The short answer
HIPAA does not prohibit VoIP for dental practices. It requires vendors who sign a Business Associate Agreement plus reasonable safeguards. The practical move is to separate your call types: route patient-facing calls through a BAA-covered VoIP provider, and run internal, vendor, and dental-lab calls that carry no PHI through simpler or lower-cost tools. You do not need every tool to be HIPAA-covered, you need the right tool for the right call.
What HIPAA requires for phone calls
The Privacy Rule covers any call that involves protected health information: a patient name paired with a diagnosis, an appointment, a billing detail, or treatment history. Even confirming an appointment using a name and a visit date counts as PHI.
HIPAA does not ban VoIP. It asks for four things when your calls touch that information.
Technical safeguards. Access, audit, integrity, and transmission-security controls. For calls, this mainly means encrypting call audio where it is feasible to do so, plus reasonable controls on anything that records or stores the conversation.
Business Associate Agreements (BAAs). Any vendor that creates, receives, maintains, or transmits electronic PHI on your behalf must sign a BAA. A VoIP provider that routes your patient calls qualifies. If a vendor will not sign one, using them for patient calls is a compliance risk you are carrying yourself.
Minimum necessary disclosure. Share only the PHI a given call actually requires. This is largely a training and process issue rather than a technology one, and it is where most real-world dental violations happen.
Access controls. Voicemail that contains PHI is stored ePHI. Any system that keeps patient messages needs restricted access and should be covered by a BAA with the vendor that stores it.
The VoIP-specific complication (PSTN handoff)
A call that starts as encrypted internet audio often reaches its destination as an unencrypted call on the public phone network. Your VoIP phone or softphone calls over the internet to the provider's media server, then hands off to the PSTN for the last leg to the patient's handset. That last leg is not encrypted.
HIPAA acknowledges this. Guidance under the Omnibus Rule notes that calling a patient's cell phone by traditional or VoIP means is generally permissible if the patient provided the number, because they effectively assumed the risk of an unencrypted network. The BAA requirement still applies to your VoIP vendor for the portions of the call they handle.
The key point for a dental office: browser-to-browser calls between two devices, with no PSTN leg at all, can be fully end-to-end encrypted. FreeCallMe's browser-to-browser calls work this way, so the audio never touches the telephone network. That is relevant for calls with staff, referral partners, or a patient who can join a browser link, though it does not by itself resolve the BAA question for PHI.
VoIP options by compliance level
| Calling type | PSTN involved? | Encryption | BAA available | HIPAA viable |
|---|---|---|---|---|
| Traditional landline | Yes | No | From carrier (varies) | Depends on BAA |
| Hosted VoIP (RingCentral, 8x8) | Yes (outbound) | Partial | From most | Yes with BAA |
| Browser-to-browser (WebRTC) | No | End-to-end | Depends on provider | Yes if BAA signed |
| Browser-to-phone (VoIP-to-PSTN) | Yes (PSTN leg) | Partial | Depends on provider | Depends on BAA |
| Consumer apps (WhatsApp, FaceTime) | No (usually) | Varies | Not available | Not suitable for PHI |
"HIPAA viable" here means viable for PHI-containing patient calls. Every row that lists a BAA still depends on actually signing one and putting the matching safeguards in place.
Handle your no-PHI calls in the browser
Free, end-to-end encrypted browser-to-browser calls for staff, vendors, and dental labs. No account, no download.
Call any phone number in 220+ countries from your browser. Your first call is free, up to $0.25, then pay-as-you-go by the minute.
Which platforms sign BAAs
Several healthcare-focused VoIP providers will sign a Business Associate Agreement. The specific tier matters, since the compliant plan is usually not the default one.
- Vonage for Healthcare
- Signs a BAA, offers compliant routing and encrypted recordings on the healthcare product.
- RingCentral
- Offers a HIPAA package with a BAA as an add-on. It is not on by default, so you have to request and enable it.
- 8x8
- Signs a BAA on its contact-center and healthcare tiers.
- Dialpad
- Signs a BAA on its enterprise tier.
- Twilio
- Signs BAAs for Programmable Voice healthcare customers who go through its compliance process.
