And, like, why? Sure, if no one ever caught them, e2e could be a reason to choose Zoom—but it's like lying on a resumé. Which, I guess is also a thing that happens sometimes, but it's generally understood to be a bad idea.
If zoom was truly trying to market themselves as e2e, why is this only buried in one document rather than shouted from the hills?
They updated their documents since, but last week they had documentation up that said they were HIPAA compliant due to end to end encryption.
I develop electronics and firmware for medical devices, I have (almost) nothing to do with regulations compliance (except to the extent that I'm working on something where there is an intersection, like storage of patient data). But anyway, not a day goes by that I don't hear someone ask, "Is that HIPAA compliant?"
So yeah. Companies that have used Zoom based on that claim are probably going to extract some blood out of Zoom.