Is Doximity HIPAA Compliant?

Doximity signs a BAA and offers secure messaging — but only verified clinicians can use it, and not every feature on the platform is covered.

Get started for free
Yes, with conditions

Yes, with conditions. Doximity signs a Business Associate Agreement automatically when a clinician registers, and its designated secure tools — messaging, eFax, Dialer, and Scribe — are covered under that BAA. However, Doximity is limited to verified healthcare professionals. Medical assistants, front desk staff, billing coordinators, and other non-clinician roles cannot create accounts. Doximity's social network features — news feed, public profiles, colleague connections — are not covered by the BAA.

Why?

BAA signed automatically at registration

Doximity enters into a Business Associate Agreement with each individual user upon registration. The BAA identifies the "Doximity App, Dialer, and Scribe" as appropriately secure for the communication of protected health information. Institutional BAAs are available as part of Doximity's Enterprise solutions.

Source: Doximity Security

Limited to verified clinicians

Doximity requires credential verification and is available only to licensed healthcare professionals — physicians, NPs, PAs, pharmacists, and similar roles. Medical assistants, care coordinators, front desk staff, and billing personnel cannot create Doximity accounts. If your communication needs include non-clinician staff at external organizations, Doximity cannot serve that use case.

Source: Doximity Terms of Service

Social network features are not covered by the BAA

Doximity is fundamentally a professional social network for physicians with secure messaging layered on top. Public profiles are viewable by default. The BAA covers only designated secure communication tools — not the news feed, public posts, colleague connections, or profile information. PHI shared through non-secure features would not be protected under the BAA.

Source: Doximity BAA

Free tier lacks organizational admin controls

Doximity's free and Pro tiers include the individual BAA and access to secure messaging. However, they do not provide the admin controls required for organizational HIPAA compliance programs — SSO, automated user management, call log reporting, and EMR integration are available only on the Enterprise tier.

Source: Doximity Security

Audit trail transparency gaps

Doximity mentions general log monitoring and external log shipping, but does not document granular per-message audit trails, role-based access controls for message-level permissions, or remote device wipe capabilities in its public security documentation.

Source: Doximity Security

What Doximity says

Doximity's security page states: "Doximity's platform allows healthcare professionals to securely communicate while maintaining compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH)." Doximity also states that it enters into a BAA with each individual user upon registration.
Source: Doximity Security

What you would need to configure

Required plan: Doximity Enterprise (for organizational HIPAA compliance with admin controls)

  1. Contact Doximity sales to execute an institutional BAA for your organization
  2. Configure Single Sign-On for centralized authentication
  3. Set up automated user management to control onboarding and offboarding
  4. Enable call log reporting for Dialer usage monitoring
  5. Train staff to distinguish between Doximity's secure communication tools (messaging, eFax, Dialer) and its social network features (news feed, posts, profiles) — only the former are covered by the BAA
  6. Establish policies for PHI communication that account for Doximity's clinician-only limitation — non-clinical staff will need a separate HIPAA-compliant communication tool

Enterprise pricing is not published — contact Doximity sales. Individual clinicians can use Doximity's secure messaging with the automatic BAA, but organizational compliance requires Enterprise for admin controls. The clinician-only restriction means most healthcare organizations will need a second communication tool for non-clinical staff.

HIPAA-compliant alternatives

BloomText

Purpose-built HIPAA messaging for everyone in your organization — clinicians and non-clinical staff alike. Signed BAA on every plan, including the free plan. Cross-organization messaging is free.

TigerConnect

Enterprise clinical messaging platform used by hospitals and health systems. Includes role-based routing and EHR integrations.

Spruce Health

HIPAA-compliant communication platform for medical practices with secure messaging, phone, fax, and telehealth in one system.

Frequently Asked Questions

Is Doximity HIPAA compliant?

Yes, conditionally. Doximity signs a BAA automatically at registration and its designated secure tools — messaging, eFax, Dialer, and Scribe — are covered. However, Doximity is limited to verified clinicians, its social network features are not covered by the BAA, and organizational admin controls require Enterprise.

Does Doximity sign a BAA?

Yes. Doximity enters into an individual BAA with each user upon registration. Institutional BAAs are available for Enterprise customers. The BAA covers Doximity's secure communication tools but not its social networking features.

Can medical assistants use Doximity?

No. Doximity requires credential verification and is available only to licensed healthcare professionals. Medical assistants, front desk staff, billing coordinators, and care coordinators cannot create Doximity accounts. If you need to communicate with non-clinician staff, you will need a different HIPAA-compliant messaging tool.

Is Doximity's news feed HIPAA compliant?

The BAA covers only Doximity's designated secure communication tools — messaging, eFax, Dialer, and Scribe. The news feed, public profiles, colleague connections, and other social network features are not covered. PHI should never be shared through non-secure features.

Sources

Last verified May 29, 2026.

  1. BloomText pricing
  2. Doximity Security
  3. Doximity BAA
  4. Doximity Terms of Service
  5. HHS HIPAA Security Rule

Need HIPAA-compliant messaging?

Get started for free

Trusted by today's leading healthcare professionals

Streamlined appointment schedulingWith BloomText Broadcast SMS Messaging, I literally took the job of 20 employees and I can do it by myself in three and a half hours.Chief Administrative Officer, Radiology
Best HIPAA app on the marketBloomText has brought our clinic into the modern age, and our patients love being able to communicate with us via text or through our website.Office Administrator, Family Medicine
Excellent for acute careBloomText is the nervous system for my business. It helps us differentiate ourselves in terms of our communication and our quality of care.Clinical Director, Acute Care