Is OpenPhone HIPAA compliant?

Business phone · vendor site ↗

BAA on select plansPHI with conditionsSOC 2 Type II
Will OpenPhone sign a HIPAA BAA?
Sometimes — OpenPhone signs a HIPAA BAA only on specific plans or add-ons.
OpenPhone (now branded Quo) offers a BAA only to customers on the Business or Scale plans, requested via a form. Once signed, the organization can use the service to communicate with patients in compliance with HIPAA.
PHI eligibility
PHI in calls, voicemails and messages may be handled only under a signed BAA on the Business or Scale plan; data that remains within the platform's infrastructure is stored encrypted.
SOC 2
SOC 2 Type II
Trust center
Sub-processors
Notes
OpenPhone rebranded to 'Quo' in 2025; old openphone.com/support URLs 301-redirect to quo.com. BAA gated to Business/Scale plans.
Last verified 2026-05-31confidence: high· Vendor terms change — confirm directly with OpenPhone before storing PHI.

Get notified when this changes

We track OpenPhone's BAA and HIPAA status. Leave your email and we'll send one note if the verdict on this page changes.

One email per change. No newsletter, no selling your address.

How to request and sign a BAA with OpenPhone

Sometimes — OpenPhone signs a HIPAA BAA only on specific plans or add-ons.

Request routeBy request — via trust center or support
  1. 1
    Get on a qualifying plan
    OpenPhone (now branded Quo) offers a BAA only to customers on the Business or Scale plans, requested via a form. Once signed, the organization can use the service to communicate with patients in compliance with HIPAA.
  2. 2
    Request the Business Associate Agreement
    OpenPhone provides the BAA on request. Open a request through OpenPhone's trust center and ask for the current Business Associate Agreement covering your plan.
  3. 3
    Confirm what PHI is allowed before you store any
    PHI in calls, voicemails and messages may be handled only under a signed BAA on the Business or Scale plan; data that remains within the platform's infrastructure is stored encrypted. Match your configuration to this scope before putting protected health information into OpenPhone.
Last verified 2026-05-31 · Plan tiers and BAA terms change often — confirm the current process directly with OpenPhone before you rely on it. This is cited public information, not legal advice.

Frequently asked questions

Does OpenPhone sign a HIPAA Business Associate Agreement (BAA)?
Sometimes — OpenPhone signs a HIPAA BAA only on specific plans or add-ons. OpenPhone (now branded Quo) offers a BAA only to customers on the Business or Scale plans, requested via a form. Once signed, the organization can use the service to communicate with patients in compliance with HIPAA.
Is OpenPhone HIPAA compliant?
OpenPhone can be HIPAA-compliant only on the specific plans or add-ons where it will sign a Business Associate Agreement (BAA). PHI in calls, voicemails and messages may be handled only under a signed BAA on the Business or Scale plan; data that remains within the platform's infrastructure is stored encrypted.
Can you store PHI (protected health information) in OpenPhone?
PHI in calls, voicemails and messages may be handled only under a signed BAA on the Business or Scale plan; data that remains within the platform's infrastructure is stored encrypted.
Is OpenPhone SOC 2 certified?
OpenPhone reports a SOC 2 Type II attestation according to its public security documentation.
How do I request a HIPAA BAA from OpenPhone?
OpenPhone provides the BAA on request. Open a request through OpenPhone's trust center and ask for the current Business Associate Agreement covering your plan. Confirm current terms directly with OpenPhone before storing PHI.
What plan do I need to sign a BAA with OpenPhone?
OpenPhone (now branded Quo) offers a BAA only to customers on the Business or Scale plans, requested via a form. Once signed, the organization can use the service to communicate with patients in compliance with HIPAA.

Sources

https://support.quo.com/core-concepts/administration/security-and-compliance
Supports: BAA available on Business/Scale plans; SOC 2 Type IIdated: undated
This page is cited public information, not legal or compliance advice. A BAA's availability can depend on your specific plan, region, and contract. Always confirm current terms with OpenPhone before processing protected health information.

Check another vendor