Compliance Guide 13 min read

HIPAA-Compliant Communications: The Complete Guide for Medical and Dental Practices

Every practice we talk to has the same two fears: missing patient calls, and getting HIPAA wrong. The cruel joke is that the fear of the second one usually causes the first. Practices scared of compliance end up not texting patients, not using voicemail properly, and not answering after hours — and patients drift to the practice down the street that figured it out.

Here's the truth this whole page is built on: HIPAA doesn't ban any communication channel. It bans being careless with protected health information on that channel. Texting, voicemail, video, even fax replacement — all of it is available to your practice, compliantly, if you set it up right.

This guide covers every channel in one place: what's allowed, what breaks compliance, what agreements you need, and what to write into your staff policy. If you want the deep dive on texting specifically — consent capture, message content rules, the SMS encryption nuance — our HIPAA-compliant texting guide is the flagship resource, and we'll point to it throughout.

One scope note before we start: this page covers the communications layer — phones, texting, video, fax, voicemail. HIPAA compliance for your practice as a whole (risk assessments, EHR security, workstations, backups, breach response plans) is an IT and compliance-program discipline, and our sister company owns that territory: the HIPAA compliance guide for healthcare IT. Read that for the program; read this for the phones.

First, the two concepts that govern everything

You can derive almost every rule on this page from two definitions.

PHI (Protected Health Information) is any information that identifies a patient and relates to their health, care, or payment for care. A name plus an appointment time at a general practice? Low sensitivity. A name plus a diagnosis, test result, or medication? Full-strength PHI. The channel rules below all turn on how much PHI is in the message.

BAA (Business Associate Agreement) is the contract that makes a vendor legally responsible for protecting PHI they handle on your behalf. Any vendor that transmits or stores your patient communications — your phone system, your texting platform, your video visit tool — must sign one before PHI touches their servers. No BAA, no PHI. Ever. A vendor that won't sign a BAA has told you their platform isn't for healthcare, no matter what their marketing says. (Talk Is Cheap signs BAAs — see healthcare for which plans include it.)

With those two ideas in hand, let's walk the channels.

Channel by channel: what's compliant, what breaks it

ChannelCompliant when...Breaks compliance when...
TextingBAA-covered platform, patient consent, PHI kept minimal or behind secure linksStaff text patients from personal cell phones; clinical detail sent in plain SMS
Voice callsStandard calls are fine; identity-verify before discussing PHIDiscussing PHI with whoever answers; call recordings stored without safeguards
VoicemailMinimum-necessary messages: name, callback number, office nameLeaving results or diagnoses on machines others may hear; unencrypted voicemail-to-email
Fax → digitalBAA-covered cloud delivery with access controlsUnattended physical fax trays; misdialed numbers with no cover-sheet protocol
Video visitsBAA-covered video platform, private setting, verified patient identityConsumer video tools with no BAA; sessions recorded without consent and safeguards
Appointment remindersLogistics only: date, time, office name, callback numberReminders that name the specialty-revealing procedure or diagnosis
EmailOnly with encryption or patient-requested plain email documentedPHI in standard unencrypted email as routine practice

Now the detail on each.

Texting: the channel patients actually want

Texting is the highest-value channel in this guide — patients read texts nearly instantly, confirm appointments, and reply when they'd never answer a call. It's also the channel with the most misplaced fear.

The working rules: use a business texting platform under a BAA (not staff personal phones — more on that below), capture patient consent at intake, and keep message content to logistics — confirmations, reschedules, balance notices, "we have information for you, call us" prompts, and secure links for anything clinical. Standard SMS is unencrypted on the carrier leg, which is exactly why the content rules matter: a reminder with minimal PHI is broadly permissible, while a test result in a text bubble is a reportable problem.

That's the summary. The full treatment — consent language, opt-out handling, the reminders-vs-PHI line, the compliance checklist — lives in the HIPAA-compliant texting guide. If your practice adopts one thing from this page, make it compliant texting; it's the single biggest patient-communication upgrade available, and it's the one your front desk will thank you for. See messaging for how it works on our platform.

The A2P 10DLC nuance: registered is not the same as compliant

Here's a trap that catches practices every month. To text patients at all from a business number in the US, your number must be registered with carriers under A2P 10DLC rules — a spam-prevention framework covering every business, from pizza shops to pediatricians. Full details: A2P 10DLC business texting rules.

The trap is conflating the two regimes:

A2P 10DLC registrationHIPAA compliance
Who requires itMobile carriersFederal law (HHS)
What it coversAnti-spam: who's sending and whyPatient privacy: what's in the message and who can see it
What it gets youYour texts actually deliverYour texts are legal to send

A carrier-registered number sending unencrypted clinical details is fully 10DLC-compliant and fully a HIPAA violation. A BAA-covered platform that never registered its numbers is HIPAA-ready but its texts get filtered as spam. You need both. When a vendor says "our texting is compliant," make them say compliant with what.

