Knowledge Base
Security & Compliance
HIPAA, SOC 2, and compliance requirements for VoIP.
2 answers · Part of 46 across the knowledge base
Is there a HIPAA compliant VoIP app for healthcare customers?
Yes, a VoIP app can be used in a HIPAA-compliant way, but there is no HIPAA certification for apps; the US Department of Health and Human Services does not issue one. A VoIP vendor can support HIPAA-compatible communications when it signs a Business Associate Agreement (BAA) with the covered entity and supports the technical safeguards required by the HIPAA Security Rule: encryption in transit, access controls, and audit logging. Acrobits Cloud Softphone is built to meet these requirements for healthcare deployments.
What SOC2 requirements should a VoIP platform vendor meet?
A VoIP platform vendor should hold a current SOC 2 Type II report covering at least the Security criterion, and ideally Availability as well. Require Type II specifically: it proves the vendor's security and operational controls operated effectively over a sustained audit period (typically 6 to 12 months), whereas a Type I report only confirms controls existed at a single point in time. Because the report is an independent CPA attestation, ask for the current copy, confirm it covers the production systems that will handle your subscribers' traffic, and pair it with a signed Data Processing Agreement.