Guide · Compliance · Updated July 2026

VoIP and HIPAA Compliance: What Healthcare Practices Need to Know (2026)

Nearly every phone system touches a patient at some point, and most practices never formally check whether their VoIP provider will sign a Business Associate Agreement. Here is when your phone system falls under HIPAA, what a BAA actually gets you, and which providers cover it at which plan tier.

Last updated July 21, 2026
Quick Answer

If protected health information (PHI) moves through your phone system in calls, voicemail, patient texting, call recording, or a contact center flow, your VoIP provider is a business associate under HIPAA and needs a signed Business Associate Agreement (BAA) before you use it for anything patient-facing. Most major UCaaS and CCaaS providers will sign one, but coverage is not uniform: some include it on every plan, others gate it behind a mid or top tier that costs more than the plan you would otherwise choose. There is no such thing as an HHS-certified "HIPAA compliant" VoIP vendor; the BAA plus your own configuration and staff training are what actually satisfy the rule.

Why this matters now

Telehealth and patient texting have pulled the phone system deeper into clinical workflow than it used to be. Front desks confirm appointments and relay results by text, AI-generated voicemail transcripts land in inboxes, and virtual visits route through the same UCaaS platform used for ordinary business calls. Every one of those is a new place PHI can sit outside your EHR's controls.

OCR enforcement has also kept moving toward smaller practices, not just hospital systems. Settlements increasingly cite missing or informal BAAs, not just breaches themselves, meaning a practice can be found non-compliant even before anything leaks. A phone system nobody thought to check is one of the most common gaps auditors find.

Is your phone system in scope?

The test is the same one HIPAA applies everywhere: does PHI get created, received, maintained, or transmitted through the platform? Walk through where it actually shows up in a phone system:

If any of those happen on your phone system today, and they almost always do somewhere, the platform is a business associate and needs a BAA in place.

A capable plan without a signed BAA does not count. Being on a tier that technically supports HIPAA controls is not the same as having an executed Business Associate Agreement with that vendor. If nobody has actually signed one, the practice is out of compliance regardless of which plan it is paying for.

What a BAA actually requires from your provider

A Business Associate Agreement is a contract, not a checkbox. Signing one obligates the vendor to safeguard PHI the way HIPAA's Security and Privacy Rules require, and it makes the vendor directly liable for its own compliance failures rather than leaving all the risk with your practice. Providers that offer a BAA typically back it with encryption in transit and at rest, access controls and audit logging, configurable retention and deletion for recordings and voicemail, and a signed agreement covering breach notification timelines.

None of this is optional and none of it is standardized by a government certification body. HHS does not run a "HIPAA certified" program for software vendors. When a pricing page says "HIPAA compliant," it means the vendor will execute a BAA and has built the controls to support it, and your practice still has to configure retention, restrict who can text patients, and train staff on what not to say in an unencrypted channel.

Which providers offer a BAA, and at what tier

Coverage is common but uneven. Several vendors include HIPAA support at every plan level; others hold it back for a higher tier, which matters if you were planning to buy the entry-level plan.

ProviderHIPAA / BAA coverage
net2phoneYes, all tiers
NextivaAll tiers
Avaya Cloud OfficeYes, all tiers
Panterra NetworksYes, all tiers (HITRUST also)
RingCentralYes
Microsoft Teams PhoneYes
Cisco Webex CallingYes
8x8Yes
GoTo ConnectYes, on Connect+ and above
DialpadPro and Enterprise tiers only, not Standard
Zoom PhoneBusiness+ and above only
Mitel Cloud (MiCloud Connect)Yes, all tiers
Five9Yes (contact center / CCaaS)
TalkdeskYes (contact center / CCaaS)
NICE CXoneYes, broadest certification set including HIPAA, PCI, and FedRAMP

Always confirm current BAA availability directly with the provider before signing, since tier structures and included compliance features change between contract renewals.

What else to check beyond the BAA

Three realistic paths

Path 1 · Most common for small and mid-size practices

Move the whole practice to a plan tier that includes a BAA

Pick the tier, across the provider's lineup, that includes HIPAA support and put the whole practice on it rather than splitting lines. Simplest to manage and to explain to an auditor, at the cost of sometimes paying for a higher tier than a non-healthcare business the same size would need.

Path 2 · Most common for hospital systems and large multi-site groups

Standardize on a compliance-first platform

Choose a vendor with the broadest compliance certification set and dedicated healthcare features, such as secure patient texting and EHR click-to-call, and run the whole organization on it. Highest license cost, but the cleanest story across sites, departments, and a single BAA covering everyone.

Path 3 · The hybrid

HIPAA-eligible tier for clinical and patient-facing lines, standard tier elsewhere

Put clinicians, front desk, and any line that touches patients on the plan tier with a BAA, and leave marketing, vendor relations, or back-office lines that never touch PHI on a standard plan. Lower blended cost than moving everyone up, at the price of managing two tiers and being disciplined about which extensions can touch patient calls.

Our view

The mistake we see most often is not picking the wrong provider, it is skipping the BAA conversation entirely because the plan "supports HIPAA" on paper. Confirm the BAA gets signed, not just that the feature exists. After that, the tier question is usually straightforward once you map which lines actually touch PHI and which don't.

Wholesale pricing applies to HIPAA-eligible tiers the same as any other plan. Providers price the compliance tier at a premium over entry-level, but you should not be paying list rate for it.

Choosing a HIPAA-eligible phone system?

We quote HIPAA-eligible tiers across every major UCaaS and CCaaS provider and can price a full-practice or hybrid split for your actual headcount.

Get wholesale pricing