If your practice handles PHI daily through calls, texts, and voicemails, you need a HIPAA-compliant phone system. Otherwise, your patients’ privacy is at risk. You could also face fines ranging anywhere from $100 to $50,000 per violation.*
So if you’re considering RingCentral for your business phone needs, you might be asking: is RingCentral HIPAA compliant?
Yes, RingCentral can be HIPAA compliant, but only when you have a signed Business Associate Agreement, or BAA. RingCentral offers HIPAA compliance on all its plans. Even with a BAA in place, coverage is scoped to specific channels and doesn’t automatically extend to standard SMS. Healthcare teams need to confirm exactly what their BAA covers before logging Protected Health Information, or PHI.
In this article, we’ll cover the features RingCentral’s BAA covers and where it falls short. We’ll also highlight where teams need to adopt best practices to maintain HIPAA compliance even when they have a BAA in place. Finally, we’ll share a RingCentral alternative that helps you manage patient communications smoothly.
How RingCentral’s HIPAA compliance works

Voice over Internet Protocol, or VoIP, phone systems enable communication over the internet. Traditional phone systems transmit calls over physical phone lines. VoIP phone systems convert voice signals into digital packets. Then they send them to recipients via an internet connection.
A HIPAA-compliant VoIP phone system keeps patient information safe when you communicate with them. It adheres to data privacy requirements under the Health Insurance Portability and Accountability Act, or HIPAA.
A compliant provider signs a BAA to document these obligations. This enables healthcare teams to safeguard their patients’ PHI and ePHI.
You need a HIPAA-compliant healthcare communication platform if you’re a covered entity, like:
- A health plan
- A healthcare provider
- A healthcare clearinghouse
- Any other organization that handles patient health information
To get access to RingCentral’s BAA, you have to ask your RingCentral sales rep. You can also message RingCentral’s support team for one.
What RingCentral’s BAA covers
RingCentral’s BAA covers the following services:
- RingCentral Fax
- RingEX
- RingCX
- RingCentral Contact Center
- RingCentral Engage Digital, excluding third-party channel communications
- RingCentral AI Conversation Expert
- RingCentral AI Quality Management
- RingCentral AIR Pro
- RingCentral AI Receptionist
- RingCentral AI Supervisor Assist
- RingCentral AI Agent Assist
- Customer Engagement Bundle
For RingEX customers using RingCentral to manage their patient communications, the platform covers all types of interactions. That includes voice calls, video conferences, SMS text messaging, and online faxing. It also includes AI call summaries, transcriptions, and conversations with RingCentral’s AI Receptionist.
RingCentral’s HIPAA safeguards
RingCentral provides administrative, physical, and technical safeguards to ensure your patient data is protected. Here’s a list of these safeguards to help you understand the security measures they take:
Administrative safeguards
- Security management process. RingCentral maintains a written information security program with documented policies governing protected data. It also has an employee code of conduct with a sanctions policy for violations.
- Risk management. RingCentral runs regular cybersecurity risk assessments under a risk assessment policy to identify threats to its business and operations.
- Assigned security responsibility. Organizational security roles are defined and published internally, with senior employees accountable for implementing the security program.
- Workforce security and information access management. Access controls limit protected data to personnel with a reasonable need and block unauthorized access. Personnel also have to run through a documented account creation, modification, and removal process.
- Security awareness and related training. All employees and contractors complete annual security and privacy training covering cybersecurity awareness, GDPR, and CCPA.
- Security incident procedures. RingCentral maintains an incident response capability for events affecting the confidentiality, integrity, or availability of its services and data.
- Evaluation. RingCentral runs regular internal and external network vulnerability scans against its information processing systems.
Physical safeguards
- Facility access controls. Every physical area where RingCentral processes protected data is monitored, controlled, and restricted to authorized individuals.
- Workstation security. Employees work from RingCentral-owned devices or personal devices enrolled in the company’s managed device program.
- Device and media controls. RingCentral keeps a current hardware and software asset register and wipes or physically destroys assets before disposal.
Technical safeguards
- Access control. Password requirements follow current NIST guidance, and production network access is role-based and governed by least privilege.
- Integrity. Access is limited to need-to-know under least privilege. Every system handling protected data generates audit logs detailed enough to detect unauthorized activity.
- Transmission security. Protected data is encrypted in transit across public wired and wireless networks. Communication over public switched telephone networks is excluded.
With these safeguards, RingCentral apps like RingEX and RingCX have earned HITRUST CSF Certification. HITRUST CSF Certified status indicates that these RingCentral applications have met industry-defined security requirements and are appropriately managing risk.
Is SMS messaging HIPAA compliant?
Texting is convenient, but standard SMS isn’t HIPAA compliant on its own. It lacks the technical safeguards the HIPAA Security Rule requires. Once a message leaves your phone, you have no control over where it goes or how it’s stored.
The main security gaps in standard SMS include:
- No encryption in transit. SMS travels through carriers in plain text. Anyone could intercept the message during delivery.
