HIPAA for contact centers and UC
Verified 2026-10-01 · 60 sources · tier 1–2 · 2 disputed · 1 superseded
Also known as HIPAA call center.
Under 45 CFR 160.103, a business associate includes a person who, on behalf of a covered entity, creates, receives, maintains, or transmits protected health information (PHI) for a regulated function or activity 9. PHI is individually identifiable health information that is transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium 45.
Who is a business associate
The business associate definition expressly includes a person that provides data transmission services with respect to PHI to a covered entity and that requires routine access to that PHI 8. In the 2013 Omnibus Rule preamble, HHS stated that the conduit exception is limited to transmission services, including any temporary storage of transmitted data incident to that transmission 20. HHS also stated that a data storage company with access to PHI is a business associate even if it does not view the information, or views it only randomly or infrequently 54.
We infer that a UCaaS or CCaaS provider that stores call recordings, voicemail, transcripts, or chat history containing PHI for a covered entity is unlikely to qualify for the conduit exception and should be treated as a business associate needing a BAA 18.
Recordings, transcripts, and de-identification
WarmTransfer's reading of the sources is that call recordings, voicemail, and transcripts held by a covered entity or its business associate fall within the PHI definition when they contain health information about an identifiable caller, because the definition is not limited to written or structured records 17.
Under the HIPAA safe-harbor method, telephone numbers are among the identifiers that must be removed to de-identify health information 51. Biometric identifiers, including voice prints, are also among the safe-harbor identifiers that must be removed 52. We infer that a call recording whose spoken PII has been silenced still carries the caller's voice and is unlikely to be de-identified under the safe-harbor method 46.
AWS states that Amazon Connect conversational analytics redaction does not meet HIPAA de-identification requirements, and recommends continuing to treat redacted output as PHI 23. AWS warns that the redaction is machine-learning based, so it may not identify and remove all sensitive data in a transcript, and recommends reviewing redacted output 22. With redaction enabled, Amazon Connect keeps redacted, unredacted, and raw analysis files in the instance's S3 buckets 21. Those files are accessible through the S3 console, and the original analyzed file is the only complete record of a voice conversation 21.
Business associate agreements
A covered entity may disclose PHI to a business associate, and let it create, receive, maintain, or transmit PHI on the covered entity's behalf, only if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information 19. A business associate may disclose PHI to a subcontractor only after obtaining satisfactory assurances that the subcontractor will appropriately safeguard it 10. These assurances must be documented through a written contract or other written agreement or arrangement 12.
A business associate contract must require the business associate to: 14111513
- use appropriate safeguards and comply, where applicable, with the Security Rule (subpart C) for electronic PHI 14;
- report to the covered entity any use or disclosure not provided for by the contract, including breaches of unsecured PHI 11;
- ensure that subcontractors handling PHI on its behalf agree to the same restrictions and conditions 15;
- return or destroy all PHI at termination, with no copies retained where feasible 13.
Covered entities and business associates must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of a use, disclosure, or request 34.
Security Rule safeguards
The Security Rule requires, as a required implementation specification, an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI 50. It requires procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports 1. Its audit controls standard requires hardware, software, or procedural mechanisms that record and examine activity in information systems that contain or use ePHI 2.
Assigning a unique name or number for identifying and tracking user identity is a required access-control implementation specification 57. Under the current Security Rule, the following specifications are addressable rather than required: 32555
- automatic logoff after a predetermined time of inactivity 3;
- a mechanism to encrypt and decrypt ePHI 25;
- encryption of ePHI transmitted over an electronic communications network, under the transmission security standard 55.
Security Rule documentation of policies, procedures, and required actions must be retained for 6 years from creation or from the date it was last in effect, whichever is later 53.
Breach notification
An impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach 16. The presumption does not apply if the covered entity or business associate demonstrates a low probability of compromise, based on a risk assessment of at least the listed factors 16. Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified in HHS guidance under HITECH section 13402(h)(2) 58.
