The Bottom Line

There is no HIPAA certification, no HIPAA seal, and no platform that is compliant on its own. Compliance is a property of three things you control: a Business Associate Agreement that actually covers the features you intend to use, a configuration that enforces access control, retention, and encryption, and a workforce that follows it. The trap specific to 2026 buying is that the newest and most attractive features — transcription, AI summaries, sentiment analysis, virtual agents — are frequently the ones outside the BAA's scope or gated to a plan tier you did not buy. Ask for the BAA feature by feature, in writing, before the demo convinces anyone.

There is no such thing as a HIPAA-certified platform

The US Department of Health and Human Services does not certify software, and no government body issues a HIPAA seal. Any vendor describing their product as "HIPAA certified" is describing a self-assessment or a third-party audit against someone else's framework, which is a useful signal and not the same claim.

What actually exists is narrower and more useful. A vendor can be a business associate — an entity that creates, receives, maintains, or transmits protected health information on your behalf — and can sign a Business Associate Agreement committing to specific safeguards and breach obligations. That contract, plus how you configure the platform and how your workforce uses it, is what compliance consists of. You remain the covered entity, and the obligation stays with you.

The practical consequence for a buying process: a platform cannot make you compliant, and it can certainly make compliance harder. Evaluate the contract and the configuration options, not the badge on the datasheet.

Take the inventory first

Where PHI actually lives in a contact center

Most organizations underestimate the surface area, because the obvious artifact — the call recording — is only the beginning. A patient identifying themselves in an IVR, an agent typing a note, and an AI model producing a summary all create protected health information in different systems with different retention rules.

Inventory every one of these before you evaluate anything, because the list determines which parts of the BAA you actually need:

Call recordings and voicemail

The obvious one, and usually the only one on the security review. Includes the recording, its metadata, and every copy in backup.

Transcripts and AI summaries

A transcript is PHI in text form, and an AI-generated wrap-up summary is PHI the platform authored. Both are frequently stored separately from the recording, with their own retention.

IVR-captured identifiers

Date of birth, member number, and reason for calling, entered before a human is involved. This data often lands in logs nobody classified as clinical.

Chat, SMS, and email threads

Digital channels carry the same obligations as voice and are routinely omitted from a review scoped around "call recording."

CRM and EHR screen pops

The integration surfaces the record to the agent, which makes the CTI layer and any middleware part of the PHI path. Our Epic guide covers what native versus middleware changes here.

Agent notes and dispositions

Free-text fields where agents write what the patient said. Unstructured, rarely redacted, and usually retained as long as the interaction record.

Screen and desktop recording

Quality tooling that captures the agent's screen captures whatever record was open on it.

Analytics, wallboards, and exports

Aggregates are usually fine; the underlying interaction-level exports feeding them are not, and they often live in a reporting system with looser access control.

Backups and disaster recovery copies

Every copy of the above, in every region the platform replicates to. Ask where, specifically.

The BAA, and four ways its scope is narrower than you think

A signed BAA is necessary and not sufficient, because BAAs are scoped documents. The four limits below account for most of the gap between what buyers believe they bought and what the contract actually says. Each is answerable in writing before you sign — and each is much harder to fix after.

The limitWhat it meansWhat to ask for
Plan-tier eligibilityBAA coverage is frequently available only on specific enterprise or healthcare plans, not on the tier a price-led evaluation lands on."Which plan tiers is the BAA available on, and is the quoted tier one of them?"
Feature exclusionsThe BAA may cover the core platform while carving out specific capabilities — commonly the newer AI and analytics features."List every feature excluded from BAA scope, by name."
Configuration requirementsCoverage can be conditional on you configuring the platform a particular way, which means a default deployment may fall outside it."What configuration is required for the BAA to apply, and how do we evidence it?"
The subprocessor chainThe platform vendor is rarely alone in the data path. Model providers, transcription services, cloud infrastructure, and analytics tools may each touch PHI."Name every subprocessor that touches PHI and confirm coverage for each."
The 2026 gap

The AI question almost nobody asks

This is the gap worth the most attention in 2026, because it sits exactly where buying enthusiasm is highest. Transcription, sentiment analysis, agent assist, auto-QA, and virtual agents all process PHI by definition — that is what makes them useful — and they are the newest parts of the product, which means they are the parts most likely to sit outside a BAA written around the core platform.

