
Indiana, Kentucky, and Rhode Island rolled out new consumer privacy laws on January 1, pushing the national count to 19 states.
California, Connecticut, Oregon, and Utah tightened their existing rules, with Arkansas joining the list in July.
Regulators aren't waiting around either.
Texas collected a settlement of over $1 billion last year. Meanwhile, Connecticut fined a company $85,000 for a weak privacy notice.
Yet, here's the part most small businesses miss—daily phone calls, text messages, and voicemails can carry names, health details, and payment information. And, all of it counts as personal data.
In this article, we'll break down the new rules, what regulators expect, and where iPlum comes in when client communication contains sensitive personal information.
Table of Contents
2. What do regulators expect from your business?
3. So, where do business phones create privacy exposure?
4. How does iPlum help you protect client communication under new privacy rules?
6. New data privacy regulations: frequently asked questions
7.Protect client communication with iPlum
So, what changed?
Privacy rules changed on three fronts. States passed new laws, older laws got tougher, and a big federal update is on the table.
Let's look at all three.
Three new state laws took effect
Indiana, Kentucky, and Rhode Island now enforce comprehensive consumer privacy laws. Now, businesses above certain data thresholds must:
- Publish honest privacy policies
- Get opt-in consent before touching sensitive data
- Honor requests to view, correct, or delete personal information
Sensitive data here includes health conditions, financial details, race, religion, and citizenship status.
Kentucky went a step ahead and opened an Office of Data Privacy to oversee enforcement.
Existing state privacy rules have expanded
California, Connecticut, Oregon, and Utah amended their statutes this year. Some states removed cure periods or lowered applicability thresholds, and both moves change the equation for small businesses.
Now:
- A cure period gave you a window to correct a violation before any fine. Once it's gone, you can get penalized on the first offense.
- Lower thresholds pull smaller companies under laws that previously exempted them.
Arkansas also introduced a law taking effect in July. It restricts online services from collecting children's and teenagers' personal information for targeted advertising.
HIPAA is getting its first security rewrite since 2003
HHS proposed a full overhaul of the HIPAA Security Rule, with a final rule expected late in 2026.
Under the proposal, these safeguards would shift from optional to mandatory:
- Multi-factor authentication
- Encryption for protected health information
- Rapid patching of software flaws
- Round-the-clock system monitoring
So if you're in healthcare, start preparing now. Once the proposals become law, you'll have only a limited time to meet the new requirements.
What do regulators expect from your business?
While different laws use different terms, their expectations come down to five core duties.
Here's what those duties mean for your daily operations.
- Collect only the data you need for a stated purpose: If you request a phone number for appointment reminders, don't quietly add it to a marketing list. The same rule applies to call recordings, payment details, and identity documents. More data creates more responsibility.
- Ask for opt-in consent before processing sensitive data: Ask for affirmative permission before collecting or using such information, such as PHI or financial details, when the applicable law requires it.
- Honor consumer data requests: Provide customers with a process for accessing, correcting, or deleting their personal information. Also, assign a staff member to respond, verify the customer's identity, and document the outcome. And because state deadlines vary, you need to record when the request arrived and when your business responded.
- Put reasonable safeguards in place: Encrypt personal data during transmission and storage. Also, implement multi-factor authentication. In addition, limit account access according to job duties. On top of that, be sure to revoke credentials promptly when an employee leaves or changes roles.
- Review your vendor agreements: Any vendor that receives personal data must have a written agreement that defines permitted use, protection, retention, deletion, and breach notification obligations.
Healthcare organizations also need a Business Associate Agreement before a vendor creates, receives, stores, or transmits protected health information on their behalf.
Did you notice something? Four of these five duties come into play when you call or text a client. Your phone system must therefore meet regulatory compliance requirements.
So, where do business phones create privacy exposure?
Calls and texts are easy to overlook because they seem routine.
After all, it's routine for a receptionist to confirm an appointment, an adviser to text an account update, or a lawyer to leave a voicemail about a case.
However, those conversations can contain names, diagnoses, account numbers, payment details, and other personal information. Once the information enters a call or message, privacy responsibilities come into play.
Here are the habits that get small businesses in trouble.
Texting clients from a personal number
When an employee texts a client from their own phone, a couple of things happen.
One. You can't easily see who accessed the information. Two. You can't retrieve the complete history. There. You can't revoke access after an employee leaves.
In addition, the conversation can remain on personal backups or connected devices. If a customer requests a copy or deletion under Indiana or Rhode Island law becomes impossible when the data resides on hardware outside your reach.
Sending sensitive details over standard SMS
Standard SMS doesn't provide end-to-end encryption. As a result, carriers can read them, and interception is possible in transit.
Sending a patient's appointment details or a client's account information this way contradicts the "reasonable safeguards" duty in nearly every state law.
For healthcare providers, it invites a HIPAA violation. The proposed Security Rule would make encryption mandatory, effectively closing the door on standard SMS for PHI.
Having no records when an auditor asks
Compliance depends on proof. A regulator or auditor could ask:
- Who sent the message?
- Did the client consent to receive it?
- Who accessed the conversation?
- How long was the record stored?
If your calls and texts are scattered across personal devices, you'll have nothing to show.
Think back to the Connecticut case. Nobody hacked TicketNetwork — the company got fined over a faulty privacy notice. Lack of records can cost you, even without data leaks.
So the question is— how can you fix all three at once? Well, you can use a compliant business phone system. And that's where iPlum comes in.
How does iPlum help you protect client communication under new privacy rules?
Sure, iPlum won't write your privacy policy, train staff, or respond to consumer data requests.
What it does is solve the communication side of compliance — the calls, texts, and voicemails where personal data moves every day.
