Most clinics think of their phone system as plumbing. It rings, it routes, it takes messages. What is easy to miss is that a modern VoIP system also stores and moves patient information, and that changes how HIPAA treats it. If your phone system carries protected health information, it belongs in your Security Risk Analysis, and leaving it out is a scope gap an auditor can find.
Here is how to tell whether your phone system is in scope, and what to confirm before you assume it is handled.
The short answer
The HIPAA Security Rule applies to electronic protected health information that a healthcare organization creates, receives, maintains, or transmits. That phrase is the test. A phone system that records a voicemail describing a patient's symptoms, saves a call recording, or sends a fax over the internet is maintaining and transmitting that information. Once it does, the system is inside the Security Rule, not beside it.
That does not make VoIP a problem. It makes VoIP a system you have to account for, the same way you account for the EHR and the billing platform.
Where PHI hides in a phone system
The patient information in a phone system is rarely obvious, because it accumulates in the features people rely on most.
- Voicemail. A patient leaves a message about a prescription or a test result. That recording is protected health information, sitting on the vendor's servers until someone deletes it.
- Call recordings. Clinics that record calls for training or quality are storing clinical conversations, often for months.
- Faxes over VoIP. Digital fax rides the same network. The referral, the lab result, and the records request are all PHI in transit.
- Text and chat. Appointment and follow-up messaging through the phone platform can carry clinical detail even when it is not supposed to.
- Call metadata. Who called, when, and how often can be sensitive on its own for a specialty practice.
Any one of these puts the system in scope. Most clinics have several.
Why the risk analysis has to include it
A Security Risk Analysis is a review of the risks to all of the electronic protected health information an organization holds. Thorough means it reaches every system that handles that information, not the ones that were easy to remember. The Security Rule sets three categories of safeguards to assess against: administrative, physical, and technical. A phone system touches all three. There is a vendor relationship to manage, hardware and handsets in the building, and encryption and access settings in the software.
The phone system is a frequent blind spot precisely because it feels like infrastructure rather than a records system. An analysis that covers the EHR and the laptops but never names the VoIP platform has a hole in it, and the hole is in a system that quietly holds recordings of patients describing their care.
The questions that settle it
You do not need a security background to place your phone system correctly in a risk analysis. A short set of questions does the work, and the answers belong in writing so they can be attached to the analysis itself.
| Ask your VoIP vendor | Why it matters |
|---|---|
| Will you sign a Business Associate Agreement? | If they handle PHI on your behalf, one is required before they touch it. |
| Are calls, voicemail, and messages encrypted in transit? | Voice traffic crossing the internet is exposed without it. |
| Where are recordings and voicemail stored, and for how long? | Storage location and retention are risks you are accountable for. |
| Who on your side can access our stored data? | Vendor access is part of your risk picture. |
| How do we export or delete our data if we leave? | PHI you cannot retrieve or remove is a lingering liability. |
Any vendor that serves healthcare can answer these. A vendor that cannot, or will not put the answers in writing, has told you something useful.
The Business Associate Agreement
The Business Associate Agreement is the document that formalizes the vendor's obligations. When a phone provider stores or transmits PHI for you, it is a business associate under HIPAA and is directly regulated. The agreement has to be in place before the vendor handles the information, and it should name what the vendor may do with the data, require safeguards, and set breach notification duties.
Discovering during an incident that the agreement was never signed, or was signed years ago with a company that has since been acquired, is its own finding, separate from whatever went wrong. It is also entirely preventable with a file check.
The takeaway
If your phone system records voicemail, saves calls, or sends faxes, treat it as a system that holds patient information, because it does. Name it in your Security Risk Analysis, confirm the Business Associate Agreement, and get the vendor's security answers in writing. It is a small amount of work that closes a gap most clinics do not know they have.
For related reading, see Is VoIP HIPAA Compliant?, Voicemail and PHI: What a Clinic Can Leave in a Message, and Business Associate Agreements and Your Phone System.
Common questions
Is a VoIP phone system covered by HIPAA? It is covered when it creates, receives, maintains, or transmits electronic protected health information for a healthcare organization. Voicemail with clinical details, saved recordings, and internet fax are common examples, and a vendor handling that data needs a Business Associate Agreement.
Does a phone system belong in a Security Risk Analysis? Yes, if it carries PHI. The analysis has to account for the electronic protected health information across every system that handles it, and a voice platform that stores or transmits clinical information qualifies.
What should a clinic ask a VoIP vendor about HIPAA? Whether they will sign a Business Associate Agreement, whether traffic is encrypted in transit, where recordings and voicemail are stored and for how long, and who can access that data. In writing.
Is VoIP encryption required by HIPAA? Encryption is an addressable specification, not automatically required. You assess whether it is reasonable and appropriate, implement it if it is, and document your reasoning otherwise. For clinical voice traffic over the internet, it is usually the reasonable choice.
Sources for verification: U.S. Department of Health and Human Services, HIPAA Security Rule; Electronic Code of Federal Regulations, 45 CFR Part 164.