
Your clinic probably uses VoIP daily.
Staff answer patient calls, return voicemails, send appointment details, and discuss billing through the same phone system.
But can you confidently say your VoIP system is HIPAA-compliant?
Sure, a provider might advertise encryption or call its service "HIPAA ready."
However, neither claim gives you the full answer.
Compliance also depends on a Business Associate Agreement being in effect, secure data storage, access permissions, activity records, and how your staff uses the service.
So, how can you tell if your setup meets HIPAA requirements?
In this article, we'll break down exactly what to check, which warning signs deserve attention, and what your clinic must do on its end.
We'll also explain how iPlum ensures HIPAA compliance to protect patient communications and records.
Table of Contents
1. Can VoIP be HIPAA compliant?
2. How to tell if your VoIP is HIPAA compliant
3. Warning signs your current VoIP needs closer review
4. Your practice has HIPAA duties too
5. How iPlum meets the HIPAA VoIP checklist
6.HIPAA-compliant VoIP: frequently asked questions
7. Choose a HIPAA-compliant VoIP service for your clinic
Can VoIP be HIPAA compliant?
Yes, VoIP can be HIPAA compliant.
However, no VoIP service is compliant out of the box. In addition, no provider can sell you compliance as a finished product.
Furthermore, the Department of Health and Human Services (HHS) doesn’t certify or approve specific VoIP products. Thus, a "HIPAA compliant" badge on a provider's website carries no significant weight on its own.
What matters is electronic protected health information (ePHI) flowing through your phone system. In a typical clinic, ePHI shows up in:
- Voicemails from patients
- Call recordings
- Text conversations
- Electronic fax records
- Call logs
- Contact records
Once a provider creates, receives, maintains, or transmits any of this on your behalf, HIPAA treats it as a business associate.
The clinic and provider must then enter into a Business Associate Agreement that states how the provider can use PHI and which safeguards, reporting duties, and data terms apply.
That said, both your practice and the provider share compliance responsibilities.
On one hand, the provider must offer the required contractual and technical protections. Your practice, on the other hand, must properly configure the service and train staff to use it correctly. One side alone won't satisfy HIPAA.
How to tell if your VoIP is HIPAA compliant
Now comes the real test.
You shouldn't stop at a provider's marketing page. Ask the vendor to explain in writing how the service protects ePHI, who can access it, which records it creates, and what happens after a security incident.
Then, use the following five checks.
1. Confirm that a Business Associate Agreement is in effect
Start with the BAA.
If a provider stores, processes, or transmits ePHI for your clinic, a BAA must be in effect before staff send patient information through the service.
A privacy policy, "HIPAA-ready" label, or encryption statement doesn't replace a BAA.
Next, examine the agreement's scope. Does it apply to your exact plan? Does it apply to voicemail, texts, recordings, fax files, and stored communication?
Also, confirm how the provider issues the agreement. Some providers use an electronic, account-specific BAA rather than exchanging manually signed copies.
The agreement should identify the client, the provider, the effective period, and the account connected to it.
Look for terms addressing:
- Permitted uses of PHI
- Security incident reporting
- Subcontractor obligations
- Data return or destruction
Pay close attention to plan limits. Some providers reserve the BAA for certain subscriptions, leaving other tiers outside the agreement. Your clinic needs the correct subscription before staff begin using regulated features.
If a sales representative promises a BAA but the contract excludes important features, get the details in writing before moving forward.
2. Check how the provider protects ePHI
Next, look beyond "we use encryption."
Ask if the provider encrypts data during transmission and storage. Protection should apply to:
- Call recordings
- Texts and attachments
- Voicemail files
- Electronic faxes
- Call logs and contact records
Also, find out where downloaded files go. A voicemail recording saved to a personal email account or a text copied into an unapproved app can expose ePHI.
HHS treats encryption as part of the Security Rule. Availability, record integrity, identity checks, and written policies also count.
In addition, ask about backups and data copies. The provider should explain where it stores them, who can access them, how it protects them, and when it deletes them.
3. Review the access controls
After that, ask who can access specific communication.
A receptionist might need calls and texts, while a biller might only need fax access. In addition, your system should let an administrator assign permissions based on job duties.
Check for:
- Individual user accounts
- Role-based permissions
- Secure authentication
- Immediate account removal
- Device access management
While at it, make sure every staff member has a separate login.
If several staff members share one account, you can't tell who viewed, changed, or sent patient information. Shared accounts can also expose staff to information they don't need for their jobs, which goes against HIPAA's minimum necessary standard.