The proposed Security Rule update
On 2025-01-06, HHS published the proposed rule HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) at 90 FR 898, with comments due 2025-03-07 42. The proposal would expressly require regulated entities to encrypt ePHI, with limited exceptions 41. The latest Unified Agenda entry for RIN 0945-AA22, seen on 2026-10-01, lists it under Long-Term Actions with final action targeted for July 2027 43. We infer that, as of 2026-10-01, the existing Security Rule text, with its required and addressable specifications, still governs because the 2025 proposal has not been finalised 24.
Platform differences
AWS
AWS requires covered entities and business associates to enter an AWS business associate agreement before using HIPAA eligible services with PHI 4. The following services appear on the AWS HIPAA Eligible Services Reference: 675
Microsoft
Microsoft makes its HIPAA BAA available by default, through the Microsoft Online Services Data Protection Addendum, to customers that are covered entities or business associates 36. Microsoft Teams is listed as an in-scope service for the Microsoft HIPAA BAA in both the Office 365 Commercial and GCC environments 39. Microsoft Copilot and Microsoft Copilot Chat are listed as in-scope services in the Office 365 Commercial and GCC rows 37. Dynamics 365 is listed among the Microsoft cloud services in scope for the BAA 38. Microsoft states that having its BAA does not by itself make a customer HIPAA compliant, and that the customer remains responsible for its compliance program and its particular use of the services 35.
Genesys
Genesys states that once a BAA is signed by all parties, it sets a HIPAA toggle on the Genesys Cloud organization 29. Admins can view this toggle under Account > Organization Settings > Settings 29. With HIPAA enabled, Genesys Cloud applies an automatic inactivity timeout that defaults to 15 minutes and can be set no lower than 5 minutes 27. Genesys states that ACD email and SMS cannot carry ePHI and are not covered by its BAA 26. Genesys also states that AppFoundry and social or messaging channel integrations, such as WhatsApp, require separate BAAs with both Genesys and the third party 28.
Google Cloud
Google Cloud lists Google Cloud Contact Center as a Service, and Agent Assist for Google Cloud CCaaS, among the products covered by its HIPAA BAA 31. Google instructs BAA customers not to put PHI or security credentials in Conversational Agents definitions, including intents, training phrases, and entities 32. Google also instructs customers with a BAA covering PHI not to opt in to Speech-to-Text data logging 33.
NICE
NICE states that its policy is to sign a BAA with CXone tenants 40. NICE also states that the BAA requires the tenant to identify itself as a covered entity or a business associate 40.
Twilio
Twilio requires a customer to be on Security Edition or Enterprise Edition to sign its Business Associate Addendum, and does not charge separately for the addendum itself 56.
Zoom
Existing Zoom customers enable the BAA in the web portal under Plans and Billing > Plan Management by selecting Enable on the BAA tile 60. New Business Plus and Enterprise customers go through Sales 60. Zoom states that AI features are available to customers with a BAA, but that certain AI features may not be available to healthcare customers with BAAs in place 59.
RingCentral
RingCentral's March 2026 RingCentral and HIPAA document lists RingCX among the services covered by the RingCentral BAA 49. Sources disagree on RingCentral Contact Center: the RingCentral Contact Center Online Terms of Service, last revised 2015-08-27, prohibit using the Contact Center plan to transmit, store, or otherwise handle PHI, and state that RingCentral's HIPAA BAA program does not apply to that plan 48. This is disputed by RingCentral's March 2026 document, which lists RingCentral Contact Center among the services covered by the RingCentral BAA 47.
