Voicemail that says enough, and nothing more.
HIPAA does not prohibit voicemail. It limits what you leave in one. The rules, the scripts, and the vendor test, written for teams that handle patient calls at scale.
The Privacy Rule permits voicemail. Minimum necessary edits it.
HIPAA allows a provider to call a patient and leave a message. HHS says so in its Privacy Rule guidance, with a condition: limit the message to your name, your organization, and a callback number. The minimum necessary standard does the editing. Anything past what the patient needs to return the call is a disclosure you chose to make to whoever presses play.
Consent runs the opposite direction from what most operators expect. You do not need written permission to call a patient about their own care. You do need to honor reasonable requests about how you reach them: cell only, no messages on the home line, text instead of voice. The Privacy Rule treats these confidential communication requests as ones you must accommodate, so they belong on the patient record and in the calling workflow, never in one agent's memory.
Retention is the part teams forget. A voicemail that contains PHI is PHI. The recording, and the transcript your phone system helpfully emails around, need the same access controls as the chart. Messages that document a care interaction belong in the record, where your state's retention rules apply. HIPAA separately requires you to keep your policies and disclosure documentation for six years.
Two scripts. One is a disclosure.
Compliant: the minimal script.
"Hi, this is Dana from Ridgeline Health. Please call us back at (800) 555-0134." A name, an organization, a number. It covers scheduling, refills, and results, because it says nothing about any of them.
Non-compliant: the helpful script.
"Calling about your semaglutide refill, and your labs came back, so..." The drug, the test, and the implied diagnosis are each a separate disclosure. Family, roommates, and speakerphones all count as an audience.
The brand-name trap.
If your storefront is named for the condition it treats, saying the brand says the diagnosis. Condition-specific brands should leave a first name and a callback number, nothing else.
Preferences that stick.
"Never call my work number" only protects the patient if every agent can see it. Log contact preferences on the patient record and have the workflow enforce them.
No BAA, no vendor.
A phone system that stores voicemails, transcribes them, or forwards audio to email is holding PHI on your behalf. That makes the vendor a business associate, and business associates sign BAAs before patient calls run through the product. A vendor that will not sign is disqualified, whatever its security page claims. Consumer tools fail this test first; we walked through the most common example in Is Google Voice HIPAA compliant.
A signature is the floor. From there, trace where messages actually land: who can play a recording, where transcripts get delivered, whether access is logged, and what happens to mailboxes when an employee leaves. The same test applies to every channel that carries PHI. We keep parallel guides for HIPAA compliant texting and HIPAA compliant fax.
Most patient contact should never reach a mailbox.
For a telehealth e-commerce brand, most patient communication is intake follow-up, order status, refill questions, and support. None of it needs to be a phone call, and a message that stays in a governed channel cannot be overheard in a kitchen. Brands on Remedora run support with ticketing inside the HIPAA compliant platform, covered by the same signed BAA as intake, prescribing, and fulfillment.
That shrinks the voicemail problem rather than adding a vendor to manage it. Fewer systems hold PHI, the phone carries less weight, and when a provider does need to call, the message is the minimal script and the touch is logged with the rest of the operation. If you are mapping the communication stack for a launch, talk with us.
Voicemail, plainly answered.
Is it a HIPAA violation to leave a voicemail?
What may a HIPAA compliant voicemail include?
Do voicemail and phone vendors need to sign a BAA?
Do we need patient consent before leaving voicemails?
Patient communication with one BAA to sign.
HIPAA compliant. Minimal by default. Logged with everything else.