{"id":7520,"plugin_id":"Plugin_c266c85897248191be15eb07c415f89e","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T22:50:44.795Z","digest":"c53083d82351f07eaec3d967e6ef283ebd6139acd3715266c460d660b2a58399","against":null,"payload":{"description":"Configure Twilio accounts for HIPAA compliance. Covers BAA requirements, HIPAA Project designation (self-service and support), eligible services list, per-product requirements (Voice, SMS, ConversationRelay, Conversation Intelligence, Flex, Verify), message redaction, and what is NOT eligible. Use this skill when developers are building healthcare workflows on Twilio.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":245}],"name":"twilio-security-compliance-hipaa","skill_md_contents":"---\nname: twilio-security-compliance-hipaa\ndescription: >\n  Configure Twilio accounts for HIPAA compliance. Covers BAA requirements,\n  HIPAA Project designation (self-service and support), eligible services\n  list, per-product requirements (Voice, SMS, ConversationRelay, Conversation Intelligence,\n  Flex, Verify), message redaction, and what is NOT eligible. Use this\n  skill when developers are building healthcare workflows on Twilio.\n---\n\n## Overview\n\nHIPAA compliance on Twilio is a **shared responsibility** — Twilio provides eligible services and configuration tools, but your application must architect correctly. Getting this wrong means PHI exposure and compliance violations.\n\n**Sequence:** Execute BAA → Designate HIPAA Project(s) → Use only eligible services → Follow per-product requirements\n\n---\n\n## Step 1: Execute a BAA\n\n- Contact your Twilio Account Representative to execute a Business Associate Addendum\n- Purchase a **Twilio Editions package** that includes HIPAA Accounts\n- BAA is required before any PHI touches Twilio infrastructure\n\n---\n\n## Step 2: Designate HIPAA Project(s)\n\n### Self-Service (BAA initiated after June 6, 2024)\n\n1. Create an Organization in Twilio Console\n2. Link accounts/projects/subaccounts to the Organization\n3. Console → Twilio Admin → Accounts → Select account → Enable HIPAA flag\n4. Save\n\n### Support Ticket (BAA initiated before June 6, 2024)\n\nOpen a Support ticket through Console to request HIPAA designation for specific accounts/projects/subaccounts.\n\n### Subaccount Behavior\n\n- **Existing subaccounts are NOT auto-designated** — Must be individually flagged\n- **New subaccounts created AFTER designation DO auto-inherit** HIPAA status\n- Verify each subaccount's HIPAA flag — don't assume inheritance\n\n### What Changes When HIPAA Is Enabled\n\n- Console auto-logoff after 15 minutes of inactivity\n- Account exempt from certain content moderation (but still subject to carrier complaint review)\n- No PHI in support tickets — use SIDs (CallSid, MessageSid) instead of phone numbers\n\n---\n\n## HIPAA Eligible Services\n\n### Eligible (use these for PHI workflows)\n\n| Category | Services |\n|----------|----------|\n| **Voice** | Programmable Voice, Recordings*, Transcription*, Media Streams*, ConversationRelay*, Conversational Intelligence for Voice*, SIP Interface*, Elastic SIP Trunking*, Voice Insights, AMD, `<Pay>`, Conference, Coaching, Transfers |\n| **SMS** | Programmable SMS, MMS, Long Codes, Toll-Free, Short Codes, Messaging Services (opt-out, fallback, geomatch, sticky sender, scheduling, link shortening) |\n| **Identity** | Verify (SMS + Voice + Push only), Lookup |\n| **Conversations** | Chat, SMS, MMS, Group Texting (NOT WhatsApp) |\n| **Flex** | Voice, SMS, Chat, Conversations, Webchat 3.x.x*, TaskRouter, Proxy, Flex Insights* |\n| **Segment** | Connections (Sources, Destinations*, Functions*), Reverse ETL*, Unify, Engage Foundations*, Protocols, Privacy Portal* |\n| **Runtime** | Studio*, Functions, Debugger, API Explorer, Sync, Private Assets*, TwiML Bin* |\n| **Data** | Event Streams |\n\n*Items marked with * require additional configuration per \"Architecting for HIPAA on Twilio\" guidance.