HIPAA COMPLIANT ARCHITECTURE • SIGNED BAAs • ePHI ENCRYPTION • SOC 2 ALIGNED
Effective Date: September 10, 2026 | Last Updated: September 10, 2026
HIPAA compliance across COMEXCEL telecommunications infrastructure delivers secure, enterprise-grade cloud architecture engineered to support healthcare organizations in meeting their statutory obligations under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
This compliance statement governs voice, messaging, media storage, and data processing across our Business VoIP Phone Service & Cloud PBX Solutions, SIP trunking, desktop softphones, mobile applications, AI voice intelligence engines, and CRM integrations.
HIPAA Compliance & Security at a Glance
This policy functions alongside our master COMEXCEL Legal & Compliance Hub to establish binding technical, administrative, and physical safeguards across all covered healthcare communications:
- Core Permitted Use: Secure clinical, operational, administrative, and patient communications for Covered Entities and Business Associates.
- BAA Availability: Legally binding Business Associate Agreements (BAAs) executed for eligible accounts to establish permissible uses, data safeguards, and breach notification terms.
- End-to-End Cryptography: Mandatory TLS 1.3 signaling encryption, Secure Real-Time Transport Protocol (SRTP) voice encryption, and AES-256 resting encryption for call recordings, voicemails, and logs.
- Access & Audit Controls: Granular Role-Based Access Control (RBAC), multi-factor authentication (MFA), and immutable audit logs capturing user access, playback events, and administrative changes.
- Prohibited Practices: Transmitting unencrypted patient identifiers via public SMS, disabling audio recording disclosure prompts in all-party consent jurisdictions, and bypassing BAA execution on accounts handling ePHI.
Purpose, Scope & Healthcare Telecommunications
This statement establishes the technical, administrative, and physical controls implemented across COMEXCEL infrastructure to safeguard electronic Protected Health Information (ePHI). Covered services include cloud PBX routing, SIP signaling, hardware IP phones, desktop and mobile softphone clients, call recording repositories, voicemail processing, 2-way business SMS/MMS, and developer APIs.
Adherence to this policy is mandatory for all healthcare accounts and constitutes a legally binding addendum to the COMEXCEL Terms of Service. Services are hosted and maintained across our distributed tier-1 data center facilities.
Direct-Answer Capsule: Is COMEXCEL HIPAA Compliant?
The U.S. Department of Health and Human Services (HHS) and the Office for Civil Rights (OCR) do not certify, endorse, or issue compliance credentials to software or telecommunications vendors.
COMEXCEL provides communications infrastructure, technical architecture, and administrative safeguards engineered to comply with the HIPAA Security, Privacy, and Breach Notification Rules. Where COMEXCEL creates, receives, maintains, or transmits ePHI on behalf of a customer, compliance is achieved when the customer executes a formal Business Associate Agreement (BAA) with COMEXCEL and appropriately configures administrative access, user permissions, and transmission settings.
Primary Target Audiences Supported:
- Clinical & Outpatient Practices: Family medicine, pediatrics, internal medicine, cardiology, dermatology, oncology, orthopedics, physical therapy, dental groups, DSOs, behavioral health practices, and multi-site urgent care centers.
- Enterprise Health Systems & Allied Care: Regional hospital networks, telehealth organizations, medical billing companies, diagnostic imaging centers, pharmacies, and healthcare Business Associates.
- Administrative & Technical Decision Makers: Practice owners, Chief Information Officers (CIOs), Chief Information Security Officers (CISOs), HIPAA Privacy & Security Officers, Practice Administrators, and IT Directors.
Covered Entity, Business Associate & Conduit Exception
Under HIPAA regulations, organizational responsibilities are strictly partitioned:
- Covered Entity: Healthcare providers, health plans, and healthcare clearinghouses that transmit health information in electronic form.
- Business Associate: A service provider—such as COMEXCEL—that creates, receives, maintains, or transmits ePHI on behalf of a Covered Entity.
- Downstream Subcontractors: Third-party cloud infrastructure and carrier partners utilized by COMEXCEL that handle ePHI must adhere to equivalent Business Associate contractual terms.
