# HIPAA for contact centers and UC

Canonical: https://warmtransfer.net/knowledge/hipaa-contact-center

Last verified: 2026-10-01

Under 45 CFR 160.103, a business associate includes a person who, on behalf of a covered entity, creates, receives, maintains, or transmits protected health information (PHI) for a regulated function or activity[^9]. PHI is individually identifiable health information that is transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium[^45].

## Who is a business associate

The business associate definition expressly includes a person that provides data transmission services with respect to PHI to a covered entity and that requires routine access to that PHI[^8]. In the 2013 Omnibus Rule preamble, HHS stated that the conduit exception is limited to transmission services, including any temporary storage of transmitted data incident to that transmission[^20]. HHS also stated that a data storage company with access to PHI is a business associate even if it does not view the information, or views it only randomly or infrequently[^54].

We infer that a UCaaS or CCaaS provider that stores call recordings, voicemail, transcripts, or chat history containing PHI for a covered entity is unlikely to qualify for the conduit exception and should be treated as a business associate needing a BAA[^18].

## Recordings, transcripts, and de-identification

WarmTransfer's reading of the sources is that call recordings, voicemail, and transcripts held by a covered entity or its business associate fall within the PHI definition when they contain health information about an identifiable caller, because the definition is not limited to written or structured records[^17].

Under the HIPAA safe-harbor method, telephone numbers are among the identifiers that must be removed to de-identify health information[^51]. Biometric identifiers, including voice prints, are also among the safe-harbor identifiers that must be removed[^52]. We infer that a call recording whose spoken PII has been silenced still carries the caller's voice and is unlikely to be de-identified under the safe-harbor method[^46].

AWS states that Amazon Connect conversational analytics redaction does not meet HIPAA de-identification requirements, and recommends continuing to treat redacted output as PHI[^23]. AWS warns that the redaction is machine-learning based, so it may not identify and remove all sensitive data in a transcript, and recommends reviewing redacted output[^22]. With redaction enabled, Amazon Connect keeps redacted, unredacted, and raw analysis files in the instance's S3 buckets[^21]. Those files are accessible through the S3 console, and the original analyzed file is the only complete record of a voice conversation[^21].

## Business associate agreements

A covered entity may disclose PHI to a business associate, and let it create, receive, maintain, or transmit PHI on the covered entity's behalf, only if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information[^19]. A business associate may disclose PHI to a subcontractor only after obtaining satisfactory assurances that the subcontractor will appropriately safeguard it[^10]. These assurances must be documented through a written contract or other written agreement or arrangement[^12].

A business associate contract must require the business associate to:[^14][^11][^15][^13]

- use appropriate safeguards and comply, where applicable, with the Security Rule (subpart C) for electronic PHI[^14];
- report to the covered entity any use or disclosure not provided for by the contract, including breaches of unsecured PHI[^11];
- ensure that subcontractors handling PHI on its behalf agree to the same restrictions and conditions[^15];
- return or destroy all PHI at termination, with no copies retained where feasible[^13].

Covered entities and business associates must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of a use, disclosure, or request[^34].

## Security Rule safeguards

The Security Rule requires, as a required implementation specification, an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI[^50]. It requires procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports[^1]. Its audit controls standard requires hardware, software, or procedural mechanisms that record and examine activity in information systems that contain or use ePHI[^2].

Assigning a unique name or number for identifying and tracking user identity is a required access-control implementation specification[^57]. Under the current Security Rule, the following specifications are addressable rather than required:[^3][^25][^55]

- automatic logoff after a predetermined time of inactivity[^3];
- a mechanism to encrypt and decrypt ePHI[^25];
- encryption of ePHI transmitted over an electronic communications network, under the transmission security standard[^55].

Security Rule documentation of policies, procedures, and required actions must be retained for 6 years from creation or from the date it was last in effect, whichever is later[^53].

## Breach notification

An impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach[^16]. The presumption does not apply if the covered entity or business associate demonstrates a low probability of compromise, based on a risk assessment of at least the listed factors[^16]. Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified in HHS guidance under HITECH section 13402(h)(2)[^58].

## The proposed Security Rule update

On 2025-01-06, HHS published the proposed rule HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) at 90 FR 898, with comments due 2025-03-07[^42]. The proposal would expressly require regulated entities to encrypt ePHI, with limited exceptions[^41]. The latest Unified Agenda entry for RIN 0945-AA22, seen on 2026-10-01, lists it under Long-Term Actions with final action targeted for July 2027[^43]. We infer that, as of 2026-10-01, the existing Security Rule text, with its required and addressable specifications, still governs because the 2025 proposal has not been finalised[^24].