Voice calls and voicemail: the oldest channel, the oldest mistakes

Phone calls to patients are a normal, expected part of care — HIPAA explicitly accommodates them. The compliance risk isn't the call; it's the edges of the call:

  • Verify before you discuss. Confirm you're speaking with the patient (or a documented authorized person) before any PHI comes up. A spouse answering the phone is not automatically authorized.
  • Voicemail gets the minimum necessary. The safe pattern: "This is [name] from [office name]. Please call us back at [number]." Name, office, callback. Not the test result, not the diagnosis, not "about your biopsy." You don't control who plays that machine out loud in a kitchen.
  • The voicemail-to-email trap. This one is sneaky: many phone systems can forward voicemails to email as audio attachments. If a patient's message containing PHI is transcribed or attached into an unencrypted personal inbox, you've moved PHI onto an unsecured system with no BAA. Voicemail features are only as compliant as where the voicemail goes — make sure transcription and forwarding stay inside your BAA-covered platform (cloud voice covers our routing and voicemail handling).
  • Call recording needs a decision, not a default. If you record calls, those recordings contain PHI and need access controls, retention rules, and coverage under your BAA. Don't turn recording on because the checkbox was there.

Fax: stop feeding the tray

Healthcare still runs on fax, and traditional fax is a compliance liability with a paper feed: documents sitting in open trays, misdials sending records to strangers, no access log. The fix isn't heroic fax discipline — it's replacing the machine with cloud fax delivered into your BAA-covered platform, where inbound documents arrive with access controls and an audit trail instead of sitting in a tray by the break room. Same workflow your referring providers expect, minus the unattended paper.

Video visits: fine — on the right platform

Telehealth is now routine, and the rule is simple: the video platform handles PHI by definition (the session is PHI), so it needs a BAA and proper access controls, and consumer-grade video tools without one are off the table for patient visits. Beyond the platform: take visits from a private space, verify the patient's identity at the start, and treat any recording like the clinical record it is. Video meetings covers our video capability; for patient visits, confirm your plan's BAA coverage first.

Appointment reminders: permitted, with a content diet

Reminders — text, voice, or automated — are explicitly workable under HIPAA without special authorization, if you keep them to logistics: patient name, date, time, office name, callback number. The line to respect: an appointment reminder from "Dr. Smith's office" is minimal-risk; one from a practice whose name is the diagnosis deserves thought (an oncology center's reminder reveals more than a family practice's). When in doubt, generic office name + callback beats detail. The texting guide covers reminder content rules in depth.

After-hours and on-call: where compliance and missed calls collide

After-hours is where both of a practice's fears meet. Calls come in when nobody's there; some of them are urgent; and the improvised solutions — the answering machine reciting a doctor's personal cell number, the on-call doc texting patients from their own phone — are exactly where compliance breaks.

A compliant after-hours setup looks like this:

  1. 1.Auto-attendant triage. Callers hear clear options: emergencies → 911, urgent clinical → on-call routing, everything else → structured message or self-service.
  2. 2.On-call routing that hides personal numbers. The system forwards to the on-call provider's cell through the business number. The provider calls back through the platform, so their personal number is never exposed and the interaction is logged.
  3. 3.Messages that land inside the platform — not on an answering machine tape, not in a personal inbox — where access is controlled and logged.
  4. 4.An AI receptionist for the non-urgent 80%. Most after-hours calls aren't emergencies — they're reschedules, hours questions, refill requests. An AI receptionist answers those instantly, books and reschedules appointments, and takes structured messages, around the clock.

AI answering and PHI: the questions to ask

An AI receptionist for a practice is itself a system that hears and stores patient information — which means it lives under the same rules as every other channel. Before deploying one, get answers in writing: Is the AI vendor covered under a BAA? Where are transcripts stored and who can access them? Is patient data used to train models? What does the AI refuse to discuss (it should take a message for clinical questions, not improvise medical answers)?

Get those four right and AI answering isn't a compliance risk — it's a compliance upgrade over the alternative, which is usually an unlogged personal cell phone at 9 p.m. Our platform's AI receptionist is built for exactly this front-desk lane. For the deeper category question — what AI voice agents can and can't safely do in a medical practice, from intake to triage boundaries — the best guide we know is from our automation sister company: the complete guide to AI voice agents for medical practices.

The two things that break compliance most often

Forget exotic hacking scenarios. In practice, communications compliance breaks in two mundane places:

1. Personal cell phones. A staff member texts a patient from their own phone "just this once." Now PHI sits on an unmanaged device, in a personal message history, on a number that follows the employee out the door when they quit — with no BAA, no audit trail, no way to delete it. This is the single most common failure mode we see, and it happens for a sympathetic reason: staff are trying to help and the office system made it hard. The fix is making the compliant path the easy path — business texting that works from an app on the same phone, through the practice's number.

2. Convenience forwarding. Voicemail-to-personal-email. Auto-forwarding office texts to a personal number. Downloading call recordings to a laptop "to listen later." Each one moves PHI from a controlled system to an uncontrolled one. The rule of thumb for staff: if the message leaves the platform, the protection leaves with it.

