Yes, Dialpad is HIPAA-compliant with some fine print.
Dialpad describes its platform as HIPAA-ready rather than HIPAA-compliant. Getting to full HIPAA compliance starts with an admin signing a Business Associate Agreement, or BAA, directly in the app. Once that’s done, most Dialpad products can be used compliantly. The only exceptions are Dialpad Fax with PHI, or protected health information, and SMS with PHI sent to non-Dialpad users, which fall outside the BAA’s coverage.
That compliance is supported by solid security credentials: SOC 2 Type II and ISO certifications 27001, 27017, and 27018. It also encrypts data in transit with TLS and at rest with AES 256-bit. Data retention settings are also configurable on every account size, so teams can tailor how long records are kept.
But signing a BAA is only step one. Actual compliance depends on how you configure recordings, transcripts, retention, and access.
Let’s look at what that setup actually involves.
What the BAA covers and how to sign it
A BAA is the contract HIPAA requires between a covered entity like your practice and any vendor handling PHI on your behalf. It commits the vendor to specific safeguards, makes those obligations enforceable, and extends to the vendor’s own subcontractors.
Dialpad acts as that Business Associate and provides the contractual assurance a BAA requires. You can sign it directly in the Dialpad app. If you don’t see the option to sign anywhere, contact [email protected].

What’s covered? Once signed, most Dialpad products can be used compliantly by healthcare customers. But there’s one caveat worth knowing up front: Dialpad Meetings has its own separate BAA. More on this below.
What isn’t covered? Dialpad Fax for PHI and SMS used to send PHI to non-Dialpad users aren’t covered. In practice, that means you can’t text a message with health information in it from a Dialpad number to a patient’s regular phone.
What you still have to configure after you sign the BAA
Signing a BAA is only the first box to check. You’ll also need to:
- Set your retention policy. Decide how long call recordings, voicemails, transcripts, and messages should be kept, and set it up in the platform. Keep in mind: retention has both a floor and a ceiling. HIPAA requirements and state laws set minimums for certain records, and keeping ePHI indefinitely by default is its own risk.
- Limit who can access recordings and transcripts. Access to protected information should follow the minimum-necessary principle. So make sure you check which team members can open a recording.
- Decide what goes in a text. The safest rule is the simplest: text messages to a patient’s regular phone should contain no PHI. Appointment reminders and logistics are fine, but clinical details aren’t. PHI should stay within covered channels, such as Dialpad-to-Dialpad messaging. Check out our article on HIPAA-compliant texting for more information.
- Use authentication with single sign-on. Use SSO or SAML where available and require multi-factor authentication for every user who can reach patient data.
- Train the people using it. When it comes to data breaches, the breakdown is usually due to bad processes, not bad platforms.
- Keep your own documentation. Keep records of your risk assessment, your policies, and your signed BAA somewhere accessible. That way, you can produce them quickly if a regulator, auditor, or patient ever asks for them. For the recording-specific requirements, see our guide to HIPAA-compliant call recording.
Dialpad’s security and certifications
Dialpad’s compliance claims are backed by independent certifications, not just self-reporting. The platform holds SOC 2 Type 2 and ISO 27001, 27017, and 27018 certifications. It has also completed the Cloud Security Alliance’s CAIQ, which addresses controls in the HIPAA Security Rule and Privacy Rule.
Data is encrypted in transit using TLS, with SRTP protecting calls and video specifically. At rest, data is secured with AES 256-bit encryption. The infrastructure itself runs on Google Cloud Platform.
For access control, administrators can enforce SSO via SAML, and its API integrations are secured through OAuth. That gives healthcare teams control over who can authenticate into the system and how third-party tools connect to it.
Are Dialpad’s AI features HIPAA compliant?
Yes. Dialpad’s AI features fall under the same BAA as the rest of the platform. So using transcription and call summaries on patient calls doesn’t automatically lead to a HIPAA violation.
The nuance is in what the AI features create. A transcript of a patient call is protected health information in text form, and so is an AI summary. That means AI doesn’t introduce a separate compliance question. It just makes the retention and access settings more important.