## Platform differences

### AWS

AWS requires covered entities and business associates to enter an AWS business associate agreement before using HIPAA eligible services with PHI[^4]. The following services appear on the AWS HIPAA Eligible Services Reference:[^6][^7][^5]

- Amazon Connect[^6];
- Amazon Transcribe, including HealthScribe[^7];
- Amazon Bedrock[^5].

### Microsoft

Microsoft makes its HIPAA BAA available by default, through the Microsoft Online Services Data Protection Addendum, to customers that are covered entities or business associates[^36]. Microsoft Teams is listed as an in-scope service for the Microsoft HIPAA BAA in both the Office 365 Commercial and GCC environments[^39]. Microsoft Copilot and Microsoft Copilot Chat are listed as in-scope services in the Office 365 Commercial and GCC rows[^37]. Dynamics 365 is listed among the Microsoft cloud services in scope for the BAA[^38]. Microsoft states that having its BAA does not by itself make a customer HIPAA compliant, and that the customer remains responsible for its compliance program and its particular use of the services[^35].

### Genesys

Genesys states that once a BAA is signed by all parties, it sets a HIPAA toggle on the Genesys Cloud organization[^29]. Admins can view this toggle under Account > Organization Settings > Settings[^29]. With HIPAA enabled, Genesys Cloud applies an automatic inactivity timeout that defaults to 15 minutes and can be set no lower than 5 minutes[^27]. Genesys states that ACD email and SMS cannot carry ePHI and are not covered by its BAA[^26]. Genesys also states that AppFoundry and social or messaging channel integrations, such as WhatsApp, require separate BAAs with both Genesys and the third party[^28].

### Google Cloud

Google Cloud lists Google Cloud Contact Center as a Service, and Agent Assist for Google Cloud CCaaS, among the products covered by its HIPAA BAA[^31]. Google instructs BAA customers not to put PHI or security credentials in Conversational Agents definitions, including intents, training phrases, and entities[^32]. Google also instructs customers with a BAA covering PHI not to opt in to Speech-to-Text data logging[^33].

### NICE

NICE states that its policy is to sign a BAA with CXone tenants[^40]. NICE also states that the BAA requires the tenant to identify itself as a covered entity or a business associate[^40].

### Twilio

Twilio requires a customer to be on Security Edition or Enterprise Edition to sign its Business Associate Addendum, and does not charge separately for the addendum itself[^56].

### Zoom

Existing Zoom customers enable the BAA in the web portal under Plans and Billing > Plan Management by selecting Enable on the BAA tile[^60]. New Business Plus and Enterprise customers go through Sales[^60]. Zoom states that AI features are available to customers with a BAA, but that certain AI features may not be available to healthcare customers with BAAs in place[^59].

### RingCentral

RingCentral's March 2026 RingCentral and HIPAA document lists RingCX among the services covered by the RingCentral BAA[^49]. Sources disagree on RingCentral Contact Center: the RingCentral Contact Center Online Terms of Service, last revised 2015-08-27, prohibit using the Contact Center plan to transmit, store, or otherwise handle PHI, and state that RingCentral's HIPAA BAA program does not apply to that plan[^48]. This is disputed by RingCentral's March 2026 document, which lists RingCentral Contact Center among the services covered by the RingCentral BAA[^47].

## See also

- [PCI DSS for contact centers](https://warmtransfer.net/knowledge/pci-dss-contact-center)
- [GDPR for contact centers and call recording](https://warmtransfer.net/knowledge/gdpr-contact-center)
- [Recording consent and AI processing privacy](https://warmtransfer.net/knowledge/ai-recording-privacy)
- [CDR privacy redaction and evidence-safe reporting](https://warmtransfer.net/knowledge/cdr-privacy-redaction)
- [Speech and interaction analytics](https://warmtransfer.net/knowledge/speech-interaction-analytics)
- [Contact centre AI data residency retention and training boundaries](https://warmtransfer.net/knowledge/ai-data-residency-governance)
- [Identity SSO and directory provisioning for UC](https://warmtransfer.net/knowledge/identity-sso-provisioning)

