Start your 14-day free trial250 minutes included, cancel anytimeSee plans
Healthcare

A HIPAA-ready phone system, because none is HIPAA compliant

Ours included. Here is what a vendor can actually give you, what stays your practice’s job, and the one document that has to exist before a single patient call moves.

  • HIPAA ready, not “compliant”
  • The BAA comes before any PHI
  • Fax as an add-on, multi-site on every plan
Start here

Search results are full of a badge that does not exist

Every result for “HIPAA compliant phone system” carries one. Those badges are inaccurate, and knowing why protects your practice — because a vendor willing to say it on their homepage has told you something about how they will answer harder questions later.

HIPAA compliantHIPAA certifiedHIPAA ready

There is no HIPAA certification body and no approved-vendor list. Compliance is a property of your practice — your safeguards, your access policies, your training, your documentation. What a vendor can supply is technical controls and a contract.

  1. HHSCertifies nothing

    There is no government certification for software, and HHS does not recognise private ones either — a third-party certificate does not absolve you of anything.

  2. DialPhoneProvides the controls

    The technical safeguards, and a Business Associate Agreement to sign. That is the whole of a vendor’s role, and it is where ours ends.

  3. YouAre, or are not, compliant

    Your access policies, your staff training, and your BAA executed before any protected health information moves.

The gate

The BAA is the gate, and “in review” is not through it

A Business Associate Agreement is the contract that makes a vendor legally accountable for the protected health information it handles. Do not move a single patient call onto any platform before it is executed. Not “in review”, not “on legal’s desk” — executed.

It is also the question worth asking every vendor on your shortlist. Cheaper options exist, and some of them are good. Compare them on whether they will sign a BAA and what it covers, not on the badge on their homepage — and if a vendor claims to be certified, ask for the certificate and see what arrives.

The requirements

What HIPAA actually asks of a phone system

Three things, in practice. None of them is satisfied by a logo, and all three of them outlast whichever vendor you pick.

Encryption, in transit and at restA voicemail transcript with a patient name in it is PHI

So is everything else the phone system touches. The test is not what kind of file it is, it is whether a patient is identifiable in it.

  • Calls
  • Recordings
  • Voicemail transcripts
  • Faxes
  • Text messages
Confirm at-rest encryption specifically — in-transit is the claim vendors make, and it is only half the requirement.
Access controls and audit trailsWho can play it, and a record of who did

Staff turnover is where practices get exposed — not at the moment access is granted, at the moment nobody removes it.

  • Front deskSees the appointment bookCannot play recordings
  • ClinicianPlays recordings for their own patients
  • AdministratorExports, and every export is logged
Illustrative. Ask for the exact permission model and what the audit log records before you write either into a policy.
Minimum necessaryNot everyone in the practice needs everything

The standard is not “trusted staff”, it is the least access that lets someone do the job in front of them. Most practices fail this by default rather than by decision, because the default in most systems is everyone sees everything.

  • Does the front desk need to play recordings, or only see the book?
  • Does a locum covering one clinic need the history of all three?
  • Does your billing contractor need voicemail access at all?
This one is not a setting. It is a decision you make, and then configure.
The platform enforces your policy. It does not author it.Encryption, controls and logs are what a vendor can supply. Deciding who in your practice should see what is yours, and no product decides it for you.
  • End-to-end encryption
  • Audit logs
  • Role-based access
After hours

Where practices lose patients, and where risk concentrates

Calls outside opening hours are the ones an answering service used to absorb badly. Watch one arrive at 21:47 and see where it ends up — and note what the receptionist is not doing on the way.

Outside opening hours · on-call rota active
  1. 21:47A call arrives after hours

    The practice closed at six. On an answering service this is the point where a patient hears a machine, or nothing.

  2. 21:47The AI Receptionist answers

    Twenty-four hours a day. It takes the reason for the call in the caller’s own words rather than reading a menu at them.

  3. 21:48The caller says which kind of call it is

    Booking a check-up and needing a clinician tonight are different calls, and the caller is the one who knows which. Nothing at this step is a clinical judgement.

    RoutineBooks an appointmentThursday 09:20 — confirmed by text before the caller hangs up.
    UrgentStraight to the on-call clinician“Caller asked to speak to a clinician tonight.”
  4. 21:48A person picks up the urgent one

    With one sentence of context, so the on-call clinician knows what they are answering before they say hello.

The other two

Fax that is not a machine, and three sites on one number

The workflows nobody writes a landing page about, because neither of them is exciting. They are also the two a practice manager notices every single day.

Referral and prior-authorisation faxFax persists in healthcare because it is entrenched, not because it is good

Nobody is going to talk you out of it, least of all the practices sending you referrals. Online fax is an add-on on any plan, so referrals and authorisations arrive as PDFs in an inbox — and there is no machine in a back office holding protected health information on paper where anyone walking past can read it.

Multi-site routingOne main number, three front desks

Routed by time of day and by who is actually staffed, with every location keeping the local number its patients already have.

FAQ

Frequently asked questions

Is DialPhone HIPAA compliant?

No product is. DialPhone is HIPAA ready — it provides technical safeguards and signs a Business Associate Agreement. Compliance is a property of your practice, not of anything you can buy.

Will DialPhone sign a Business Associate Agreement?

Confirm this with support before moving any patient information onto the platform — and get it executed rather than acknowledged.

Are voicemail transcripts and call recordings PHI?

Yes, if a patient is identifiable in them. They need the same encryption, access controls and retention handling as any other record.

Can the AI Receptionist handle patient calls?

It can book appointments and answer routine questions. It must not be used for clinical triage. Anything a caller flags as urgent goes to a clinician.

Is online fax included?

Not in the plan price — it is an add-on, on any tier. Once it is on, referrals and prior authorisations arrive as PDFs in an inbox rather than on a machine in a back office — see online fax.

Can each location keep its own number?

Yes. Multi-site routing is on every plan.

What about patient text messaging?

Texting PHI adds consent and 10DLC obligations on top of HIPAA. Talk to support and your compliance advisor before enabling it — business SMS covers what registration involves.

What does it cost for a practice?

Calls, fax, video, transcription and E911 are on the plan; the AI Receptionist is a separate add-on rather than part of it. Rates are on pricing. Cheaper options exist — compare them on whether they will sign a BAA, not on the badge on their homepage.

Ask us for the BAA first.

Fourteen days, no card. Before a single patient call moves, get the agreement executed — and ask every other vendor on your list for theirs while you are at it.

No credit card required · Nothing here is legal advice · Cancel anytime