security identity · published

HIPAA for contact centers and UC

Verified 2026-10-01 · 60 sources · tier 1–2 · 2 disputed · 1 superseded

Also known as HIPAA call center.

Disputed: 2 sources below carry conflicting evidence.
Superseded guidance: 1 source has been superseded by newer ones.

Under 45 CFR 160.103, a business associate includes a person who, on behalf of a covered entity, creates, receives, maintains, or transmits protected health information (PHI) for a regulated function or activity 9. PHI is individually identifiable health information that is transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium 45.

Who is a business associate

The business associate definition expressly includes a person that provides data transmission services with respect to PHI to a covered entity and that requires routine access to that PHI 8. In the 2013 Omnibus Rule preamble, HHS stated that the conduit exception is limited to transmission services, including any temporary storage of transmitted data incident to that transmission 20. HHS also stated that a data storage company with access to PHI is a business associate even if it does not view the information, or views it only randomly or infrequently 54.

We infer that a UCaaS or CCaaS provider that stores call recordings, voicemail, transcripts, or chat history containing PHI for a covered entity is unlikely to qualify for the conduit exception and should be treated as a business associate needing a BAA 18.

Recordings, transcripts, and de-identification

WarmTransfer's reading of the sources is that call recordings, voicemail, and transcripts held by a covered entity or its business associate fall within the PHI definition when they contain health information about an identifiable caller, because the definition is not limited to written or structured records 17.

Under the HIPAA safe-harbor method, telephone numbers are among the identifiers that must be removed to de-identify health information 51. Biometric identifiers, including voice prints, are also among the safe-harbor identifiers that must be removed 52. We infer that a call recording whose spoken PII has been silenced still carries the caller's voice and is unlikely to be de-identified under the safe-harbor method 46.

AWS states that Amazon Connect conversational analytics redaction does not meet HIPAA de-identification requirements, and recommends continuing to treat redacted output as PHI 23. AWS warns that the redaction is machine-learning based, so it may not identify and remove all sensitive data in a transcript, and recommends reviewing redacted output 22. With redaction enabled, Amazon Connect keeps redacted, unredacted, and raw analysis files in the instance's S3 buckets 21. Those files are accessible through the S3 console, and the original analyzed file is the only complete record of a voice conversation 21.

Business associate agreements

A covered entity may disclose PHI to a business associate, and let it create, receive, maintain, or transmit PHI on the covered entity's behalf, only if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information 19. A business associate may disclose PHI to a subcontractor only after obtaining satisfactory assurances that the subcontractor will appropriately safeguard it 10. These assurances must be documented through a written contract or other written agreement or arrangement 12.

A business associate contract must require the business associate to: 14​11​15​13

  • use appropriate safeguards and comply, where applicable, with the Security Rule (subpart C) for electronic PHI 14;
  • report to the covered entity any use or disclosure not provided for by the contract, including breaches of unsecured PHI 11;
  • ensure that subcontractors handling PHI on its behalf agree to the same restrictions and conditions 15;
  • return or destroy all PHI at termination, with no copies retained where feasible 13.

Covered entities and business associates must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of a use, disclosure, or request 34.

Security Rule safeguards

The Security Rule requires, as a required implementation specification, an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI 50. It requires procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports 1. Its audit controls standard requires hardware, software, or procedural mechanisms that record and examine activity in information systems that contain or use ePHI 2.

Assigning a unique name or number for identifying and tracking user identity is a required access-control implementation specification 57. Under the current Security Rule, the following specifications are addressable rather than required: 3​25​55

  • automatic logoff after a predetermined time of inactivity 3;
  • a mechanism to encrypt and decrypt ePHI 25;
  • encryption of ePHI transmitted over an electronic communications network, under the transmission security standard 55.

Security Rule documentation of policies, procedures, and required actions must be retained for 6 years from creation or from the date it was last in effect, whichever is later 53.

