Audio-Only Telehealth Services: A Complete HIPAA Compliance Guide

Note: This guidance was originally issued by the HHS Office for Civil Rights (OCR) in June 2022 and remains the governing framework for audio-only telehealth. Always verify current requirements on the official HHS website before updating your policies.

The U.S. Department of Health and Human Services, through its Office for Civil Rights (OCR), issued guidance clarifying how HIPAA-covered entities can deliver audio-only telehealth services using remote communication technologies.

The goal is straightforward: ensure healthcare providers can offer audio-only consultations in full compliance with HIPAA’s Privacy, Security, and Breach Notification Rules, including after the COVID-era Notification of Enforcement Discretion for Telehealth ended.

This matters because audio-only telehealth is often the only realistic option for patients without reliable broadband, smartphones, or the digital literacy to join a video call. This guide breaks down what the guidance permits, what safeguards you need, and when a BAA is required.

What HHS Guidance Says About Audio-Only Telehealth Services

Many healthcare providers assume that because audio-only calls don’t involve video or images, HIPAA simply doesn’t apply. That’s not accurate. Even a basic phone consultation involves protected health information (PHI), and depending on the technology used, HIPAA’s Privacy and Security Rules can absolutely apply.

The HHS guidance addresses this gap directly, answering four core questions that providers commonly ask when offering audio-only visits:

  • Whether the Privacy Rule permits audio-only telehealth
  • When the Security Rule applies to the technology used
  • Whether a Business Associate Agreement (BAA) is required
  • Whether providers can offer audio-only visits regardless of insurance coverage

Does HIPAA Allow Audio-Only Telehealth?

Yes. The OCR confirmed that the HIPAA Privacy Rule permits covered entities to use remote communication technologies for audio-only telehealth, provided reasonable safeguards are in place to protect PHI from impermissible use or disclosure.

These safeguards include:

  • Conducting telehealth sessions in private settings where conversations can’t be overheard
  • Avoiding speakerphone unless privacy is assured
  • Speaking at a lowered volume to limit accidental disclosure of PHI
  • Verifying the patient’s identity before discussing any health information either verbally or in writing, including through electronic methods

When Does the HIPAA Security Rule Apply?

    The Security Rule does not apply to audio-only telehealth conducted over a traditional landline, because the information transmitted is not electronic.

    However, the Security Rule does apply when you use:

    • Communication apps on a smartphone or computer
    • Voice over Internet Protocol (VoIP) services
    • Technologies that electronically record or transcribe a telehealth session
    • Messaging services that electronically store voice messages

    If you use any of these, you must address security risks and vulnerabilities to electronic PHI as part of your organisation’s risk analysis and risk management process.

    Do You Need a Business Associate Agreement (BAA)?

    Not always. Consistent with its earlier position, the OCR clarified that a BAA is not required when the telecommunications vendor has only transient access to PHI during a call, acting purely as a conduit without creating, receiving, or maintaining PHI on the provider’s behalf.

    BAA not required: A provider conducts an audio-only telehealth session with a patient over a standard mobile phone call, and the carrier’s only role is to transmit the call.

    BAA required: The vendor’s app stores PHI (such as call recordings or transcripts), or translates oral communications into another language to support patients with limited English proficiency because, in doing so, the vendor creates and receives PHI.

      What If Insurance Doesn’t Cover Audio-Only Visits?

        Coverage and compliance are two separate questions, and providers sometimes conflate them. A patient’s insurance plan may or may not reimburse for an audio-only visit, but that has no bearing on whether the visit itself is HIPAA-compliant.

        The OCR confirmed that providers may offer audio-only telehealth services in line with HIPAA requirements regardless of whether a patient’s health plan covers or reimburses for that service. In practice, this means you can offer audio-only consultations as a self-pay or out-of-pocket option for patients whose plans don’t cover it without needing to change how you handle privacy and security safeguards.

        This is particularly relevant for providers serving Medicaid or uninsured populations, where audio-only care is often the most practical way to maintain continuity of care.

        Why Audio-Only Telehealth Matters for Access

        Audio-only telehealth significantly expands access to care. Many patients face barriers to video consultations, including:

        • Limited financial resources for devices or data plans
        • Limited English proficiency
        • Disabilities that make video calls difficult
        • Poor internet access or inadequate broadband
        • Weak cellular coverage in rural areas

        Consider a common scenario: an elderly patient in a rural area with a basic flip phone and no home broadband. Video consultations simply aren’t an option, but a phone call is. For this patient, audio-only telehealth isn’t a lesser alternative to video care; it’s the only form of remote care available to them.

        Audio-Only Telehealth HIPAA Compliance Checklist

        Use this as a quick reference when setting up or reviewing your audio-only telehealth workflow:

        • Conduct calls from a private setting where conversations can’t be overheard
        • Avoid speakerphone unless privacy is confirmed
        • Verify patient identity before discussing any PHI
        • Determine whether your calling technology is electronic (VoIP, app) or landline
        • If electronic, include the technology in your HIPAA risk analysis
        • Check whether your vendor stores, records, or transcribes calls; if yes, execute a BAA
        • Document your safeguards in written policies and procedures
        • Train staff on audio-only telehealth privacy practices

        New to HIPAA compliance in general? Our complete guide to HIPAA guidelines on telemedicine covers the fundamentals: what HIPAA is, what counts as a violation, and the penalties involved.

        Need a HIPAA-Compliant Telehealth Platform?

        VCDoctor supports both audio-only and video consultations with built-in HIPAA safeguards, BAA support, and secure PHI handling.

        Contact Us Today

        Conclusion

        Audio-only telehealth services are a legitimate, HIPAA-permitted way to deliver care, and for many patients, it’s the most accessible option available.

        The requirements are manageable: reasonable privacy safeguards, patient identity verification, a risk analysis covering any electronic calling technology, and a BAA where the vendor handles PHI beyond simple transmission.

        The providers who get this right expand their reach to rural, elderly, and lower-connectivity patient populations without taking on compliance risk.

        FAQs

        1. Are audio-only telehealth services HIPAA compliant?

        Yes. Audio-only telehealth is HIPAA compliant when providers use reasonable safeguards, conduct calls in private settings, avoid speakerphone, and verify patient identity before discussing PHI.

        2. Do I need a BAA for audio-only telehealth calls?

        BAA is not required when the vendor simply transmits the call without storing or processing PHI. A BAA is required if the vendor’s app stores recordings, transcripts, or provides translation services.

        3. Does HIPAA apply to landline telephone calls?

        The HIPAA Security Rule does not apply to traditional landline calls, since the information transmitted is not electronic. It does apply to VoIP, smartphone apps, and any technology that electronically records or stores audio.

        4. Can providers offer audio-only telehealth if insurance doesn’t cover it?

        Yes. OCR clarified that providers may offer audio-only telehealth regardless of whether a health plan covers or reimburses for those services.

        5. What safeguards are required for audio-only telehealth?

        Key safeguards include private call settings, limited speakerphone use, lowered voice volume, patient identity verification, and inclusion of electronic calling technologies in your organization’s HIPAA risk analysis.

        Sanjeev Agrawal profile picture

        sanjeev-agrawal-2


        Sanjeev Agrawal is a healthcare technology strategist and founder of VCDoctor. With over 10 years of experience in white label telemedicine platforms and custom telemedicine software development, he helps healthcare providers scale virtual care securely and compliantly.