- The Conduit Exception: The narrow statutory “conduit exception” applies strictly to transmission-only utilities (such as traditional PSTN copper lines) where data is transient and never stored. Because modern Cloud PBX platforms store call recordings, voicemails, CDR metadata, and message logs, COMEXCEL operates as a Business Associate and executes BAAs for covered services.
Defining ePHI in Modern Telecommunications
Electronic Protected Health Information (ePHI) comprises any individually identifiable health data transmitted or maintained in electronic media. In modern unified communications, ePHI can manifest across multiple vectors:
| Communications Vector | Potential ePHI Exposure | Security Safeguard Requirement |
|---|---|---|
| Voice Streams | Clinical consultations, treatment plans, diagnosis reviews. | Mandatory SRTP audio packet encryption. |
| Call Recordings | Verbal patient intake, clinical notes, insurance discussions. | AES-256 rest encryption + RBAC playback access. |
| Voicemail Audio & Text | Patient symptom descriptions, callback numbers, lab results. | Encrypted storage + secure portal-only delivery. |
| SMS / MMS Payloads | Appointment reminders, prescription ready notices. | Data minimization (no direct clinical diagnosis). |
| Call Detail Records (CDR) | Caller ID paired with specialized clinic identities. | Encrypted metadata repositories + restricted logging. |
Customer account privacy and organizational metadata handling are further governed under the COMEXCEL Privacy Policy.
HIPAA Security Framework: Administrative, Physical & Technical
COMEXCEL aligns its platform architecture with the three foundational pillars of the HIPAA Security Rule (45 CFR Part 164, Subpart C):
- Administrative Safeguards: Formal risk management assessments, workforce training on ePHI handling, third-party vendor vetting, and emergency contingency planning.
- Physical Safeguards: Hosting voice nodes in SSAE 18 SOC 2 Type II certified data centers featuring 24/7 biometric access controls, armed facility security, redundant cooling, and multi-source utility grids.
- Technical Safeguards: Unique user authentication, automatic session termination, cryptographic transmission protocols, and immutable activity auditing.
Transmission Security: In-Transit & At-Rest Encryption
To satisfy 45 CFR § 164.312(e), COMEXCEL enforces end-to-end cryptographic protection across the full telecommunications lifecycle:
- Signaling In-Transit: Transport Layer Security (TLS 1.3 / TLS 1.2) encrypts all SIP signaling between endpoints, softphones, and cloud servers, preventing packet sniffing and eavesdropping.
- Media In-Transit: Secure Real-Time Transport Protocol (SRTP) encrypts active voice and video streams with AES-128/AES-256 cipher suites.
- Data At-Rest: Call recordings, voicemail audio files, AI transcription databases, and administrative logs are stored using AES-256 disk-level and database-level encryption.
| Telecommunications Stage | Network Component | Cryptographic Standard | Technical Safeguard (45 CFR § 164.312) |
|---|---|---|---|
| Endpoint to Cloud Transmission | IP Desk Phone, Desktop Softphone, Mobile App | TLS 1.3 / TLS 1.2 & SRTP | Encrypts SIP call signaling and live voice media streams against eavesdropping. |
| Cloud Core Processing | COMEXCEL Cloud PBX Switching Infrastructure | FIPS 140-2 Validated In-Memory Processing | Isolates call metadata and processes real-time media streams in isolated secure memory. |
| Persistent Data Storage | Media Archives, Transcription DBs, Audit Logs | AES-256 Storage Encryption | Enforces disk-level and database-level encryption for call recordings, voicemails, and logs. |

Secure Call Recording & Encrypted Media Lifecycle
Healthcare organizations utilizing call recording for quality assurance, patient triage, or compliance must maintain strict lifecycle controls:
- Granular Playback Permissions: Only designated compliance officers and clinical supervisors can access call recordings.
- Automated Disclosure Prompts: Automated IVR announcements (“This call is recorded for clinical quality and recordkeeping”) must be enabled to comply with state wiretapping statutes and the COMEXCEL Acceptable Use Policy.