## Applicability

Applies to: AWS, AWS Amazon Connect, AWS Amazon Transcribe, AWS Amazon Bedrock, Microsoft, Microsoft Teams, Microsoft Copilot, Microsoft Dynamics 365, Twilio, Zoom, Genesys Cloud, Google Cloud Contact Center as a Service, Google Conversational Agents, Google Speech-to-Text, NICE CXone, RingCentral Contact Center, and RingCentral RingCX. Deployments: on-premises, hybrid, and multi-tenant. Sources checked 2026-10-01. We infer that the January 2025 Security Rule proposal was not in force as of 2026-10-01[^24]. Genesys states that HIPAA compliance for Genesys Cloud is available in the AWS US East and US West regions[^30]. The Microsoft Teams and Copilot BAA listings cover the Office 365 Commercial and GCC environments[^39][^37].

## What remains uncertain

The Security Rule final rule (RIN 0945-AA22) is targeted for July 2027 under Long-Term Actions[^43]. Whether it will be finalised on that schedule, and in what final form, is not covered by the sources below.

Sources disagree on the status of RingCentral Contact Center under the RingCentral BAA, so readers should verify it directly with RingCentral[^48][^47].

Zoom states that certain AI features may not be available to healthcare customers with BAAs[^59]. Which features are affected, and whether Zoom Contact Center and Zoom Virtual Agent are covered by the Zoom BAA, is not covered by the sources below.

Microsoft lists Teams, Copilot, and Copilot Chat as in-scope services[^39][^37]. Feature-level BAA scope for Microsoft Teams Premium and for individual Copilot features is not covered by the sources below.

The HIPAA BAA scope of additional contact center vendors not discussed above is not covered by the sources below.

The HIPAA BAA scope of additional UC vendors not discussed above is not covered by the sources below.

Amazon Connect Health and the AWS HCLS addendum are not covered by the sources below.

The treatment of substance use disorder records in contact centers is not covered by the sources below.

Whether call recordings form part of a designated record set, and how the right of access applies to them, is not covered by the sources below.