In addition, access shouldn't continue after an employee leaves or a phone goes missing. Therefore, administrators need tools to sign users out, revoke account access, and block lost or unauthorized devices.
Last but not least, check for multi-factor authentication, which adds another layer of protection. With multi-factor authentication, even if a password is stolen, the second verification step can stop an unauthorized user from accessing the account.
4. Review logs, retention, and deletion
HIPAA requires regulated organizations to review system activity and identify possible security incidents. So, your VoIP provider should offer records you can use.
Ask whether logs show:
- User sign-ins
- Calls and texts
- Voicemail access
- Recording access
- Permission changes
- Dates and timestamps
Then, examine retention and deletion. How long does the provider store communication records? Can your clinic archive or export them? Can authorized administrators delete them in accordance with policy?
Longer retention isn't automatically better. However, your chosen period should match legal obligations, contractual duties, and your clinic's written policy.
5. Ask about incidents, outages, and cancellations
Finally, ask the provider to explain its response to a security incident, service outage, or account cancellation.
Get written answers to these questions:
- How quickly will the provider notify your clinic?
- Which subcontractors can access or store ePHI?
- How does the provider restore data after an outage?
- Can your clinic export its records before cancellation?
- Will the provider return or delete the remaining ePHI?
- Can it provide proof of deletion?
Don't accept vague answers here. Ask the provider to put its responsibilities, response timelines, and your clinic's obligations in writing.
While passing these five checks doesn't automatically make your clinic HIPAA-compliant, it shows whether the VoIP service meets the contract terms and technical protections HIPAA requires.
Warning signs your current VoIP needs closer review
Some compliance problems are easy to spot once you know what to ask. Others hide inside plan terms, default settings, and features your clinic has already activated.
Therefore, be vigilant if:
- The provider refuses to enter into or provide a BAA.
- The BAA is available only on a plan your clinic isn't using.
- The contract applies to calls but excludes texts, voicemail, fax, or recordings.
- The provider says the service is HIPAA compliant, but won't explain its encryption.
- Employees share one account or password.
- Patient messages are transferred to personal text or email apps.
- Administrators can't limit access according to job duties.
- Former employees can still sign in.
- Activity logs don't identify individual users or changes to permissions.
- The provider can't state how long it stores communication records.
- Your clinic can't export records or request secure deletion.
- The terms for security incident notification are missing or vague.
- The provider won't identify subcontractors that can access ePHI.
One warning sign doesn't automatically prove a HIPAA violation. A provider might sign BAAs but explain the process poorly on its website, for example.
However, each sign raises a question your clinic should answer before sharing more patient information through the service.
Investigate first. If the provider can't give you a straight answer in writing, treat the silence as your answer and start comparing alternatives.
Your practice has HIPAA duties too
Choosing a HIPAA-compliant VoIP provider doesn't make your practice compliant.
The provider secures its platform and performs the duties described in its BAA. However, your clinic remains responsible for staff, devices, account settings, policies, and daily use.
Start by documenting how ePHI enters, moves through, and leaves the phone system. Then, appoint a security official to manage these tasks:
- Give every employee a separate login.
- Limit permissions according to job duties.
- Apply HIPAA's minimum necessary standard.
- Train staff on approved calls, texts, voicemail, fax, and recordings.
- Stop employees from sharing patient information through personal apps.
- Require secure passwords, multi-factor authentication, and device locks.
- Remove access after an employee leaves or changes roles.
- Block missing or unauthorized devices.
- Review account activity regularly.
- Document retention, deletion, and security incident procedures.
Your clinic should also decide what staff can say in voicemail, when calls can be recorded, where files can be downloaded, and how long communication records remain in the system.
Written policies mean little if staff don't understand them. Therefore, training should use actual clinic scenarios and explain what employees must do when they send information to the wrong person, lose a device, or notice unusual account activity.
Compliance also requires regular review.
Therefore, recheck permissions whenever staff roles change, a new feature is activated, or the clinic changes its communication process. If your clinic neglects these responsibilities, provider safeguards can't compensate for misuse.
That said, the right provider makes these duties far easier to implement. Which brings us to iPlum, a mobile-first phone system built for team management, security, and scale.
How iPlum meets the HIPAA VoIP checklist
iPlum is a VoIP provider built for regulated business communication. Here's how it measures up against the five checks above.
It provides an account-specific BAA through the client portal
iPlum makes its BAA available inside the client portal. It does not require a manual exchange of signatures with every client.
The portal generates the agreement with the clinic's company name, effective date, iPlum number, and account email. These details connect the agreement to the client account and confirm its HIPAA coverage.