Three questions settle it, and all three deserve a written answer rather than a reassuring one in a demo:

Is each AI feature inside the BAA? Not "is your platform covered" — feature by feature, by name, including transcription and generated summaries.

Who else processes the data? If the AI runs on a third-party model, that provider is in your PHI path and needs its own coverage. Ask for the list and how it is kept current when the vendor changes providers.

Is your data used for training? Ask explicitly whether interaction data trains or fine-tunes any model, how long the AI layer retains data independently of the platform's retention settings, and how to switch both off.

None of this means avoiding AI in a healthcare contact center. Auto-QA across every interaction is genuinely valuable in a regulated environment, and agent assist shortens the ramp for staff handling clinical questions. It means buying it with the contract that matches, and pricing it knowing that the covered configuration is sometimes a more expensive tier. Our contact center AI guide covers how those tiers and meters work.

Configuration is where compliance is won or lost

A platform with an excellent BAA, deployed carelessly, produces a breach. These are the settings that reliably matter, and they belong in your implementation plan rather than in a post-go-live audit finding.

Recording pause and redaction

Agents must be able to stop recording for payment card capture, and the platform should redact sensitive fields automatically rather than relying on the agent to remember.

Retention schedules

Set them deliberately per artifact — recordings, transcripts, summaries, chat — rather than accepting a default. Keeping PHI longer than you need is exposure with no upside.

Role-based access and minimum necessary

Agents, supervisors, quality reviewers, and analysts need different access. Default roles are usually broader than the minimum necessary standard contemplates.

Multi-factor authentication

For every administrative account without exception, and for agents wherever the platform supports it. This is also a proposed requirement in the pending Security Rule update.

Encryption in transit and at rest

Confirm both, and confirm it covers recordings, transcripts, and backups rather than just the signalling path.

Audit logging

You need to be able to answer who accessed which record, when. Check that logs cover playback and export, not only login, and that retention on the logs matches your obligations.

Remote and BYOD agents

Home-based agents change the physical safeguards picture. Screen locks, headset policy, prohibition on local recording, and a documented workspace standard.

Workforce training and sanctions

Required by the Privacy and Security Rules, routinely under-documented, and the first thing an investigation asks to see.

Breach notification runbook

Know in advance who declares, who notifies, and on what clock — and confirm the vendor's own notification timeline in the BAA is fast enough to let you meet yours.

Regulatory watch

What the proposed Security Rule update would change

This is the most commonly misreported item in healthcare technology buying right now, so the status is worth stating plainly: the updated HIPAA Security Rule is still a proposal. HHS published the Notice of Proposed Rulemaking on January 6, 2025, the comment period closed in March 2025 with several thousand comments, and the rule has not been finalized. HHS has since moved it to its long-term regulatory agenda with anticipated final action in July 2027 — and those dates are planning estimates, not binding commitments.

That is not a reason to ignore it. The proposals point clearly at where expectations are heading, and most of them are things a well-run contact center deployment should be doing anyway: multi-factor authentication, encryption of ePHI at rest and in transit, network segmentation, asset inventory, vulnerability scanning, and documented incident response.

The timing mechanics matter for planning. On the proposal as drafted, the rule would take effect 60 days after publication, compliance would be required 180 days after that — roughly 240 days total — and business associate agreements would need updating within a year of the effective date. If you are signing a three-to-five-year contact center contract now, that clock will land inside your term. Ask vendors how they intend to handle BAA amendments when the rule finalizes, and get the answer in the contract rather than discovering it at renewal.

The questions to put in writing

Every one of these should be answered in the contract or in a written response attached to it. A verbal reassurance from a sales engineer is not a safeguard, and it will not be what an investigator reads.

AreaThe question
BAA scopeWill you sign a BAA on the tier we are buying, and which features does it exclude?
AI coverageIs every AI feature we are licensing inside BAA scope, named individually?
SubprocessorsWho else processes PHI in this data path, and how are we notified of changes?
Model trainingIs our interaction data used to train or fine-tune any model? How do we opt out?
Data residencyWhere is PHI stored and replicated, including backups and DR copies?
RetentionWhat are the default retention periods per artifact, and what can we change?
EncryptionIs ePHI encrypted at rest and in transit, including recordings and transcripts?
Access controlWhat roles exist by default, and can we restrict playback and export separately?
Audit logsWhat is logged, for how long, and can we export it?
Breach notificationWithin how many hours of discovery will you notify us?
Independent assuranceCan we see your most recent SOC 2 Type II report and its scope?
ExitOn termination, how is PHI returned or destroyed, and on what timeline?