The platform gives staff a business number on their current phones, then adds encryption, consent records, access permissions, and archiving.
Here's how those features align with the responsibilities discussed earlier.
It separates business data from personal activity
iPlum adds a secure mobile second line to a phone you or your employee already owns.
With iPlum, calls, texts, contacts, attachments, and voicemail all go through the business number, so you'll never share private numbers or carry a second device.
And, when an employee leaves, an administrator revokes access and reassigns the number remotely. That way, client conversations don't leave with the former employee.
It is worth noting, though, that a second line alone doesn't satisfy the proposed HIPAA Security Rule.
It does, however, resolve two of the biggest BYOD problems — mixing business data with personal activity and losing access to client conversations when an employee leaves your business.
It encrypts calls, texts, and voicemail
iPlum uses encryption to protect calls, secure texts, and voicemail.
For secure texting, clients can use the iPlum app or send an encrypted message via the iPlum website. Therefore, a clinic can discuss PHI via a protected exchange rather than the standard SMS.
Encryption also helps protect financial details, legal discussions, insurance information, and other sensitive data during transmission and storage.
Of course, encryption doesn't replace consent. Your business still needs permission where the applicable law demands it.
It provides a signed BAA
HIPAA requires healthcare organizations to sign a Business Associate Agreement with vendors that create, receive, store, or transmit PHI on their behalf.
iPlum provides a signed BAA in its HIPAA-compliant phone plans.
The agreement puts iPlum's responsibilities for protecting patient information in writing. Therefore, clinics don't need to negotiate a separate agreement to use the service for qualifying patient communication.
Again, a signed BAA doesn't exempt you from meeting your HIPAA obligations. Your practice must still properly configure the account, train staff, and enforce internal policies.
It offers call-recording consent
iPlum’s provides call recording with consent rules. The phone system can play an automated consent announcement before a phone conversation starts.
As a result, a client or regulator questions whether permission existed, you have dated evidence rather than memory.
It records and archives business communication
iPlum's Enterprise tier allows you to automatically record incoming and outgoing calls. It also provides recording consent announcements, text archiving, audit logs, and searchable records.
In addition, businesses can retain call recordings and text messages for up to ten years, depending on their selected settings and regulatory obligations.
Meanwhile, for financial firms, WORM-compliant storage stores records in a non-rewriteable, non-erasable format. Employees can’t quietly alter or delete a conversation after it's archived.
That way, when an auditor requests a specific call or message, authorized administrators can search for the record and produce it.
It limits access and records user activity
iPlum allows administrators to manage users, permissions, call routing, and compliance settings through the iPlum web portal.
They can decide who gets access to calls, texts, contacts, fax, voicemail, and shared business numbers. If a role changes, the administrator can update the user's permissions or revoke access remotely.
In addition, iPlum line sharing allows authorized staff to use the same business number and view its message history. Timestamps, user attribution, and audit logs show who communicated with a client and when.
So, when a regulator asks who accessed personal data, your business has a documented answer.
Steps to take this quarter
You don't need a compliance department to act on all this.
A few focused moves this quarter will put you ahead of the businesses still ignoring the changes. These include:
- Map the personal data in your communication: List every place client information travels: office lines, mobile phones, texts, voicemails, faxes. Note which conversations involve sensitive data, such as health or financial details.
- Update your privacy notice: Connecticut fined TicketNetwork over a notice problem, so treat yours as a live document. State what you collect through calls and texts, why, and how customers can exercise their rights. Then confirm your real habits match the words.
- Set up a request process: Decide who receives consumer data requests, how you'll verify identity, and where you'll log the dates. A shared inbox and a tracking sheet get the job done on a small scale.
- Move client texting to a secure platform: Get personal data off personal phones and standard SMS. iPlum's Professional plan brings encrypted texting, a signed BAA, and one-year text archiving for $14.99 per user per month.
- Check your vendor agreements: Confirm every vendor touching personal data has a written contract. Healthcare providers should verify a BAA exists before any PHI moves. Financial firms should also review archiving terms against SEC and FINRA retention obligations.
Finally, train your staff. After all, rules only work if the person answering the phone knows them. Walk your staff through consent, sensitive data, and the request process. Repeat it twice a year.
New data privacy regulations: frequently asked questions
Which states passed new privacy laws?
Indiana, Kentucky, and Rhode Island began enforcing comprehensive privacy laws on January 1. Arkansas's law protecting minors' online data took effect July 1, alongside several state amendments during the year.
Is HIPAA going to change?
HHS has proposed a major update to the HIPAA Security Rule, but it isn’t final. The proposal would require MFA, encryption, monitoring, software patching, and detailed security documentation for regulated healthcare organizations.
Are text messages considered personal data?
Yes. A text counts as personal data when it identifies a person or contains information connected to them, such as appointments, diagnoses, account numbers, phone numbers, addresses, or payment details.
Do small businesses need to comply?
Small businesses must comply when they meet a law’s data, revenue, location, or industry threshold. Exemptions vary, and healthcare or financial rules can apply regardless of company size or revenue.
Does iPlum sign a BAA?
Yes. iPlum provides a signed Business Associate Agreement with qualifying HIPAA plans. However, the agreement doesn’t replace your organization’s policies, staff training, account configuration, or daily HIPAA compliance duties.
Protect client communication with iPlum
With the new data privacy regulations, your business needs to examine what it collects, who can access it, and what records it can produce when asked.
And this is the time to ensure compliance.
iPlum gives you encrypted communication, a separate business line, consent records, user permissions, a signed BAA, and long-term archiving.
Click the link below to sign up for iPlum and protect sensitive client communication securely from the get-go.

%20(1).avif)
.avif)