Healthcare
HIPAA-Compliant Video API in 2026: What Actually Makes One, Vendor Comparison, and Twilio Video Migration
Consultations, psychiatry meetings, medication management, triage, and other medical encounters often do not require physical presence. Adding video to your healthcare app or platform can be a great idea, as it allows you to hold sessions online without losing the human touch.
Using a messaging API to incorporate video into your application makes the whole process significantly easier and faster. But you can’t just use any API – it should meet HIPAA requirements and securely handle protected health information (PHI).
The December 2024 2024 NPRM to the HIPAA Security Rule adds further pressure. It proposes making encryption required rather than addressable for ePHI, tightening multi-factor authentication, and strengthening incident-response timelines. If you are evaluating or replacing a video layer for telehealth this year, you need more than a marketing claim that “we encrypt ibrtcn transit.”
Let’s look at what makes a video API HIPAA-compliant, compare eight vendors, find out when self-hosted WebRTC wins, and walk through a practical Twilio Video migration path.
In this blog
- What actually makes a video API HIPAA-compliant
- How to migrate from Twilio Video
- Eight-Vendor comparison
- Self-host WebRTC for HIPAA: When it wins
- Build Your Own: HIPAA Video + Chat + AI with Ethora
What actually makes a video API HIPAA-compliant
A HIPAA-compliant video API rests on four conditions that map directly to the Security Rule.
- Business Associate Agreement. The vendor should sign a BAA for the exact service and plan you use. If the Free or Starter tier sits outside the BAA, that tier cannot carry PHI. Execute the agreement before any production traffic.
- Technical safeguards. They must cover both encryption in transit and encryption at rest. WebRTC media travels under SRTP. Signaling typically uses DTLS. Multi-party calls almost always pass through an SFU, so the encryption is hop-by-hop rather than pure client-to-client. Recordings stored by the vendor must sit under AES-256 (or equivalent) at rest. The 2024 NPRM proposes elevating at-rest encryption from addressable to required. Transit encryption alone no longer meets the expected bar.
- Audit logs. Audit controls must log every access to a session: who joined, from which IP or device, when, duration, recording start and stop, screen-share events, and participant changes. Logs need to be tamper-evident and retained according to your policy – commonly six years under HIPAA.
- Authentication and authorization. You need to be sure there won’t be unauthorized access. Short-lived tokens, waiting rooms, and host-controlled admission are baseline. MFA is strongly recommended today and would become mandatory under the proposed rule for many systems.
Every HIPAA-compliant video call and every HIPAA-compliant video conferencing session must satisfy these four points. Marketing pages that stop at “encrypted” fail the test.
The E2EE trap
True E2EE (client-to-client with no intermediary able to see plaintext) is not required by HIPAA. SRTP through an SFU plus proper at-rest protection and a signed BAA is sufficient. Some vendors market “E2EE” while still routing media through an SFU; that claim is technically incomplete for multi-party rooms. Know the difference before you rely on the language in a risk analysis.
The Twilio Video sunset: what changed and how to migrate
Twilio’s original Programmable Video end-of-life target of December 5, 2024 forced a large migration wave even though the company later reversed the retirement. Many teams still completed the move. Twilio encouraged LiveKit during the planning period, but most engineering groups evaluated the full market.
The common pattern is video-first, chat-later. Keep chat or SMS on Twilio (Programmable Messaging was never scheduled for retirement) and move only the video layer. Some teams later consolidate chat and video under one vendor to reduce the number of BAAs.
If you’re going to migrate, here’s the migration checklist.
- Sign the new vendor BAA before any code work begins
- Confirm the new vendor’s region for ePHI if you previously used a specific Twilio geography
- Rewrite the signaling and token layer for the new SDK
- Export and re-encrypt existing recordings if they move
- Update the audit-trail schema to match the new event model
- Run parallel production traffic for two to four weeks
- Rotate and retire Twilio Video credentials
SDK surfaces differ enough that clean migrations often take two to six weeks of engineering per platform. TURN relay costs are frequently 30-50 percent lower than older Twilio rates. Recording storage is often billed separately and can become an unexpected line item. SFU behavior under real bandwidth constraints only appears in production testing.
After cut-over, re-run the readiness assessment: BAA on file, encryption modes verified, audit schema documented, incident-response plan updated, and breach-notification template adjusted for the new stack. This Twilio Video migration work is also a natural moment to review whether a combined chat-and-video chat SDK reduces long-term compliance surface.
Eight-vendor comparison
The table that follows pulls together the practical differences. Every vendor listed has a documented route to a BAA on at least one paid tier. Consumer free accounts rarely qualify.