## Sources

[^1]: The Security Rule requires procedures to regularly review records of information system activity such as audit logs access reports and security incident tracking reports. Source: [45 CFR § 164.308 - Administrative safeguards](https://www.law.cornell.edu/cfr/text/45/164.308), § 164.308(a)(1)(ii)(D). Checked 2026-10-01.
[^2]: The Security Rule audit controls standard requires hardware software or procedural mechanisms that record and examine activity in information systems that contain or use ePHI. Source: [45 CFR § 164.312 - Technical safeguards](https://www.law.cornell.edu/cfr/text/45/164.312), § 164.312(b). Checked 2026-10-01.
[^3]: Automatic logoff after a predetermined time of inactivity is an addressable not a required implementation specification under the current Security Rule. Source: [45 CFR § 164.312 - Technical safeguards](https://www.law.cornell.edu/cfr/text/45/164.312), § 164.312(a)(2)(iii). Checked 2026-10-01.
[^4]: AWS requires covered entities and business associates to enter an AWS business associate agreement before using HIPAA eligible services with PHI. Source: [HIPAA Eligible Services Reference](https://aws.amazon.com/compliance/hipaa-eligible-services-reference/), page preamble above the eligible-services list. Checked 2026-10-01.
[^5]: Amazon Bedrock appears on the AWS HIPAA Eligible Services Reference. Source: [HIPAA Eligible Services Reference](https://aws.amazon.com/compliance/hipaa-eligible-services-reference/), eligible services list, Amazon Bedrock entry. Checked 2026-10-01.
[^6]: Amazon Connect appears on the AWS HIPAA Eligible Services Reference. Source: [HIPAA Eligible Services Reference](https://aws.amazon.com/compliance/hipaa-eligible-services-reference/), eligible services list, Amazon Connect entry. Checked 2026-10-01.
[^7]: Amazon Transcribe (including HealthScribe) appears on the AWS HIPAA Eligible Services Reference. Source: [HIPAA Eligible Services Reference](https://aws.amazon.com/compliance/hipaa-eligible-services-reference/), eligible services list, Amazon Transcribe entry. Checked 2026-10-01.
[^8]: The business associate definition expressly includes a person that provides data transmission services with respect to PHI to a covered entity and that requires access on a routine basis to that PHI. Source: [45 CFR § 160.103 - Definitions](https://www.law.cornell.edu/cfr/text/45/160.103), § 160.103, definition of Business associate, paragraph (3)(i). Checked 2026-10-01.
[^9]: Under 45 CFR 160.103 a business associate includes a person who on behalf of a covered entity creates receives maintains or transmits protected health information for a regulated function or activity. Source: [45 CFR § 160.103 - Definitions](https://www.law.cornell.edu/cfr/text/45/160.103), § 160.103, definition of Business associate, paragraph (1)(i). Checked 2026-10-01.
[^10]: A business associate may disclose PHI to a subcontractor only after obtaining satisfactory assurances that the subcontractor will appropriately safeguard the information. Source: [45 CFR § 164.502 - Uses and disclosures of protected health information: General rules](https://www.law.cornell.edu/cfr/text/45/164.502), § 164.502(e)(1)(ii). Checked 2026-10-01.
[^11]: A business associate contract must require the business associate to report to the covered entity any use or disclosure not provided for by the contract including breaches of unsecured PHI. Source: [45 CFR § 164.504 - Uses and disclosures: Organizational requirements](https://www.law.cornell.edu/cfr/text/45/164.504), § 164.504(e)(2)(ii)(C). Checked 2026-10-01.
[^12]: The satisfactory assurances required for business associates must be documented through a written contract or other written agreement or arrangement. Source: [45 CFR § 164.502 - Uses and disclosures of protected health information: General rules](https://www.law.cornell.edu/cfr/text/45/164.502), § 164.502(e)(2). Checked 2026-10-01.
[^13]: A business associate contract must require return or destruction of all PHI at termination with no copies retained where feasible. Source: [45 CFR § 164.504 - Uses and disclosures: Organizational requirements](https://www.law.cornell.edu/cfr/text/45/164.504), § 164.504(e)(2)(ii)(J). Checked 2026-10-01.
[^14]: A business associate contract must require the business associate to use appropriate safeguards and comply where applicable with the Security Rule (subpart C) for electronic PHI. Source: [45 CFR § 164.504 - Uses and disclosures: Organizational requirements](https://www.law.cornell.edu/cfr/text/45/164.504), § 164.504(e)(2)(ii)(B). Checked 2026-10-01.
[^15]: A business associate contract must require the business associate to ensure that subcontractors handling PHI on its behalf agree to the same restrictions and conditions. Source: [45 CFR § 164.504 - Uses and disclosures: Organizational requirements](https://www.law.cornell.edu/cfr/text/45/164.504), § 164.504(e)(2)(ii)(D). Checked 2026-10-01.
[^16]: An impermissible acquisition access use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate demonstrates a low probability of compromise based on a risk assessment of at least the listed factors. Source: [45 CFR § 164.402 - Definitions (Breach Notification)](https://www.law.cornell.edu/cfr/text/45/164.402), § 164.402, definition of Breach, paragraph (2). Checked 2026-10-01.