Breach notification

An impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach 16. The presumption does not apply if the covered entity or business associate demonstrates a low probability of compromise, based on a risk assessment of at least the listed factors 16. Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified in HHS guidance under HITECH section 13402(h)(2) 58.

The proposed Security Rule update

On 2025-01-06, HHS published the proposed rule HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) at 90 FR 898, with comments due 2025-03-07 42. The proposal would expressly require regulated entities to encrypt ePHI, with limited exceptions 41. The latest Unified Agenda entry for RIN 0945-AA22, seen on 2026-10-01, lists it under Long-Term Actions with final action targeted for July 2027 43. We infer that, as of 2026-10-01, the existing Security Rule text, with its required and addressable specifications, still governs because the 2025 proposal has not been finalised 24.

Platform differences

AWS

AWS requires covered entities and business associates to enter an AWS business associate agreement before using HIPAA eligible services with PHI 4. The following services appear on the AWS HIPAA Eligible Services Reference: 6​7​5

  • Amazon Connect 6;
  • Amazon Transcribe, including HealthScribe 7;
  • Amazon Bedrock 5.

Microsoft

Microsoft makes its HIPAA BAA available by default, through the Microsoft Online Services Data Protection Addendum, to customers that are covered entities or business associates 36. Microsoft Teams is listed as an in-scope service for the Microsoft HIPAA BAA in both the Office 365 Commercial and GCC environments 39. Microsoft Copilot and Microsoft Copilot Chat are listed as in-scope services in the Office 365 Commercial and GCC rows 37. Dynamics 365 is listed among the Microsoft cloud services in scope for the BAA 38. Microsoft states that having its BAA does not by itself make a customer HIPAA compliant, and that the customer remains responsible for its compliance program and its particular use of the services 35.

Genesys

Genesys states that once a BAA is signed by all parties, it sets a HIPAA toggle on the Genesys Cloud organization 29. Admins can view this toggle under Account > Organization Settings > Settings 29. With HIPAA enabled, Genesys Cloud applies an automatic inactivity timeout that defaults to 15 minutes and can be set no lower than 5 minutes 27. Genesys states that ACD email and SMS cannot carry ePHI and are not covered by its BAA 26. Genesys also states that AppFoundry and social or messaging channel integrations, such as WhatsApp, require separate BAAs with both Genesys and the third party 28.

Google Cloud

Google Cloud lists Google Cloud Contact Center as a Service, and Agent Assist for Google Cloud CCaaS, among the products covered by its HIPAA BAA 31. Google instructs BAA customers not to put PHI or security credentials in Conversational Agents definitions, including intents, training phrases, and entities 32. Google also instructs customers with a BAA covering PHI not to opt in to Speech-to-Text data logging 33.

NICE

NICE states that its policy is to sign a BAA with CXone tenants 40. NICE also states that the BAA requires the tenant to identify itself as a covered entity or a business associate 40.

Twilio

Twilio requires a customer to be on Security Edition or Enterprise Edition to sign its Business Associate Addendum, and does not charge separately for the addendum itself 56.

Zoom

Existing Zoom customers enable the BAA in the web portal under Plans and Billing > Plan Management by selecting Enable on the BAA tile 60. New Business Plus and Enterprise customers go through Sales 60. Zoom states that AI features are available to customers with a BAA, but that certain AI features may not be available to healthcare customers with BAAs in place 59.

RingCentral

RingCentral's March 2026 RingCentral and HIPAA document lists RingCX among the services covered by the RingCentral BAA 49. Sources disagree on RingCentral Contact Center: the RingCentral Contact Center Online Terms of Service, last revised 2015-08-27, prohibit using the Contact Center plan to transmit, store, or otherwise handle PHI, and state that RingCentral's HIPAA BAA program does not apply to that plan 48. This is disputed by RingCentral's March 2026 document, which lists RingCentral Contact Center among the services covered by the RingCentral BAA 47.

