Skip to main content

Zoom & Microsoft Teams Integration: Technical and Security Overview

Learn how Caredove’s Zoom and Microsoft Teams integrations work, what data is shared, and how we keep your information secure.

K
Written by Katie Doleweerd
Updated over a month ago

Integration Overview

Caredove enables secure, user-initiated integrations with Zoom and Microsoft Teams to automatically generate unique virtual meeting links within booked appointments and referrals. While the video meeting takes place in Zoom or Teams, the appointment—including scheduling, rescheduling, reminders, and confirmations—is fully managed within Caredove.

  • Integrations are optional and require individual user authorization.

  • Caredove securely connects to Zoom and Microsoft Teams using their official APIs to create virtual meetings and retrieve meeting details like the link, time, and organizer.

  • These actions are authorized through OAuth 2.0 using user-specific access tokens with limited permissions.

  • No personal health information (PHI) is shared with Zoom or Microsoft. The registrant’s initials may appear in the meeting title, but no other personally identifiable information (PII) is included.

Authentication & Authorization

Zoom

  • Uses OAuth 2.0 via Zoom App Marketplace

  • Scopes requested: meeting:write, user:read

Microsoft Teams

  • Uses OAuth 2.0 via Microsoft Identity Platform

  • Scopes requested: OnlineMeetings.ReadWrite, User.Read

Caredove does not request broad access—only the permissions required to create meetings. Tokens are encrypted and tied to the individual Caredove user.

Users can revoke access at any time via their Caredove profile or Zoom/Microsoft account settings.

What Data Is Shared?

Data Element

Shared with Zoom/Teams

Stored in Caredove

Notes

Meeting time, title, organizer

Used to create the virtual meeting

Meeting link (URL)

🔁 (returned to Caredove)

Displayed in calendar, referral, and confirmation/reminder emails sent to client

Registrant initials

Included in meeting title in Zoom

Client personal info (PHI)

Never shared with Zoom or Teams

Meeting content (video/chat)

Managed entirely by Zoom or Teams

Security Practices

  • OAuth tokens are encrypted in transit and at rest

  • All data in transit is protected using TLS 1.2+

  • No PHI or full client data is shared with virtual meeting providers

  • Meetings are created on behalf of the user only after explicit authorization

  • Caredove’s systems are hosted in secure, HIPAA-compliant infrastructure in Canada

Disconnecting the Integration

  • Users can disconnect Zoom or Teams from their Caredove profile at any time

  • Tokens are immediately revoked and deleted

  • Virtual meetings cannot be generated again until the integration is reconnected

Need More Info?

This integration adheres to the controls defined in Caredove’s Third-Party Management Policy, available upon request.

If you have questions or need additional security information, you can:

  • Reach out to our team via chat when logged into Caredove

  • Review our Legal Page

  • Request access to our Trust Center

Did this answer your question?