Cox Communications is a telecommunications and business connectivity provider that offers internet, WiFi, phone, managed network, cloud, and business communication services.

With Cox, businesses can purchase connectivity and communication services that support day-to-day operations, including healthcare office internet, business phone systems, and related network services.

Is Cox HIPAA compliant? Yes, Cox may be HIPAA compliant but only for certain services.

 

What changed this year?

In April 2026, Cox updated its public Business General Terms to state that covered entity customers “may obtain a business associate agreement (BAA) with Cox” for limited services.

It is a narrower form of HIPAA coverage. The update does not mean every Cox service is HIPAA compliant. Cox’s terms also state that customers should not provide PHI to Cox in connection with other services and that any BAA applies only to the services outlined in the BAA.

 

Will Cox sign a BAA?

Yes, Cox will sign a limited BAA, which can be reviewed in its Cox Business General Terms.

However, Cox’s BAA availability is limited to certain services and does not make all Cox products HIPAA compliant.

 

What does the Cox BAA cover?

The Cox BAA covers only specific services identified in Cox’s public Business General Terms. Cox states that its BAA is “available only for certain Services.”

Their BAA covers:

  • RingCentral
  • Call Recording, also known as Dubber
  • Cox Voicemail

This means Cox may support HIPAA regulated use for those services when the customer is eligible, accepts the Cox form BAA, configures the service appropriately, and follows HIPAA requirements.

 

What does the Cox BAA exclude?

Cox’s BAA does not apply to all Cox services. Cox states that any BAA with Cox “does not apply to any other Service” purchased from Cox.

Cox also states, “Customer should not provide any protected health information (PHI) to Cox” in connection with services outside the BAA’s scope.

Cox Business Internet, WiFi, general network services, and other Cox services should not be treated as HIPAA compliant merely because Cox offers a limited BAA for RingCentral, Call Recording, and Cox Voicemail. Healthcare organizations should confirm the exact service, BAA status, configuration requirements, and PHI use case before using Cox services in connection with protected health information.

 

Conclusion

Cox may be HIPAA compliant, but only for specific covered services under its limited BAA. Cox should not be treated as HIPAA compliant for all services, and healthcare organizations should verify that their Cox service is specifically covered before using it with PHI.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

FAQS

What is a business associate agreement?

A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.

 

What is HIPAA?

HIPAA sets national standards for protecting the privacy and security of certain health information.

HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.