See also

Applicability

Applies to: AWS, AWS Amazon Connect, AWS Amazon Transcribe, AWS Amazon Bedrock, Microsoft, Microsoft Teams, Microsoft Copilot, Microsoft Dynamics 365, Twilio, Zoom, Genesys Cloud, Google Cloud Contact Center as a Service, Google Conversational Agents, Google Speech-to-Text, NICE CXone, RingCentral Contact Center, and RingCentral RingCX. Deployments: on-premises, hybrid, and multi-tenant. Sources checked 2026-10-01. We infer that the January 2025 Security Rule proposal was not in force as of 2026-10-01 24. Genesys states that HIPAA compliance for Genesys Cloud is available in the AWS US East and US West regions 30. The Microsoft Teams and Copilot BAA listings cover the Office 365 Commercial and GCC environments 39​37.

What remains uncertain

The Security Rule final rule (RIN 0945-AA22) is targeted for July 2027 under Long-Term Actions 43. Whether it will be finalised on that schedule, and in what final form, is not covered by the sources below.

Sources disagree on the status of RingCentral Contact Center under the RingCentral BAA, so readers should verify it directly with RingCentral 48​47.

Zoom states that certain AI features may not be available to healthcare customers with BAAs 59. Which features are affected, and whether Zoom Contact Center and Zoom Virtual Agent are covered by the Zoom BAA, is not covered by the sources below.

Microsoft lists Teams, Copilot, and Copilot Chat as in-scope services 39​37. Feature-level BAA scope for Microsoft Teams Premium and for individual Copilot features is not covered by the sources below.

The HIPAA BAA scope of additional contact center vendors not discussed above is not covered by the sources below.

The HIPAA BAA scope of additional UC vendors not discussed above is not covered by the sources below.

Amazon Connect Health and the AWS HCLS addendum are not covered by the sources below.

The treatment of substance use disorder records in contact centers is not covered by the sources below.

Whether call recordings form part of a designated record set, and how the right of access applies to them, is not covered by the sources below.

See also

Related to

  • GDPR for contact centers and call recording — Sibling privacy-compliance topic (EU) for contact-center data; HIPAA is the US health-data equivalent. No claims in this packet are tagged to it.
  • PCI DSS for contact centers — Sibling regulatory-compliance topic for contact centers; both cover recordings and transcripts holding regulated data. No claims in this packet are tagged to it.

