- 4/01/20: MIT Tech Review summarizes the security issues with Zoom, including information about a Class Action Lawsuit.
- 3/31/20: Vice.com reports that Zoom is leaking personal emails and photos to strangers.
- 3/31/20: The Intercept reports that Zoom is not using End to End Encryption as claimed in their marketing materials and user interface.
- 3/31/20: New York Times reports that Zoom, the videoconferencing app whose traffic has surged, is under scrutiny by the New York attorney general’s office for its data privacy and security practices.
- 3/30/20: FBI Warns of Teleconferencing and Online Classroom Hijacking During COVID-19 Pandemic
- Name, physical address, and other similar personally identifying information
- Information about your job, such as your title and employer
- Your Facebook profile information (when you use Facebook to log-in to Zoom or to create a Zoom)
- General information about your product and service preferences (including software installed and/or in use on your computer)
- Information about your device
Per Zoom’s policy, downloading and using the Zoom app provides Zoom with consent to share any personal information they collect with third parties.
In reference to the use of third party services, the policy states
“We use these tools to help us improve your advertising experience (such as serving advertisements on our behalf across the Internet, serving personalized ads on our website, and providing analytics services).”
In other words, Zoom may use the personal information of any person using their services to market to that person across their use of the Internet.
Additionally, we do not see any effort by Zoom to determine the age of individuals using the service, so they are likely collecting and using the personal information of children.
Vice.com is reporting that Zoom’s iOS app sends data to Facebook even if you do not have a Facebook account.
Our current assessment of the impact is as follows:
- Data collection is based on the way each meeting participant enters the meeting. Even if the organizer is on a paid and secure business or education edition, meeting attendees using the free client or entering as a guest are subject to dating mining and sharing.
- For businesses and schools, some of the data Zoom collects and shares is prohibited under the Children’s Online Privacy Protection Act (COPPA).
- For schools and libraries, not using the K12 version of Zoom for faculty and students may result in violations of the Children’s Internet Protection Act (CIPA)
- Zoom does provide a means for users to instruct Zoom to “Do not Sell” their personal information. This help with California Consumer Privacy Act (“CCPA”) and EU’s General Data Protection Regulation (“GDPR”) compliance. It may not be practical to advise all meeting attendees of this option.
If you organization uses G Suite or Microsoft Office 365, you already have the ability to securely conduct audio and video conferencing with services that do not mine and share attendee data.
- G Suite
- Hangouts Meet (the new service) is secure and HIPAA compliant. Individuals outside your organization can join via shared URL, without providing personal information. Through June 2020, Google has enabled all G Suite users to conduct meetings with up to 250 participants and provided organizers with the ability to record meetings. Participants can mute their own audio/video and can present to the meeting. Meeting include dial-in numbers and pins to allow access from phones.
- Participants can join via web browser or use the free iOS and Adroid Apps.
- Traditional Hangouts and Chat, while not HIPAA compliant, are still secure and work within organizations and with guests.
- Office 365
- Teams (and formerly Skype for Business) is a secure video/audio conferencing service with screen sharing, waiting rooms, and other helpful features. As with all of Office 365, Teams can be deployed to meet HIPAA compliance. Teams does not collect and share personal information.
- Teams, by default is device-to-device conferencing. You can add the ability for individuals to connect by phone for a small monthly fee for each meeting organizer that needs this function.
- Participants can join via web browser, or use the free apps for Windows, Mac, iOS, and Android.
Before adding another service or tool for audio/video conferencing, take full advantage of the services you have. Contact us if you need help with user training and support.
If you are not using G Suite or Office 365, several communications and conferencing services are offering secure, free access for up to 90 days. These include, but are not limited to, Dialpad, UberConference, Ring Central, and Cisco WebEx. Please contact us for help selecting and deploying the right service for you and your teams.