[^17]: Call recordings voicemail and transcripts held by a covered entity or its business associate that contain health information about an identifiable caller fall within the PHI definition because the definition is not limited to written or structured records (inferred). Source: [45 CFR § 160.103 - Definitions](https://www.law.cornell.edu/cfr/text/45/160.103), § 160.103, definition of Protected health information, paragraph (1)(iii) read with the definition of Individually identifiable health information. Checked 2026-10-01.
[^18]: A UCaaS or CCaaS provider that stores call recordings voicemail transcripts or chat history containing PHI for a covered entity is unlikely to qualify for the conduit exception and should be treated as a business associate needing a BAA (inferred). Source: [Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules (Final rule, 78 FR 5566)](https://www.govinfo.gov/content/pkg/FR-2013-01-25/html/2013-01073.htm), 78 FR 5571-5572, conduit and persistent-storage discussion; applied to UC and CCaaS storage. Checked 2026-10-01.
[^19]: A covered entity may disclose PHI to a business associate and let it create receive maintain or transmit PHI on its behalf only if it obtains satisfactory assurance that the business associate will appropriately safeguard the information. Source: [45 CFR § 164.502 - Uses and disclosures of protected health information: General rules](https://www.law.cornell.edu/cfr/text/45/164.502), § 164.502(e)(1)(i). Checked 2026-10-01.
[^20]: HHS stated in the 2013 Omnibus Rule preamble that the conduit exception is limited to transmission services including any temporary storage of transmitted data incident to that transmission. Source: [Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules (Final rule, 78 FR 5566)](https://www.govinfo.gov/content/pkg/FR-2013-01-25/html/2013-01073.htm), 78 FR 5571-5572, preamble discussion of the business associate definition (conduit exception). Checked 2026-10-01.
[^21]: With redaction enabled Amazon Connect keeps redacted unredacted and raw analysis files in the instance's S3 buckets where they are accessible through the S3 console and the original analyzed file is the only complete record of a voice conversation. Source: [Use sensitive data redaction to protect customer privacy using conversational analytics](https://docs.aws.amazon.com/connect/latest/adminguide/sensitive-data-redaction.html), About redacted files section. Checked 2026-10-01.
[^22]: AWS warns that because redaction is machine-learning based it may not identify and remove all sensitive data in a transcript and recommends reviewing redacted output. Source: [Use sensitive data redaction to protect customer privacy using conversational analytics](https://docs.aws.amazon.com/connect/latest/adminguide/sensitive-data-redaction.html), Important callout at top of page (first paragraph). Checked 2026-10-01.
[^23]: AWS states that Amazon Connect conversational analytics redaction does not meet HIPAA de-identification requirements and recommends continuing to treat redacted output as PHI. Source: [Use sensitive data redaction to protect customer privacy using conversational analytics](https://docs.aws.amazon.com/connect/latest/adminguide/sensitive-data-redaction.html), Important callout at top of page (second paragraph). Checked 2026-10-01.
[^24]: As of 2026-10-01 the existing Security Rule text with its required and addressable specifications still governs because the 2025 proposal has not been finalised (inferred). Source: [View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - latest agenda edition](https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22), Stage Long-Term Actions; no final rule FR citation in timetable. Checked 2026-10-01.
[^25]: A mechanism to encrypt and decrypt ePHI is an addressable access-control implementation specification under the current Security Rule. Source: [45 CFR § 164.312 - Technical safeguards](https://www.law.cornell.edu/cfr/text/45/164.312), § 164.312(a)(2)(iv). Checked 2026-10-01.
[^26]: Genesys states that ACD email and SMS cannot carry ePHI and are not covered by its BAA. Source: [HIPAA compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/articles/hipaa-compliance/), section on channels and features not covered. Checked 2026-10-01.
[^27]: With HIPAA enabled Genesys Cloud applies an automatic inactivity timeout that defaults to 15 minutes and can be set no lower than 5 minutes. Source: [HIPAA compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/articles/hipaa-compliance/), section on changes when HIPAA is enabled. Checked 2026-10-01.
[^28]: Genesys states that AppFoundry and social or messaging channel integrations such as WhatsApp require separate BAAs with both Genesys and the third party. Source: [HIPAA compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/articles/hipaa-compliance/), section on third-party integrations. Checked 2026-10-01.
[^29]: Once a BAA is signed by all parties Genesys sets a HIPAA toggle on the Genesys Cloud organization which admins can view under Account > Organization Settings > Settings. Source: [HIPAA compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/articles/hipaa-compliance/), article opening section on the BAA and HIPAA setting. Checked 2026-10-01.
[^30]: Genesys states that HIPAA compliance for Genesys Cloud is available in the AWS US East and US West regions. Source: [HIPAA compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/articles/hipaa-compliance/), region availability paragraph. Checked 2026-10-01.