Referenced by

Sources

  1. 1
    The Security Rule requires procedures to regularly review records of information system activity such as audit logs access reports and security incident tracking reports.
    45 CFR § 164.308 - Administrative safeguards · § 164.308(a)(1)(ii)(D) · Checked 2026-10-01
  2. 2
    The Security Rule audit controls standard requires hardware software or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.
    45 CFR § 164.312 - Technical safeguards · § 164.312(b) · Checked 2026-10-01
  3. 3
    Automatic logoff after a predetermined time of inactivity is an addressable not a required implementation specification under the current Security Rule.
    45 CFR § 164.312 - Technical safeguards · § 164.312(a)(2)(iii) · Checked 2026-10-01
  4. 4
    AWS requires covered entities and business associates to enter an AWS business associate agreement before using HIPAA eligible services with PHI.
    HIPAA Eligible Services Reference · page preamble above the eligible-services list · Checked 2026-10-01
  5. 5
    Amazon Bedrock appears on the AWS HIPAA Eligible Services Reference.
    HIPAA Eligible Services Reference · eligible services list, Amazon Bedrock entry · Checked 2026-10-01
  6. 6
    Amazon Connect appears on the AWS HIPAA Eligible Services Reference.
    HIPAA Eligible Services Reference · eligible services list, Amazon Connect entry · Checked 2026-10-01
  7. 7
    Amazon Transcribe (including HealthScribe) appears on the AWS HIPAA Eligible Services Reference.
    HIPAA Eligible Services Reference · eligible services list, Amazon Transcribe entry · Checked 2026-10-01
  8. 8
    The business associate definition expressly includes a person that provides data transmission services with respect to PHI to a covered entity and that requires access on a routine basis to that PHI.
    45 CFR § 160.103 - Definitions · § 160.103, definition of Business associate, paragraph (3)(i) · Checked 2026-10-01
  9. 9
    Under 45 CFR 160.103 a business associate includes a person who on behalf of a covered entity creates receives maintains or transmits protected health information for a regulated function or activity.
    45 CFR § 160.103 - Definitions · § 160.103, definition of Business associate, paragraph (1)(i) · Checked 2026-10-01
  10. 10
    A business associate may disclose PHI to a subcontractor only after obtaining satisfactory assurances that the subcontractor will appropriately safeguard the information.
  11. 11
    A business associate contract must require the business associate to report to the covered entity any use or disclosure not provided for by the contract including breaches of unsecured PHI.
    45 CFR § 164.504 - Uses and disclosures: Organizational requirements · § 164.504(e)(2)(ii)(C) · Checked 2026-10-01
  12. 12
    The satisfactory assurances required for business associates must be documented through a written contract or other written agreement or arrangement.
  13. 13
    A business associate contract must require return or destruction of all PHI at termination with no copies retained where feasible.
    45 CFR § 164.504 - Uses and disclosures: Organizational requirements · § 164.504(e)(2)(ii)(J) · Checked 2026-10-01
  14. 14
    A business associate contract must require the business associate to use appropriate safeguards and comply where applicable with the Security Rule (subpart C) for electronic PHI.
    45 CFR § 164.504 - Uses and disclosures: Organizational requirements · § 164.504(e)(2)(ii)(B) · Checked 2026-10-01
  15. 15
    A business associate contract must require the business associate to ensure that subcontractors handling PHI on its behalf agree to the same restrictions and conditions.
    45 CFR § 164.504 - Uses and disclosures: Organizational requirements · § 164.504(e)(2)(ii)(D) · Checked 2026-10-01
  16. 16
    An impermissible acquisition access use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate demonstrates a low probability of compromise based on a risk assessment of at least the listed factors.
    45 CFR § 164.402 - Definitions (Breach Notification) · § 164.402, definition of Breach, paragraph (2) · Checked 2026-10-01
  17. 17
    Call recordings voicemail and transcripts held by a covered entity or its business associate that contain health information about an identifiable caller fall within the PHI definition because the definition is not limited to written or structured records.inferred
    45 CFR § 160.103 - Definitions · § 160.103, definition of Protected health information, paragraph (1)(iii) read with the definition of Individually identifiable health information · Checked 2026-10-01
  18. 18
    A UCaaS or CCaaS provider that stores call recordings voicemail transcripts or chat history containing PHI for a covered entity is unlikely to qualify for the conduit exception and should be treated as a business associate needing a BAA.inferred
  19. 19
