Need IT help now? Call (321) 221-7117 — We respond within 2 hours.

Need IT help? Help Desk Request Assistance Get in Touch
Medical IT

Is VoIP HIPAA Compliant? What a Medical Practice’s Phone System Actually Needs

Sep 29, 2026·8 min read·By Ric Acevedo

Is VoIP HIPAA compliant?

VoIP can be used in a HIPAA-compliant way, but no phone system is compliant on its own. HHS does not certify any product as “HIPAA compliant.” What changed when practices moved off landlines is that the HIPAA Security Rule now applies to the phone system. Compliance comes from three things: the agreement with your provider, how the system is set up, and how your staff use it.

Almost every phone vendor in this market puts “HIPAA compliant” on its website. That phrase tells you less than it sounds like. The Office for Civil Rights says plainly that HHS and OCR “do not certify any persons or products as ‘HIPAA compliant.'” A vendor can give you the tools. Whether your practice is compliant depends on what you do with them.

This guide is the IT side of that question: what HHS actually says about phone systems, when your provider needs to sign a Business Associate Agreement, and where patient information leaks out of a phone system in practice.

Why does it matter that we moved off landlines?

Because the rules are different. HHS’s guidance on audio-only telehealth says the HIPAA Security Rule does not apply to a traditional landline, “because the information transmitted is not electronic.” It then says what most practices now use instead:

“The HIPAA Security Rule applies when a covered entity uses such electronic communication technologies. Covered entities using telephone systems that transmit ePHI need to apply the HIPAA Security Rule safeguards to those technologies.”

“Such electronic communication technologies” means VoIP, mobile phones, and anything carried over the internet, cellular or Wi-Fi. If your practice switched to a cloud phone system in the last few years, and most have, the phone system belongs in your HIPAA risk analysis alongside your EHR and email.

Does my phone provider need to sign a BAA?

It depends on whether the provider only carries your calls or also keeps anything. HIPAA has a narrow “conduit” exception for services that just transmit information, the way the postal service carries mail. HHS says a practice is not required to sign a BAA with a phone company “that has only transient access to the PHI it transmits, because the vendor is acting merely as a conduit.”

The exception ends the moment the provider stores something. When HHS wrote the rule in 2013, it said the conduit exception covers transmission and any temporary storage incident to it, while an entity that maintains health information for you is a business associate “even if the entity does not actually view the protected health information.” Its cloud computing guidance goes further: a provider storing only encrypted data it cannot read still needs a BAA.

Modern cloud phone systems store a lot. Here is how the common features fall:

FeatureWhat the provider does with itWhat that means
Live calls onlyCarries the audio; nothing keptConduit. A BAA is not required for this alone
Voicemail stored in the phone systemKeeps the recording on its serversMaintaining PHI. BAA required
Call recordingKeeps recordings, often for monthsBAA required, and Florida consent rules apply
AI transcripts and call summariesCreates and stores text of the conversationBAA required. HHS names transcripts specifically
Fax-to-email or online faxReceives and stores the documentStored PHI. Treat it like voicemail and get it covered

In practice, nearly every cloud phone system a practice would buy today stores voicemail, so assume you need a BAA. Get it in writing, and confirm it covers the plan and the features you actually use, not just the base service. The last row is our reading of HHS’s conduit and cloud guidance, since HHS has not addressed online fax services directly.

Where do phone systems actually leak patient information?

The BAA is paperwork. The leaks happen in the configuration and in daily habits, and these are the ones we find most often.

Voicemail-to-email that goes to the wrong place

Voicemail-to-email is convenient, and it copies a patient’s message into an inbox. That inbox needs the same protection as the voicemail system: a practice mailbox covered by your email provider’s BAA, protected with multi-factor authentication. The problems are forwarding rules to a personal Gmail account, a shared front-desk inbox everyone logs into with one password, and a former employee’s mailbox still receiving messages months after they left.

Call recordings nobody decided to keep

Recording is often switched on during setup “for training” and never revisited. Every recording of a patient call is health information that has to be protected, included in your risk analysis and eventually deleted. If nobody can say why you record calls or how long recordings are kept, turn it off until someone can.

AI features switched on in an update

Phone vendors are adding AI transcription and call summaries, and new features can arrive in a routine update. Each one creates a stored transcript of a patient conversation. HHS’s telehealth guidance uses exactly this example: a service that stores recordings or transcripts in its own cloud is not a conduit, and needs a BAA before you use it with patients. Check the admin portal after every major update, and keep new AI features off until you have confirmed the BAA covers them. We have written separately about front desk staff using AI for patient messages.