*\n\n### NOT Eligible (do NOT use for PHI)\n\n- **WhatsApp** — Meta does not offer a BAA\n- **SendGrid Email** (including Email in Flex and Verify Email channel)\n- **AI Assistants** (including Voice for AI Assistants)\n- **Verify Fraud Guard**\n- **Conversational Intelligence for Conversations** (only Voice channel is eligible)\n- **Agent Copilot**, **Unified Profiles** in Flex\n- **Engage Premier**, **Generative Audiences**, **Campaigns**\n- **Twilio Marketplace add-ons** — even with third-party BAA\n- **Autopilot**\n- **Flex Webchat 2.x.x** (must migrate to 3.x.x)\n\n**Geographic restriction:** Only US area codes for Voice and SMS HIPAA traffic.\n\n---\n\n## Per-Product Requirements\n\n### Voice & Recordings\n\n- **HTTP auth required for recording URLs** — Enable in Console → Voice Settings. Recording URLs are public by default.\n- **Voice Recording Encryption recommended** — Encrypts with your public key before cloud storage\n- **ConversationRelay:** Your AI Provider must have their own BAA. Cannot use for clinical/medical decision-making.\n- **Conversation Intelligence for Voice:** Only Azure OpenAI for generative operators. No PHI in operator prompts. Data use auto-disabled for HIPAA accounts. PII Redaction recommended (auto-redacts 21 PHI field types).\n\n### SMS & MMS\n\n- **HTTP auth required for MMS Media URLs** — Enable in Console → Messaging → Settings → General\n- **Message Redaction recommended** — Redacts message bodies and phone numbers from Console/API/support\n- **No PHI in Message Tags** — custom attributes in Message Tagging must not contain PHI\n- **Message Redaction prerequisites:**\n  1. Disable Sticky Sender and Fallback to Long Code on Messaging Services\n  2. Contact Support to disable built-in STOP filtering (then implement custom STOP handling)\n  3. Set all webhooks to POST (GET logs params for 7 days, defeating redaction)\n  4. Incompatible with Studio, Flex, and Conversations\n\n### Verify\n\n- **Only SMS, Voice, and Push channels** — Email channel is NOT eligible\n- **Fraud Guard is NOT eligible** — do not enable for HIPAA workflows\n\n### Flex\n\n- **Flex Insights:** Twilio auto-redacts PII from TaskRouter attributes (names, phone, email). Visual waveform and speech metrics disabled.\n- **Customer must:** Ensure no PHI in preserved Attribute fields, Comments, or Assessments. Implement session timeout (Flex has no built-in timeout). Secure Flex Plugins for HIPAA.\n- **No WhatsApp, Facebook Messenger, or SendGrid Email** in Flex HIPAA workflows\n\n### Event Streams\n\n- Customer responsible for HIPAA-compliant sink configuration (e.g., AWS Kinesis requires Amazon's HIPAA architecture)\n- Non-eligible product event types must not process PHI\n\n---\n\n## CANNOT\n\n- **Cannot use WhatsApp for HIPAA workflows** — Meta does not offer a BAA. Applies to all Twilio products (Conversations, Flex, Frontline).\n- **Cannot use SendGrid Email** — Not HIPAA eligible in any context (Verify, Flex, standalone).\n- **Cannot use Verify Fraud Guard or Email channel** — Not eligible. Only SMS, Voice, Push.\n- **Cannot use AI Assistants** — Even with ConversationRelay, AI Assistants integration is not eligible.\n- **Cannot use non-US area codes** — Voice and SMS HIPAA traffic limited to US area codes.\n- **Cannot put PHI in support tickets** — Use SIDs for troubleshooting. Use Console chat, email, or Support Center.\n- **Cannot assume subaccount HIPAA inheritance** — Existing subaccounts must be individually flagged.\n- **Cannot use GET webhooks with Message Redaction** — GET parameters are logged for 7 days.\n- **Cannot use Marketplace add-ons** — Even with a third-party BAA, Marketplace is not eligible.\n- **Cannot use Conversation Intelligence for Conversations** — Only Voice channel is HIPAA eligible.\n\n---\n\n## Next Steps\n\n- **Authentication setup:** `twilio-security-api-auth`\n- **Account structure for HIPAA isolation:** `twilio-account-setup`\n- **Credential security:** `twilio-security-hardening`\n- **Traffic compliance (TCPA, GDPR, PCI):** `twilio-compliance-traffic`\n\n**Official docs:** [HIPAA Eligible Services (PDF)](https://www.twilio.com/content/dam/twilio-com/global/en/other/hipaa/pdf/HIPAA-Eligible-Services.pdf) | [Architecting for HIPAA (PDF)](https://www.twilio.com/content/dam/twilio-com/global/en/other/hipaa/pdf/Architecting-for-HIPAA.pdf) | [HIPAA account flag](https://www.twilio.com/docs/iam/organizations#turn-on-hipaa-and-eligible-accounts) | [Message Redaction](https://www.twilio.com/docs/messaging/guides/privacy-message-redaction)\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}