A patient leaves a voicemail after hours: her name, her date of birth, the name of the medication she needs refilled, and the pharmacy. The cloud phone system transcribes it, attaches the audio, and emails both to the on-call number's mailbox, which forwards to the doctor's personal Gmail because that was easier to check from the car. By morning the message exists in four places, and the practice is aware of one.
Is RingCentral HIPAA compliant? RingCentral says yes, and the evidence behind that claim is real, but the part that matters to a practice comes through sales and a settings page. RingCentral's healthcare page answers its own FAQ with "Yes, RingCentral is HIPAA-compliant and secures communication through enterprise-grade encryption, 99.999% availability, and global compliance" attestations "like HITRUST, SOC 2, and GDPR." Its Trust Center publishes a "SOC 2+ FINRA CSR, HIPAA Report" for its RingEX and RingCX products, and its own vendor agreement states that "RingCentral is a Business Associate to certain clients that are Covered Entities or Business Associates." What the public pages do not include is the customer-facing B.A.A. (Business Associate Agreement) or a statement of which plans carry it. This guide covers what RingCentral publishes, what a practice has to obtain, and the configuration that decides whether a covered phone system is a compliant one.
Is RingCentral HIPAA Compliant: Published Evidence, the Missing Page, and the Settings
Whether RingCentral Signs a BAA
RingCentral acts as a business associate; its vendor BAA says so in its first recital and requires RingCentral's own subcontractors to "comply with the requirements in 45 C.F.R. Part 164, subpart C" and to provide an annual third-party HIPAA compliance report. That is the downstream half of 45 CFR 164.308(b)(2), under which "a business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances." A vendor that flows those terms down to its suppliers is behaving like a business associate that has signed upstream.
The upstream document, the BAA between RingCentral and your practice, is not on a public RingCentral page that could be fetched for this article. Treat it as a sales conversation: ask for the BAA, ask which products and plans it covers (RingEX, RingCX, video, SMS, fax, and the AI features), sign it before any patient call is answered on the system, and file it. 45 CFR 164.308(b)(3) makes the "written contract or other arrangement" a Required specification, and the business associate agreement guide lists what the document must contain so you can check RingCentral's version against the rule.
The RingCentral Plans and HIPAA Eligibility
Not stated publicly. The Trust Center's HIPAA report covers RingEX (the phone, messaging, video, and fax product) and RingCX (the contact center product), which suggests those are the products RingCentral is prepared to stand behind. Whether every RingEX tier is eligible, and whether the AI Receptionist and AI note-taking features sit inside the BAA, are questions for the sales representative to answer in writing.
Why a Phone System Is a HIPAA System
The old phone line was mostly outside the Security Rule. 45 CFR 160.103 says transmissions "of voice, via telephone, are not considered to be transmissions via electronic media if the information being exchanged did not exist in electronic form immediately before the transmission." A cloud phone platform changes that in three ways: voicemails are stored as audio files, transcriptions are stored as text, and faxes arrive as PDFs. All of that is P.H.I. (Protected Health Information) "maintained in electronic media," which is the definition of ePHI, and every safeguard in 45 CFR 164.308 through 164.312 applies to it.
| RingCentral feature | What it creates | The HIPAA question |
|---|---|---|
| Voicemail and voicemail-to-email | Stored audio, emailed copies | Where does the email go, and does that mailbox have its own BAA? |
| Voicemail transcription | Stored text of patient messages | Same routing question; transcription makes the content searchable |
| SMS and MMS | Stored message threads with patients | Content limits, opt-in, and retention under the texting rules |
| Cloud fax | PDFs of referrals and records | Storage, forwarding, and misdials, covered in the faxing guide |
| Call recording | Audio of clinical conversations | Consent under state law, retention, and access |
| AI notes and summaries | Machine-written records of calls | Inside the BAA? Where do they flow, and who reviews them? |
| Team messaging and file sharing | Chat threads and attachments | Internal PHI use, external guests, and retention |
| EHR integrations | Data moving both ways | A documented data flow and a BAA on both ends |
| Softphone apps on personal phones | ePHI on unmanaged devices | Device and media controls under 164.310(d): screen lock, encryption, remote wipe |
What the RingCentral BAA Does Not Cover
- The mailbox you forward to. Voicemail-to-email lands in Google Workspace, Microsoft 365, or a personal account. The first two can be covered by their own BAAs; the third never is. The Microsoft 365 guide explains the Microsoft side.
- What staff say and type. A BAA covers RingCentral's handling of the message, not the front desk reading a diagnosis into a voicemail greeting or texting lab results.
- Recording consent. HIPAA governs the stored recording; whether you may record at all is state law.
- Retention decisions. Voicemails and faxes that are part of the record must be moved into the chart and kept under the practice's retention policy, not left to a mailbox quota.
- Third-party apps. Integrations from the app gallery that read call data are separate vendors.
How to Set Up RingCentral for HIPAA
- Obtain and sign the BAA through sales, with the covered products and features listed in writing, before go-live. File it with the date.