- Configurable Retention & Deletion: Organizations can establish automated retention windows (e.g., 30, 90, 365 days) after which recordings are permanently and cryptographically shredded.
Access Controls, Role-Based Permissions & MFA
To enforce the principle of least privilege under 45 CFR § 164.312(a):
- Role-Based Access Control (RBAC): Distinct permission tiers isolate administrative settings, call recording playback, user directory modifications, and billing details.
- Multi-Factor Authentication (MFA): Mandatory MFA across administrative portals and user web interfaces via TOTP authenticator apps or hardware security keys.
- Automatic Session Timeout: Softphone clients and administrative dashboards terminate inactive sessions after a configurable inactivity threshold.
Audit Controls, Immutable Logging & Traceability
In compliance with 45 CFR § 164.312(b), COMEXCEL maintains tamper-evident audit logs capturing system interactions:
- User Authentication Events: Successful logins, failed password attempts, and password reset requests.
- Media Access Logs: Exact timestamp, user ID, IP address, and duration of every call recording or voicemail playback event.
- Configuration Changes: Real-time logging of permission escalations, routing modifications, and user deprovisioning.
Business Associate Agreement (BAA) Execution
A signed Business Associate Agreement is legally required before routing or storing ePHI on the COMEXCEL network.
Key Provisions Covered in the COMEXCEL BAA:
- Permitted and required uses and disclosures of ePHI.
- Mandatory implementation of administrative, physical, and technical safeguards.
- Security incident and breach reporting timelines under 45 CFR § 164.410.
- Subcontractor compliance assurances and downstream BAA execution.
- Data return or secure destruction upon contract termination.
Account administrators can request and execute a formal BAA directly by emailing [email protected].

HIPAA-Aware Business SMS/MMS & 10DLC Registration
Standard SMS and MMS protocols are inherently unencrypted across public cellular networks. Healthcare organizations must balance TCPA/10DLC compliance with HIPAA Privacy rules:
- 10DLC Registration: Healthcare messaging must be registered under verified TCR Healthcare use cases in accordance with our 10DLC & Business Messaging Policy.
- Data Minimization: Outbound automated texts must omit sensitive clinical details, specific diagnosis terms, and test results.
- Permitted SMS Usage: Appointment reminders (“Your appointment with Dr. Smith is tomorrow at 2 PM”), clinic location links, general office closure alerts, and check-in instructions.
- Patient Consent: Prior express consent must be documented before initiating SMS notifications.
Voicemail-to-Email & Electronic Notification Security
Standard SMTP email transmission across public mail servers lacks default cryptographic enforcement. To prevent ePHI leakage via unencrypted .wav audio email attachments, COMEXCEL provides two distinct delivery configurations:
| Configuration Mode | Delivery Architecture | ePHI Risk Profile | Recommended Use Case |
|---|---|---|---|
| Secure Notification Mode (Default) | Sends caller metadata alongside an authenticated HTTPS link requiring secure portal login. | Zero ePHI exposure: Voice audio never leaves AES-256 encrypted cloud storage. | Standard Recommended Standard: Required for all outpatient clinics, DSOs, and standard email configurations. |
| Encrypted Attachment Mode | Attaches the audio file (.wav) directly to the inbound email notification. | Conditional ePHI exposure: Requires verified corporate email encryption. | Enterprise Only: Permitted strictly when the customer enforces TLS mail relays and holds an active BAA with their email provider. |
AI Voice Intelligence, Transcription & Summaries
COMEXCEL’s artificial intelligence features—including automated call transcription, clinical call summarization, and keyword spotting—are governed under our healthcare security architecture:
- BAA Subcontractor Alignment: All underlying natural language processing (NLP) and speech-to-text models operate under strict Business Associate contractual terms.
- Zero Model Training on ePHI: Customer voice streams, transcripts, and clinical summaries are never utilized to train public or foundational machine learning models.
- Encrypted Transcription Repositories: Generated transcripts are stored with AES-256 encryption and restricted to authorized personnel under RBAC policies.
