and admins can enable/disable HIPAA Support. Managers and admins can mark registration form fields as ePHI/PII. Staff will not have access to this information.
The Health Insurance Portability and Accountability Act (including the Privacy Rule, Security Rule, Breach notification Rule, and Health Information Technology for Economic and Clinical Health Act) ("HIPAA"), requires
Covered Entities and Business Associates
to take certain measures to protect health information that can identify an individual. It also provides certain rights to individuals. Zoho does not collect, use, store or maintain health information protected by HIPAA for its own purposes. However, Zoho Bookings provides certain features (as described below) to help its customers use Zoho Bookings in a HIPAA compliant manner.
HIPAA requires Covered Entities to sign a Business Associate Agreement (BAA) with its Business Associates. You can request our BAA template by sending an email to
Zoho Bookings has provisions to protect ePHI. When collecting customer information (ePHI/PII), registration form fields can be set up for secure handling.
Below are what you can do with respect to HIPAA compliance inside Zoho Bookings:
- Enabling HIPAA
- Encrypting ePHI/PII
- Disabling HIPAA
- Click the Manage Business icon and select General.
- Click Privacy & Security. You can see the HIPAA Support section which is set to 'Disabled' by default. Click the toggle to enable HIPAA Support.
HIPPA Support is now
Encryption & Auditing
The data captured in registration form fields marked as ePHI/PII is
- encrypted at rest
- not shared outside Zoho Bookings (not even to other Zoho apps)
- masked while displayed anywhere inside the app
- audited continuously and monitored for activity
Data audits help you secure your customers' data and monitor for unexpected changes or usage trends. Zoho Bookings will record the audit logs–i.e., information about every addition, update, and deletion made to customer database records–in the backend for a duration of up to 1 year. The audit log can be shared with you only upon request.
: HIPAA support can be invoked only on
guest user fields
and on SingleLine, CheckBox, DropDown, Email, RadioButton, and Date
types only. HIPAA support cannot be invoked on
(Name, Email, and Contact Number) and on custom MultiLine field types, as of now.
To mark fields as ePHI/PII:
- Navigate to Manage Business > Workspaces > (select a workspace) > Booking Form. Edit the field (Blood Pressure, in this case) that would contain sensitive information.
Check Mark as ePHI/PII to denote that the field (Blood Pressure, in this case) would contain sensitive information and click Save.
The selected field is marked as ePHI/PII.
Encrypting Multiple Fields
HIPAA support can be invoked on more than one field. However, when you try to mark more than one field as ePHI/PII, you might receive an error message like the below.
This is because once a registration form field is marked as ePHI/PII, it takes some time in the backend to set it up. If another field is marked as ePHI/PII simultaneously while the setup for the first field is in progress, it might disrupt the setting altogether. To avoid this, it is advised to try marking the other field as ePHI/PII at a little while later.
Disabling HIPAA Support
Plans supporting this feature
Note: You can view all the pricing plans for Zoho Bookings here.