Is RingCentral HIPAA Compliant? Clinic Phone Data
Yes, RingCentral makes a BAA available to paying covered entity customers for named services. What the BAA covers, and where clinic phone data still reaches ad platforms.
Yes, on paid plans with an executed Business Associate Agreement covering the specific services you use. RingCentral's own HIPAA documentation states that it makes a BAA available to paying covered entity customers and lists exactly which services that agreement covers, including RingEX, RingCX, RingCentral Fax, and Contact Center. The condition is scope: anything not on the list sits outside the agreement. For the marketing side of clinic phone data, where call outcomes get pushed to Google and Meta, Curve is the HIPAA-compliant tracking layer that keeps attribution working without the disclosure, with a signed BAA on every plan.
The direct answer, in more detail
RingCentral is a unified communications platform. Phone, video, messaging, fax, and contact center in one place. For a clinic that means it carries appointment calls, prescription questions, billing conversations, referral coordination, and voicemail from patients describing symptoms in detail. That is protected health information travelling through a vendor's infrastructure, which makes RingCentral a business associate the moment you use it for patient communication.
RingCentral acknowledges this directly. Its HIPAA document, updated March 2026, states that RingCentral does not require customers to provide PHI in order to deliver its services, that customers may nonetheless use its products to process PHI, and that covered entities doing so may consider RingCentral a business associate. It then states that RingCentral makes a BAA available to paying covered entity customers, and that the same BAA requirements are passed down to its own subcontractors who may process PHI on its behalf.
On assurance, RingCentral reports HITRUST CSF Certified status for RingEX, RingCX, and the RingCentral App, and an annual third-party SOC 2 audit incorporating HIPAA Security Rule controls for RingEX and RingCX. HITRUST is the framework most healthcare security teams actually recognize, so that is a substantive signal rather than a marketing badge.
The word doing the most work in all of this is "paying." A free or trial account is not covered. Neither is a service that falls outside the named list.
What the BAA covers, and what it does not
RingCentral publishes its covered service list rather than leaving you to guess, which is more transparency than most vendors offer. The services named as covered by the RingCentral BAA include RingCentral Fax, RingEX, RingCX, RingCentral Contact Center, RingCentral Engage Digital with third party channel communications excluded, a set of AI products including AI Conversation Expert, AI Quality Management, AIR Pro, AI Receptionist, AI Supervisor Assist, and AI Agent Assist, and the Customer Engagement Bundle. Third party products are covered unless their own terms or specific data protection terms say otherwise.
Two things follow from reading that carefully.
First, the exclusion inside Engage Digital matters. Third party channel communications are carved out, which is the sensible position for a vendor that cannot control what a social platform or messaging network does with a conversation once it crosses onto that network. If your clinic answers patient questions through a third party channel, that conversation is not inside the agreement.
Second, the third party products clause means the boundary can move without you noticing. A marketplace app installed by an office manager to sync calls into a scheduling tool may carry its own terms that place it outside the BAA. The vendor did nothing wrong. The scope simply ends where its list ends.
What the BAA never covers is anywhere you send the data next. That is the part that produces complaints.
Where RingCentral is genuinely fine
Under an executed BAA, ordinary clinical communication is exactly the use case RingCentral has built for. Patient calls, secure internal messaging between staff, fax of records to a referring provider, contact center queues handling appointment requests, voicemail transcription of a patient describing why they called. All of that is inside the boundary and covered.
The AI features deserve a specific mention because clinics tend to assume they are the risky part. Several of them are explicitly named in RingCentral's covered list, which means using an AI receptionist or AI quality management on calls containing PHI is contemplated by the agreement rather than a gray area. Confirm the specific product name against the list in your executed copy, because vendors ship AI capabilities faster than they revise scope documents.
Where clinics get into trouble is not clinical use. It is marketing use.
Where the ad tracking problem shows up
Phone conversions are the most valuable signal a clinic has and the most awkward to measure. The click happens online, the conversion happens in conversation, and the two only connect if something carries the identity across.
The common solutions all create the same exposure. Dynamic number insertion places a tracking number on a landing page so the call ties back to a campaign. Call outcome data gets pushed into Google Ads as an offline conversion so smart bidding learns from booked appointments. Contact center dispositions get exported into a reporting stack that also feeds ad audiences.
Look at what actually travels in that last case. A conversion tied to a Google click identifier, which is tied to a browsing session, which is tied to a person. It arrives labeled with a conversion action name, and healthcare conversion action names are almost always the service line, because that is how marketers name things. What the ad platform receives is: this identifiable click belongs to someone who called about this treatment. Meta and Google do not sign BAAs for their advertising products, and they are not going to.
That disclosure is the theory behind the healthcare pixel litigation that has produced more than $100 million in cumulative settlements, with Advocate Aurora settling at roughly $12.225 million. The theory never required a diagnosis to be transmitted. It required an identifiable person's health interest to be disclosed to a third party who had signed nothing.
The landing page compounds it. A page carrying a tracking number usually also carries a raw Meta Pixel or an untamed Google tag, and those scripts ship the page URL, which typically names the procedure, directly from the browser. Multi-location groups have this problem multiplied by every location page. Our piece on attribution tracking across multiple practices covers how that scales badly.
The architecture that works
Separate three jobs that clinics usually collapse into one pipe.
- Carry the conversation under a BAA. RingCentral holds the call, the recording, the transcript, and the disposition. This is where the clinical detail lives and where it stays.
- Reduce the outcome to a neutral signal. Before anything leaves your controlled environment, a rich disposition collapses into a conversion event an ad platform can optimize on without learning anything clinical. Not "consultation booked for a named procedure" but a neutral event plus a matching key.
