Is OpenPhone (now Quo) HIPAA compliant?
Yes for calls if you are on the Business or Scale plan and sign the agreement — but text messaging is explicitly excluded from it, so anything you text a patient sits outside the agreement entirely.
Applies to Quo business phone and messaging, formerly OpenPhone. Last reviewed against Quo's own documentation. Next review December 13, 2026.
Reviewed by Carlos Mendez — IT Security Manager, regional healthcare network.
What you must do
- Be on the Business or Scale plan. Quo describes itself as HIPAA-ready on those plans only.
- Sign the agreement before any patient information passes through the account. Existing customers use the request form linked from Quo's HIPAA documentation; prospects go through sales.
- Treat SMS and MMS as outside the agreement. If you text patients anyway, Quo requires you to obtain patient authorization, limit content to the minimum necessary, document the decision and its risks in your policies, and implement your own safeguards.
- Get patient consent before sending non-secure texts and honour withdrawal of consent at any time.
- Comply with A2P 10DLC carrier rules as well: no promotional content, no solicitation, and no messages about prescription medications that are not sold over the counter.
- Before enabling AI features or call recording, tell patients when AI tools are used, notify them when calls are recorded as required by law, obtain authorization, limit what AI processes to the minimum necessary, and document the decision.
- Do not route patient information into third-party integrations — they are not covered services.
- Quo only logs users out after 15 days of inactivity, so enforce shorter timeouts yourself through device auto-lock and screen timeout.
Does OpenPhone (now Quo) sign a business associate agreement?
Yes. Quo offers one. Business or Scale plan Existing customers: submit the request form linked from Quo's HIPAA compliance documentation. Not yet a customer: contact Quo sales.
What this means in practice
This verdict has a sting in it. Quo, formerly OpenPhone, will sign for Business and Scale customers, and calls are covered. Text messaging is not. Quo states SMS and MMS are not covered services under its agreement because of technical limitations. Since texting patients is precisely why most small practices buy a product like this, the thing you wanted is the thing outside the agreement.
Quo does not forbid texting patients outright, but the conditions it attaches are real work: obtain the patient's authorization, keep content to the minimum necessary, document the decision and its risks in your written policies, honour withdrawal of consent at any time, and put your own safeguards around it. Carrier messaging rules stack on top, ruling out promotional content, solicitation and messages about prescription medications that are not sold over the counter.
Two settings deserve attention on day one. Quo only logs users out after fifteen days of inactivity, so shorter device auto-lock and screen timeouts are yours to enforce. And AI features and call recording require you to tell patients, obtain authorization and document the decision first.
How organizations get this wrong
The specific mistakes we see with OpenPhone (now Quo), not generic advice.
- Buying Quo specifically to text patients reminders and results, which is the one function excluded from the agreement.
- Texting a patient after a call without the authorization, minimum-necessary limits and documented policy decision Quo requires of you.
- Leaving a shared front-desk phone signed in, since Quo only logs users out after fifteen days of inactivity.
- Enabling AI note-taking or call recording without telling patients, obtaining authorization and recording why the decision was made.
What the agreement does not cover
- Text messaging. Quo states SMS/MMS is not a covered service under its agreement due to technical limitations.
- All third-party integrations and connected services, including CRM, email delivery, messaging platforms and analytics.
- Patient information once it leaves Quo through an integration — your organization takes sole responsibility.
- Patient information processed through AI features, where Quo states your organization assumes full responsibility.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
Messaging sits inside the covered-services list rather than outside it
Purpose-built for healthcare communication, where secure patient messaging is covered
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with OpenPhone (now Quo), someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Quo’s own published documentation, read on the date shown.
- HIPAA compliance — Quo (OpenPhone Technologies). No publication date given. Read July 29, 2026.
- Security and compliance — Quo (OpenPhone Technologies). No publication date given. Read July 29, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Quo’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.