The fax line

Most practices still cannot retire the fax. An online fax service drops referrals and records straight into email, so the same mailbox rules apply. HHS’s own example of a reasonable safeguard is simple: when faxing to a number you do not use regularly, confirm the number with the recipient first.

Calling patients back from a personal cell phone

When the office line is busy, staff call patients back from their own phones. Patient names and numbers end up in personal call logs and texts, outside anything the practice controls. The phone system’s mobile app, which keeps calls on the practice’s number and records, is the fix. See our guide to staff using personal phones at work.

Shared logins to the phone admin portal

Whoever can log into the admin portal can listen to voicemail, download recordings and reroute calls. That portal needs individual accounts with multi-factor authentication, and it belongs on your offboarding checklist so access ends the day someone leaves.

Can we record patient calls in Florida?

Only with the consent of everyone on the call. Florida is an all-party consent state. Under section 934.03, recording is lawful “when all of the parties to the communication have given prior consent,” and a violation is a third-degree felony. Separately, section 934.10 lets the person recorded sue for damages of at least $1,000, plus punitive damages and attorney’s fees.

The usual gap is not the main number. Practices add a “this call may be recorded” message to the main line and forget the other ways calls arrive: direct extensions, the after-hours route, the answering service, and outbound calls to patients. Every path that records needs notice. The same rule applies to AI note-takers on video calls. This is what the statute says, not legal advice; if you already hold recordings made without notice, talk to an attorney.

Is a landline more HIPAA compliant than VoIP?

Not in any way that helps. The Security Rule does not apply to calls on a true landline, but the Privacy Rule still governs what is said on any phone, and most practices no longer have a true landline to go back to. A well-configured VoIP system with a BAA, individual logins and controlled voicemail is easier to defend than a landline whose voicemail box nobody has changed the PIN on in years.

Are the HIPAA rules for phone systems about to change?

Possibly, but not yet. HHS proposed a stricter Security Rule in January 2025. As of September 2026 it is still a proposal, and the federal regulatory agenda lists final action for July 2027. The controls it proposes, such as multi-factor authentication and an inventory of every system that holds patient data, are worth doing now regardless. Your phone system belongs on that inventory.

What should a HIPAA-compliant phone setup include?

  • A signed BAA with your phone provider that covers voicemail, recording, transcription and fax features you use
  • Encryption for calls in transit where the system supports it, and for stored voicemail and recordings (“addressable” does not mean optional)
  • Individual logins with multi-factor authentication for the admin portal and every user’s app
  • Voicemail-to-email only into practice mailboxes covered by your email provider’s BAA, with no forwarding to personal accounts
  • A decision about recording: off unless you need it, and if on, consent notice on every route and a retention limit
  • New AI features off until reviewed and covered
  • Online fax delivered to a controlled mailbox, with unfamiliar fax numbers confirmed before sending
  • Phone accounts removed the same day someone leaves
  • The phone system listed in your annual risk analysis

Your IT provider usually has access to all of this too, which is why your IT company needs a BAA as well.

Setting Up Phones for a Practice in Polk or Osceola?

iTech Plus sets up and manages HIPAA-compliant phone systems for medical and dental offices across Central Florida, from our base in Haines City to practices in Lakeland, Winter Haven, Davenport and Kissimmee. That includes the BAA, the configuration and the parts vendors leave to you: voicemail routing, recording notices, fax and staff access.

If you want your current phone setup checked, we offer a free IT assessment with a written report and prioritised recommendations. Call (321) 221-7117 or email info@itechplus.co.

Recent Articles

Can Front Desk Staff Use AI to Write Patient Emails?
Medical IT
Can Front Desk Staff Use AI to Write Patient Emails?
Aug 26, 2026
Can a Law Firm Use ChatGPT Without Breaching Confidentiality?
Medical IT
Can a Law Firm Use ChatGPT Without Breaching Confidentiality?
Aug 26, 2026
Does Using AI on Client Tax Data Trigger Section 7216?
Medical IT
Does Using AI on Client Tax Data Trigger Section 7216?
Aug 26, 2026
Who Still Has Access to Your Property After Move-Out?
Medical IT
Who Still Has Access to Your Property After Move-Out?
Aug 25, 2026
Is It Legal to Use an AI Note-Taker in Florida?
Medical IT
Is It Legal to Use an AI Note-Taker in Florida?
Aug 25, 2026

Related posts

Digital Business Card