SmartMeet DeskStart the 7-day free trial
Compare tools

Does Calendly sign a BAA? What its own security and pricing pages say

As of October 5, 2026, Calendly's security page and the retrieved part of its pricing page do not mention a BAA or HIPAA. This guide covers what the pages list, a published BAA, and how to decide.

Calendly's public security page, as retrieved on October 5, 2026, does not say whether Calendly signs a Business Associate Agreement (BAA), and it does not mention HIPAA or protected health information (PHI) [1]. The copy of Calendly's pricing page retrieved the same day ends partway through its feature comparison, and the retrieved portion does not mention a BAA, HIPAA or PHI either [2]. This does not show that Calendly declines to sign a BAA. It shows only that the answer is not published in the material reviewed here [1][2]. Both pages offer a Talk to sales link, and the security page points to a Trust Center for security and compliance documentation, but neither says whether a BAA is available through those routes, so a buyer who needs one would have to ask Calendly directly [1][2]. A practice that wants to read the agreement before signing up can compare an alternative that publishes its BAA and includes it in a single plan, such as SmartMeet [SmartMeet][3].

What a BAA is and where scheduling tools touch it

A BAA is a contract under the HIPAA Rules between a covered entity, such as a clinic or health team, and a vendor acting as its business associate [3][SmartMeet]. The published SmartMeet agreement, for example, takes the meanings of its terms from the HIPAA Rules at 45 C.F.R. Parts 160 and 164, and treats PHI as protected health information the vendor handles for the covered entity through its service [3]. That agreement sets out what the vendor may do with PHI, which safeguards it applies, how quickly it reports breaches, how it binds subcontractors and what happens to the data when the agreement ends [3].

Scheduling software can hold more than a time slot. On the plans listed on Calendly's pricing page as of October 5, 2026, several features store information about invitees [2]:

  • forms that screen invitees and route them based on responses [2]
  • contact profiles with notes, custom fields and relationship history [2]
  • an optional Notetaker add-on that produces recordings, transcripts and shareable meeting recaps [2]

The security page and the retrieved portion of the pricing page do not say whether information entered into these features would be PHI for a given practice, or whether Calendly would cover those features under a BAA [1][2].

What Calendly's security page lists, as of October 5, 2026

For data protection, the page lists logical tenant separation, encryption in transit (TLS 1.2 or higher), encryption at rest (AES-256), PII deletion controls, and domain control and account oversight [1]. For platform security, it lists hosting on a cloud infrastructure provider, network and perimeter protection, a web application firewall, DDoS protections, regular vulnerability scanning and annual penetration testing [1].

The listed account controls are single sign-on (SSO), SCIM user provisioning, multi-factor authentication (2FA), login notifications, a real-time audit log and flexible admin roles [1]. SCIM is a method for automating the provisioning and deprovisioning of user accounts from an identity system [1][2]. The operational items are security awareness training, 24/7 monitoring and incident response, vendor risk management and business continuity planning [1].

Under compliance, the page lists SOC 2 (Type 2), SOC 3, CSA STAR, PCI and ISO/IEC 27001; HIPAA does not appear in that list [1]. The page says customers doing security reviews or procurement assessments can get further documentation through Calendly's Trust Center [1].

On data use, the page says submitted data and AI outputs are used only to provide the service, that customer data is not sold or used to train AI models, and that third-party AI providers are prohibited from using customer data to train their models [1]. These are security controls, attestations and data-use statements; a BAA, as the SmartMeet agreement shows, is a separate contract covering permitted uses, breach reporting, subcontractors and termination [1][3].

What Calendly's pricing page lists, as of October 5, 2026

The pricing page shows four tiers [2]:

  • Free: one event type, one calendar connection, one-on-one scheduling, a customizable booking page and a browser extension [2].
  • Standard: $10 per seat per month, adding unlimited event types, up to 6 calendar connections, automations and reminders, HubSpot and Mailchimp connections, and Stripe and PayPal payments; Notetaker is marked as not included [2].
  • Teams: $16 per seat per month, adding round-robin and team scheduling, lead qualification and routing, centrally managed event types, Salesforce, Marketo and Pardot connections, and an optional SSO security add-on [2].
  • Enterprise: starts at $15k per year and at 50 seats, in USD only, adding Salesforce lookup routing, Microsoft Dynamics, SSO and SAML, domain control, audit log compliance, a data deletion API, onboarding and dedicated account support [2].

The page offers monthly and yearly billing and advertises savings of up to 20% for yearly billing, so buyers should confirm which billing period a quoted per-seat figure assumes [2]. Seats are required for users who connect calendars and host meetings; invitees do not need a seat [2].

In the retrieved portion of the feature comparison, the row for support with security and legal reviews appears to be marked only for Enterprise, and no row refers to a BAA; because the retrieved copy is incomplete, a buyer should check the full page directly [2].

