Remedora
Start building
HIPAA Compliant Voicemail

Voicemail that says enough, and nothing more.

HIPAA does not prohibit voicemail. It limits what you leave in one. The rules, the scripts, and the vendor test, written for teams that handle patient calls at scale.

DisclosureMinimum necessary
VendorsBAA required
PreferencesLogged · enforced
i. What the rules say

The Privacy Rule permits voicemail. Minimum necessary edits it.

HIPAA allows a provider to call a patient and leave a message. HHS says so in its Privacy Rule guidance, with a condition: limit the message to your name, your organization, and a callback number. The minimum necessary standard does the editing. Anything past what the patient needs to return the call is a disclosure you chose to make to whoever presses play.

Consent runs the opposite direction from what most operators expect. You do not need written permission to call a patient about their own care. You do need to honor reasonable requests about how you reach them: cell only, no messages on the home line, text instead of voice. The Privacy Rule treats these confidential communication requests as ones you must accommodate, so they belong on the patient record and in the calling workflow, never in one agent's memory.

Retention is the part teams forget. A voicemail that contains PHI is PHI. The recording, and the transcript your phone system helpfully emails around, need the same access controls as the chart. Messages that document a care interaction belong in the record, where your state's retention rules apply. HIPAA separately requires you to keep your policies and disclosure documentation for six years.

ii. Scripts

Two scripts. One is a disclosure.

i.

Compliant: the minimal script.

"Hi, this is Dana from Ridgeline Health. Please call us back at (800) 555-0134." A name, an organization, a number. It covers scheduling, refills, and results, because it says nothing about any of them.

ii.

Non-compliant: the helpful script.

"Calling about your semaglutide refill, and your labs came back, so..." The drug, the test, and the implied diagnosis are each a separate disclosure. Family, roommates, and speakerphones all count as an audience.

iii.

The brand-name trap.

If your storefront is named for the condition it treats, saying the brand says the diagnosis. Condition-specific brands should leave a first name and a callback number, nothing else.

iv.

Preferences that stick.

"Never call my work number" only protects the patient if every agent can see it. Log contact preferences on the patient record and have the workflow enforce them.

iii. Evaluating phone vendors

No BAA, no vendor.

A phone system that stores voicemails, transcribes them, or forwards audio to email is holding PHI on your behalf. That makes the vendor a business associate, and business associates sign BAAs before patient calls run through the product. A vendor that will not sign is disqualified, whatever its security page claims. Consumer tools fail this test first; we walked through the most common example in Is Google Voice HIPAA compliant.

A signature is the floor. From there, trace where messages actually land: who can play a recording, where transcripts get delivered, whether access is logged, and what happens to mailboxes when an employee leaves. The same test applies to every channel that carries PHI. We keep parallel guides for HIPAA compliant texting and HIPAA compliant fax.

iv. Where voice fits

Most patient contact should never reach a mailbox.

For a telehealth e-commerce brand, most patient communication is intake follow-up, order status, refill questions, and support. None of it needs to be a phone call, and a message that stays in a governed channel cannot be overheard in a kitchen. Brands on Remedora run support with ticketing inside the HIPAA compliant platform, covered by the same signed BAA as intake, prescribing, and fulfillment.

That shrinks the voicemail problem rather than adding a vendor to manage it. Fewer systems hold PHI, the phone carries less weight, and when a provider does need to call, the message is the minimal script and the touch is logged with the rest of the operation. If you are mapping the communication stack for a launch, talk with us.

v. FAQ

Voicemail, plainly answered.

Is it a HIPAA violation to leave a voicemail?
No. The Privacy Rule permits providers to call patients and leave messages, and HHS guidance directs staff to limit what they leave: a name, the organization, and a callback number. Violations come from the content, most often a diagnosis, medication, or test result spoken into a shared mailbox.
What may a HIPAA compliant voicemail include?
The caller's name, the organization, a callback number, and a request to return the call. It should not include the reason for the call, medication names, test results, or appointment details that reveal treatment. If the organization's name itself reveals a condition, leave a first name and number only.
Do voicemail and phone vendors need to sign a BAA?
Yes, when the system stores, transcribes, or forwards messages that contain PHI. That makes the vendor a business associate, and a signed BAA is required before patient calls run through the product. Consumer phone tools typically will not sign one, which rules them out.
Do we need patient consent before leaving voicemails?
Written consent is not required for treatment-related calls. You must honor reasonable requests about how and where you contact patients, such as cell only or text instead of voice. Record those preferences where the whole team can see them and the workflow can enforce them.
vi. Begin

Patient communication with one BAA to sign.

HIPAA compliant. Minimal by default. Logged with everything else.

Live in hoursReply within 24 hours
Remedora pill mascot

Launch your telehealth brand
this week.

Storefront, doctors, pharmacy, payments, and compliance, included and ready. The only thing missing is your brand.

LegitScript Certified
HIPAA COMPLIANT · BAA
© 2026 Remedora Inc.