Phoner
BP-54 Buying guide

HIPAA compliant phone system: who signs a BAA

No phone system is compliant out of the box. The BAA is the checkable part.

September 2, 2026 · 9 min read · BY THE PHONER TEAM

Try it · Pick a number

From $15/user/mo · Live in about 5 minutes

Phone Studio · Line 01 Live

01 · Pick your number

+1 (···) ···-····

02 · Your phone menu

03 · Incoming call

REC · consent announced

Press a key to answer the menu yourself

Voicemail to text

transcribed · texted to you · 0:42

Call sheet

Today

This number can be yours in about 5 minutes.

Recording consent laws vary by state and country. You are responsible for lawful use.

A HIPAA compliant phone system is one whose vendor will sign a business associate agreement covering the calls, voicemails, recordings and texts that carry protected health information, and whose settings you then configure to match. Six of the providers a US practice is likely to shortlist publish that they will sign a BAA: RingCentral, Google Voice through Google Workspace, Nextiva, Dialpad, Phone.com and Quo. The cheapest documented route is $15 per user per month, and two vendors sit there: Phone.com, which names no tier requirement at all, and Dialpad, whose own plan matrix marks HIPAA and BAA compliance as included on its $15 Connect Standard tier.

The word "compliant" does a lot of unearned work in this category. No phone system is HIPAA compliant out of the box, and any vendor page that says otherwise is selling. HIPAA puts the obligation on you, the covered entity. A vendor can only do two things about it: sign an agreement that makes it a business associate with its own legal exposure, and give you the technical controls to hold up your end.

So the useful question is not "is this provider HIPAA compliant". It is "will this provider sign a BAA, on which plan, and what does the BAA actually cover". That has a checkable answer, and it is different for every vendor below.

Which VoIP providers sign a BAA

Every row here was read from the provider's own published documentation in September 2026, not from a roundup. Where a provider does not publish a tier requirement, the table says so rather than guessing, because a missing answer and a "no tier needed" answer are not the same thing and the difference costs money.

ProviderSigns a BAA?Cheapest plan that carries itWhat the vendor's own documentation says
Phone.comYesBasic, $15 per user (no tier named)Will "create and sign a Business Associate Agreement" for covered entities that create PHI and for business associates that handle but do not create it
Quo (formerly OpenPhone)YesBusiness, $23 per user"Customers on Business or Scale plans can request a Business Associate Agreement (BAA)"
RingCentralYesNo tier named in its HIPAA document"Makes available a business associate agreement (BAA) for our paying Covered Entity customers"; lists RingEX, RingCX, Contact Center and Fax as covered services
Google VoiceYes, through Google WorkspaceAny Voice tier on a managed Workspace accountListed as a Covered Service on Google's HIPAA Included Functionality list, qualified "managed users only"
NextivaYesNot publishedPublishes HIPAA guidelines and a BAA covering voice, call recording, analytics and fax; the tier requirement is not stated publicly
DialpadYesConnect Standard, $15 per userSays "BAAs are available to eligible healthcare customers as part of the contracting and onboarding process", and its own plan matrix marks HIPAA and BAA compliance as included on all three Connect tiers, read September 3, 2026
OomaHIPAA Mode documented; BAA not stated on that pageOoma Office Pro, $24.95 per userIts HIPAA support page documents encryption of media at rest and in transit on Ooma Office Pro but does not mention a BAA. Ask before you buy
GrasshopperNot published either wayUnknownWe could not find a first-party Grasshopper statement on BAAs in September 2026. Rival vendors assert it does not sign one; we are not repeating a competitor's claim as fact
PhonerNoNot availableWe do not sign BAAs. If you handle PHI, buy from one of the vendors above instead

That last row is the one we would rather not write, and it is the reason this article exists. We would sell more phone systems by staying quiet about it, and a covered entity that bought from us on the strength of a vague page would have a compliance problem that is genuinely expensive to unwind.

What is a HIPAA compliant phone system?

It is a phone service where two things are true at once. The vendor has signed a business associate agreement accepting its own legal duties under the Privacy, Security and Breach Notification Rules, and the deployment has been configured so that PHI in voicemails, recordings, transcripts, faxes and texts is encrypted, access-controlled and retained according to your policy. Neither half is sufficient alone.

The second half is where practices come unstuck. A signed BAA does not change a single setting in your account. Default configurations across this category email voicemail audio and transcriptions to users in plain text, keep call recordings indefinitely, and let any admin download the lot in bulk. Each of those is a straightforward Security Rule problem, and each is a checkbox somebody has to find.

Do I need a BAA for my phone system?

If protected health information can reach the system, yes. That is a lower bar than most practices assume. A patient leaving a voicemail that says their name and why they are calling has created PHI on your vendor's servers. A recorded appointment-confirmation call is PHI. An SMS reminder with a patient name and a date is PHI. You do not have to intend to store health information for the obligation to attach, you only have to receive it, and a published phone number receives whatever callers say into it.

The narrow exception is the conduit rule: a service that only transmits information and does not store it, in the way a telephone carrier historically did, is not a business associate. Almost no cloud phone system qualifies any more, because voicemail, transcription, recording and message history all involve storage. If your provider keeps a voicemail for thirty days, it is storing PHI.

Is Google Voice HIPAA compliant?

Google Voice can be used compliantly, with two conditions. It is listed as a Covered Service under the Google Workspace HIPAA Business Associate Addendum, but the entry is qualified "managed users only", so a personal Google Voice number is not covered no matter what settings you change. And a super administrator has to actively accept the BAA in the Admin console under Legal and compliance; it does not apply by default just because you pay Google.