- Forward that signal server-side through a system that signed a BAA with you. Not through a direct vendor-to-ad-platform connection whose payload you cannot inspect.
Step two is the step everyone skips, because native integrations are designed to send more rather than less. Richness sells the integration. In healthcare, richness is the liability.
How Curve handles clinic phone data
Curve is HIPAA-compliant ad tracking, attribution, and analytics built for healthcare. It sits between your systems and the ad platforms so decisions get made before data leaves.
On the web side, the Curve tracking script installs in place of the Meta Pixel and Google tag. Events go to Curve's US-hosted infrastructure rather than straight to ad platforms. From there:
- Per-destination field mapping controls what forwards. Only fields you explicitly map reach a given destination, configured separately for each one. The default is that nothing goes, so page URLs naming a procedure and call dispositions stay behind unless mapped deliberately.
- Identifiers are hashed. Email, phone, and name are SHA-256 hashed to each platform's conversion API requirements before forwarding.
- Neutral event aliases replace descriptive names. The ad platform interface shows a generic conversion label, so the service line never appears in a reporting view that agency staff and platform reps can open.
- PHI-pattern detection monitors payloads. Curve flags PHI-shaped values including SSNs, MRN-style identifiers, dates, and long numeric sequences. It is a monitoring layer that tells you when something upstream changed. The protection is the field mapping plus hashing.
- Bridge tokens preserve attribution across handoffs. When a patient clicks from your site into a separate booking or intake tool, attribution normally breaks at the exact moment it becomes valuable.
For the phone leg specifically, call outcomes reach Curve through incoming webhooks or offline conversion uploads rather than being piped directly from a communications platform to an ad account. Webhook matching works on email, click ID, or bridge token, and incoming data cannot override protected core attribution and contact fields. Offline uploads take bulk CRM or EHR outcomes and match them on click ID, which is how an appointment that books three weeks after the first call still credits the campaign that produced it.
Clean conversions forward server-side to Meta CAPI, Google Ads Enhanced Conversions, TikTok Events API, Microsoft, and LinkedIn. Because the path is server-side, ad blockers and browser tracking prevention do not erode it, which usually improves measured conversion volume. Every Curve plan includes a signed BAA. The full setup is covered in our guide to HIPAA-compliant conversion tracking across Google, Meta, and Microsoft.
What to check in your own deployment
- Confirm the BAA is executed, not merely requested. Ask for the countersigned copy and its effective date, and confirm the account is a paying account.
- Match the covered service list against what you actually use. Read your executed agreement's list rather than a web page, and flag anything you use that is missing from it.
- Audit marketplace and third party apps. Anything installed by a local office may carry its own terms and sit outside the agreement.
- Read your conversion action names. If a conversion in Google Ads is named after a procedure, rename it. Names travel into reports, audiences, and shared accounts.
- Check who can play recordings and read transcripts. Agency logins into a call platform are a disclosure surface the BAA does not address.
- Scan the landing pages carrying tracking numbers. Open the network tab and read what leaves during a normal visit, or run our free compliance scanner for a first pass.
- Set retention deliberately. Recordings kept indefinitely accumulate liability long after their attribution value expires.
Frequently asked questions
Does RingCentral sign a BAA?
Yes. RingCentral states that it makes a BAA available to paying covered entity customers and that it passes the same requirements down to subcontractors who process PHI on its behalf. Request it through your account representative and keep the countersigned copy.
Which RingCentral products does the BAA cover?
RingCentral publishes a covered service list that includes RingCentral Fax, RingEX, RingCX, Contact Center, Engage Digital with third party channel communications excluded, several named AI products, and the Customer Engagement Bundle. Third party products are covered unless their own terms say otherwise. Verify the list in your executed agreement, since scope documents get revised.
Are the AI features safe to use on patient calls?
Several AI products appear by name in RingCentral's covered list, so their use with PHI is contemplated by the agreement rather than an exception to it. Confirm the exact product name against your executed copy before enabling anything new, and ask separately whether transcripts are used to train models beyond your own account.
Is a free or trial RingCentral account covered?
No. The BAA is described as available to paying covered entity customers. A trial or free tier used for patient communication is uncovered, which is a common and easily avoided mistake in newly opened locations.
Can we push call outcomes into Google Ads if we have the BAA?
The BAA with your communications vendor does not extend to Google. What matters is whether the payload reaching Google is identifiable and health-revealing. Send a neutral conversion signal with a hashed matching key through a path you control, and keep the disposition detail inside your BAA-covered systems.
Does HITRUST certification make us compliant?
It makes the vendor's security posture credible. It does not create the contractual relationship HIPAA requires, and it says nothing about your configuration. Certification plus an executed BAA plus a disciplined deployment is the combination that holds up.
Where to start
RingCentral is one of the few pieces of a clinic stack where the compliance answer is genuinely straightforward. Pay for it, execute the BAA, check your services against the covered list, and use it for patient communication with reasonable confidence. Confirm the current list directly with RingCentral before you rely on it, because scope documents change more often than contracts get reread.
The risk sits one step downstream, in the connections that carry call outcomes into advertising platforms that never signed anything. Curve closes that leg: server-side collection, per-destination field mapping, SHA-256 hashed identifiers, neutral event aliases, PHI-pattern monitoring, webhook and offline-upload matching for phone conversions, and bridge-token attribution across booking handoffs, with a signed BAA included on every plan. Run the free compliance scanner against a location landing page to see what is leaving today, or visit curvecompliance.com to work through the architecture. If automation tools are stitching your phone data to other systems, our verdict on whether Zapier is HIPAA compliant covers that link in the chain.
Reviewed August 2026. Vendor BAA policies change. Confirm current terms with the vendor.
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit