3CX HIPAA Policy

Purpose of this Policy

  1. This HIPAA Policy clarifies the extent to which the Health Insurance Portability and Accountability Act of 1996 (HIPAA) applies to the services offered by 3CX and sets out the responsibilities of customers who may process Protected Health Information (PHI) through the 3CX communication platform.
  2. This Policy is intended to be read together with:
  1. the 3CX Privacy Policy
  2. the 3CX Terms & Conditions
  3. the 3CX Data Processing Addendum (DPA)
  4. the 3CX EULA
  5. the 3CX Fair Usage Policy
  6. the 3CX Privacy & Cookie Policy, and
  7. any other policy documents 3CX may publish from time to time.

3CX Is Not a HIPAA Business Associate by Default

  1. 3CX provides enterprise communications software and related services (PBX, messaging, call handling and integrations).
  2. 3CX does not create, receive, maintain, or transmit PHI on behalf of a covered entity for HIPAA-regulated purposes.

Accordingly:

  1. 3CX does not qualify as a “Business Associate” under HIPAA and does not offer HIPAA-compliant services by default.
  2. Use of 3CX services does not automatically meet HIPAA security, privacy, or administrative requirements.

Customer Responsibility for HIPAA Compliance

  1. If a customer is a Covered Entity or a Business Associate under HIPAA, customer is solely responsible for:
  1. Assessing whether 3CX’s features are appropriate for processing PHI.
  2. Implementing all necessary administrative, technical, and organisational safeguards.
  3. Ensuring that PHI is not transmitted or stored using features of the 3CX system that are not suitable for HIPAA environments (e.g., voicemail storage, call recordings, call transcription, third-party integrations).
  4. Preventing PHI from being shared through unencrypted channels or features not intended for secure medical communications.
  5. Ensuring that their personnel comply with applicable HIPAA requirements.
  1. Nothing in 3CX documentation should be interpreted as certifying that 3CX is a HIPAA-compliant communications system or that its services are designed to process PHI.

3CX Processing of Customer Data

  1. 3CX processes customer data in accordance with:
  1. applicable data protection laws (e.g., GDPR)
  2. the 3CX Privacy Policy, and
  3. the 3CX DPA

However:

  1. 3CX does not monitor, access, or inspect the content of calls, messages, or communications except as required by law, and does not assume any obligation to identify or protect PHI within customer communications.
  2. Customers remain responsible for configuring their systems to avoid transmitting PHI through 3CX where not appropriate.

Call Recordings, Transcriptions & Storage Considerations

  1. Certain optional 3CX features may involve storage or processing of voice or text data (e.g., call recordings, call queues, chat logs).
  2. 3CX does not represent that these features meet HIPAA’s stringent encryption and audit requirements.
  3. Customers handling PHI must:
  1. disable any features not appropriate for PHI;
  2. ensure encryption, access controls, retention settings, and audit procedures consistent with HIPAA;
  3. avoid transmitting PHI in any form unless they have independently assessed and validated their compliance obligations.

Law Enforcement & Government Requests (HIPAA Interaction)

  1. Where 3CX receives a request from law-enforcement authorities for access to customer data, 3CX will respond only:
  1. where required by applicable law
  2. where a request is properly served on the relevant 3CX entity
  3. and always in line with GDPR, contractual, and due-process obligations
  1. HIPAA does not impose on 3CX any independent obligation to disclose PHI
  2. Informal, unsupported, or improperly served requests—including those alleging healthcare-related fraud—will not be acted upon by 3CX.

No HIPAA Warranties

  1. To the maximum extent permitted by law:
  1. 3CX disclaims all warranties, express or implied, relating to HIPAA compliance or suitability for processing PHI.
  2. The Services are provided “as is” and are not certified for HIPAA-regulated use unless explicitly stated in a written agreement.

Optional HIPAA-Compliant Configurations

  1. If a customer requires HIPAA-aligned use of the 3CX system, the following apply:
  1. This must be addressed through a separate agreement with 3CX.
  2. A HIPAA-specific security assessment will be required.
  3. Additional controls, restrictions, or architectural limitations may apply.
  4. 3CX may refuse to support HIPAA-regulated use if the system architecture does not align with regulatory requirements.

Updates to this Policy

  1. 3CX may update this Policy to reflect changes in the Services, legal requirements, or industry practices. Updates will be published on the 3CX website.

See Also

Last Updated

This document was last updated 26 June 2026

https://www.3cx.com/company/hipaa-policy/