See also
- PCI DSS for contact centers
- GDPR for contact centers and call recording
- Recording consent and AI processing privacy
- CDR privacy redaction and evidence-safe reporting
- Speech and interaction analytics
- Contact centre AI data residency retention and training boundaries
- Identity SSO and directory provisioning for UC
Applicability
Applies to: AWS, AWS Amazon Connect, AWS Amazon Transcribe, AWS Amazon Bedrock, Microsoft, Microsoft Teams, Microsoft Copilot, Microsoft Dynamics 365, Twilio, Zoom, Genesys Cloud, Google Cloud Contact Center as a Service, Google Conversational Agents, Google Speech-to-Text, NICE CXone, RingCentral Contact Center, and RingCentral RingCX. Deployments: on-premises, hybrid, and multi-tenant. Sources checked 2026-10-01. We infer that the January 2025 Security Rule proposal was not in force as of 2026-10-01 24. Genesys states that HIPAA compliance for Genesys Cloud is available in the AWS US East and US West regions 30. The Microsoft Teams and Copilot BAA listings cover the Office 365 Commercial and GCC environments 3937.
What remains uncertain
The Security Rule final rule (RIN 0945-AA22) is targeted for July 2027 under Long-Term Actions 43. Whether it will be finalised on that schedule, and in what final form, is not covered by the sources below.
Sources disagree on the status of RingCentral Contact Center under the RingCentral BAA, so readers should verify it directly with RingCentral 4847.
Zoom states that certain AI features may not be available to healthcare customers with BAAs 59. Which features are affected, and whether Zoom Contact Center and Zoom Virtual Agent are covered by the Zoom BAA, is not covered by the sources below.
Microsoft lists Teams, Copilot, and Copilot Chat as in-scope services 3937. Feature-level BAA scope for Microsoft Teams Premium and for individual Copilot features is not covered by the sources below.
The HIPAA BAA scope of additional contact center vendors not discussed above is not covered by the sources below.
The HIPAA BAA scope of additional UC vendors not discussed above is not covered by the sources below.
Amazon Connect Health and the AWS HCLS addendum are not covered by the sources below.
The treatment of substance use disorder records in contact centers is not covered by the sources below.
Whether call recordings form part of a designated record set, and how the right of access applies to them, is not covered by the sources below.
See also
Related to
- GDPR for contact centers and call recording — Sibling privacy-compliance topic (EU) for contact-center data; HIPAA is the US health-data equivalent. No claims in this packet are tagged to it.
- PCI DSS for contact centers — Sibling regulatory-compliance topic for contact centers; both cover recordings and transcripts holding regulated data. No claims in this packet are tagged to it.
Referenced by
- GDPR for contact centers and call recording — Parallel US health-privacy regime for contact centers
- Speech and interaction analyticsstub — AWS states analytics redaction is not HIPAA de-identification
Sources
- 1The Security Rule requires procedures to regularly review records of information system activity such as audit logs access reports and security incident tracking reports.45 CFR § 164.308 - Administrative safeguards · § 164.308(a)(1)(ii)(D) · Checked 2026-10-01
- 2The Security Rule audit controls standard requires hardware software or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.45 CFR § 164.312 - Technical safeguards · § 164.312(b) · Checked 2026-10-01
- 3Automatic logoff after a predetermined time of inactivity is an addressable not a required implementation specification under the current Security Rule.45 CFR § 164.312 - Technical safeguards · § 164.312(a)(2)(iii) · Checked 2026-10-01
- 4AWS requires covered entities and business associates to enter an AWS business associate agreement before using HIPAA eligible services with PHI.HIPAA Eligible Services Reference · page preamble above the eligible-services list · Checked 2026-10-01
- 5Amazon Bedrock appears on the AWS HIPAA Eligible Services Reference.HIPAA Eligible Services Reference · eligible services list, Amazon Bedrock entry · Checked 2026-10-01
- 6Amazon Connect appears on the AWS HIPAA Eligible Services Reference.HIPAA Eligible Services Reference · eligible services list, Amazon Connect entry · Checked 2026-10-01