    A covered entity may disclose PHI to a business associate and let it create receive maintain or transmit PHI on its behalf only if it obtains satisfactory assurance that the business associate will appropriately safeguard the information.
  20. 20
    HHS stated in the 2013 Omnibus Rule preamble that the conduit exception is limited to transmission services including any temporary storage of transmitted data incident to that transmission.
  21. 21
    With redaction enabled Amazon Connect keeps redacted unredacted and raw analysis files in the instance's S3 buckets where they are accessible through the S3 console and the original analyzed file is the only complete record of a voice conversation.
  22. 22
    AWS warns that because redaction is machine-learning based it may not identify and remove all sensitive data in a transcript and recommends reviewing redacted output.
    Use sensitive data redaction to protect customer privacy using conversational analytics · Important callout at top of page (first paragraph) · Checked 2026-10-01
  23. 23
    AWS states that Amazon Connect conversational analytics redaction does not meet HIPAA de-identification requirements and recommends continuing to treat redacted output as PHI.
    Use sensitive data redaction to protect customer privacy using conversational analytics · Important callout at top of page (second paragraph) · Checked 2026-10-01
  24. 24
    As of 2026-10-01 the existing Security Rule text with its required and addressable specifications still governs because the 2025 proposal has not been finalised.inferred
  25. 25
    A mechanism to encrypt and decrypt ePHI is an addressable access-control implementation specification under the current Security Rule.
    45 CFR § 164.312 - Technical safeguards · § 164.312(a)(2)(iv) · Checked 2026-10-01
  26. 26
    Genesys states that ACD email and SMS cannot carry ePHI and are not covered by its BAA.
    HIPAA compliance - Genesys Cloud Resource Center · section on channels and features not covered · Checked 2026-10-01
  27. 27
    With HIPAA enabled Genesys Cloud applies an automatic inactivity timeout that defaults to 15 minutes and can be set no lower than 5 minutes.
    HIPAA compliance - Genesys Cloud Resource Center · section on changes when HIPAA is enabled · Checked 2026-10-01
  28. 28
    Genesys states that AppFoundry and social or messaging channel integrations such as WhatsApp require separate BAAs with both Genesys and the third party.
    HIPAA compliance - Genesys Cloud Resource Center · section on third-party integrations · Checked 2026-10-01
  29. 29
    Once a BAA is signed by all parties Genesys sets a HIPAA toggle on the Genesys Cloud organization which admins can view under Account > Organization Settings > Settings.
    HIPAA compliance - Genesys Cloud Resource Center · article opening section on the BAA and HIPAA setting · Checked 2026-10-01
  30. 30
    Genesys states that HIPAA compliance for Genesys Cloud is available in the AWS US East and US West regions.
    HIPAA compliance - Genesys Cloud Resource Center · region availability paragraph · Checked 2026-10-01
  31. 31
    Google Cloud lists Google Cloud Contact Center as a Service and Agent Assist for Google Cloud CCaaS among products covered by its HIPAA BAA.
    HIPAA Compliance on Google Cloud · Covered products list · Checked 2026-10-01
  32. 32
    Google instructs BAA customers not to put PHI or security credentials in Conversational Agents definitions including intents training phrases and entities.
    HIPAA Compliance on Google Cloud · product-specific guidance, Conversational Agents · Checked 2026-10-01
  33. 33
    Google instructs customers with a BAA covering PHI not to opt in to Speech-to-Text data logging.
    HIPAA Compliance on Google Cloud · product-specific guidance, Speech-to-Text · Checked 2026-10-01
  34. 34
    Covered entities and business associates must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of a use disclosure or request.
  35. 35
    Microsoft states that having its BAA does not by itself make a customer HIPAA compliant and the customer remains responsible for its compliance program and its particular use of the services.
    Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance · Frequently asked questions: Does having a Business Associate Agreement with Microsoft ensure my organization's compliance · Checked 2026-10-01
  36. 36
    Microsoft makes its HIPAA BAA available by default through the Microsoft Online Services Data Protection Addendum to customers that are covered entities or business associates.
  37. 37
    Microsoft Copilot and Microsoft Copilot Chat are listed as in-scope services for the Microsoft HIPAA BAA in the Office 365 Commercial and GCC rows.
  38. 38
    Dynamics 365 is listed among Microsoft cloud services in scope for the Microsoft HIPAA BAA.
  39. 39
    Microsoft Teams is listed as an in-scope service for the Microsoft HIPAA BAA in both the Office 365 Commercial and GCC environments.
  40. 40
    NICE states that its policy is to sign a BAA with CXone tenants and that the BAA requires the tenant to identify itself as a covered entity or a business associate.
