Direct answer
Every claim is sourced below
Healthcare UCaaS deployments must meet HIPAA Security and Privacy Rules for any voice, video, chat, or voicemail that touches electronic protected health information (ePHI) — including encryption in transit and at rest, access controls, audit logs, and a signed Business Associate Agreement with the provider [1][2]. HITECH breach notification, state privacy laws, and 42 CFR Part 2 for behavioral health may stack on top [1].