Back to blog
Compliance

Ensuring HIPAA Compliance in Business Communications

Interlink Team
Mar 29, 2026
9 min read

For healthcare providers, securing communications is critical. Learn how our encrypted VoIP and secure endpoints ensure strict HIPAA compliance.

The Compliance Gap Most Healthcare Organizations Don't Know They Have

HIPAA's communications requirements are often reduced to a single checkbox: "Is our email encrypted?" The reality is considerably more complex. The HIPAA Security Rule requires covered entities and their business associates to protect the confidentiality, integrity, and availability of all electronic protected health information (ePHI) — and ePHI moves through far more channels than most organizations track: desk phones, mobile devices, fax machines, voicemail systems, video conferencing platforms, and the VoIP infrastructure underlying all of them.

The HIPAA Journal has tracked 5,887 large healthcare data breaches (affecting 500 or more individuals) reported to the HHS Office of Civil Rights since the breach notification requirement took effect in 2009. In 2023 alone, 725 breaches were reported, affecting over 133 million individuals — the highest annual total on record. These aren't hypothetical risks.

What Healthcare Breaches Actually Cost

IBM's 2024 Cost of a Data Breach Report provides the most authoritative annual measurement of breach economics. The healthcare sector continued its streak as the most expensive industry for breaches: the average healthcare breach cost $9.77 million in 2024, down slightly from $10.93 million in 2023 but still more than double the global average of $4.88 million. The average cost per record in healthcare was $408, compared to $148 across all industries.

The mean time to identify and contain a healthcare breach was 258 days — over eight months during which data is potentially being exfiltrated, sold, or misused before the organization even knows a breach has occurred. By the time the breach is publicly announced, the organization is managing simultaneous pressures: regulatory investigation, patient notification, media coverage, litigation exposure, and operational disruption from forensic investigation and system recovery.

HIPAA civil monetary penalties are structured by culpability:

  • Unknown violation (no negligence): $100–$50,000 per violation, up to $25,000/year per category
  • Reasonable cause: $1,000–$50,000 per violation, up to $100,000/year per category
  • Willful neglect, corrected: $10,000–$50,000 per violation, up to $250,000/year
  • Willful neglect, not corrected: $50,000 per violation, up to $1.9 million/year per category

The HHS Office of Civil Rights has collected over $135 million in penalties and settlements since 2008, with enforcement becoming more active in recent years as breach volumes have increased.

How VoIP Becomes a HIPAA Problem

Most healthcare organizations have secured their EHR systems. Far fewer have secured their communications infrastructure with equal rigor. A standard business VoIP or telephony platform transmits call audio as unencrypted RTP packets across the internet — readable by anyone positioned between the endpoints. Voicemail messages stored on the server may not be encrypted at rest. Call recordings might be retained without access controls. Faxes may be received on a shared multi-function device with no audit trail.

Each of these gaps is a potential HIPAA violation when the communication involves ePHI. A physician leaving a voicemail about a patient's test results, a billing coordinator discussing insurance information over an unencrypted VoIP call, or a referral fax sent to an insecure machine — all of these can trigger audit findings and, in cases of breach, enforcement action.

What HIPAA-Compliant Communications Requires

For VoIP and fax communications to be HIPAA-compliant, they must satisfy several controls simultaneously:

Encryption in Transit

All voice communications must be encrypted using TLS (Transport Layer Security) for signaling and SRTP (Secure Real-time Transport Protocol) for call audio. This prevents interception by network-level attackers. Interlink's managed VoIP deployments enforce TLS/SRTP on all calls by default.

Encryption at Rest

Voicemail recordings, call recordings, and fax documents stored on the system must be encrypted at rest. Storage must use AES-256 or equivalent, and access must be controlled by role-based permissions with audit logging of who accessed what and when.

Business Associate Agreement (BAA)

Any vendor that has access to ePHI — including your VoIP provider — must sign a Business Associate Agreement. The BAA establishes the vendor's obligations to protect ePHI, notify you of breaches, and support your compliance program. Interlink provides a BAA as a standard part of the managed VoIP agreement for healthcare customers.

Minimum Necessary Access

Not every staff member should have access to every call recording or voicemail. HIPAA's minimum necessary principle requires that access to ePHI — including call recordings involving patient information — be restricted to those with a legitimate need. Role-based access controls, enforced at the VoIP platform level, satisfy this requirement.

Fax Compliance

Interlink's cloud eFax service receives and transmits faxes as encrypted PDFs delivered to individual email inboxes, rather than to a shared fax machine. Fax documents are stored with the same AES-256 encryption and access controls as other ePHI. Every fax transaction generates an audit trail — timestamp, sender, recipient, and delivery status — that satisfies HIPAA's audit control requirements.

The Risk of "Good Enough"

HHS has pursued enforcement actions against organizations whose security programs were documented but not implemented, updated but not tested, and compliant on paper but not in practice. The bar isn't having a HIPAA policy — it's being able to demonstrate, through documented controls and audit trails, that ePHI is actually protected. Communications infrastructure is an area where the gap between policy and reality is often widest, and where investigators focus attention after a breach.

Sources

  • IBM — Cost of a Data Breach Report, 2024
  • HIPAA Journal — Healthcare Data Breach Statistics, 2024
  • HHS Office of Civil Rights — HIPAA Enforcement Highlights
  • Bright Defense — Healthcare Data Breach Statistics 2024
Share: