Is Voicemail HIPAA Compliant? 7 Scripts You Can Use
Leaving voicemails for patients is allowed under HIPAA — but what you say, how you say it, and where messages are stored all have compliance implications.

Yes. HIPAA does not prohibit leaving voicemails for patients. HHS answered this directly in FAQ 198: the Privacy Rule permits providers to communicate with patients at home, by mail or by phone, and "does not prohibit covered entities from leaving messages for patients on their answering machines." This is not a gray area.
What HHS asks for in the same answer is that you "take care to limit the amount of information disclosed on the answering machine" in order to reasonably safeguard the patient's privacy. That is the reasonable safeguards standard at §164.530(c), not the minimum necessary rule — a point worth being precise about, because a lot of published guidance gets it backwards.
A voicemail intended for the patient is a disclosure to the individual, and §164.502(b)(2)(ii) expressly exempts disclosures to the individual from minimum necessary. The reason you still limit what you say is different: someone other than the patient may hear the message. That secondary disclosure is permitted under §164.502(a)(1)(iii) as incidental to a permitted disclosure, but only if you have applied reasonable safeguards. Limit the message, and the incidental disclosure is permitted. Do not, and it is not.
The voicemail itself is not the problem. What you say in it, how your phone system stores it, and whether you honor a patient's request to be contacted differently — that is where compliance risk lives.
What You Can Say in a Voicemail
Safeguarding the message is practical, not restrictive. A compliant voicemail can include:
- Your name and practice name. "This is Sarah from Lakeview Dental."
- A callback number.
- A generic reason for calling. "I'm calling about your upcoming appointment" or "regarding your recent visit."
- Appointment reminders. Date, time, and location are acceptable — appointment reminders are part of treatment operations under the Privacy Rule.
- A request to call back.
This covers the vast majority of reasons a practice leaves a voicemail. You can accomplish the goal — getting the patient to return your call — without disclosing clinical details.
What You Should Not Say in a Voicemail
Do not include clinical specifics that go beyond what is necessary:
- Diagnosis or condition names. "We're calling about your diabetes management" discloses a condition to anyone who hears the message.
- Test results. Do not confirm or deny results. "Your lab work came back positive" is a HIPAA violation if someone other than the patient hears it.
- Treatment details. "We need to discuss your chemotherapy schedule" reveals protected information.
- Prescription information. Medication names can reveal conditions.
- Billing amounts or insurance details. Financial information tied to healthcare services is PHI.
- Anything beyond what is necessary to get the patient to call back. This is the test. If the information is not required for the voicemail to serve its purpose, leave it out.
The risk is not theoretical. A voicemail left on a shared family phone, a wrong number, or a device that plays messages on speaker can expose PHI to unauthorized individuals.
HIPAA-compliant voicemail scripts you can use
Practices searching for a "HIPAA compliant voicemail script" or "voicemail example" want copy-able language. Below are compliant templates for the seven most common voicemail scenarios. Each is deliberately short, minimum-necessary, and legally defensible.
1. Generic callback request (default)
"Hello, this is [Practice Name] calling for [Patient First Name]. Please give us a call back at [phone number] at your earliest convenience. Thank you."
2. Appointment reminder
"Hi, this is [Practice Name]. We're calling to remind [Patient First Name] of an appointment on [date] at [time]. Please call us at [phone number] if you need to reschedule."
3. Appointment confirmation request
"Hello, this is [Practice Name] calling for [Patient First Name]. We're confirming your upcoming appointment. Please give us a call at [phone number] to confirm. Thank you."
4. Callback for test results (do not disclose results themselves)
"Hi [Patient First Name], this is [Nurse Name] from [Practice Name]. We have some information to share with you. Please give us a call back at [phone number]. Thank you."
5. Prescription refill or medication callback
"Hi, this is [Practice Name] calling for [Patient First Name]. We received your recent request and would like to speak with you. Please call us back at [phone number]."
6. Missed appointment / rescheduling
"Hello [Patient First Name], this is [Practice Name]. We missed you today and want to help you reschedule. Please call us back at [phone number]."
7. After-hours message
"Hi, this is [Practice Name]. We're currently closed. Please leave your name and callback number, and we'll return your call during regular business hours. For medical emergencies, please dial 911."
Fill-in template you can print for staff:
"Hello, this is _____________ from _____________. We're calling for _____________. Please call us back at _____________. Thank you."
What every script above deliberately omits:
- Reason for the visit (unless it's a generic reminder)
- Any diagnosis, condition, test result, or medication name
- Insurance or billing amounts
- Anything beyond what is necessary to prompt a callback
Print these next to every phone in the practice. The compliance failure most often happens when staff improvise — a script eliminates the improvisation.
