Thirteen of fifteen leading CCaaS vendors sign Business Associate Agreements (BAAs) and ship HIPAA-eligible service. The two without enterprise-grade BAAs at June 2026 are Aircall (BAA on request, not default) and Avaya Infinity (partial — the new platform launched April 22, 2025 without complete certification stack at GA). Every other Magic Quadrant vendor — NICE CXone, Genesys Cloud CX, Five9, Talkdesk, Amazon Connect, RingCentral, Dialpad, Vonage, 8x8, Nextiva, Webex Contact Center, Twilio Flex, Salesforce Service Cloud — publishes BAA-signing capability.
What HIPAA compliance for a contact center actually requires
A HIPAA-compliant contact center is a covered entity or business associate operating a system that handles Protected Health Information (PHI). The vendor must sign a Business Associate Agreement (BAA) with the buyer and meet the HIPAA Security Rule's administrative, physical and technical safeguards.
Technical requirements that matter at vendor selection:
- Encryption — at rest (AES-256) and in transit (TLS 1.2+)
- Access controls — unique user authentication, role-based permissions, MFA on admin accounts
- Audit logs — immutable record of who accessed which PHI, retained 6+ years
- Recording controls — ability to pause/resume recording during card-data or PHI segments
- Data residency — US-only storage option (for HIPAA + state-law overlap)
- PHI handling in transcripts and AI — many CCaaS vendors now redact PHI from AI training data; verify in the BAA
The 15-vendor HIPAA status matrix
| Vendor | BAA available | Verified | Notes |
|---|---|---|---|
| NICE CXone | yes | HIPAA-eligible service | Healthcare vertical packages available |
| Genesys Cloud CX | yes | HIPAA-eligible service | Healthcare CX Solutions partner program |
| Five9 | yes | HIPAA-eligible service | Healthcare-specific configurations |
| Talkdesk | yes | HIPAA-eligible service | Talkdesk for Healthcare industry cloud at $225/seat/mo (3-yr min) |
| Amazon Connect | yes | HIPAA-eligible AWS service | BAA via AWS; covered when Amazon Connect is configured per AWS HIPAA reference architecture |
| RingCentral RingCX | yes | HIPAA-eligible service | BAA at Standard tier and above |
| Dialpad | yes | HIPAA-eligible service | Healthcare BAA standard |
| Vonage Contact Center | yes | HIPAA-eligible service | NewVoiceMedia heritage; Salesforce-native CTI |
| 8x8 | yes | HIPAA-eligible service | XCaaS for Healthcare configuration |
| Aircall | partial | BAA on request | Not enterprise-default; verify before deploying |
| Nextiva | yes | HIPAA-eligible service | BAA at Professional tier and above |
| Webex Contact Center | yes | HIPAA-eligible service | Cisco healthcare partner ecosystem |
| Avaya Infinity | partial | Limited verification at GA | New platform; verify scope before signing |
| Twilio Flex | yes | HIPAA-eligible service | BAA on Programmable Voice + Messaging + Flex |
| Salesforce Service Cloud | yes | HIPAA-eligible service | Salesforce HIPAA-compliant since 2020; BAA standard |
What the BAA does not cover
A signed BAA covers PHI processed inside the vendor's HIPAA-eligible service boundary. It does not cover:
- PHI inadvertently sent to non-HIPAA-eligible services (e.g. a Slack integration not configured for HIPAA)
- PHI in agent-typed free-text fields synced to a CRM without its own BAA
- Recording transcripts processed by third-party AI providers if the vendor doesn't have a sub-BAA in place
- Test environments and sandboxes (these are usually outside BAA scope unless explicitly extended)
- Voicemail transcription using consumer-grade voice models (verify vendor's transcription provider)
Healthcare buyers commonly miss the transcription provider question. If the vendor uses a sub-processor for speech-to-text and that sub-processor isn't HIPAA-covered, transcripts can leak PHI to a service outside the BAA. Ask in RFP: "List all sub-processors handling voice data, and confirm each has a BAA in place with your organization."
Vendors with healthcare-specific configurations
Five vendors publish a healthcare-vertical SKU or configuration in 2026:
- NICE CXone for Healthcare — pre-configured routing for patient access, claims, member services
- Genesys Cloud CX Healthcare — partner program with healthcare CRM connectors
- Talkdesk Healthcare Industry Cloud — listed at $225/seat/mo with healthcare workflows
- Salesforce Health Cloud + Service Cloud Voice — full healthcare CRM with native voice
- Amazon Connect for Healthcare — AWS reference architecture for patient access lines
These cost 15-30% more than baseline tiers but ship the patient-access call flows, prior authorization scripts and HEDIS-friendly reporting templates out of the box.
Recording, retention and PHI redaction
HIPAA does not specify retention duration — state laws do. California requires 7 years for medical records; New York 6 years. Most healthcare contact centers retain recordings for 7-10 years to cover both HIPAA audit needs and state regulations.
Modern CCaaS vendors offer:
- Pause-and-resume recording during PHI/card-data segments (table-stakes)
- Automated PHI redaction in transcripts via NLP (Five9, NICE, Genesys, Talkdesk, Amazon Connect)
- Tiered storage — hot (90 days), cool (1-3 years), cold (3-7 years) for cost optimization
- Recording legal hold for litigation discovery
- Immutable audit log of who accessed recordings
When recording compliance is critical, NICE, Genesys, Verint and Calabrio lead on QM/recording features. Amazon Connect handles recording at the underlying Amazon S3 layer — flexible but requires custom retention policy implementation.