Before turning AI features on for patient-facing phone numbers, ask three things:
- How long are transcripts retained?
- Who can read them?
- Is that transcript data ever used to train Dialpad’s models?
On that last point, the BAA does the work for you. Once signed, Dialpad treats your account as ineligible for AI training, so it doesn’t use your conversation data to train its models. For more details, we break down every AI feature and what it costs in our guide to Dialpad AI.
What to double-check before you put ePHI through Dialpad
You’re off to a strong start once you’ve signed the BAA. But a few gaps can still trip up your healthcare team. Here’s what’s worth confirming before any ePHI flows through the platform:
- Video and telehealth need their own agreement. Dialpad Meetings has a separate BAA. You can sign it from the Meetings dashboard rather than the main Dialpad app. If you meet with patients over video, confirm that agreement is in place before your first appointment. The BAA you signed for calls and messaging doesn’t automatically cover it.
- The BAA is easy to skip. Because it’s self-serve in the app, it’s also easy to start using the platform before anyone signs it. Nothing blocks you from putting ePHI through an uncovered account.
- Integrations extend your exposure. If Dialpad syncs to a CRM or an AI agent, protected health information travels with it. So that downstream tool also needs its own BAA. Your Dialpad agreement won’t be enough.
Is Dialpad a good fit for a small practice?
It depends on your setup. Dialpad is built around the contact center, so if you run a multi-site practice with a call queue, a front-desk team, and call QA or quality assurance, it’s a great fit. The AI coaching becomes a real advantage rather than a nice-to-have.
If you’re a solo therapist, a small clinic, or a two-person front desk, it’s a different story: You’d be buying a contact-center platform to do front-desk work.
The pricing reflects that mismatch.

The $15 Standard plan is a one-seat, bare-bones phone line with three ring groups, no hold queues, and no CRM integrations. That means the communication features that justify choosing Dialpad live a tier up.
The $25 Pro plan unlocks call queues and more routing but requires a three-user minimum. So a two-person practice pays for a seat it doesn’t need. The real contact-center capability is in Dialpad Support, a separate product starting around $80 per user. For a small practice, that can mean paying for and maintaining capability you’ll never use.
Verdict: Is Dialpad right for your healthcare team?
Dialpad can be used in a HIPAA-compliant manner once you sign the BAA in the app or via email. But that only covers the legal foundation. You still have to answer the fit question: Is a contact-center platform right for a practice your size, or are you paying for features you’ll never touch?
If you’re weighing a simpler alternative, see how Quo compares to Dialpad.
FAQs
No. HIPAA-compliant features aren’t tied to a minimum tier, and data retention is the same across all plans. So, your HIPAA cost is just your regular plan cost. What can affect the total price are things unrelated to compliance itself, like seat minimums on paid plans and add-ons for advanced AI.
For a full breakdown of tiers, minimums, and add-ons, see our Dialpad pricing guide.
Not really. Most established providers sign BAAs, including RingCentral, Zoom, Nextiva, and Quo. HIPAA support alone doesn’t separate them. The real differences are more practical: how easy it is to get a BAA signed and how fine-tuned the retention and access controls are once you have one. For a healthcare team, the deciding factor usually isn’t compliance. It’s whether it fits how your practice actually works.
To compare the field, see our roundup of HIPAA-compliant VoIP providers.
Yes, as long as you’ve signed a BAA with Dialpad and configured the platform correctly. HIPAA requires that any vendor that handles protected health information does so under a signed BAA with the right safeguards in place. Without one, using Dialpad for sharing electronic protected health information isn’t compliant, no matter how it’s configured. Once the BAA is signed, compliance comes down to how you set up retention, access, and which channels you use. Confirm your specific setup with your compliance officer or counsel.
Yes, but with limits. You should never text PHI, like a diagnosis or test results, to a patient’s regular phone number. Texting is fine for appointment reminders, scheduling, and logistics. Send anything clinical or identifying through a secure portal instead.