- No control over storage. You can’t manage how a patient’s phone or carrier stores messages, who accesses them, or whether it’s deleted securely.
- No access controls. Anyone who picks up either device can read, screenshot, or forward the message.
- No audit trails. HIPAA requires audit logs of access and activity, but standard SMS has no built-in tracking or reporting.
See how teams can use SMS in a HIPAA-compliant manner in our HIPAA-compliant VoIP overview.
Limitations of RingCentral HIPAA compliance
With RingCentral’s HIPAA safeguards, it might seem like it covers all your compliance needs. Unfortunately, if you run a healthcare business, RingCentral’s platform has some major limitations you should be aware of:
1. SMS registration delays
Healthcare practices that text patients must complete The Campaign Registry registration to remain compliant with US carrier texting requirements. But users indicate that RingCentral’s TCR registration led to waiting months for approval, getting rejected multiple times, or being declared ineligible based on unexpected policy changes.
“Signed up and paid for SMS service last Sept. Have received no help. They continue to draw money from my account and have now denied the application.” — RingCentral user on TrustPilot
If a practice switches from another provider to RingCentral, this means a gap in patient communication during the transition.
2. Call recording storage limits
RingCentral limits how long it stores your call recordings on its platform. It deletes recordings 90 days after they’re created. This can make it complicated to maintain information related to medical records, which can affect compliance with state laws. For example, in Nevada, healthcare providers are required to maintain medical records for a minimum of five years.
If you want to store your recordings without a time-based limit, you should look at a different business phone platform.
💡Learn more about the challenges of RingCentral call recording.
3. SMS caps and overage fees
Texting has become a common communication channel for healthcare practices. From appointment confirmations, reminders, and follow-ups, patients frequently interact with their providers over SMS. These text exchanges are solely focused on interactions where PHI isn’t shared to maintain HIPAA compliance.
Similar to its call recording limits, RingCentral caps SMS and MMS texting in each of its plans. Here are RingCentral SMS limits in each plan:
- Core: 25 texts per user per month
- Advanced: 100 texts per user per month
- Ultra: 200 texts per user per month
If you exceed these limits, RingCentral charges you for every additional message you send. These fees can rack up over time, inflating your monthly phone costs.
How Quo compares for HIPAA compliance

With Quo, you can safely use VoIP services to improve customer relationships and serve patients more effectively. Beyond building patient trust, Quo helps teams get more done in a day. Automate appointment reminders, set up detailed phone menus, and add auto-replies to set expectations on incoming customer communication when your team is away.
HIPAA compliance is available for Quo users in its Business and Scale plans. Similar to RingCentral, you must sign a BAA to use Quo in a HIPAA-compliant manner. If you’re an active Quo customer that isn’t on a free trial, you can request a BAA here.
Here are a few ways Quo has an advantage over RingCentral for teams that require HIPAA compliance:
- Faster texting registration. RingCentral takes weeks and months to approve teams for registration with The Campaign Registry. Quo, on the other hand, only takes between 1–3 days to approve teams. Start texting patients faster with our platform.
- Unlimited call recording storage. Record your calls without worrying about accessing them with Quo. We offer unlimited call recording storage in your Quo account. You don’t have a limit on how many calls you can record, and you don’t have to worry about data retention, either. Teams that have an active Quo account can access their call recordings at any time.
- Unlimited domestic texting. Message your patients without worrying about hitting any SMS limits. Quo offers teams unlimited texting to US and Canadian numbers on every plan. With zero texting overage fees, you’ll always know how much you’ll spend on Quo each month.
Don’t just take our word for it. Healthcare teams love using Quo to manage their day-to-day patient communications.
“We will employ around 40,000 caregivers this year. Snippets, AI transcripts, and the ability to jump into any line save us thousands of hours. Quo has become a real partner in helping us grow and adapt.” — Owen Wible, Sr. Director of Operations, Cornerstone Caregiving.
Get a modern business phone with Quo. See the full side-by-side comparison in our Quo vs RingCentral breakdown.
*American Medical Association, HIPAA violations & enforcement
FAQs
Yes, RingCentral’s internet fax is compliant with HIPAA regulations on all plans with a signed BAA. Faxes are encrypted in transit and stored securely in the RingCentral portal. The fax-to-email feature delivers faxes as PDF attachments, but healthcare practices must ensure the receiving email system is also HIPAA compliant for end-to-end protection.
RingCentral encrypts voice, voicemail, fax, and team messaging, which supports secure patient communication. For video conferencing, RingCentral recommends that teams speak to patients using the RingCentral Video Pro app. By doing so, teams can speak to their patients under the security standards required by HIPAA.
RingCentral and Zoom offer identical forms of HIPAA compliance. Zoom also provides a BAA for teams to sign to safeguard PHI. Zoom is also HITRUST CSF certified and makes a SOC 2 + HITRUST report available to users.












