The few with smarter lawyers and IT departments, usually academic, do but a majority of all of the new "AI" health tech products I've heard about pitched to hospitals use customer PHI for product development.
They basically claim that the customer (the one who signs the contract, not the Zoom user) who hosts the meeting is responsible for GDPR compliance by defining the right account settings. So if you are invited on a call you basically have no rights.