SingleComm
Industries

HIPAA compliance for contact centers — what your vendor actually needs to prove

BAAs, encryption posture, PII redaction, access controls, retention rules, and the audit checklist your compliance officer will eventually send you. Walk into a vendor call with the right questions.

4 min readUpdated April 2026
On this page

Why HIPAA claims aren't all equal

"HIPAA compliant" is a phrase every CCaaS vendor puts in their pitch deck. Very few of them mean the same thing when they say it. When your compliance officer audits the platform handling your patient conversations, they're looking at roughly a dozen specific controls. A vendor who is solid on some and weak on others will fail the audit.

This guide walks through what HIPAA actually requires of a contact center platform — and what to ask vendors before the procurement call.

Business Associate Agreement (BAA) — non-negotiable

A Business Associate Agreement is the contract between your covered entity and the vendor that handles PHI on your behalf. Without a signed BAA, your vendor is not permitted to touch protected health information. Full stop.

Ask: "Will you sign our BAA, or do you require yours? Which clauses are non-negotiable on your side?"

Red flag: vendors who claim HIPAA compliance but resist BAA signing or try to substitute a generic vendor agreement.

Encryption at rest and in transit

HIPAA requires encryption of PHI both while it's stored and while it's moving across networks. At a minimum:

  • In transit: TLS 1.2 or later for every API call, every web session, every inter-service hop
  • At rest: AES-256 or stronger for stored call recordings, transcripts, chat logs, customer records
  • Key management: who holds the encryption keys? Is there key rotation? Can the vendor's employees access decrypted data?

Ask: "What's your encryption posture? Who manages keys? Can your employees decrypt our call recordings?"

PII / PHI redaction in workflows

This is where most vendors fall short. It's not enough to encrypt data — the data should never reach places it doesn't need to be in the first place.

SingleComm's Workflow builder shields sensitive fields from agent screens by default. When a workflow collects an SSN, DOB, or medical condition, the agent sees XXXX in their interface while the underlying data flows to the customer record. AI in-call transcription can redact PHI from the transcript in real time.

Ask: "When an agent is on a call that collects medical information, can they see that information on their screen? What about in the call recording? What about in transcripts?"

Call recording retention

HIPAA doesn't dictate a specific retention period — your own policies do. But the vendor must give you the tools to enforce your policy:

  • Configurable retention per program, per caller type, per interaction channel
  • Automatic purge when retention windows expire
  • Legal hold capability (override automatic purge when a specific recording is subject to preservation orders)

Ask: "Can I set different retention periods for different programs? What happens when the retention window expires? Is there a legal hold feature?"

Access controls (minimum necessary access)

HIPAA's "minimum necessary" rule means employees and agents should only have access to the PHI they actually need for their job. Role-based access control (RBAC) is the implementation:

  • Agents see only their own queue's data
  • Supervisors see their own team's data
  • Compliance officers get read-only audit views, no modify permissions
  • System administrators cannot access raw PHI without audit trail

Ask: "Show me the RBAC model. Can I give my compliance team read-only access to recordings without giving them the ability to modify or export? Are administrative actions logged?"

Audit logging

When OCR (Office for Civil Rights) investigates an incident, they'll ask for detailed logs of who accessed what, when, and why. Your contact center platform must produce these.

  • All logins logged with timestamp, IP, user
  • All access to PHI logged (which record, by whom, at what time)
  • Administrative actions logged (RBAC changes, retention policy changes, user creation)
  • Log retention independent of interaction retention

Ask: "Show me a sample audit log. How long are logs retained? Can my compliance team query the logs directly or do we have to request extracts?"

Breach notification capability

When a breach occurs, HIPAA requires notification within 60 days. Your vendor needs to:

  • Detect breaches through internal monitoring
  • Alert you promptly when one occurs
  • Provide a forensic trail to determine scope
  • Support your notification obligations with detailed impact reports

Ask: "Walk me through your breach detection and notification process. What's your contractual notification window to us?"

Subprocessors and data residency

If your vendor uses AWS, Azure, or Google Cloud underneath — those providers are subprocessors. They have their own HIPAA postures, BAAs, and data residency options.

Ask: "Who are your subprocessors? Where is our data stored geographically? Can we require US-only data residency?"

Annual audit / attestation

The practical question: when my compliance officer asks for proof, what do they get?

  • SOC 2 Type II report (annual, covers security, availability, confidentiality, privacy)
  • HIPAA security risk assessment
  • Penetration test reports
  • Policies and procedures documentation

Ask: "Can you share your most recent SOC 2 Type II report and HIPAA risk assessment under NDA?"

The SingleComm posture

SingleComm's HIPAA posture covers all of the above:

  • BAAs available on request for every deployment
  • TLS 1.2+ in transit, AES-256 at rest
  • Workflow-level PHI redaction from agent screens
  • Configurable retention per program with automatic purge + legal hold
  • RBAC on every module, audit-logged
  • SOC 2 Type II audited annually
  • US-based data residency; EU residency on request for GDPR overlays

For healthcare contact centers with specific state-level requirements (California CMIA, Texas HB 300), SingleComm supports configurable workflows that layer state-specific controls on top of the federal HIPAA baseline.

What to do next

  1. Take your compliance officer's HIPAA checklist into your next CCaaS vendor evaluation.
  2. Use the questions above verbatim.
  3. Flag any vendor who can't give you concrete answers.
  4. If you want to skip the evaluation theater and see a working compliant platform: schedule a SingleComm demo.

Back to

Industries

Return to the main industries page to see the full product family.

Related guides

See how SingleComm fits your industry's compliance and workflow posture.

Schedule a demo