The Obligation Most Practices Have Never Heard Of
Everything above is about what you choose to put in a message. §164.522(b) is different: it is something a patient can require of you.
Under the confidential communications provision, an individual may request that you communicate with them by alternative means or at an alternative location, and you must accommodate reasonable requests. HHS gives examples in FAQ 198 — mail in a closed envelope rather than a postcard, a post office box rather than a home address, calls to a work number rather than a home number — and treats each as reasonable absent extenuating circumstances.
For a practice, that translates into three concrete things:
- A patient can tell you not to leave voicemails at all, or to use a specific number, and you have to honor it if the request is reasonable. A provider may not require the patient to explain why.
- The request has to be recorded where staff will see it before dialing. A preference that lives in a scanned form and not in the chart is a preference you will breach.
- You may ask for the request in writing, and you may ask for the alternative contact details — §164.522(b)(2) permits both, along with information about how payment will be handled where that is relevant. What you may not ask for is a reason.
This is the one voicemail duty that is genuinely enforceable against the practice rather than being a matter of judgment, and it is missing from almost every voicemail policy we see.
Voicemail System Requirements
This is where most practices miss the compliance picture. They train staff on what to say but never evaluate whether their voicemail system itself meets HIPAA requirements.
Cloud and VoIP Phone Systems
If your phone system stores voicemails digitally — which includes virtually every modern cloud or VoIP system — the provider handling those recordings has access to PHI. That makes them a business associate under HIPAA. You need a Business Associate Agreement (BAA).
This applies to essentially every cloud PBX and VoIP service a practice is likely to be using. Whether a BAA is available, what it covers, and how you get it varies enough between them that the vendor's own documentation is the only reliable answer — see the six questions below. The same analysis applies across the rest of the communications stack; HIPAA-compliant messaging covers the text and chat side of it.
Voicemail-to-Email Transcription
Voicemail-to-email services are a particularly high-risk area. When a voicemail is transcribed to text and sent via email, two things happen:
- A text record of PHI is created — one that is often more searchable and shareable than the original audio.
- That text record is transmitted via email, which may not be encrypted.
If your phone system automatically transcribes voicemails and sends them to staff email, confirm that both the transcription service and the email system meet HIPAA security requirements. Most practices never think to evaluate this — and the email side has its own answer, covered in HIPAA-compliant email.
Traditional Landline Answering Machines
A physical answering machine on a traditional landline is generally lower risk because no third party stores the recording. However, the device should be in a secure area where unauthorized individuals cannot access it. A shared waiting room or open front desk where messages play aloud is not a compliant setup.
Choosing a phone system that can hold PHI
Most "HIPAA-compliant phone system" lists are shopping tables: a vendor name, a plan tier, a checkmark. We had one on this page and we removed it, because when we checked the tier claims against the vendors' own documentation, almost none of them held up. Coverage is rarely gated on a plan tier. It is gated on which product you bought, what the vendor's agreement actually names, and whether the practice is on a managed business account at all.
So here is what to verify instead. These six questions decide the answer for any vendor, and unlike a tier table they do not go stale every quarter.
1. Are you on the business or managed product, not a consumer account? This is the first fork and it disqualifies more practices than anything else. Consumer and free tiers of otherwise-capable services are generally outside any business agreement. A personal account with the same brand name on it is not the same product.
2. Will the vendor receive, maintain, or transmit PHI on your behalf? If the system stores or forwards recordings, this is a business associate relationship and a BAA is required. If a call simply passes over a conduit without the provider retaining the content, the analysis differs. Storage and transcription are what usually settle it.
3. Is the specific service actually inside the vendor's BAA scope? Not "does this company sign BAAs" — does the agreement name this product. Vendors routinely cover one product line and not another under the same corporate brand, and the phone product and the messaging product are often not the same line.
4. Does the agreement attach automatically, or does it take an administrative step? Some vendors include it in the standard terms for eligible organizations. Some attach it through a data-protection addendum by default. Some require you to accept it at checkout, request it from an account manager, or buy a specifically designated variant of the service. Knowing which one you are dealing with is the difference between covered and assuming you are covered.
5. Are transcription, SMS, fax, call recording, integrations and AI features inside the same scope? This is where practices get caught. Voicemail-to-email transcription, an AI summary feature, or a CRM integration can sit outside the agreement that covers the calls themselves. Ask about each feature you intend to switch on, not about the platform in general.
6. What is still yours to do? A BAA covers the vendor. Retention windows, who on your staff can access the mailbox, whether your access is logged, and what your team says in a message are all configuration and policy on your side. No agreement moves those. For a view of where those obligations stand across your practice, the free risk assessment covers vendor coverage alongside the rest.