    HIPAA - CXone Help Center · HIPAA page, BAA paragraph · Checked 2026-10-01
  41. 41
    The January 2025 Security Rule proposal would expressly require regulated entities to encrypt ePHI with limited exceptions.
  42. 42
    HHS published the proposed rule HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) on 2025-01-06 at 90 FR 898 with comments due 2025-03-07.
  43. 43
    The latest Unified Agenda entry for RIN 0945-AA22 seen on 2026-10-01 lists it under Long-Term Actions with final action targeted for July 2027.
  44. 44
    The Spring 2025 Unified Agenda listed RIN 0945-AA22 at the Final Rule Stage with final action targeted for May 2026.
  45. 45
    Protected health information is individually identifiable health information that is transmitted by electronic media maintained in electronic media or transmitted or maintained in any other form or medium.
    45 CFR § 160.103 - Definitions · § 160.103, definition of Protected health information, paragraph (1)(i)-(iii) · Checked 2026-10-01
  46. 46
    Because voice prints are a safe-harbor identifier a call recording whose spoken PII has been silenced still carries the caller's voice and is unlikely to be de-identified under the safe-harbor method.inferred
    45 CFR § 164.514 - Other requirements relating to uses and disclosures of protected health information · § 164.514(b)(2)(i)(P) applied to redacted audio · Checked 2026-10-01
  47. 47
    RingCentral's March 2026 RingCentral and HIPAA document lists RingCentral Contact Center among the services covered by the RingCentral BAA.disputed
    RingCentral and HIPAA (March 2026) · page 3, footnote 1 (list of services covered by the RingCentral BAA) · Checked 2026-10-01
  48. 48
    The RingCentral Contact Center Online Terms of Service (last revised 2015-08-27) prohibit using the Contact Center plan to transmit store or otherwise handle PHI and state that RingCentral's HIPAA BAA program does not apply to the Contact Center plan.disputed
    RingCentral Contact Center Online Terms of Service · Section II (RingCentral Contact Center and HIPAA) and Section III.B (Prohibited Use) · Checked 2026-10-01
  49. 49
    RingCentral's March 2026 RingCentral and HIPAA document lists RingCX among the services covered by the RingCentral BAA.
    RingCentral and HIPAA (March 2026) · page 3, footnote 1 (list of services covered by the RingCentral BAA) · Checked 2026-10-01
  50. 50
    The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality integrity and availability of ePHI as a required implementation specification.
    45 CFR § 164.308 - Administrative safeguards · § 164.308(a)(1)(ii)(A) · Checked 2026-10-01
  51. 51
    Telephone numbers are among the identifiers that must be removed to de-identify health information under the HIPAA safe-harbor method.
  52. 52
    Biometric identifiers including voice prints are among the safe-harbor identifiers that must be removed for de-identification.
  53. 53
    Security Rule documentation of policies procedures and required actions must be retained for 6 years from creation or the date it was last in effect whichever is later.
  54. 54
    HHS stated that a data storage company with access to PHI is a business associate even if it does not view the information or views it only randomly or infrequently.
  55. 55
    Encryption of ePHI transmitted over an electronic communications network is an addressable implementation specification under the transmission security standard.
    45 CFR § 164.312 - Technical safeguards · § 164.312(e)(1) and (e)(2)(ii) · Checked 2026-10-01
  56. 56
    Twilio requires a customer to be on Security Edition or Enterprise Edition to sign its Business Associate Addendum and does not charge separately for the addendum itself.
    HIPAA Compliance | Twilio · BAA section of the HIPAA page · Checked 2026-10-01
  57. 57
    Assigning a unique name or number for identifying and tracking user identity is a required access-control implementation specification.
    45 CFR § 164.312 - Technical safeguards · § 164.312(a)(2)(i) · Checked 2026-10-01
  58. 58
    Unsecured PHI is PHI not rendered unusable unreadable or indecipherable to unauthorized persons through a technology or methodology specified in HHS guidance under HITECH section 13402(h)(2).
    45 CFR § 164.402 - Definitions (Breach Notification) · § 164.402, definition of Unsecured protected health information · Checked 2026-10-01
  59. 59
    Zoom states that AI features are available to customers with a BAA but that certain AI features may not be available for healthcare customers with BAAs in place.
    HIPAA Business Associate Agreement (BAA) · AI features paragraph · Checked 2026-10-01
  60. 60
    Existing Zoom customers enable the BAA in the web portal under Plans and Billing > Plan Management by selecting Enable on the BAA tile while new Business Plus and Enterprise customers go through Sales.
    HIPAA Business Associate Agreement (BAA) · How to obtain a BAA section · Checked 2026-10-01