Healthcare-compliant tiers generally run $30.00 to $60.00 per user per month, higher than the standard plans, because the BAA and compliance tooling ride on top. Consumer apps like WhatsApp, FaceTime, and Google Duo are not HIPAA-eligible for PHI at all, since they do not offer BAAs.
Where browser-based calling fits
Browser calling is a strong fit for the calls that do not involve PHI: vendor calls, staff-to-staff coordination, supplier check-ins, and dental-lab calls. For patient-facing calls that carry appointment details or health information, verify whether the platform offers a BAA before you use it.
To be direct about our own tool: FreeCallMe is a general-purpose calling tool and should not be used for PHI-containing patient calls without first confirming HIPAA compliance and signing a BAA. We are not going to overclaim on that.
For browser-to-browser team calls where no patient data is discussed, such as staff at different locations or an on-call dentist checking in, end-to-end encrypted browser calling is efficient, private, and free. That is the lane where it earns its place in a dental practice.
Practical compliance steps
Audit your current calling setup
List every platform you use to make or receive calls, then mark which ones ever touch PHI. You cannot fix what you have not mapped.
Request BAAs from your VoIP vendors
Ask every provider that handles patient calls to sign a BAA. If one will not, that is a documented gap you either close or route around.
Separate your call types
Send patient-facing calls through your BAA-covered VoIP. Route internal, vendor, and lab calls that carry no PHI through simpler or lower-cost tools.
Train staff on minimum necessary disclosure
The most common dental HIPAA problem is not technology, it is staff discussing patient details where others can overhear. Train for it directly.
Review voicemail handling
Any system that stores patient messages stores ePHI. Restrict access to it and make sure the vendor storing it is covered by a BAA.
Encryption vs. compliance
Encryption matters, but it is not the whole picture. A platform can encrypt every call and still not be compliant if there is no BAA. A traditional carrier may qualify if it does sign one. Ask two questions of any vendor: Will they sign a BAA? Do they have documented safeguards for call metadata and recordings? The BAA is the legal foundation.
The nuance for a dental practice with mixed call types is that you do not need every tool to be HIPAA-covered. You need the right tool for the right call. Patient appointment and billing calls go through your BAA-covered VoIP. Lab coordination, vendor calls, and internal staff communication can run through lower-cost or simpler tools. That separation keeps compliance costs reasonable without creating risk where it actually matters.
Frequently asked questions
- Does HIPAA ban VoIP for dental practices?
- No. HIPAA does not prohibit VoIP. It requires that you work with vendors who will sign a Business Associate Agreement for the portions of the call they handle, and that you put reasonable safeguards in place. VoIP is fully usable for patient calls once those pieces are in place.
- Can we use FreeCallMe for patient calls?
- FreeCallMe is a general-purpose calling tool and should not be used for calls that contain PHI without first confirming HIPAA compliance and signing a BAA. It is a good fit for calls that carry no patient data, such as staff-to-staff coordination, supplier check-ins, and dental-lab calls. Browser-to-browser calls are end-to-end encrypted and never touch the phone network, which suits internal team calls where no patient details are discussed.
- What is a BAA and why does it matter?
- A Business Associate Agreement is a contract between your practice and any vendor that handles ePHI on your behalf. It is the legal foundation of compliance for phone calls. A platform can encrypt every call and still not be compliant without a BAA, and a traditional carrier may qualify if it signs one. The BAA, not encryption alone, is what makes a vendor usable for patient calls.
- Are consumer apps like WhatsApp or FaceTime HIPAA-eligible?
- No. Consumer apps such as WhatsApp, FaceTime, and Google Duo do not offer Business Associate Agreements, so they are not suitable for calls that contain PHI. They may be fine for casual, non-PHI conversation, but they cannot be your channel for patient health information.
Free, encrypted calls for your no-PHI conversations
Use FreeCallMe for staff, vendor, and dental-lab calls that carry no patient data. Browser-to-browser, end-to-end encrypted, no account or download. Keep patient PHI on a BAA-covered line.
Call any phone number in 220+ countries from your browser. Your first call is free, up to $0.25, then pay-as-you-go by the minute.