CRM Integrations & Healthcare Contact Center Workflows
When integrating COMEXCEL with Electronic Health Record (EHR) platforms or healthcare CRMs (e.g., Salesforce Health Cloud, Epic, Athenahealth):
- Independent BAA Requirement: Connecting COMEXCEL to a third-party CRM does not automatically extend BAA coverage; the customer must execute a separate BAA with the CRM vendor.
- Secure API Connectors: Data synchronizations between COMEXCEL and external CRMs operate exclusively over TLS 1.3 encrypted REST APIs and authenticated webhooks.
- Contact Center Queues: Dynamic skill-based routing ensures sensitive patient intake calls route strictly to certified clinical agents.
Remote & Hybrid Workforce Security Safeguards
Healthcare staff operating from home or remote clinical settings must adhere to strict endpoint security protocols:
- Enterprise Softphone Security: Employees must utilize official COMEXCEL desktop and mobile apps with enforced biometric or PIN access controls.
- Acoustic & Visual Privacy: Clinicians must use dedicated headsets and privacy screens in remote work environments to prevent visual and acoustic eavesdropping of patient information.
- Network Integrity: Softphones operating on residential Wi-Fi networks should route over corporate VPNs or secure TLS tunnels to isolate traffic from insecure IoT devices.
- E911 Nomadic Updates: Remote healthcare workers must maintain accurate dispatchable location profiles under our E911 Emergency Service Disclosure.
Business Continuity, Emergency Failover & Breach Protocol
Business Continuity & Emergency Failover
COMEXCEL maintains active-active, geographically redundant cloud voice switches across North America. Automated disaster recovery routing redirects incoming patient calls to alternate backup facilities, secondary clinics, or mobile hunt groups during localized ISP or utility outages.
Security Incident & Breach Notification Protocol
In compliance with 45 CFR §§ 164.400–414, COMEXCEL maintains a formal Incident Response Plan. In the event of a confirmed security incident or unauthorized acquisition of unencrypted ePHI, COMEXCEL will notify affected Covered Entities without unreasonable delay and within the contractual timeframe specified in the executed Business Associate Agreement.
HIPAA Compliance Frequently Asked Questions (FAQs)
Does COMEXCEL sign Business Associate Agreements (BAAs)?
Yes. COMEXCEL executes legally binding BAAs for qualifying healthcare organizations, medical practices, dental clinics, and enterprise health systems.
Can healthcare organizations use COMEXCEL Cloud PBX for patient calls?
Yes. All voice signaling and media streams are encrypted using TLS 1.3 and SRTP, providing secure voice communications across desk phones, softphones, and mobile apps.
Are call recordings compliant with HIPAA regulations?
Yes. When call recording is enabled, audio files are stored in AES-256 encrypted storage with granular role-based access controls and comprehensive audit logging.
Is SMS messaging inherently HIPAA compliant?
Standard cellular SMS is unencrypted on recipient mobile devices. COMEXCEL supports HIPAA-compliant SMS for appointment reminders and logistical alerts, provided sensitive clinical diagnoses and test results are omitted.
Does COMEXCEL qualify under the HIPAA “Conduit Exception”?
No. Because modern Cloud PBX platforms process, store, and manage voicemails, call recordings, and metadata, COMEXCEL operates as a Business Associate and provides signed BAAs rather than claiming transient conduit status.
How are voicemails containing patient health information protected?
Voicemails are encrypted at rest with AES-256. COMEXCEL recommends using secure notification links that require authenticated portal login rather than sending unencrypted audio files via email.
Can remote and telehealth clinicians use COMEXCEL softphones from home?
Yes. Remote staff can securely make and receive clinical calls using COMEXCEL desktop and mobile softphones over encrypted TLS/SRTP connections.
How do I request a Business Associate Agreement (BAA)?
Account administrators can request a BAA by contacting our compliance team directly at [email protected].
Protect Your Healthcare Communications with a Signed BAA
Ensure your clinical voice, messaging, and call recording workflows meet HIPAA Security Rule standards. Our healthcare compliance team is ready to execute your Business Associate Agreement.
