Somewhere in your practice right now, a voicemail naming a patient and a test result sits on a server you have never seen. The EHR vendor answered a security questionnaire; the Wi‑Fi got attention at the last review; the phone system — the thing that talks about patients all day — never came up. If you are not sure whether HIPAA applies to your phones, you are in good company.
Where a phone system touches PHI
Protected health information is anything that identifies a patient and relates to their health, care, or payment for care. By that standard, an ordinary business phone system handles PHI constantly:
- Voicemail. “Calling for David about his biopsy results” is PHI the moment it is recorded — and hosted voicemail stores it on the provider’s platform, not in your building.
- Voicemail-to-email transcription. That spoken message becomes text in an inbox — PHI now lives in email too, and email gets forwarded.
- Text reminders and replies. Your reminder can stick to logistics, but patients reply with whatever they want: symptoms, medications, questions about results.
- Call recordings. Recordings for training or documentation capture entire clinical conversations, kept indefinitely by default on most systems.
- E-fax. Still everywhere in healthcare — and e-fax turns each document into a file on a vendor’s servers, often forwarded by email.
The rule of thumb: HIPAA regulates the information, not the device
Search the HIPAA Security Rule for the phrase “phone system” and you will not find it. The rule names no technologies; it requires safeguarding electronic PHI wherever it is created, received, stored, or transmitted. That framing makes phones easy to overlook and impossible to exempt.
The moment your phone platform stores a voicemail about a patient, transcribes it, records a call, or holds a fax image, it is holding ePHI, and the same questions apply as to your EHR: who can get in, is it encrypted, who accessed what, how long is it kept, and has the vendor accepted HIPAA obligations in writing? Your risk analysis is supposed to answer those questions for every system touching ePHI — and in the analyses we review through our HIPAA compliance services, the phone system is a commonly missing entry.
What a phone system carrying PHI actually needs
A Business Associate Agreement from the provider
This is the single most common gap. A vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate, and HIPAA generally requires a written Business Associate Agreement before PHI flows. A hosted VoIP provider storing voicemail, an e-fax service holding fax images, a transcription platform — in most cases, each is a business associate. The uncomfortable part: many consumer plans, and even many business plans, will not sign a BAA — those services were never built for HIPAA obligations. If PHI touches the system and the provider will not sign, no setting on your end fixes that — the fix is a provider that will.
Encryption in transit
Calls, voicemail retrieval, faxes, and messages carrying PHI should be encrypted in motion — for VoIP, that generally means TLS for call signaling and SRTP for the voice stream; for e-fax, encrypted transfer rather than plain email attachments. The current Security Rule makes encryption an “addressable” specification: implement it or document why an equivalent measure is reasonable. In practice, treat it as required — it costs little and it is what insurers and investigators expect.
Access controls — not one shared password
Unique identification for each person is a required technical safeguard; one voicemail PIN known to the whole front desk fails it. Give each person their own login and mailbox PIN, limit shared mailboxes to people who need them, deliver transcriptions only to company mailboxes with multi-factor authentication, and end access the day someone leaves.
Audit trails
The Security Rule requires audit controls on systems containing ePHI: you need to see who listened to a message, read a transcription, played a recording, or downloaded a fax. Most hosted platforms keep such logs; the question is whether yours are on, retained, and producible when they matter.
Retention decisions
HIPAA does not set one retention period for voicemail or recordings, but your policies must address stored PHI. Keeping everything forever maximizes breach exposure; deleting haphazardly undermines documentation. Decide on purpose, write it down, configure the system to match. Recording also raises state-law consent questions — a topic for counsel, not a phone vendor.
A deliberate answer for texting
Standard SMS is not encrypted; messages sit readable with carriers and on handsets. That does not make every text a violation — regulators have generally allowed texting a patient who has been warned of the risks and still asks for it — but it demands a decision: restrict SMS to appointment logistics with documented patient consent, or adopt a secure-messaging tool whose vendor signs a BAA. The trouble is the accidental middle — staff texting results from personal phones because nobody decided anything.
Analog landlines, VoIP, and the conduit exception
You may have heard that phone companies are exempt from HIPAA — the real rule is narrower. The “conduit exception” covers organizations that merely transport information with only random or transient access — the postal service, couriers, a carrier moving a live call. A conduit is generally not a business associate and needs no BAA. A live conversation over a true analog line also sits largely outside the Security Rule, which governs electronic PHI; HHS has indicated that voice over a traditional line is not ePHI. A plain analog landline used only for live conversation is, in most cases, the simplest situation.