- 7Amazon Transcribe (including HealthScribe) appears on the AWS HIPAA Eligible Services Reference.HIPAA Eligible Services Reference · eligible services list, Amazon Transcribe entry · Checked 2026-10-01
- 8The business associate definition expressly includes a person that provides data transmission services with respect to PHI to a covered entity and that requires access on a routine basis to that PHI.45 CFR § 160.103 - Definitions · § 160.103, definition of Business associate, paragraph (3)(i) · Checked 2026-10-01
- 9Under 45 CFR 160.103 a business associate includes a person who on behalf of a covered entity creates receives maintains or transmits protected health information for a regulated function or activity.45 CFR § 160.103 - Definitions · § 160.103, definition of Business associate, paragraph (1)(i) · Checked 2026-10-01
- 10A business associate may disclose PHI to a subcontractor only after obtaining satisfactory assurances that the subcontractor will appropriately safeguard the information.45 CFR § 164.502 - Uses and disclosures of protected health information: General rules · § 164.502(e)(1)(ii) · Checked 2026-10-01
- 11A business associate contract must require the business associate to report to the covered entity any use or disclosure not provided for by the contract including breaches of unsecured PHI.45 CFR § 164.504 - Uses and disclosures: Organizational requirements · § 164.504(e)(2)(ii)(C) · Checked 2026-10-01
- 12The satisfactory assurances required for business associates must be documented through a written contract or other written agreement or arrangement.45 CFR § 164.502 - Uses and disclosures of protected health information: General rules · § 164.502(e)(2) · Checked 2026-10-01
- 13A business associate contract must require return or destruction of all PHI at termination with no copies retained where feasible.45 CFR § 164.504 - Uses and disclosures: Organizational requirements · § 164.504(e)(2)(ii)(J) · Checked 2026-10-01
- 14A business associate contract must require the business associate to use appropriate safeguards and comply where applicable with the Security Rule (subpart C) for electronic PHI.45 CFR § 164.504 - Uses and disclosures: Organizational requirements · § 164.504(e)(2)(ii)(B) · Checked 2026-10-01
- 15A business associate contract must require the business associate to ensure that subcontractors handling PHI on its behalf agree to the same restrictions and conditions.45 CFR § 164.504 - Uses and disclosures: Organizational requirements · § 164.504(e)(2)(ii)(D) · Checked 2026-10-01
- 16An impermissible acquisition access use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate demonstrates a low probability of compromise based on a risk assessment of at least the listed factors.45 CFR § 164.402 - Definitions (Breach Notification) · § 164.402, definition of Breach, paragraph (2) · Checked 2026-10-01
- 17Call recordings voicemail and transcripts held by a covered entity or its business associate that contain health information about an identifiable caller fall within the PHI definition because the definition is not limited to written or structured records.inferred45 CFR § 160.103 - Definitions · § 160.103, definition of Protected health information, paragraph (1)(iii) read with the definition of Individually identifiable health information · Checked 2026-10-01
- 18A UCaaS or CCaaS provider that stores call recordings voicemail transcripts or chat history containing PHI for a covered entity is unlikely to qualify for the conduit exception and should be treated as a business associate needing a BAA.inferredModifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules (Final rule, 78 FR 5566) · 78 FR 5571-5572, conduit and persistent-storage discussion; applied to UC and CCaaS storage · Checked 2026-10-01
- 19A covered entity may disclose PHI to a business associate and let it create receive maintain or transmit PHI on its behalf only if it obtains satisfactory assurance that the business associate will appropriately safeguard the information.45 CFR § 164.502 - Uses and disclosures of protected health information: General rules · § 164.502(e)(1)(i) · Checked 2026-10-01
- 20HHS stated in the 2013 Omnibus Rule preamble that the conduit exception is limited to transmission services including any temporary storage of transmitted data incident to that transmission.Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules (Final rule, 78 FR 5566) · 78 FR 5571-5572, preamble discussion of the business associate definition (conduit exception) · Checked 2026-10-01
