There is no such thing as "HIPAA certified" software
This is worth stating plainly because vendor marketing regularly implies otherwise: HIPAA does not have a formal third-party certification program that a software vendor can complete and display as a badge, the way SOC 2 or ISO 27001 audits work. HIPAA compliance is a legal and contractual obligation that applies to covered entities and their business associates, governed by a Business Associate Agreement (BAA) and the entity’s own risk analysis — not a certificate a platform can hold on your behalf. Any vendor claiming "HIPAA certification" as a product feature should be questioned on that specific claim.
What actually matters: the BAA and who is responsible for what
A covered entity working with any vendor that touches protected health information (PHI) needs a signed Business Associate Agreement defining each party’s responsibilities. The deployment model changes what falls on each side of that line. In a cloud-only SaaS relationship, the vendor’s operational environment — physical security, access controls, incident response for the underlying infrastructure — is part of what the covered entity has to trust and evidence through the vendor’s own compliance program. In a private-cloud deployment, more of that operational responsibility (and audit evidence) sits directly with the covered entity’s own team, inside infrastructure they already operate and can inspect.
Data residency and audit control shift with deployment model
Two questions a healthcare compliance officer typically needs to answer are: where does PHI physically reside, and can we produce a complete, tamper-evident audit trail on demand? A private-cloud deployment answers both more directly — PHI resides inside infrastructure the covered entity controls, and audit evidence does not depend on requesting logs from a third-party operator. This does not make private cloud automatically HIPAA-compliant; it changes who has direct control over the answers to those questions.
What Voz360 provides as controls, not as a certification
Voz360 provides technical controls relevant to a HIPAA governance program: per-tenant AES-256-GCM encryption of sensitive content (recording and voicemail bodies) under a Data Encryption Key wrapped by a platform Key Encryption Key, a SHA-256 hash-chained audit log covering privileged actions, RBAC, and a genuine private-cloud deployment option with the same isolation architecture as managed SaaS. None of this constitutes a HIPAA certification claim — it is the control-level foundation a covered entity’s own risk analysis and BAA process would evaluate.
What self-hosting does not change
Self-hosting does not remove the covered entity’s obligation to conduct its own risk analysis, train staff, define minimum-necessary access policies, or manage its own incident-response process. A private-cloud contact-center platform is infrastructure inside a larger compliance program, not a substitute for one.
Can the vendor tell you — in one sentence — which of their AI capabilities are rule-based, which are generative, and which are still roadmap?