Write down the answers before you sign. The vendor's own documentation is the source — not a comparison article, and not this one.
Examples we verified
Not rankings, not an exhaustive list, and not recommendations. These are three arrangements we checked against the vendor's own documentation on the date shown, chosen because each illustrates a different answer to question 4 above.
Spruce Health — included in the standard terms for eligible organizations. Spruce's help documentation states that its HIPAA Business Associate Agreement is included automatically, where applicable, in the standard terms of service for organizations, with no separate agreement to execute. Its published plans list the BAA as a feature of the paid tiers rather than as an add-on. Verified 2026-08-28 against Spruce's HIPAA and BAA overview and its plans page.
RingRx — signed when service starts. RingRx's support documentation answers the question directly: "Yes we do sign a Business Associate Agreement ('BAA') when you start service," with the agreement available after a free trial has begun. Its current plan materials represent BAA support across the offering rather than confining it to a tier. Verified 2026-08-28 against RingRx support.
Google Voice — covered, but only for managed users under a Workspace BAA. This one needs the qualifier stated precisely, because the distinction is the whole answer. Google's HIPAA Included Functionality list, as of May 14 2026, names "Google Voice (managed users only)" among the services covered by the applicable HIPAA Business Associate Addendum. That means a Google Workspace organization that has entered the BAA with Google and has licensed Voice for the users handling PHI — the wider Workspace picture is in Is Google Workspace HIPAA compliant?. It does not mean the free consumer Google Voice product, which sits outside any business agreement.
An earlier version of this page listed Google Voice among systems that do not sign BAAs. That was wrong, and it mattered: for a small practice already on Workspace, licensed Google Voice is one of the more accessible covered configurations available. Verified 2026-08-28 against Google's HIPAA Included Functionality list and HIPAA compliance with Google Workspace.
Three examples is deliberately few. We would rather name a short list we can keep current than a long one we cannot.
Common Mistakes
Five voicemail-related compliance failures appear repeatedly:
-
Staff leaving detailed clinical information. Without training, front desk staff default to being helpful — which means leaving specific details about why the patient needs to call back. Helpful intent does not prevent a HIPAA violation.
-
No BAA with the phone provider. The practice signs BAAs with the EHR vendor and the billing company but never considers the phone system that records and stores voicemails containing PHI.
-
Voicemail-to-email sending PHI to unencrypted inboxes. The transcription feature is turned on by default. No one evaluated whether the email destination meets security requirements.
-
Shared voicemail boxes without access controls. A single voicemail box accessed by all staff, with no audit trail of who listened to which messages, fails the access control and audit requirements of the Security Rule.
-
Not verifying phone numbers before leaving messages. A voicemail left at a wrong number is an unauthorized disclosure of PHI. Staff should verify the number on file before leaving any message.
Common voicemail scenarios: what's OK, what's not
Real-world voicemail questions come up faster than policies can anticipate them. Here are direct answers to the ones we hear most often.
Can doctors leave test results on a voicemail? No — do not disclose results (positive, negative, or specifics) in a voicemail. You may leave a message asking the patient to call back to discuss results, without revealing what those results are.
Would a hospital leave a voicemail? Yes, in specific circumstances. Hospitals leave voicemails for appointment reminders, discharge follow-up, and callback requests. They do not disclose diagnoses, test results, or treatment details in voicemails.
Is it a HIPAA violation to leave a voicemail on a family member's phone? It can be. Leaving a detailed clinical message on a shared or wrong number is an unauthorized disclosure. Leaving a generic callback message with the practice name and phone number is generally acceptable — it does not disclose PHI.
Can I leave a voicemail about a positive pregnancy test? No — never disclose the result. Leave a callback request: "This is Dr. Smith's office calling for [Patient Name]. Please give us a call back at [number]."
Are ringless voicemails HIPAA compliant? Ringless voicemail (dropping a voicemail without ringing the phone) can be compliant if it follows the same content rules as regular voicemails: no clinical details, minimum necessary information. Some ringless voicemail vendors sign BAAs; many do not.
Can I leave a voicemail for a patient's spouse or caregiver? Prior written authorization is not the test. Under §164.510(b)(3), a covered entity may disclose limited information to a family member or other person involved in the individual's care, using professional judgment, even when the individual is not present — and HHS says so directly in FAQ 198. The limits are that the disclosure must be relevant to that person's involvement in the care, and that you must exercise judgment about whether it is in the patient's interest. The practical rule for a front desk is unchanged: leave generic content only, because you cannot verify who is on the other end of a phone.
Is it OK to leave a voicemail about a missed appointment? Yes, with limits. "You missed your appointment today, please call us to reschedule" is OK. "You missed your chemotherapy appointment" is not — it discloses treatment context.