- Route voicemail and fax only to covered mailboxes. Managed Workspace or Microsoft 365 accounts with their BAAs in force, never personal email. Better: keep audio and PDFs inside RingCentral and send notifications without attachments.
- Decide transcription deliberately. If transcripts are on, they are ePHI in every place voicemail goes.
- Write the SMS policy. Appointment logistics with patient opt-in; no clinical content; a rule for what happens when a patient texts a symptom.
- Set fax handling. Inbound faxes go to a named queue, get filed into the chart, and are deleted from the phone system on a schedule. Confirmation cover sheets and misdial procedures per the faxing guide.
- Configure recording and AI features to the BAA's scope. If a feature is not confirmed inside the BAA, it stays off. Where it is on, decide where summaries flow and who reviews them before anything enters the record.
- One login per person, MFA on, roles set. 45 CFR 164.312(a)(2)(i) requires unique user identification; the receptionist should not administer the account. Add RingCentral deprovisioning to the termination checklist.
- Manage the devices. Softphones on personal phones need screen lock, encryption, remote wipe, and a written rule about what may be stored locally.
- Turn on audit logs and review them. 45 CFR 164.312(b) requires mechanisms that "record and examine activity" in systems holding ePHI, and 164.308(a)(1)(ii)(D) requires someone to actually look.
- Train the front desk. Greetings, hold messages, and voicemail scripts are covered in the front desk rules; the phone system only stores what the person says.
- Add RingCentral to the risk analysis as a system that creates and stores ePHI, with every forwarding rule documented.
Common RingCentral HIPAA Mistakes
The forwarding rule to personal email. Set once, forgotten, and the biggest ePHI leak in most small practices.
Assuming "HIPAA-compliant" on the sales page equals a signed BAA. The page is marketing; the BAA is the contract.
Fax as a filing system. Two years of referrals sitting in a cloud fax inbox nobody has purged.
Shared logins for the front desk. One "frontdesk@" account makes the audit log meaningless.
Alternatives and Comparisons
| Platform | BAA path | Notes |
|---|---|---|
| RingCentral (RingEX, RingCX) | Through sales; HIPAA report published on the Trust Center | Configuration of forwarding, fax, SMS, recording, and AI features decides the outcome |
| Microsoft Teams Phone (commercial Microsoft 365) | In-scope under the Microsoft 365 BAA | Same forwarding discipline applies |
| Zoom Phone on a covered plan | Yes, on the right account type; see the Zoom guide | Confirm phone features are inside the BAA |
| Healthcare-specific answering and phone services | Usually standard | Fewer features, fewer settings to get wrong |
RingCentral publishes more HIPAA evidence than most phone vendors, and a practice can run on it with a clear conscience once the BAA is filed and the forwarding rules are fixed. The voicemail in the opening paragraph did not leak because of the platform. It leaked because someone chose convenience in 2021 and nobody has looked since.
---
FAQ
Does RingCentral sign a HIPAA Business Associate Agreement?
RingCentral states it is a business associate to covered-entity clients and publishes a SOC 2+ HIPAA report for RingEX and RingCX, but the customer BAA is not on a public page. Request it through sales, get the covered products in writing, and sign before go-live.
Which RingCentral plan is HIPAA compliant?
RingCentral's public pages do not name a plan. The Trust Center's HIPAA report covers RingEX and RingCX. Confirm plan and feature eligibility, including AI features, with RingCentral in writing.
Is voicemail-to-email HIPAA compliant on RingCentral?
Only if the destination mailbox is itself covered, such as a managed Google Workspace or Microsoft 365 account with a BAA in force. Forwarding to personal email is a disclosure to an uncovered vendor. Keeping audio inside RingCentral and sending notifications without attachments is safer.
Can I text patients from RingCentral?
Appointment logistics with patient opt-in are generally workable; clinical content by text is not. Stored SMS threads are ePHI and need retention, access, and audit rules like any other record.
Are RingCentral's AI notes and AI receptionist covered by the BAA?
Not stated on the fetched public pages. Treat any feature not confirmed in writing as outside the BAA and keep it off for PHI until RingCentral confirms coverage.
Conclusion
The phone system is the HIPAA system nobody audits, and it holds more patient voicemails than the EHR holds notes. One Guy Consulting's Full-Scope plan includes vendor and BAA management, the device and media controls and transmission security policy templates, and consulting time to walk every RingCentral setting that moves PHI. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- RingCentral: healthcare communications solutions page with HIPAA FAQ (vendor page)
- RingCentral Trust Center: Compliance (SOC 2+ FINRA CSR, HIPAA Report for RingEX and RingCX)
- RingCentral Legal: Vendor Business Associate Agreement (vendor page)
- 45 CFR 160.103 (definitions, including electronic media)
- 45 CFR 164.308 (administrative safeguards; business associate contracts at (b))
- 45 CFR 164.312 (technical safeguards)
Related Reading