CTRLK

Shared components

HIPAA-eligible Voice services [#hipaa-eligible-voice-services-add-ons-and-options]

The Voice API supports a dedicated HIPAA-eligible deployment designed for handling voice traffic that may contain Protected Health Information (PHI). When using the HIPAA-eligible voice configuration, the platform applies additional safeguards to protect sensitive data during call setup, routing, and delivery.

HIPAA-eligible voice services support the transmission of PHI only within the limits defined in this section. Any feature, functionality, or use case not explicitly listed as supported is excluded from HIPAA-eligible voice services and must not be used to transmit, process, or store PHI.

This capability is intended for anyone operating under HIPAA requirements and is used together with appropriate contractual agreements, such as a Business Associate Agreement (BAA).

Key characteristics

  • Dedicated HIPAA configuration for PHI voice traffic
  • Secure Voice Trunking (SIP Trunk) over HTTPS APIs
  • Tight data-minimization practices: call audio and content are not stored or indexed in standard logs
  • No recording or transcription capabilities within the HIPAA flow
  • Restricted features that could expose call content

HIPAA-eligible voice scope of use [#hipaa-eligible-voice-scope-of-use-add-ons-and-options]

HIPAA-eligible Voice services consist exclusively of Voice Trunking (SIP Trunk) calls initiated or received through the Infobip platform using the Infobip API over HTTPS, and are available only to customers who have completed the Infobip HIPAA onboarding process.

Voice traffic containing PHI must:

  • Originate in the United States of America
  • Terminate in the United States of America
  • Be transmitted only through the HIPAA-eligible voice configuration
IMPORTANT

Customers are responsible for ensuring that all voice traffic containing Protected Health Information (PHI) is transmitted exclusively through the HIPAA-eligible voice configuration and is not transmitted, processed, or stored using any non-HIPAA-eligible endpoint, service, or combination of Infobip services unless explicitly designated as HIPAA-eligible.

HIPAA-ineligible services and features [#hipaa-ineligible-services-and-features-add-ons-and-options]

Voice used in combination with other Infobip services is excluded from HIPAA-eligible voice services unless explicitly stated otherwise in the relevant product description.

The following services and functionalities are not HIPAA-eligible and must not be used with PHI:

  • Recording calls
  • Transcribing calls
  • Storing call audio or transcripts
  • Monitoring, analyzing, or otherwise accessing call content
  • Retaining or archiving voice recordings
  • Any feature that captures, processes, or exposes call media or voice payloads
  • Any integrations, workflows, or services not expressly designated as HIPAA

Storage and retention for HIPAA-eligible voice [#storage-and-retention-add-ons-and-options]

Call data retention, storage, logging, and archival capabilities may be restricted or disabled to support HIPAA compliance.

NOTE

HIPAA-related support requests must be submitted to HIPAA_Support@infobip.com.
You must not include PHI in any support tickets. When troubleshooting, use call SIDs, message SIDs, or other Infobip-specific identifiers instead of phone numbers or other sensitive information.

Was this page helpful?