Portal, billing and account

HIPAA and the BAA

Accepting the agreement, what it covers, and the channels it never covers.

The short answer

Not automatic: HIPAA mode is switched on in the portal, and the agreement is accepted electronically. Until then it is not in force.
Where: The Compliance page. The acceptance records the date, time, IP address and login.
What it never covers: Texting, WhatsApp, voicemail to email, email to fax, and emailed reports. Email is not a covered channel.
Cost: Nothing. There is no HIPAA tier.

The platform is configurable for HIPAA compliance. It becomes effective for your account only when an authorized person enables HIPAA mode in the portal and electronically accepts the Business Associate Agreement. We are not "HIPAA certified," because no such government credential exists, and we say so plainly.

Accepting the agreement

Sign in to the portal with an Advanced login, open the Compliance page, read the agreement, confirm you have the authority to bind your company, and accept. The acceptance is recorded with the date, time, IP address and the login that clicked, and that record is your proof in an audit. The agreement itself, and the list of services it covers, are at vocatech.com/policies/hipaa-baa.

What we are responsible for

Securing the hosted platform: encryption at rest and in transit, call processing, recordings, voicemail and fax inside our systems, the portal and the API, role-based access, audit logs, monitoring, and breach notification within sixty days as the law requires. Any subcontractor we use that could touch protected information is bound in writing to the same protection, may use the data only to deliver the service, and we remain responsible for it. The current subcontractor list is available on request under a non-disclosure agreement. Our main subprocessor is Google Cloud, which hosts the platform and the AI summaries under its own HIPAA agreement with us.

What you are responsible for

  • Configuring the system correctly. A menu that reads patient names to callers is on you.
  • Managing logins, and removing them when people leave. See portal logins.
  • Securing the computers, browsers and phones your people use.
  • Your other vendors, and their own agreements.
  • Training staff on what may be said and sent where.
  • Keeping protected information out of the channels the agreement does not cover.

What the agreement never covers

The agreement covers the services on the eligible services list and nothing else. Email is not a covered channel, and neither are text messages, WhatsApp, or the public telephone and mobile networks, which only carry the call. So these stay outside it, and no setting or addendum brings them in:

  • Text messages and WhatsApp. Appointment reminders with no clinical detail are fine; a diagnosis is not.
  • Voicemail to email.
  • Email to fax, and fax notices sent by email. Faxing through the portal's Faxing page is covered.
  • Emailed call reports.

HIPAA mode does not switch any of these off. The Compliance page scans your account and raises a flag on each channel that is configured, and you decide what to turn off. A company that enables HIPAA mode and leaves voicemail to email running still has protected information going out by email until it is switched off.

What changes day to day

For most customers, nothing visible. Calls, recordings and the portal work the same. Behind the scenes your account carries the stricter controls in the agreement, and the portal warns on settings that need care. If your compliance officer asks whether the agreement is in place, the record on the Compliance page answers.

Checked against the product on 6 September 2026. If something on this page is behind, tell us and we fix the page.

Still stuck?

A real person at Vocatech picks up, usually within minutes during business hours. A message from the contact page opens a ticket with our team.