Documents

tier 1 standards and regulators

45 CFR § 160.103 - Definitions

Legal Information Institute (Cornell Law School), reproducing the eCFR · accessed 2026-10-01

tier 1 standards and regulators

45 CFR § 164.308 - Administrative safeguards

Legal Information Institute (Cornell Law School), reproducing the eCFR · accessed 2026-10-01

tier 1 standards and regulators

45 CFR § 164.312 - Technical safeguards

Legal Information Institute (Cornell Law School), reproducing the eCFR · accessed 2026-10-01

tier 1 standards and regulators

45 CFR § 164.316 - Policies and procedures and documentation requirements

Legal Information Institute (Cornell Law School), reproducing the eCFR · accessed 2026-10-01

tier 1 standards and regulators

45 CFR § 164.402 - Definitions (Breach Notification)

Legal Information Institute (Cornell Law School), reproducing the eCFR · accessed 2026-10-01

tier 1 standards and regulators

45 CFR § 164.502 - Uses and disclosures of protected health information: General rules

Legal Information Institute (Cornell Law School), reproducing the eCFR · accessed 2026-10-01

tier 1 standards and regulators

45 CFR § 164.504 - Uses and disclosures: Organizational requirements

Cornell Law School Legal Information Institute · accessed 2026-09-24

tier 1 standards and regulators

45 CFR § 164.514 - Other requirements relating to uses and disclosures of protected health information

Legal Information Institute (Cornell Law School), reproducing the eCFR · accessed 2026-10-01

tier 1 standards and regulators

HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (Proposed rule, 90 FR 898)

U.S. Department of Health and Human Services Office for Civil Rights via Office of the Federal Register / GovInfo · 2025-01-06 · accessed 2026-10-01

tier 1 standards and regulators

Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules (Final rule, 78 FR 5566)

U.S. Department of Health and Human Services via Office of the Federal Register / GovInfo · 2013-01-25 · accessed 2026-10-01

tier 1 standards and regulators

View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - latest agenda edition

Office of Information and Regulatory Affairs (OMB) / reginfo.gov · accessed 2026-10-01

tier 1 standards and regulators

View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - Spring 2025 Unified Agenda

Office of Information and Regulatory Affairs (OMB) / reginfo.gov · 2025-04-01 · accessed 2026-10-01

tier 2 current vendor documentation

HIPAA - CXone Help Center

NICE · accessed 2026-10-01

tier 2 current vendor documentation

HIPAA Business Associate Agreement (BAA)

Zoom Communications · accessed 2026-10-01

tier 2 current vendor documentation

HIPAA compliance - Genesys Cloud Resource Center

Genesys · accessed 2026-10-01

tier 2 current vendor documentation

HIPAA Compliance | Twilio

Twilio · accessed 2026-10-01

tier 2 current vendor documentation

HIPAA Compliance on Google Cloud

Google Cloud · 2026-09-30 · accessed 2026-10-01

tier 2 current vendor documentation

HIPAA Eligible Services Reference

Amazon Web Services · 2026-09-03 · accessed 2026-09-24

tier 2 current vendor documentation

RingCentral and HIPAA (March 2026)

RingCentral · 2026-03-01 · accessed 2026-10-01

tier 2 current vendor documentation

RingCentral Contact Center Online Terms of Service

RingCentral · 2015-08-27 · accessed 2026-10-01

tier 2 current vendor documentation

Use sensitive data redaction to protect customer privacy using conversational analytics

Amazon Web Services · accessed 2026-10-01

Cite this page

APA

WarmTransfer. (2026, October 1). HIPAA for contact centers and UC. WarmTransfer. https://warmtransfer.net/knowledge/hipaa-contact-center

BibTeX

@misc{warmtransfer-hipaa-contact-center,
  title  = {HIPAA for contact centers and UC},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/hipaa-contact-center},
  note   = {Verified 2026-10-01}
}