The agreement identifies iPlum as the Business Associate and the client as the Covered Entity. It governs PHI that iPlum creates, receives, maintains, or transmits when providing the services described in the agreement.
However, clinics must review the communication scope. The BAA caters to voice and text messages that begin and end within iPlum's covered products and services. Standard SMS or other messages that begin or end outside iPlum's service platform are not covered by the agreement.
Therefore, staff should use iPlum's secure in-platform messaging when conversations contain patient information.
That said, your clinic should still select the Professional or Enterprise plan for HIPAA compliance and verify that the agreement covers all the features staff will use.
It separates patient communication from personal activity
iPlum allows staff to add a dedicated business number to an existing mobile phone. That way, they can call or text patients from that number while keeping their personal number private.
With iPlum, calls, texts, fax, and voicemail remain connected to the business account. Consequently, patient communication doesn't mix with personal messages on the same number.
iPlum uses encrypted channels for calling and messaging. It also offers secure texting for conversations containing patient information. In addition, it provides a free patient account that enables secure, bi-directional messaging between your practice and patients, separate from SMS or MMS.
The BAA applies to text messages that start and end within iPlum. Thus, clinics should not treat regular SMS, MMS, or external messaging as communication protected under the BAA.
Meanwhile, dual-call reliability also allows staff to use VoIP or the carrier voice network while displaying the iPlum business number.
It gives administrators access and record controls
iPlum allows administrators to manage user access from the web portal. They can assign users and decide who can access calls, texts, fax, voicemail, and other communication records.
Since staff have separate accounts, administrators can identify user activity. They can also revoke access when an employee leaves, adjust permissions after a role change, and review usage records.
In addition, iPlum offers call recording, text archiving, voicemail management, and activity logs. Enterprise archiving can retain communication records for up to ten years and store them in a write-once, read-many format.
With iPlum, clinics have the records needed for internal reviews, retention policies, and investigations. It is worth noting that feature availability depends on the selected plan, so administrators should review account settings during setup.
That said, iPlum's BAA states incident reporting and data return duties
It sets written timelines for security incidents and breaches. iPlum must report a security incident or an unapproved use or disclosure of PHI in writing no later than three business days after becoming aware of it.
If iPlum determines that a reportable breach of unsecured PHI occurred, it must send the clinic a written report no later than 30 calendar days after discovering the breach.
The agreement also requires subcontractors that create, receive, maintain, or transmit PHI to enter into BAAs with the same restrictions and requirements.
After termination or expiration, iPlum must return or destroy the remaining PHI when feasible. If return or destruction is not feasible, iPlum must continue applying the agreement's protections for as long as it retains the information.
Combined with its account-specific portal BAA, defined communication scope, safeguards, incident reporting timelines, subcontractor requirements, and PHI return or destruction terms, these administrative features address the main provider requirements on the checklist.
Your clinic remains responsible for staff training, account settings, approved communication methods, and daily use. However, iPlum provides a healthcare-ready phone system for managing those responsibilities.
HIPAA-compliant VoIP: frequently asked questions
Is VoIP HIPAA compliant by default?
No. VoIP becomes suitable for HIPAA-regulated communication only when the provider signs a BAA, protects ePHI, offers access controls, and the healthcare organization configures and uses the service correctly in daily operations.
Does encryption alone make VoIP HIPAA compliant?
No. Encryption protects ePHI during transmission and storage, but HIPAA also requires access controls, activity reviews, written policies, staff training, incident procedures, and a BAA in effect with the provider.
Do I need a BAA with my VoIP provider?
Yes, if the provider creates, receives, maintains, or transmits ePHI. A BAA must be in effect, though iPlum issues an account-specific agreement electronically through its client portal for covered clients.
Are voicemails and call recordings protected under HIPAA?
Yes, when they contain identifiable patient information. Clinics must protect stored voicemail and recordings, limit access, set retention periods, review activity, and, when permitted by policy, dispose of files securely.
Can healthcare staff use HIPAA-compliant VoIP on personal phones?
Yes, provided the clinic uses an approved business app, separates patient communication from personal activity, requires secure authentication, manages device access, and promptly revokes accounts after loss or departure.
Choose a HIPAA-compliant VoIP service for your clinic
So, is your VoIP HIPAA compliant? Now you can answer with conviction.
Verify the BAA, encryption, access permissions, activity records, retention terms, and security incident procedures. Then hold your clinic to its own duties: configuration, policies, and staff training.
If your current provider fails the test, iPlum passes every check.
Click the link below to sign up today and give your clinic a separate, HIPAA-ready business phone system.

%20(1).avif)
.avif)