Can I leave a voicemail about a bill or payment? Generic yes, specific no. "Please call us regarding a recent account matter" is OK. "You owe $547 for your recent MRI" is not.
What if the patient's outgoing voicemail identifies someone else's household? If a voicemail greeting suggests the phone belongs to a shared household ("You've reached the Jones family"), leave only a callback request with your practice name and number. Do not use the patient's name.
What if I dial a wrong number and leave a message before realizing? Document the incident, notify your privacy officer, and evaluate whether the disclosed information rises to the level of a reportable breach. Wrong-number voicemails with clinical content have triggered OCR investigations.
Best Practices for HIPAA-Compliant Voicemails
Compliance here is not complicated. It requires a policy, a script, and the right vendor agreements.
- Create a standard voicemail script. Give staff exact language to use. Remove the guesswork. A compliant script is short: practice name, callback number, generic reason, request to call back.
- Train staff and document the training. The script only works if staff know to use it. Include voicemail policy in onboarding and annual HIPAA refreshers.
- Verify phone numbers before leaving messages. If the number on file has not been confirmed recently, confirm it before leaving a voicemail.
- Get a BAA from your phone provider. If your VoIP or cloud phone system stores voicemail recordings, request a BAA. If the provider will not sign one, switch to one that will.
- Evaluate voicemail-to-email. If this feature is active, confirm that the email system uses encryption and that the transcription service is covered by a BAA. If you cannot confirm both, disable the feature.
- Document your voicemail policy. Your HIPAA policies and procedures should include a section on voicemail — OCR will look for it if a complaint is filed.
Documenting voicemail attempts in patient records
Medical assistants and front-desk staff document voicemail attempts in the patient chart every day. The phrasing matters — for HIPAA, for medico-legal defensibility, and for downstream care coordination.
Acceptable chart-note phrasing:
- "Left voicemail requesting patient callback."
- "Left detailed voicemail informing pt of upcoming appt."
- "Left detailed voicemail informing pt's parent/guardian of upcoming appt."
- "Voicemail left; patient asked to call back regarding recent visit."
- "OB/RET/ left message in voicemail."
- "Unable to reach patient; voicemail left with callback number."
The convention is to note what happened (voicemail was left, callback was requested) without repeating the clinical content of the message itself in the chart note.
Phrasing to avoid in chart notes:
- "Left voicemail informing patient of positive test result" — the chart note itself now documents that the practice disclosed PHI in a voicemail
- "Left voicemail with medication instructions" — same problem
- "Left voicemail confirming Rx for [medication name] refill" — details that should not have been in the voicemail if the note reflects reality
If the chart note reads like the voicemail contained clinical details, that is a self-documented compliance issue. The rule of thumb: the note documents the attempt, not the content of any disclosed information.
Why this matters for HIPAA:
- OCR reviews chart notes during investigations. A chart note that describes an over-disclosive voicemail is evidence of the disclosure.
- Chart notes are part of the designated record set — patients have the right to access them under §164.524.
- Overly detailed chart notes about voicemail content create discovery exposure in any subsequent litigation.
Best practice for practices that document heavily:
Create a short set of approved chart-note phrases and train front-desk and clinical staff to use them. Common approved options: "VM left, CB requested," "Left detailed VM re: appt," "Attempted contact, no VM," "Unable to leave message per patient preference." If your EHR has quick-text or macro functionality, load these phrases in as one-tap inserts. Consistency in phrasing reduces compliance risk and speeds up documentation.
Frequently Asked Questions
Can I leave a voicemail about a patient's appointment?
Yes. Appointment reminders — including date, time, and location — are permitted under HIPAA as part of treatment operations. Keep the message to logistics. Do not include the reason for the appointment or any clinical details.
Do I need a BAA with my phone provider?
If your phone provider stores voicemail recordings digitally — which includes all cloud-based and VoIP systems — they are a business associate and a BAA is required. This applies to any service that records, stores, or transmits voicemails containing PHI on your behalf.
Is voicemail-to-email HIPAA compliant?
It can be, but only if the transcription service is covered by a BAA and the email system uses encryption that meets HIPAA security requirements. In practice, most default voicemail-to-email setups do not meet these standards. Evaluate yours before assuming it is compliant.
Can I leave voicemails on a patient's cell phone?
Yes. HIPAA does not distinguish between landlines and cell phones for voicemail purposes. The same rules apply: limit the message to the minimum necessary information. Be aware that cell phone voicemails may be played on speaker, displayed as visual transcriptions, or accessible to others with access to the device.
Voicemail compliance is not about avoiding phone calls. It is about applying the same discipline to voice messages that you apply to email, fax, and electronic records. Keep the message minimal, secure the system that stores it, and train your staff.
Corrections & Updates
Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