- 21With redaction enabled Amazon Connect keeps redacted unredacted and raw analysis files in the instance's S3 buckets where they are accessible through the S3 console and the original analyzed file is the only complete record of a voice conversation.Use sensitive data redaction to protect customer privacy using conversational analytics · About redacted files section · Checked 2026-10-01
- 22AWS warns that because redaction is machine-learning based it may not identify and remove all sensitive data in a transcript and recommends reviewing redacted output.Use sensitive data redaction to protect customer privacy using conversational analytics · Important callout at top of page (first paragraph) · Checked 2026-10-01
- 23AWS states that Amazon Connect conversational analytics redaction does not meet HIPAA de-identification requirements and recommends continuing to treat redacted output as PHI.Use sensitive data redaction to protect customer privacy using conversational analytics · Important callout at top of page (second paragraph) · Checked 2026-10-01
- 24As of 2026-10-01 the existing Security Rule text with its required and addressable specifications still governs because the 2025 proposal has not been finalised.inferredView Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - latest agenda edition · Stage Long-Term Actions; no final rule FR citation in timetable · Checked 2026-10-01
- 25A mechanism to encrypt and decrypt ePHI is an addressable access-control implementation specification under the current Security Rule.45 CFR § 164.312 - Technical safeguards · § 164.312(a)(2)(iv) · Checked 2026-10-01
- 26Genesys states that ACD email and SMS cannot carry ePHI and are not covered by its BAA.HIPAA compliance - Genesys Cloud Resource Center · section on channels and features not covered · Checked 2026-10-01
- 27With HIPAA enabled Genesys Cloud applies an automatic inactivity timeout that defaults to 15 minutes and can be set no lower than 5 minutes.HIPAA compliance - Genesys Cloud Resource Center · section on changes when HIPAA is enabled · Checked 2026-10-01
- 28Genesys states that AppFoundry and social or messaging channel integrations such as WhatsApp require separate BAAs with both Genesys and the third party.HIPAA compliance - Genesys Cloud Resource Center · section on third-party integrations · Checked 2026-10-01
- 29Once a BAA is signed by all parties Genesys sets a HIPAA toggle on the Genesys Cloud organization which admins can view under Account > Organization Settings > Settings.HIPAA compliance - Genesys Cloud Resource Center · article opening section on the BAA and HIPAA setting · Checked 2026-10-01
- 30Genesys states that HIPAA compliance for Genesys Cloud is available in the AWS US East and US West regions.HIPAA compliance - Genesys Cloud Resource Center · region availability paragraph · Checked 2026-10-01
- 31Google Cloud lists Google Cloud Contact Center as a Service and Agent Assist for Google Cloud CCaaS among products covered by its HIPAA BAA.HIPAA Compliance on Google Cloud · Covered products list · Checked 2026-10-01
- 32Google instructs BAA customers not to put PHI or security credentials in Conversational Agents definitions including intents training phrases and entities.HIPAA Compliance on Google Cloud · product-specific guidance, Conversational Agents · Checked 2026-10-01
- 33Google instructs customers with a BAA covering PHI not to opt in to Speech-to-Text data logging.HIPAA Compliance on Google Cloud · product-specific guidance, Speech-to-Text · Checked 2026-10-01
- 34Covered entities and business associates must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of a use disclosure or request.45 CFR § 164.502 - Uses and disclosures of protected health information: General rules · § 164.502(b)(1) · Checked 2026-10-01
- 35Microsoft states that having its BAA does not by itself make a customer HIPAA compliant and the customer remains responsible for its compliance program and its particular use of the services.Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance · Frequently asked questions: Does having a Business Associate Agreement with Microsoft ensure my organization's compliance · Checked 2026-10-01