Where this fits with the rest of your evaluation

HIPAA is a constraint on the shortlist, not the shortlist itself. Once you have established which platforms will sign a BAA covering the features you actually want, the decision returns to the ordinary criteria — routing, workforce management, integration depth, and price.

For health systems running Epic, the integration question usually dominates and is covered in our contact center for Epic guide. If you also serve government programs, the FedRAMP guide covers the authorization picture, which is a separate and more verifiable question than HIPAA because there is an actual government marketplace to check. When you get to the evaluation itself, our RFP guide has the security section written to produce answers rather than reassurance, and the pricing guide covers what the compliant tier tends to cost against the entry tier.

One closing caution that applies to everything above: this page is a buyer's guide written by technology advisors, not legal advice. Your privacy officer and counsel own the compliance determination. What we can do is make sure the contract in front of them says what you think it says.

FAQ

Common questions about HIPAA and contact centers

Is any contact center platform HIPAA certified?

No. HHS does not certify software and there is no official HIPAA certification. Vendors may hold SOC 2 Type II or HITRUST attestations, which are useful evidence of a security programme, but they are not HIPAA certifications. What matters legally is whether the vendor will sign a Business Associate Agreement, what that agreement covers, and how you configure and operate the platform.

What is a BAA and do we need one?

A Business Associate Agreement is a contract between you, as the covered entity, and any vendor that creates, receives, maintains, or transmits protected health information on your behalf. If your contact center handles PHI in any form — recordings, transcripts, chat, IVR-captured identifiers — you need one with the platform vendor, and you need to satisfy yourself that its subprocessors are covered too.

Are AI features covered by our vendor's BAA?

Do not assume so. AI capabilities such as transcription, sentiment analysis, agent assist, and generated summaries are frequently the newest parts of a platform, are sometimes delivered through third-party model providers, and are commonly gated to specific plan tiers — all of which are reasons they may fall outside a BAA written around the core product. Ask for the exclusion list in writing, feature by feature, and ask which subprocessors are in the path.

Does the 2026 HIPAA Security Rule update apply to us yet?

Not yet. The proposed update was published on January 6, 2025 and has not been finalized; HHS has moved it to its long-term agenda with anticipated final action in July 2027, and those dates are estimates. The current Security Rule still applies. That said, the proposals — multi-factor authentication, encryption, network segmentation, asset inventory, vulnerability scanning — are reasonable to build toward now, particularly on a contract that will outlast the rulemaking.

Can we record calls that contain PHI?

Yes, with the usual safeguards: a lawful basis, appropriate notice, access controls limiting playback to those who need it, a deliberate retention schedule, encryption at rest, and audit logging of access and export. Recording is not the risk; indefinite retention with broad access is. Note also that state wiretap and consent laws apply independently of HIPAA and are stricter in some states.

What about payment card data on the same calls?

PCI DSS applies alongside HIPAA and the two have different requirements. In practice most healthcare contact centers handle this with recording pause-and-resume or automatic redaction around payment capture, or by routing payments to an IVR or a tokenized capture flow so card data never reaches the recording or the agent's screen. Confirm which mechanisms the platform supports before you design the call flow.

Do remote agents change our obligations?

The obligations are identical; the safeguards need re-thinking. Physical safeguards that a contact center floor provided implicitly — no unauthorized observers, no personal devices, controlled printing — become policy and configuration for home-based agents. Expect to document a workspace standard, enforce screen locks and MFA, prohibit local recording, and train specifically on the home environment.

Handling PHI? Get the BAA questions answered before the demo.

An independent advisor puts the BAA scope, the AI exclusions, and the subprocessor list in front of you in writing — alongside quotes for the tier that actually carries the coverage. Free, no vendor bias.

Talk to an Advisor Get an Estimate

844-506-2299 · Free advisory · No obligation