[^31]: Google Cloud lists Google Cloud Contact Center as a Service and Agent Assist for Google Cloud CCaaS among products covered by its HIPAA BAA. Source: [HIPAA Compliance on Google Cloud](https://cloud.google.com/security/compliance/hipaa), Covered products list. Checked 2026-10-01.
[^32]: Google instructs BAA customers not to put PHI or security credentials in Conversational Agents definitions including intents training phrases and entities. Source: [HIPAA Compliance on Google Cloud](https://cloud.google.com/security/compliance/hipaa), product-specific guidance, Conversational Agents. Checked 2026-10-01.
[^33]: Google instructs customers with a BAA covering PHI not to opt in to Speech-to-Text data logging. Source: [HIPAA Compliance on Google Cloud](https://cloud.google.com/security/compliance/hipaa), product-specific guidance, Speech-to-Text. Checked 2026-10-01.
[^34]: Covered entities and business associates must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of a use disclosure or request. Source: [45 CFR § 164.502 - Uses and disclosures of protected health information: General rules](https://www.law.cornell.edu/cfr/text/45/164.502), § 164.502(b)(1). Checked 2026-10-01.
[^35]: Microsoft states that having its BAA does not by itself make a customer HIPAA compliant and the customer remains responsible for its compliance program and its particular use of the services. Source: [Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance](https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech), Frequently asked questions: Does having a Business Associate Agreement with Microsoft ensure my organization's compliance. Checked 2026-10-01.
[^36]: Microsoft makes its HIPAA BAA available by default through the Microsoft Online Services Data Protection Addendum to customers that are covered entities or business associates. Source: [Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance](https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech), Frequently asked questions: Can my organization enter into a BAA with Microsoft?. Checked 2026-10-01.
[^37]: Microsoft Copilot and Microsoft Copilot Chat are listed as in-scope services for the Microsoft HIPAA BAA in the Office 365 Commercial and GCC rows. Source: [Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance](https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech), Office 365 applicability and in-scope services table, Commercial and GCC rows. Checked 2026-10-01.
[^38]: Dynamics 365 is listed among Microsoft cloud services in scope for the Microsoft HIPAA BAA. Source: [Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance](https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech), Microsoft in-scope cloud platforms and services list. Checked 2026-10-01.
[^39]: Microsoft Teams is listed as an in-scope service for the Microsoft HIPAA BAA in both the Office 365 Commercial and GCC environments. Source: [Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act - Microsoft Compliance](https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech), Office 365 applicability and in-scope services table, Commercial and GCC rows. Checked 2026-10-01.
[^40]: NICE states that its policy is to sign a BAA with CXone tenants and that the BAA requires the tenant to identify itself as a covered entity or a business associate. Source: [HIPAA - CXone Help Center](https://help.nicecxone.com/Content/globalfeatures/tsa/securitylayers/compliance/hipaa.htm), HIPAA page, BAA paragraph. Checked 2026-10-01.
[^41]: The January 2025 Security Rule proposal would expressly require regulated entities to encrypt ePHI with limited exceptions. Source: [HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (Proposed rule, 90 FR 898)](https://www.govinfo.gov/content/pkg/FR-2025-01-06/html/2024-30983.htm), SUMMARY / overview of proposed modifications. Checked 2026-10-01.
[^42]: HHS published the proposed rule HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) on 2025-01-06 at 90 FR 898 with comments due 2025-03-07. Source: [HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (Proposed rule, 90 FR 898)](https://www.govinfo.gov/content/pkg/FR-2025-01-06/html/2024-30983.htm), Federal Register header; DATES section. Checked 2026-10-01.
[^43]: The latest Unified Agenda entry for RIN 0945-AA22 seen on 2026-10-01 lists it under Long-Term Actions with final action targeted for July 2027. Source: [View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - latest agenda edition](https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22), Timetable: Final Action 07/00/2027; Stage field. Checked 2026-10-01.
[^44]: The Spring 2025 Unified Agenda listed RIN 0945-AA22 at the Final Rule Stage with final action targeted for May 2026. Source: [View Rule: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (RIN 0945-AA22) - Spring 2025 Unified Agenda](https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202504&RIN=0945-AA22), Timetable: Final Action 05/00/2026; Stage field. Checked 2026-10-01.
[^45]: Protected health information is individually identifiable health information that is transmitted by electronic media maintained in electronic media or transmitted or maintained in any other form or medium. Source: [45 CFR § 160.103 - Definitions](https://www.law.cornell.edu/cfr/text/45/160.103), § 160.103, definition of Protected health information, paragraph (1)(i)-(iii). Checked 2026-10-01.
