Phones
HIPAA-compliant phone system: what the BAA must cover and what to ask
A HIPAA-compliant phone system is a calling, texting and voicemail service that a covered entity can use to handle protected health information because the vendor has signed a Business Associate Agreement, encrypts calls and messages in transit, and gives the practice control of who can access recordings and records.
When a phone vendor needs a Business Associate Agreement
HIPAA does not certify phone systems. It sets rules for the practice, and for any vendor that handles protected health information (PHI) for the practice.
A vendor is a business associate when it creates, receives, maintains or transmits PHI on the practice's behalf (45 CFR 160.103). A recorded patient call, a text about an appointment and a faxed referral all contain PHI.
The Security Rule says a practice may let a business associate handle electronic PHI only after it obtains satisfactory assurances that the information will be safeguarded, in a written contract (45 CFR 164.308(b)). That contract is the Business Associate Agreement, or BAA.
So the first test of a HIPAA-compliant phone system is simple. The vendor signs a BAA that covers the features you will use.
What a BAA should cover on a phone system
Read the list of covered services, not the headline.
- Calls and voicemail. Including recordings and voicemail transcription.
- Texting. Two-way messages with patients.
- Fax. Sent and received.
- AI features. Call summaries, transcripts and any AI that answers or places calls.
- Subcontractors. The vendor's own cloud, carrier and AI providers. A business associate must get the same assurances from its subcontractors (45 CFR 164.308(b)(2)).
If a feature is not on the list, ask for it in writing before you use it with patients.
Encryption
The Security Rule's transmission security standard asks a practice to guard against unauthorized access to electronic PHI sent over a network (45 CFR 164.312(e)). Encryption is an addressable specification: the rule says to implement a mechanism to encrypt electronic PHI whenever deemed appropriate.
Ask the vendor how calls, texts, recordings and faxes are encrypted in transit and at rest.
Questions to ask any phone vendor
- Will you sign a BAA, and which products and features does it cover?
- Is the BAA included in every plan, or only some?
- How are calls, texts, recordings and faxes encrypted?
- Who at my practice can listen to a recording or read a transcript, and is access logged?
- How long are recordings kept, and can I set the period?
- Which subcontractors touch PHI?
- What happens to my records if I leave?
Where the chart comes in
A phone system can pass every question above and still leave the patient record empty. HIPAA compliance governs how the contact is handled. It does not put the contact on the chart.
A chart-linked phone system matches each call, text and fax to a patient and records it on that patient's chart. Ask for both: a BAA, and a call you can find on the patient afterward.
Caesar Health and HIPAA
Caesar runs on HIPAA-compliant, encrypted infrastructure. A Business Associate Agreement is executed at contract signing. SOC 2 Type II is in progress. Each AI-handled call keeps a transcript and a record of what the agent did and why.
Frequently asked questions
What makes a phone system HIPAA compliant?
A HIPAA-compliant phone system is one a practice can use to handle PHI because the vendor has signed a Business Associate Agreement, protects calls and messages in transit, and lets the practice control who can access recordings and records. HIPAA does not certify products, so compliance is a property of the contract and the way the system is used.
Does a phone vendor have to sign a BAA?
If the vendor creates, receives, maintains or transmits PHI for the practice, it is a business associate under 45 CFR 160.103, and the practice needs a written agreement under 45 CFR 164.308(b). Ask the vendor to state in writing whether it will sign one.
Does the BAA cover texting, fax and AI features?
Not necessarily. A BAA lists the services it covers. Check that calls, voicemail, recordings, texting, fax and any AI summaries or answering are named.
Is call recording allowed under HIPAA?
A recording of a patient call contains PHI, so it needs the same protection as any other PHI, including a BAA with the vendor that stores it. Consent rules for recording calls vary by state; ask your counsel.
Is encryption required?
Under 45 CFR 164.312(e), encryption of electronic PHI in transit is an addressable implementation specification: the rule says to implement a mechanism to encrypt it whenever deemed appropriate. Ask every vendor how calls, texts, recordings and faxes are encrypted.
Is Caesar Health's phone system HIPAA compliant?
Caesar runs on HIPAA-compliant, encrypted infrastructure and signs a Business Associate Agreement at contract signing. SOC 2 Type II is in progress. Ask for the BAA's list of covered services during a demo.
Does a HIPAA-compliant phone system link to the patient chart?
Not by default. HIPAA covers how contacts are protected, not where they are recorded. See what a chart-linked phone system is.
A phone system that also fills the chart
Ask for the BAA and for a call you can find on the patient afterward.