| Vendor | BAA Availability | Starting Price (public list) | Video Architecture Notes | Primary Strengths | Real Weaknesses / BAA-Tier Limits |
| Zoom for Healthcare | Qualifying paid plans (Healthcare / Business / Enterprise); request required | Pro ~$14/mo; Business ~$18/Enterprise contact sales | Cloud meetings + optional Video SDK | Familiar interface, large meetings, EHR integrations | Free/Pro often ineligible; HIPAA mode can disable certain AI features; configuration required |
| Doxy.me | All plans including Free (individual); Clinic-level for groups | Free; Pro $29-35/provider/mo; Clinic $42-50/user/mo | Browser-based, no patient download | Zero-friction patient join, BAA on free tier | Limited advanced admin/analytics on lower tiers; not a full practice-management suite |
| Microsoft Teams | Business and Enterprise Microsoft 365 plans; automatic via Data Protection Addendum | Business Premium ~$22/user/mo (includes Teams) | Integrated with M365 ecosystem | Existing M365 customers get BAA with little friction; strong admin controls | Requires correct plan + configuration (MFA, waiting rooms, sharing restrictions); not purpose-built telehealth UI |
| Cisco Webex | Paid plans; BAA available | Meet ~$12–14.50/user/mo; Suite higher; Enterprise custom | Enterprise cloud + hardware ecosystem | Strong enterprise security posture, E2E options, FedRAMP paths | Higher mid-tier pricing; interface can feel heavier for small practices |
| VSee | Free Clinic and paid plans (signed BAA) | Free; Plus $29/provider/mo; Premium $49/provider/mo | Telehealth-focused waiting rooms | Low-bandwidth optimization, device streaming options | Older interface reports; Enterprise features require custom quote |
| Daily.co | Healthcare add-on | Usage ~$0.004/participant-min after free tier + $500/mo Healthcare add-on | Managed WebRTC SFU | Developer-friendly API, good performance metrics | Fixed $500/mo floor for BAA; recordings often directed to customer storage under HIPAA mode |
| LiveKit | Scale ($500/mo) and Enterprise | Build free; Ship $50/mo; Scale $500/mo | Managed + open-source SFU | Self-host escape hatch, strong AI/agent tooling | BAA gated behind Scale tier; usage metering complexity |
| Ethora | Enterprise plans | Free tier; Business ~$99/mo range; Enterprise $599+/mo | WebRTC with SFU, chat + video SDK | Embeddable, self-host options, AI/RAG features, built-in compliance | SFU scale smaller than dedicated video vendors; BAA limited to higher tier |
Most of these platforms rely on WebRTC. Key exchange typically happens over DTLS, and the media itself rides on SRTP. An SFU (Selective Forwarding Unit) keeps multi-party calls efficient by routing streams rather than mixing them on a central server. Optional E2EE is available on some products. Any recordings, chat logs, or metadata the vendor stores must sit under encryption at rest, and the BAA has to cover those elements.
Self-host WebRTC for HIPAA: When it wins
Large hospital systems often prefer to keep third-party BAAs to a minimum. Self-hosting collapses the video surface to infrastructure you already control. At high volume, the per-minute math on managed vendors also turns against you. Full control of the audit trail and the ability to co-locate a self-hosted chat server, an on-premises chat server, and a self-hosted LLM on the same internal communication platform become practical advantages.
Common open-source choices are LiveKit self-host (modern SFU plus auth), Jitsi Meet (mature but heavier ops), mediasoup (library that you assemble), and Ethora. All require real WebRTC operations skills – STUN/TURN, recording pipelines, monitoring, and patch management.
At roughly 100K MAU with moderate call volume, managed vendors often land between $3,000 and $8,000 per month. Self-host infrastructure can sit at $1,000-3,500 plus 0.3-0.5 FTE of DevOps allocation. Break-even typically appears between 50K and 100K MAU depending on session frequency. The sovereignty pattern – self-hosted chat server + self-hosted SFU + self-hosted Llama-class model for HIPAA-compliant LLM workloads – fits hospitals that treat the internal communication platform as regulated infrastructure. Ethora paired with LiveKit or Jitsi on a private cloud is a common architecture for teams that want both chat and video under one operational roof.
Build Your Own: HIPAA Video + Chat + AI with Ethora
Ethora’s Chat & AI SDK packages chat, video, and AI modules that can run self-hosted on your infrastructure or managed under a BAA. Six modules come in one pack – all you need to do is install Ethora (npm install @ethora/sdk) and then choose which modules to use, choose the deployment target (hospital private cloud, AWS Marketplace, EU sovereign cloud, or managed), and point the AI layer at Azure OpenAI under its BAA or at a self-hosted Llama-class model.
Five practical differences for telehealth teams:
- Chat, video, audit, and AI sit in one SDK, reducing the number of BAAs (often to one-your own-when fully self-hosted)
- Native self-host path removes third-party dependency for hospital private-cloud policies
- BYO LLM support includes self-hosted models for HIPAA-compliant LLM workloads
- Modules can be enabled independently (patient chat, provider chat, video visits, AI triage)
- Pricing is flat-tier rather
Besides the Chat & Docs engine, Ethora SKD also offers voice and video options for healthcare teams, as well as artificial intelligence capabilities (with a RAG crawler that can learn from your data, ensuring accuracy), and customizable UI components.
Compliance coverage includes HIPAA BAA support, GDPR via EU cloud pairing, and SOC 2 readiness. Per-message and per-session audit logs support both the Security Rule and EU AI Act Article 12 record-keeping needs.
If you need a HIPAA-compliant chat API for your messaging app or patient communication platform with video conferencing, drop us a line. Our experts will explain how Ethora ensures compliance and what configurations are expected from your side.
More Articles
Development
Oct 5, 2026
Cross-Platform App Development Frameworks in 2026: 10 Options Compared, Real Trade-offs, and Chat + AI SDK Fit
In 2026, evaluating cross-platform frameworks is a complex matter. There are many practical questions: Which ones have solid chat and AI SDK support today? Which ones won’t force a painful migration when the next major OS version drops? And what are the real engineering trade-offs once you move past the marketing claims? We’ll look at […]
Healthcare
Sep 28, 2026
Telemedicine App Development in 2026: Architecture, HIPAA, AI, and the Build-vs-Buy Decisions That Matter
Telemedicine app development in 2026: HIPAA + EU AI Act, architecture, AI-native patterns, video/chat SDK decisions, and real cost math.
Try Out Ethora in Action
Experience Ethora's messaging with a dedicated demo from our CEO or start building your App right now!