- 36Microsoft makes its HIPAA BAA available by default through the Microsoft Online Services Data Protection Addendum to customers that are covered entities or business associates.Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance · Frequently asked questions: Can my organization enter into a BAA with Microsoft? · Checked 2026-10-01
- 37Microsoft Copilot and Microsoft Copilot Chat are listed as in-scope services for the Microsoft HIPAA BAA in the Office 365 Commercial and GCC rows.Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance · Office 365 applicability and in-scope services table, Commercial and GCC rows · Checked 2026-10-01
- 38Dynamics 365 is listed among Microsoft cloud services in scope for the Microsoft HIPAA BAA.Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance · Microsoft in-scope cloud platforms and services list · Checked 2026-10-01
- 39Microsoft Teams is listed as an in-scope service for the Microsoft HIPAA BAA in both the Office 365 Commercial and GCC environments.Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance · Office 365 applicability and in-scope services table, Commercial and GCC rows · Checked 2026-10-01
- 40NICE states that its policy is to sign a BAA with CXone tenants and that the BAA requires the tenant to identify itself as a covered entity or a business associate.HIPAA - CXone Help Center · HIPAA page, BAA paragraph · Checked 2026-10-01
- 41The January 2025 Security Rule proposal would expressly require regulated entities to encrypt ePHI with limited exceptions.HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (Proposed rule, 90 FR 898) · SUMMARY / overview of proposed modifications · Checked 2026-10-01
- 42HHS published the proposed rule HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) on 2025-01-06 at 90 FR 898 with comments due 2025-03-07.HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (Proposed rule, 90 FR 898) · Federal Register header; DATES section · Checked 2026-10-01
- 43The latest Unified Agenda entry for RIN 0945-AA22 seen on 2026-10-01 lists it under Long-Term Actions with final action targeted for July 2027.View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - latest agenda edition · Timetable: Final Action 07/00/2027; Stage field · Checked 2026-10-01
- 44The Spring 2025 Unified Agenda listed RIN 0945-AA22 at the Final Rule Stage with final action targeted for May 2026.View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - Spring 2025 Unified Agenda · Timetable: Final Action 05/00/2026; Stage field · Checked 2026-10-01
- 45Protected health information is individually identifiable health information that is transmitted by electronic media maintained in electronic media or transmitted or maintained in any other form or medium.45 CFR § 160.103 - Definitions · § 160.103, definition of Protected health information, paragraph (1)(i)-(iii) · Checked 2026-10-01
- 46Because voice prints are a safe-harbor identifier a call recording whose spoken PII has been silenced still carries the caller's voice and is unlikely to be de-identified under the safe-harbor method.inferred45 CFR § 164.514 - Other requirements relating to uses and disclosures of protected health information · § 164.514(b)(2)(i)(P) applied to redacted audio · Checked 2026-10-01
- 47RingCentral's March 2026 RingCentral and HIPAA document lists RingCentral Contact Center among the services covered by the RingCentral BAA.disputedRingCentral and HIPAA (March 2026) · page 3, footnote 1 (list of services covered by the RingCentral BAA) · Checked 2026-10-01
- 48The RingCentral Contact Center Online Terms of Service (last revised 2015-08-27) prohibit using the Contact Center plan to transmit store or otherwise handle PHI and state that RingCentral's HIPAA BAA program does not apply to the Contact Center plan.disputedRingCentral Contact Center Online Terms of Service · Section II (RingCentral Contact Center and HIPAA) and Section III.B (Prohibited Use) · Checked 2026-10-01
- 49RingCentral's March 2026 RingCentral and HIPAA document lists RingCX among the services covered by the RingCentral BAA.RingCentral and HIPAA (March 2026) · page 3, footnote 1 (list of services covered by the RingCentral BAA) · Checked 2026-10-01
- 50The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality integrity and availability of ePHI as a required implementation specification.45 CFR § 164.308 - Administrative safeguards · § 164.308(a)(1)(ii)(A) · Checked 2026-10-01