Common HIPAA implementation mistakes
- Skipping the sub-processor inventory. Vendor signs BAA, but the speech-to-text or sentiment analysis sub-processor doesn't. PHI leaks to an unprotected service.
- Recording the wrong queue. A queue meant for non-PHI billing inquiries records a patient's mental health discussion. Solution: queue-level recording policy, not blanket.
- Free-text agent notes. Agent types diagnosis details into a CRM field synced to a non-HIPAA-covered analytics tool. Solution: HIPAA-covered CRM integration only.
- Test environments with production data. Sandboxes used for training contain real patient PHI. Solution: synthetic data only in non-prod.
- Voicemail transcripts to email. Vendor sends transcript email to agent inbox — Gmail/Outlook is outside the BAA unless Workspace/365 BAA is in place.
Pricing impact: HIPAA-eligible tiers
Most vendors offer BAA-signing as a standard contract amendment at no surcharge — but a few gate HIPAA capabilities behind higher tiers:
- Nextiva — BAA at Professional tier and above (not Essential)
- RingCentral RingCX — BAA at Standard tier and above
- Aircall — BAA on request, only for Professional/Custom (not Essentials)
Run the TCO calculator at your seat count to compare implementation cost across HIPAA-eligible vendors. The compliance filter on the vendor directory lets you check HIPAA + BAA in one click.
Bottom line
Thirteen of fifteen leading CCaaS vendors are HIPAA-eligible and sign enterprise BAAs by default in 2026. The selection criteria that actually differentiates: depth of recording controls, native PHI redaction in transcripts/AI, sub-processor BAA coverage, and healthcare-vertical configurations. For HIPAA-critical environments, NICE CXone, Genesys Cloud CX, Five9, Talkdesk Healthcare Industry Cloud, Amazon Connect (with proper AWS reference architecture) and Salesforce Service Cloud are the safest defaults.
Recommended vendors
RingCentral
★ 4.0 (1234)UCaaS-first vendor with a tightly integrated CCaaS suite (RingCX).
Genesys
★ 4.3 (1412)Enterprise CCaaS leader with Genesys Cloud CX and AI Experience platform.
Five9
★ 4.2 (987)Outbound-strong CCaaS with mature predictive dialer and AI agents.
Talkdesk
★ 4.3 (2456)Mid-market CCaaS with industry clouds and Talkdesk Copilot generative AI.
NICE
★ 4.4 (1685)NICE CXone — CCaaS + WEM leader with strong AI (Enlighten) and QA.
Vonage
★ 4.0 (412)UCaaS + CCaaS + CPaaS vendor (Ericsson) with developer-friendly APIs.
Dialpad
★ 4.4 (1893)AI-first UCaaS + CCaaS with real-time transcription and Dialpad Ai.
8x8
★ 4.0 (523)XCaaS — combined UCaaS + CCaaS with global PSTN and X-Series tiers.
Aircall
★ 4.5 (1247)SMB-focused cloud call center with deep CRM integrations.
Nextiva
★ 4.5 (3185)Unified Customer Experience Management (UCXM) — UCaaS + CCaaS + CRM.
Webex Contact Center
★ 4.2 (287)Cisco enterprise CCaaS — collaboration-first with deep PSTN and security.
Avaya
★ 3.9 (183)Legacy enterprise vendor moving to Avaya Experience Platform (AXP) cloud.
Amazon Connect
★ 4.1 (765)AWS-native, pay-per-use CCaaS with deep cloud and ML services.
Twilio Flex
★ 4.4 (634)Programmable, developer-first contact center built on Twilio CPaaS.
Salesforce Service Cloud
★ 4.4 (5612)CRM-native service platform with Service Cloud Voice CCaaS module.
Frequently asked questions
Thirteen of fifteen leading vendors sign BAAs by default in 2026: NICE CXone, Genesys Cloud CX, Five9, Talkdesk, Amazon Connect, RingCentral RingCX, Dialpad, Vonage Contact Center, 8x8, Nextiva, Webex Contact Center, Twilio Flex, Salesforce Service Cloud. Aircall offers BAA on request (not default). Avaya Infinity has partial coverage at GA.
No. The BAA covers PHI inside the vendor's HIPAA-eligible service boundary. Integrations with non-HIPAA tools, third-party transcription sub-processors without their own BAA, voicemail transcription emails sent to non-HIPAA email accounts, and test environments with production data are common gaps.
HIPAA does not specify retention duration — state laws do. California requires 7 years for medical records, New York 6 years. Most healthcare contact centers retain recordings for 7-10 years to satisfy state regulations and HIPAA audit needs.
For HIPAA-heavy use cases, yes. NICE CXone for Healthcare, Genesys Cloud CX Healthcare, Talkdesk Healthcare Industry Cloud, Salesforce Health Cloud + Service Cloud Voice and Amazon Connect for Healthcare ship patient-access call flows, prior-authorization scripts and HEDIS reporting out of the box at 15-30% above baseline tiers.
Skipping the sub-processor inventory. The vendor signs the BAA but their speech-to-text or sentiment analysis sub-processor does not. PHI leaks to an unprotected service. Ask in RFP for the complete sub-processor list with BAA confirmation for each.