Your staff policy: one page, actually followed

You don't need a binder. You need one page your team actually follows:

  1. 1.Approved channels only. Patient communication happens through the practice platform — never personal phones, personal texting apps, or personal email. No exceptions, including "quick" ones.
  2. 2.Content rules by channel. Texts and voicemails: logistics and callback prompts only. Clinical content: phone call after identity verification, or secure link.
  3. 3.Individual logins, role-based access. Everyone has their own account; front desk doesn't need what clinicians see. No shared logins — an audit trail that says "everyone" says no one.
  4. 4.Verify, then discuss. Identity confirmation before PHI, every call.
  5. 5.Departure checklist. When staff leave, access ends the same day. (With platform-based communications, that's one deactivation — with personal phones, it's impossible, which is the point.)
  6. 6.See something, say something. Misdirected message? Wrong recipient? Report it same-day. Small incidents handled fast stay small.

Train on it at hire, revisit annually, and document both. Whether a mistake becomes a reportable breach often turns on whether you can show reasonable safeguards and quick response — the difference between "an incident we caught and corrected" and a very expensive letter.

What's actually at stake

HIPAA penalties are tiered by culpability — roughly, from "didn't know despite reasonable care" up to "willful neglect, uncorrected" — with per-violation fines that scale into six and seven figures for the worst categories, plus corrective action plans and, for individuals in extreme cases, criminal exposure. We're deliberately not quoting exact dollar figures here because HHS adjusts them for inflation almost yearly; current numbers are on HHS.gov. The practical takeaways don't change: penalties scale with negligence, so documented good-faith safeguards are your best protection — and the reputational cost of a breach notification letter to your patient list usually outruns the fine anyway. For breach response planning and the broader compliance program, that's TMG territory again: HIPAA compliance for healthcare IT.

The checklist: is your communications stack compliant?

Run your practice against this list. Every "no" is a to-do, not a catastrophe.

  • BAA signed with every vendor that touches patient communications — phone, texting, video, fax, AI answering
  • Texting runs through the platform with consent captured at intake (full checklist)
  • A2P 10DLC registration done, and understood as separate from HIPAA (details)
  • Voicemail scripts follow minimum-necessary; voicemail forwarding/transcription stays inside the platform
  • Fax arrives digitally with access controls, not in a tray
  • Video visits on a BAA-covered platform only
  • After-hours routes through the system — no personal numbers exposed, all messages logged
  • AI answering (if used) is BAA-covered with documented data handling
  • No personal devices in the patient-communication path
  • Individual logins, role-based access, same-day offboarding
  • One-page policy signed by every staff member, revisited annually

If you can check every box, your communications layer is in better shape than most practices we meet.

The bottom line

HIPAA-compliant communication isn't about avoiding channels — it's about running every channel through a platform that's contractually and technically built for PHI, and keeping humans on a one-page policy. Practices that get this right don't just avoid penalties; they answer more calls, confirm more appointments, and keep patients who would otherwise drift to whoever texts back first.

And this is a case where compliant doesn't mean expensive. The whole stack — calls, compliant texting, video, AI answering, with a BAA — is on our public price list, because we think practices should know what compliance costs before a sales call, not after. That's the "talk is cheap" part: /pricing.

Frequently asked questions

Is texting patients HIPAA compliant?+

Yes, when done right: a texting platform covered by a signed BAA, patient consent captured at intake, and message content kept to logistics — with clinical details delivered by secure link or phone call instead of plain SMS. Full rules: HIPAA-compliant texting guide.

What is a BAA and does my phone provider need one?+

A Business Associate Agreement is the contract making a vendor legally responsible for PHI it handles for you. Any provider that transmits or stores patient communications — calls, texts, voicemails, video — needs one signed before PHI touches their systems. No BAA, no PHI.

Can I leave patients voicemails under HIPAA?+

Yes — keep them to minimum necessary: your name, the office name, and a callback number. Don't leave results, diagnoses, or appointment details that reveal sensitive care on a machine others may hear.

Are appointment reminder texts allowed under HIPAA?+

Yes. Logistics-only reminders — name, date, time, office, callback number — are broadly permissible. The risk is content creep: reminders that name procedures or conditions. Keep them boring.

Does A2P 10DLC registration make my texting HIPAA compliant?+

No. 10DLC is a carrier anti-spam requirement that makes your texts deliverable; HIPAA governs patient privacy. You need both, and they're checked by different people. Details: A2P 10DLC rules.

Can an AI receptionist answer my practice's phones without violating HIPAA?+

Yes, if the AI system is covered under a BAA, stores transcripts with access controls, doesn't train models on your patient data, and takes messages for clinical questions rather than answering them. See our AI receptionist and ask any vendor those four questions in writing.

Why can't staff just text patients from their own phones?+

Because that puts PHI on an unmanaged personal device with no BAA, no audit trail, and no way to retrieve or delete it — and the message history walks out the door with the employee. It's the most common communications violation in small practices. Give staff a compliant app on the same phone instead.

Want compliant patient communications without the pricing runaround? Every plan — including which tiers carry a BAA — is public at /pricing. Have a setup question about your practice? Talk to us.

Ready to stop overpaying for dial tone?

Get the whole platform — voice, text, video, AI — from $14.99 per user. Set up today, port your number free, cancel whenever. Talk is cheap; switching is even cheaper.