The cost line worth knowing before you plan around it: Google Voice for business is $10 per user per month on Starter, $20 on Standard and $30 on Premier, and every one of those tiers also requires a Google Workspace license billed separately at $7, $14 or $22. So the real floor for a compliant Google Voice seat is $17, and Starter has no auto attendant and no ring groups, which means a practice with a front desk is realistically pricing Standard at $27 all in. We put both bills side by side in our Google Voice vs RingCentral pricing comparison.

Is RingCentral HIPAA compliant?

RingCentral publishes a dated HIPAA document, refreshed in March 2026, stating that it makes a BAA available to its paying covered entity customers, and it lists which of its products the BAA covers: RingCentral Fax, RingEX, RingCX, Contact Center, the Customer Engagement Bundle and its AI products. It also holds HITRUST CSF certification for RingEX, RingCX and the RingCentral app, and undergoes an annual third-party SOC 2 audit mapped to the HIPAA Security Rule.

Two things that get repeated about RingCentral and are not in its own document: that the BAA requires the Advanced or Ultra tier, and that standard SMS is automatically in scope. The March 2026 document names no plan requirement at all, and coverage is scoped to the listed services rather than to everything the account can do. Confirm your specific deployment in writing rather than inheriting either claim from a comparison article. RingCentral Core is $20 per user billed annually and $30 month to month; the full rate card with the toll-free and texting caps sits on our RingCentral pricing and alternatives page.

What does a BAA actually cover?

Only the services it names. This is the detail that turns a signed agreement into a false sense of safety. RingCentral's BAA lists specific products. Google's covers a defined list of Workspace services with Voice restricted to managed users. If your practice uses a vendor's phone service under a BAA but runs appointment reminders through a third-party texting tool bolted on with an integration, that tool is a separate business associate needing its own agreement, and nobody will tell you so.

The same applies to anything that pulls call data out for analytics, transcription or CRM sync. Before signing anything it is worth mapping which systems a patient's information can end up in, because the answer is usually longer than expected once integrations are counted, and there are tools that will trace where a person's data actually lives across your systems rather than relying on memory. Your BAA coverage needs to reach every one of those destinations.

What settings do I have to change after signing?

These are the five that matter most on a phone system specifically, in the order they tend to cause problems.

Stop emailing voicemail audio and transcripts. Almost every system emails a voicemail as an attachment or pastes the transcription into the message body by default. Unless your mail is itself under a BAA and encrypted, that quietly moves PHI into a system that is not covered. Ooma's HIPAA Mode strips attachments and transcriptions from notifications automatically; on most other systems it is a per-user setting.

Set a recording retention period and stick to it. Recordings default to indefinite retention almost everywhere. Indefinite retention is not a policy, and under the Security Rule you need a documented one. Decide the period, configure it, and write down why.

Turn off bulk recording downloads. A single admin exporting every call in the account is the highest-consequence action available in a phone system, and it is on by default in most of them.

Restrict admin access and enable two-factor authentication. Who can listen to recordings is an access control decision, not a convenience one, and it belongs to the smallest set of people who need it.

Handle recording consent separately. HIPAA does not govern whether you may record a call; state wiretap law does, and eleven states require every party on the call to consent. Our state-by-state guide to call recording consent covers which is which. A practice recording patient calls needs both the BAA and the consent announcement.

Does a HIPAA compliant phone system cost more?

Usually not much, and occasionally nothing. Phone.com's BAA carries no published tier requirement, so the entry Basic plan at $15 per user is the cheapest documented route in the table above. Quo requires the Business plan at $23 rather than Starter at $15, which is a real $8 per user premium for the agreement. Ooma's HIPAA Mode sits on Office Pro at $24.95 against Essentials at $19.95. Google Voice charges nothing extra for the BAA itself but requires the Workspace license underneath regardless.

The bigger cost is rarely the license. It is that healthcare buyers frequently discover the tier carrying the BAA is not the tier they priced, and they discover it after the demo. Ask which plan the BAA attaches to in the first sales conversation, in writing, before you compare anything else. If you are still narrowing the field, our roundup of business VoIP providers prices every plan both annually and month to month.

Can a practice use a regular business phone system?

Yes, if the vendor signs a BAA and you configure it. There is no separate class of medical phone hardware you are required to buy, and vendors marketing "healthcare phone systems" at a premium are usually selling the same platform with the compliance settings pre-enabled and a BAA in the paperwork. That convenience can be worth paying for if nobody at your practice wants to own the configuration, but it is not a technical necessity.

What you should not do is assume. The three failure modes we see repeatedly are a practice on a personal Google Voice number believing the Workspace BAA covers it, a practice that signed a BAA and never changed the voicemail-to-email default, and a practice using a texting add-on that sits outside the phone vendor's agreement entirely. All three pass a casual look at the invoice.

Where we stand

Phoner does not sign business associate agreements. We are a business phone system for teams that need a published number answered well, with an IVR menu, ring groups, business texting, voicemail to text and call recording with consent announcements, at $15 to $29 per user billed yearly ($19 to $35 month to month). If PHI will touch the system, that is a genuine reason to buy elsewhere, and the six providers listed above all publish a route we could not honestly claim.

If you are outside healthcare and got here comparing systems generally, the pricing work behind this article is the useful part: what each provider costs, on which tier, once the requirements nobody advertises are counted. That is on our business phone system cost breakdown.

Line open

Get your business number

Phoner is a business phone system with voip providers built in: a local or toll-free number your whole team can answer, with an IVR menu, voicemail-to-text, and routing from $15 per user per month. No hardware, no contracts.

See voip providers