HIPAA Support

HIPAA Support

Super admins and admins can enable/disable HIPAA Support. Managers and admins can mark registration form fields as ePHI/PII. Staff will not have access to this information.


The Health Insurance Portability and Accountability Act (including the Privacy Rule, Security Rule, Breach notification Rule, and Health Information Technology for Economic and Clinical Health Act) ("HIPAA"), requires  Covered Entities and Business Associates  to take certain measures to protect health information that can identify an individual. It also provides certain rights to individuals. Zoho does not collect, use, store or maintain health information protected by HIPAA for its own purposes. However, Zoho Bookings provides certain features (as described below) to help its customers use Zoho Bookings in a HIPAA compliant manner.   


HIPAA requires Covered Entities to sign a Business Associate Agreement (BAA) with its Business Associates. You can request our BAA template by sending an email to  legal@zohocorp.com .


Zoho Bookings has provisions to protect ePHI. When collecting customer information (ePHI/PII), registration form fields can be set up for secure handling.


Below are what you can do with respect to HIPAA compliance inside Zoho Bookings:

  1. Enabling HIPAA
  2. Encrypting ePHI/PII
  3. Disabling HIPAA

Enabling HIPAA

  1. Click the Manage Business  icon and select General. 



  2. Click Privacy & Security. You can see the HIPAA Support section which is set to 'Disabled' by default. Click the toggle to enable HIPAA Support.



  3. HIPPA Support is now Enabled. 



Encrypting ePHI/PII

You can facilitate encryption and decryption on sensitive data for both new or existing custom registration form fields .

Encryption & Auditing

The data captured in registration form fields marked as ePHI/PII is

  1. encrypted at rest 
  2. not shared outside Zoho Bookings (not even to other Zoho apps)
  3. masked while displayed anywhere inside the app
  4. audited continuously and monitored for activity

Data audits help you secure your customers' data and monitor for unexpected changes or usage trends. Zoho Bookings will record the audit logs–i.e., information about every addition, update, and deletion made to customer database records–in the backend for a duration of up to 1 year. The audit log can be shared with you only upon request.


Drop in an email to support@zohobookings.com, if you'd like to access audit logs.

Note: HIPAA support can be invoked only on guest user fields and on SingleLine, CheckBox, DropDown, Email, RadioButton, and Date custom field types only. HIPAA support cannot be invoked on default fields (Name, Email, and Contact Number) and on custom MultiLine field types, as of now.

Marking ePHI/PII

To mark fields as ePHI/PII:

  1. Navigate to Manage Business > Workspaces > (select a workspace) > Booking Form. Edit the field (Blood Pressure, in this case) that would contain sensitive information.



  2. Check Mark as ePHI/PII to denote that the field (Blood Pressure, in this case) would contain sensitive information and click Save.



  3. The selected field is marked as ePHI/PII.


Encrypting Multiple Fields

HIPAA support can be invoked on more than one field. However, when you try to mark more than one field as ePHI/PII, you might receive an error message like the below.



This is because once a registration form field is marked as ePHI/PII, it takes some time in the backend to set it up. If another field is marked as ePHI/PII simultaneously while the setup for the first field is in progress, it might disrupt the setting altogether. To avoid this, it is advised to try marking the other field as ePHI/PII at a little while later.

Disabling HIPAA Support

  1. Click the Manage Business  icon and select General. 



  2. Click Privacy & Security. Click the HIPAA Support toggle which is set to 'Enabled'.



  3. A delete confirmation appears and informs you that the registration form fields will not be treated as sensitive. You will also not be able to mark them as ePHI/PII going forward. Click Yes, Disable HIPAA Support to proceed.



  4. The HIPAA Support section is set to 'Disabled' now.



  5. Existing registration form fields are no longer marked ePHI/PII. They also do not have the option to be marked as ePHI/PII.

Plans supporting this feature


Product/Service

Applicable Plans

Zoho BookingsPremium

Note: You can view all the pricing plans for Zoho Bookings here.

    • Related Articles

    • Customer Support

      Customer Support - An Overview Zoho CRM provides the Customer Support & Service management (Help Desk) features, such as Cases (Trouble tickets), Solutions (Knowledge base), Case Routing & Escalation through Workflow rules, and easy to deploy ...
    • Troubleshooting

      Troubleshooting integration of Zoho CRM with Zoho Advanced Analytics 1. Why am I unable to integrate Zoho Advanced Analytics with Zoho CRM? Make sure that you have admin privilege before integrating Zoho Analytics with Zoho CRM. The integration of ...
    • Block Spammers

      You might face many spammers and harassers who try to fake a genuine chat and trick your operator into wasting their time and resources. Most spammers will try to gain your operator's trust by sounding like an actual customer but eventually trick ...
    • How to add a GC bot to your IM channel

      Let's create a bot that will help you attend to your customers around the clock. Bots work all day every day to provide your customers with comprehensive support— they can effectively respond to customers, ask the right questions at the right time, ...
    • Defining Departments inside Zoho SalesIQ

      To better organize your Support operation, and maximize the ability to connect with customers, we made it easy to create Departments within your Zoho SalesIQ. Add all your customer supporting departments inside Zoho SalesIQ, and each Department can ...