Integration Overview
Caredove enables secure, user-initiated integrations with Zoom and Microsoft Teams to automatically generate unique virtual meeting links within booked appointments and referrals. While the video meeting takes place in Zoom or Teams, the appointment—including scheduling, rescheduling, reminders, and confirmations—is fully managed within Caredove.
Integrations are optional and require individual user authorization.
Caredove securely connects to Zoom and Microsoft Teams using their official APIs to create virtual meetings and retrieve meeting details like the link, time, and organizer.
These actions are authorized through OAuth 2.0 using user-specific access tokens with limited permissions.
No personal health information (PHI) is shared with Zoom or Microsoft. The registrant’s initials may appear in the meeting title, but no other personally identifiable information (PII) is included.
Authentication & Authorization
Zoom
Uses OAuth 2.0 via Zoom App Marketplace
Scopes requested:
meeting:write
,user:read
Microsoft Teams
Uses OAuth 2.0 via Microsoft Identity Platform
Scopes requested:
OnlineMeetings.ReadWrite
,User.Read
Caredove does not request broad access—only the permissions required to create meetings. Tokens are encrypted and tied to the individual Caredove user.
Users can revoke access at any time via their Caredove profile or Zoom/Microsoft account settings.
What Data Is Shared?
Data Element | Shared with Zoom/Teams | Stored in Caredove | Notes |
Meeting time, title, organizer | ✅ | ✅ | Used to create the virtual meeting |
Meeting link (URL) | 🔁 (returned to Caredove) | ✅ | Displayed in calendar, referral, and confirmation/reminder emails sent to client |
Registrant initials | ✅ | ✅ | Included in meeting title in Zoom |
Client personal info (PHI) | ❌ | ✅ | Never shared with Zoom or Teams |
Meeting content (video/chat) | ✅ | ❌ | Managed entirely by Zoom or Teams |
Security Practices
OAuth tokens are encrypted in transit and at rest
All data in transit is protected using TLS 1.2+
No PHI or full client data is shared with virtual meeting providers
Meetings are created on behalf of the user only after explicit authorization
Caredove’s systems are hosted in secure, HIPAA-compliant infrastructure in Canada
Disconnecting the Integration
Users can disconnect Zoom or Teams from their Caredove profile at any time
Tokens are immediately revoked and deleted
Virtual meetings cannot be generated again until the integration is reconnected
Need More Info?
This integration adheres to the controls defined in Caredove’s Third-Party Management Policy, available upon request.
If you have questions or need additional security information, you can:
Reach out to our team via chat when logged into Caredove
Review our Legal Page
Request access to our Trust Center