What a BAA-included alternative looks like

SmartMeet by iPMS combines booking pages and video meetings in one plan at $15 a month, with everything included; guests never pay, and a 7-day free trial is available [SmartMeet]. The plan includes booking pages, video, live captions, AI meeting summaries, reminders by email and text, and no meeting time limit; it checks the host's calendar to prevent double bookings, and guests can reschedule themselves [SmartMeet].

The BAA is included: clinics and health teams accept it when they sign up, with no sales call and no extra plan [SmartMeet]. The published version is dated 2026-10-01, the exact text a subscriber accepted is kept with their account, and acceptance is electronic, with the typed name, time and network address kept as the record of signature [3].

The main terms of that published agreement are these [3]:

  • Permitted uses: PHI may be used only to provide the service, as required by law, or for proper management and administration under 45 C.F.R. § 164.504(e)(4), and it will not be sold or used for marketing [3].
  • Safeguards: the agreement commits to Subpart C of 45 C.F.R. Part 164; meeting audio and video are encrypted between participants using DTLS-SRTP, any relay operates under its own business associate agreement, and recordings are stored on access-controlled servers in the United States [3].
  • Reporting: breaches of unsecured PHI must be reported without unreasonable delay and no later than 60 calendar days after discovery, with the details 45 C.F.R. § 164.410 calls for [3].
  • Subcontractors: any subcontractor handling PHI must agree in writing to the same restrictions and conditions [3].
  • Individual rights: where SmartMeet holds PHI in a designated record set, a term taken from the HIPAA Rules, it commits to support access, amendment and accounting of disclosures under 45 C.F.R. §§ 164.524, 164.526 and 164.528; subscribers can download and delete recordings and attendance records from their account at any time [3].
  • Termination: the agreement lasts as long as the subscription, and the subscriber may end it if SmartMeet materially breaches it and has not fixed the breach within 30 days of notice; PHI is then returned or destroyed, or stays protected where that is infeasible [3].
  • Customer obligations: the subscriber must obtain any consent needed to record a meeting and keep PHI out of parts of the service not intended to hold it, such as meeting titles visible to guests [3].

A BAA does not by itself make a practice's use of a tool compliant; compliance also depends on how the customer uses the service, as the customer-obligations clause makes explicit [SmartMeet][3].

Where Calendly may be the better fit

Based on what its pages list as of October 5, 2026, Calendly may suit some readers better [1][2]:

  • A coach or consultant who does not handle PHI and wants to start at no cost can use the Free tier [2].
  • Teams that route bookings by HubSpot or Salesforce assignment, or sync with Marketo or Microsoft Dynamics, will find those integrations on Calendly's plans; SmartMeet's approved facts do not list CRM routing [2][SmartMeet].
  • Practices that take payment at booking will find Stripe and PayPal collection, payment links, prepaid packages and invoices on Calendly's page; SmartMeet's approved facts do not list payment collection [2][SmartMeet].
  • IT-managed organizations that require SSO, SAML, SCIM provisioning, domain control, audit logs or a data deletion API will find these on Calendly's security and pricing pages; SmartMeet's approved facts do not list them [1][2][SmartMeet].

How to decide

  • Which features would hold patient information: booking forms, contact notes, recordings or transcripts? That list is the starting point for deciding, with a privacy or legal adviser, whether a BAA is needed [2].
  • If you prefer Calendly, will it confirm in writing whether it signs a BAA, and which plan and features, including Notetaker, the BAA would cover? The security page and the retrieved portion of the pricing page do not answer this [1][2].
  • Does any BAA you are offered state a breach-notification deadline, subcontractor terms, and return or destruction of PHI at termination? The published SmartMeet terms set 60 calendar days after discovery as the outer limit for breach notice and allow 30 days after notice to fix a material breach [3].
  • Which fields in the tool are visible to guests, and can staff keep PHI out of them? The SmartMeet BAA requires this for meeting titles [3].
  • What does your actual headcount cost? Calendly lists Standard at $10 and Teams at $16 per seat per month, and Enterprise from $15k per year at 50 seats; SmartMeet lists $15 a month, so confirm what each price covers when there are multiple hosts [2][SmartMeet].
  • Do you need payments at booking, CRM routing, or SSO and SCIM, and does the tool you choose list them [1][2][SmartMeet]?
  • Can you test the workflow first with Calendly's Free tier or SmartMeet's 7-day trial, without placing real patient information in either tool until an agreement is in place [2][SmartMeet][3]?

References

  1. calendly.com. Security | Calendly. Accessed October 5, 2026. calendly.com
  2. calendly.com. Pricing | Calendly. Accessed October 5, 2026. calendly.com
  3. smartmeet.myipms.app. Business Associate Agreement. Accessed October 5, 2026. smartmeet.myipms.app

How this was written: drafted with AI from the sources listed above, then checked automatically, claim by claim, against them before publishing. The SmartMeet Desk writes about scheduling, video visits, productivity, time management and running a care team, and the privacy rules around them, from public guidance and published research. Every factual statement links to its source.

SmartMeet Desk

Today's front page

The newest articles and the day's news on Compare tools, Telehealth policy, Scheduling and more.

Go to the front page →