Almost nothing about a modern system stays that simple. The exception covers pure transmission, and HHS has been explicit that a vendor storing PHI is a business associate even if it never looks at the data. Hosted voicemail, transcriptions, recordings, fax images, message logs — all storage. Many services sold as “landlines” today are VoIP behind the scenes. The conservative reading: the conduit exception protects the carrier moving your live call, not the platform holding your messages. When in doubt, ask the vendor for a BAA — and ask counsel where your setup falls.
A quick audit: feature, risk, and what compliant looks like
| Phone feature | Where the risk is | What compliant generally looks like |
|---|---|---|
| Voicemail | Messages naming patients sit on the provider’s platform, often behind one shared PIN. | Provider signs a BAA; a mailbox and PIN per person; encrypted storage where offered; deletion on a chosen schedule. |
| Voicemail-to-email transcription | PHI becomes plain text in inboxes and gets forwarded. | The BAA covers transcription; delivery only to company mailboxes with MFA; no forwarding to personal accounts. |
| Text appointment reminders | Standard SMS is unencrypted; replies carry clinical detail. | Logistics-only content; documented patient consent; a BAA that covers the messaging feature. |
| Two-way patient texting | Conversations drift into symptoms, medications, and results. | A secure-messaging tool with a BAA — or written policy, consent, and trained staff if SMS stays logistics-only. |
| Call recording | Entire clinical conversations retained indefinitely by default. | A deliberate retention setting; playback restricted; access logged; storage covered by the BAA. |
| E-fax | Fax images stored on vendor servers and forwarded by email. | Vendor signs a BAA; encrypted transfer; confirmed destination numbers; the receiving mailbox locked down. |
What to ask your current provider this week
- “Will you sign a Business Associate Agreement?” Ask in writing. A no — or silence — while PHI touches the system is your biggest gap.
- “Where are our voicemails, transcriptions, recordings, and faxes stored, and are they encrypted?” Expect specifics, not reassurance.
- “Can every person have their own login and voicemail PIN?” And can an administrator see access logs?
- “Can we control how long messages and recordings are kept?” If retention cannot be configured, your policy cannot be followed.
- “Does texting ride on standard SMS or a secure channel, and does the BAA cover it?” The answer decides what staff may put in a message.
Wrong answers do not necessarily mean replacing the system tomorrow; they mean the phones go into your risk analysis with a dated plan to close each gap — generally the posture regulators expect.
Phones are an IT system — treat them like one
The phone system stopped being an appliance years ago. It is software that stores patient information, and it belongs inside the same security program as your EHR, email, and backups — easiest with one accountable team running both. NSN Management is a Tulsa-owned IT company — since 2012 — that builds business VoIP phone systems as a 3CX Gold Partner alongside its HIPAA compliance work, and we sign a Business Associate Agreement with every healthcare client. For the medical, dental, and behavioral health practices we support around Tulsa, voicemail, e-fax, and messaging are configured against the risk analysis, not around it.
Not sure whether your provider would sign a BAA, or what your phones are storing right now? That is a short conversation, not a project. Book a Discovery Call and we will walk through where PHI touches your phones and what closing the gaps would take.
Questions Tulsa businesses ask about this
Is texting patients a HIPAA violation?
Not automatically. Standard SMS is unencrypted, so in most cases it should not carry clinical details. Regulators have generally allowed texting a patient who has been warned of the risks and still asks for it, and plain logistics carry less exposure than results. For routine two-way messaging, use a secure tool whose vendor signs a BAA, document the consent decision, and have counsel review the policy.
Does my phone provider need to sign a BAA?
A provider that stores PHI or has more than transient access — hosted voicemail, transcription, recordings, texting, e-fax — is in most cases a business associate, and a BAA is required. A carrier that only transmits a live call generally falls under the narrow conduit exception. Many consumer and even business phone plans will not sign a BAA — the single most common gap we find.
Are voicemails PHI?
Generally yes, when they identify a patient and relate to health, care, or payment — which describes most messages a practice receives. Stored on a hosted platform or forwarded to email, a voicemail is electronic PHI, so it needs access controls, encryption, audit logging, and a retention decision.
Is a landline HIPAA compliant?
No phone system is HIPAA compliant by itself — compliance describes your whole program, and there is no HIPAA certification for any product. A live conversation over a true analog line generally does not create ePHI, but add voicemail, e-fax, or forwarding to email and electronic PHI exists that must be safeguarded. Many lines sold as landlines today are VoIP behind the scenes, so confirm what you actually have.
Does NSN Management sign a BAA for phone projects?
Yes. NSN Management signs a Business Associate Agreement with every healthcare client, and as a 3CX Gold Partner we configure phone systems so voicemail, faxing, and messaging match your risk analysis — one accountable team instead of two vendors pointing at each other.