- 51Telephone numbers are among the identifiers that must be removed to de-identify health information under the HIPAA safe-harbor method.45 CFR § 164.514 - Other requirements relating to uses and disclosures of protected health information · § 164.514(b)(2)(i)(D) · Checked 2026-10-01
- 52Biometric identifiers including voice prints are among the safe-harbor identifiers that must be removed for de-identification.45 CFR § 164.514 - Other requirements relating to uses and disclosures of protected health information · § 164.514(b)(2)(i)(P) · Checked 2026-10-01
- 53Security Rule documentation of policies procedures and required actions must be retained for 6 years from creation or the date it was last in effect whichever is later.45 CFR § 164.316 - Policies and procedures and documentation requirements · § 164.316(b)(2)(i) · Checked 2026-10-01
- 54HHS stated that a data storage company with access to PHI is a business associate even if it does not view the information or views it only randomly or infrequently.Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules (Final rule, 78 FR 5566) · 78 FR 5571-5572, preamble discussion of the business associate definition (persistent storage) · Checked 2026-10-01
- 55Encryption of ePHI transmitted over an electronic communications network is an addressable implementation specification under the transmission security standard.45 CFR § 164.312 - Technical safeguards · § 164.312(e)(1) and (e)(2)(ii) · Checked 2026-10-01
- 56Twilio requires a customer to be on Security Edition or Enterprise Edition to sign its Business Associate Addendum and does not charge separately for the addendum itself.HIPAA Compliance | Twilio · BAA section of the HIPAA page · Checked 2026-10-01
- 57Assigning a unique name or number for identifying and tracking user identity is a required access-control implementation specification.45 CFR § 164.312 - Technical safeguards · § 164.312(a)(2)(i) · Checked 2026-10-01
- 58Unsecured PHI is PHI not rendered unusable unreadable or indecipherable to unauthorized persons through a technology or methodology specified in HHS guidance under HITECH section 13402(h)(2).45 CFR § 164.402 - Definitions (Breach Notification) · § 164.402, definition of Unsecured protected health information · Checked 2026-10-01
- 59Zoom states that AI features are available to customers with a BAA but that certain AI features may not be available for healthcare customers with BAAs in place.HIPAA Business Associate Agreement (BAA) · AI features paragraph · Checked 2026-10-01
- 60Existing Zoom customers enable the BAA in the web portal under Plans and Billing > Plan Management by selecting Enable on the BAA tile while new Business Plus and Enterprise customers go through Sales.HIPAA Business Associate Agreement (BAA) · How to obtain a BAA section · Checked 2026-10-01
Documents
45 CFR § 160.103 - Definitions
45 CFR § 164.308 - Administrative safeguards
45 CFR § 164.312 - Technical safeguards
45 CFR § 164.316 - Policies and procedures and documentation requirements
45 CFR § 164.402 - Definitions (Breach Notification)
45 CFR § 164.502 - Uses and disclosures of protected health information: General rules
45 CFR § 164.504 - Uses and disclosures: Organizational requirements
45 CFR § 164.514 - Other requirements relating to uses and disclosures of protected health information
HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (Proposed rule, 90 FR 898)
Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules (Final rule, 78 FR 5566)
View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - latest agenda edition
View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - Spring 2025 Unified Agenda
Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance
HIPAA - CXone Help Center
HIPAA Business Associate Agreement (BAA)
HIPAA compliance - Genesys Cloud Resource Center
HIPAA Compliance | Twilio
HIPAA Compliance on Google Cloud
HIPAA Eligible Services Reference
RingCentral and HIPAA (March 2026)
RingCentral Contact Center Online Terms of Service
Use sensitive data redaction to protect customer privacy using conversational analytics
Cite this page
APA
WarmTransfer. (2026, October 1). HIPAA for contact centers and UC. WarmTransfer. https://warmtransfer.net/knowledge/hipaa-contact-center
BibTeX
@misc{warmtransfer-hipaa-contact-center,
title = {HIPAA for contact centers and UC},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/hipaa-contact-center},
note = {Verified 2026-10-01}
}