[^46]: Because voice prints are a safe-harbor identifier a call recording whose spoken PII has been silenced still carries the caller's voice and is unlikely to be de-identified under the safe-harbor method (inferred). Source: [45 CFR § 164.514 - Other requirements relating to uses and disclosures of protected health information](https://www.law.cornell.edu/cfr/text/45/164.514), § 164.514(b)(2)(i)(P) applied to redacted audio. Checked 2026-10-01.
[^47]: RingCentral's March 2026 RingCentral and HIPAA document lists RingCentral Contact Center among the services covered by the RingCentral BAA (disputed). Source: [RingCentral and HIPAA (March 2026)](https://assets.ringcentral.com/legal/rc-ringcentral-hipaa.pdf), page 3, footnote 1 (list of services covered by the RingCentral BAA). Checked 2026-10-01.
[^48]: The RingCentral Contact Center Online Terms of Service (last revised 2015-08-27) prohibit using the Contact Center plan to transmit store or otherwise handle PHI and state that RingCentral's HIPAA BAA program does not apply to the Contact Center plan (disputed). Source: [RingCentral Contact Center Online Terms of Service](https://www.ringcentral.com/legal/rcoffice-cc-tos.html), Section II (RingCentral Contact Center and HIPAA) and Section III.B (Prohibited Use). Checked 2026-10-01.
[^49]: RingCentral's March 2026 RingCentral and HIPAA document lists RingCX among the services covered by the RingCentral BAA. Source: [RingCentral and HIPAA (March 2026)](https://assets.ringcentral.com/legal/rc-ringcentral-hipaa.pdf), page 3, footnote 1 (list of services covered by the RingCentral BAA). Checked 2026-10-01.
[^50]: The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality integrity and availability of ePHI as a required implementation specification. Source: [45 CFR § 164.308 - Administrative safeguards](https://www.law.cornell.edu/cfr/text/45/164.308), § 164.308(a)(1)(ii)(A). Checked 2026-10-01.
[^51]: Telephone numbers are among the identifiers that must be removed to de-identify health information under the HIPAA safe-harbor method. Source: [45 CFR § 164.514 - Other requirements relating to uses and disclosures of protected health information](https://www.law.cornell.edu/cfr/text/45/164.514), § 164.514(b)(2)(i)(D). Checked 2026-10-01.
[^52]: Biometric identifiers including voice prints are among the safe-harbor identifiers that must be removed for de-identification. Source: [45 CFR § 164.514 - Other requirements relating to uses and disclosures of protected health information](https://www.law.cornell.edu/cfr/text/45/164.514), § 164.514(b)(2)(i)(P). Checked 2026-10-01.
[^53]: Security Rule documentation of policies procedures and required actions must be retained for 6 years from creation or the date it was last in effect whichever is later. Source: [45 CFR § 164.316 - Policies and procedures and documentation requirements](https://www.law.cornell.edu/cfr/text/45/164.316), § 164.316(b)(2)(i). Checked 2026-10-01.
[^54]: HHS stated that a data storage company with access to PHI is a business associate even if it does not view the information or views it only randomly or infrequently. Source: [Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules (Final rule, 78 FR 5566)](https://www.govinfo.gov/content/pkg/FR-2013-01-25/html/2013-01073.htm), 78 FR 5571-5572, preamble discussion of the business associate definition (persistent storage). Checked 2026-10-01.
[^55]: Encryption of ePHI transmitted over an electronic communications network is an addressable implementation specification under the transmission security standard. Source: [45 CFR § 164.312 - Technical safeguards](https://www.law.cornell.edu/cfr/text/45/164.312), § 164.312(e)(1) and (e)(2)(ii). Checked 2026-10-01.
[^56]: Twilio requires a customer to be on Security Edition or Enterprise Edition to sign its Business Associate Addendum and does not charge separately for the addendum itself. Source: [HIPAA Compliance | Twilio](https://www.twilio.com/en-us/hipaa), BAA section of the HIPAA page. Checked 2026-10-01.
[^57]: Assigning a unique name or number for identifying and tracking user identity is a required access-control implementation specification. Source: [45 CFR § 164.312 - Technical safeguards](https://www.law.cornell.edu/cfr/text/45/164.312), § 164.312(a)(2)(i). Checked 2026-10-01.
[^58]: Unsecured PHI is PHI not rendered unusable unreadable or indecipherable to unauthorized persons through a technology or methodology specified in HHS guidance under HITECH section 13402(h)(2). Source: [45 CFR § 164.402 - Definitions (Breach Notification)](https://www.law.cornell.edu/cfr/text/45/164.402), § 164.402, definition of Unsecured protected health information. Checked 2026-10-01.
[^59]: Zoom states that AI features are available to customers with a BAA but that certain AI features may not be available for healthcare customers with BAAs in place. Source: [HIPAA Business Associate Agreement (BAA)](https://support.zoom.us/hc/en-us/articles/207652183-HIPAA-Business-Associate-Agreement-BAA-), AI features paragraph. Checked 2026-10-01.
[^60]: Existing Zoom customers enable the BAA in the web portal under Plans and Billing > Plan Management by selecting Enable on the BAA tile while new Business Plus and Enterprise customers go through Sales. Source: [HIPAA Business Associate Agreement (BAA)](https://support.zoom.us/hc/en-us/articles/207652183-HIPAA-Business-Associate-Agreement-BAA-), How to obtain a BAA section. Checked 2026-10-01.
