The short answer
The platform is configurable for HIPAA compliance. It becomes effective for your account only when an authorized person enables HIPAA mode in the portal and electronically accepts the Business Associate Agreement. We are not "HIPAA certified," because no such government credential exists, and we say so plainly.
Accepting the agreement
Sign in to the portal with an Advanced login, open the Compliance page, read the agreement, confirm you have the authority to bind your company, and accept. The acceptance is recorded with the date, time, IP address and the login that clicked, and that record is your proof in an audit. The agreement itself, and the list of services it covers, are at vocatech.com/policies/hipaa-baa.
What we are responsible for
Securing the hosted platform: encryption at rest and in transit, call processing, recordings, voicemail and fax inside our systems, the portal and the API, role-based access, audit logs, monitoring, and breach notification within sixty days as the law requires. Any subcontractor we use that could touch protected information is bound in writing to the same protection, may use the data only to deliver the service, and we remain responsible for it. The current subcontractor list is available on request under a non-disclosure agreement. Our main subprocessor is Google Cloud, which hosts the platform and the AI summaries under its own HIPAA agreement with us.
What you are responsible for
- Configuring the system correctly. A menu that reads patient names to callers is on you.
- Managing logins, and removing them when people leave. See portal logins.
- Securing the computers, browsers and phones your people use.
- Your other vendors, and their own agreements.
- Training staff on what may be said and sent where.
- Keeping protected information out of the channels the agreement does not cover.
What the agreement never covers
The agreement covers the services on the eligible services list and nothing else. Email is not a covered channel, and neither are text messages, WhatsApp, or the public telephone and mobile networks, which only carry the call. So these stay outside it, and no setting or addendum brings them in:
- Text messages and WhatsApp. Appointment reminders with no clinical detail are fine; a diagnosis is not.
- Voicemail to email.
- Email to fax, and fax notices sent by email. Faxing through the portal's Faxing page is covered.
- Emailed call reports.
HIPAA mode does not switch any of these off. The Compliance page scans your account and raises a flag on each channel that is configured, and you decide what to turn off. A company that enables HIPAA mode and leaves voicemail to email running still has protected information going out by email until it is switched off.
What changes day to day
For most customers, nothing visible. Calls, recordings and the portal work the same. Behind the scenes your account carries the stricter controls in the agreement, and the portal warns on settings that need care. If your compliance officer asks whether the agreement is in place, the record on the Compliance page answers.