- Voicemail-to-email carrying PHI, tax data, or client confidences.
- Call recordings stored without clear access controls.
- No reliable audit trail.
- No MFA for administrators or remote users.
- Employees forwarding business calls to personal cell phones.
- A carrier outage or failed PBX taking down the front desk.
- “Hey Margaret!” becoming the unofficial incident-response plan.
Your phone system may be one of the least examined parts of your security environment, and one of the easiest places for sensitive information to escape.
For law firms, medical practices, accounting firms, tax preparers, financial advisors, and other businesses with confidentiality or regulatory obligations, legacy telephony is no longer just old technology. It may be a compliance, security, and business continuity risk.
The Phone System Has Become a Data System
Voice conversations are data.
Voicemails are data. Call recordings are data. Transcripts, caller identification records, call logs, and shared voicemail inboxes are data.
The FTC Safeguards Rule even defines an information system broadly enough to include telephone switching and private branch exchange systems that contain customer information or connect to systems containing it.
That matters because your phone platform may now touch:
- Protected health information.
- Social Security numbers and tax records.
- Bank and investment details.
- Client legal strategy and confidential communications.
- Payment information.
- Insurance and identification data.
If your business stores or transmits that information through a phone system, the system belongs in your risk assessment.
Not someday. Now.
How Legacy Telephony Creates Modern Compliance Gaps
Older PBX systems and consumer-grade VoIP platforms often worked well when everyone sat in the same office and phones only made calls.
That is not how your business operates today.
Your staff work from home. Voicemail is emailed to mobile devices. Calls are recorded for training or quality control. Vendors provide remote support. Customers expect calls to route across departments, locations, and time zones.
The technology evolved. The controls often did not.
1. Voicemail-to-email can spread sensitive information
A voicemail may contain a patient’s condition, a client’s legal matter, or a taxpayer’s financial details. When that message is automatically forwarded to an inbox, it may be copied to:
- Personal phones.
- Unmanaged email accounts.
- Consumer cloud storage.
- Shared mailboxes with excessive permissions.
- Devices that are not encrypted or centrally managed.
For medical practices, voicemail containing PHI requires careful review of HIPAA safeguards, vendor responsibilities, access controls, and whether a Business Associate Agreement is appropriate.
For accounting firms and tax preparers covered by GLBA, customer information must be protected through a written information security program that addresses access, encryption, monitoring, vendor oversight, and secure disposal.
2. Call recordings may have weak security and retention controls
Recording calls can be useful. It can also create a permanent library of sensitive conversations.
Ask yourself:
- Who can listen to recordings?
- Is access role-based?
- Is MFA enforced?
- Are recordings encrypted at rest and in transit?
- Is access logged?
- How long are recordings retained?
- Are they deleted securely?
- Can former employees still access them?
- Does the vendor notify you promptly about an incident?
If the answer is “I think so,” that is not an audit trail.
3. Remote forwarding creates shadow communications
“I’m working from home, so I’ll just forward the office line to my cell.”
Convenient. Familiar. Risky.
Personal phones may not have mobile device management, encryption enforcement, screen-lock policies, remote-wipe capability, or business retention controls. Callers may leave confidential information on a device your IT team cannot secure or investigate.
A modern business phone system should support secure mobile applications, controlled call routing, identity-based access, and administrative visibility without forcing employees to improvise.
4. A phone outage can become an operational outage
Legacy systems often depend on a single on-site PBX, one carrier connection, or hardware that is difficult to replace.
When it fails:
- Patients may not reach the practice.
- Clients may assume the law firm is unavailable.
- Tax deadlines may be missed.
- Emergency calls may not route properly.
- Staff may lose access to voicemail and call history.
- Your business continuity plan may stop at “call the phone guy.”
Business continuity is not complete if your customers cannot reach you.

A Real-World Scenario: “Hey Margaret, Can You Fix the Phones?”
Imagine a 35-person law firm with an aging PBX.
A partner leaves a voicemail containing confidential settlement details. The system forwards it to a shared email inbox. Several employees can access that inbox, but nobody knows whether access is logged. A remote employee forwards the main line to a personal cell phone. The phone carrier experiences an outage, and the firm’s clients hear a busy signal for two hours.
Then someone asks:
“Can we prove who accessed the voicemail, where it was stored, and when it was deleted?”
“Hey Margaret” may know how to reboot the PBX.
That does not answer the question.
This is the difference between basic IT support and a managed IT and cybersecurity program. The goal is not only to make the phone ring. It is to design a communication environment that is secure, resilient, documented, and aligned with the way your business operates.
Pros and Cons of Keeping the Old Phone System
Replacing telephony requires planning, budgeting, and change management. Keeping the old system may appear cheaper, but the decision deserves an honest comparison.
Potential advantages
- Familiar hardware and workflows.
- No immediate migration project.
- Existing desk phones may continue working.
- Staff training requirements are limited.
- Short-term costs may appear predictable.
Potential disadvantages
- Unsupported hardware may be difficult to repair.
- Security updates may be unavailable.
- MFA, encryption, and audit logging may be limited.
- Remote work often depends on insecure forwarding.
- Call routing may be difficult to manage.
- Recordings and voicemails may lack retention controls.
- A single failure can disrupt the entire office.
- Vendor support may depend on one individual. The classic “I got a guy” arrangement.
The old system may still be functional. Functional is not the same as secure, supportable, or defensible.
What a 2026-Ready Business Phone System Should Include
A cloud-based VoIP or business phone system is not automatically compliant. Cloud services still require configuration, vendor review, policies, and ongoing management.
Look for a platform and implementation that support:
-
MFA and strong identity controls
Protect administrator portals, voicemail access, mobile applications, recording libraries, and integrations. -
Encryption
Confirm how voice traffic, voicemail, recordings, transcripts, and account data are protected in transit and at rest. -
Role-based access
Receptionists, clinicians, attorneys, accountants, and administrators should not automatically have access to the same data. -
Audit logging
You should be able to determine who accessed a recording, changed a routing rule, modified a user, or downloaded a voicemail. -
Controlled call routing
Route calls to approved users, devices, departments, and locations without relying on personal numbers. -
Retention and secure disposal
Define how long voicemails and recordings are kept. Delete them according to documented business, legal, and regulatory requirements. -
Failover and continuity
Support alternate numbers, geographic redundancy, mobile applications, backup routing, and documented recovery procedures. -
Vendor oversight
Review security documentation, incident-notification terms, data-handling practices, and, when PHI is involved, whether appropriate contractual arrangements are available.
For covered financial institutions, the FTC Safeguards Rule also requires a written information security program, risk assessment, access controls, MFA, monitoring, service-provider oversight, employee training, and an incident response plan. The FTC’s guidance specifically notes that telephone switching systems may be part of the relevant information environment.
Treat Telephony Like Clinical Care, Not Like a Desk Accessory
A useful analogy is medical care.
You would not wait for a patient to collapse before checking vital signs. You would not prescribe treatment without understanding the patient’s history. You would not assume that one appointment solves every future risk.
Your phone environment deserves the same discipline:
- Assess how it is used.
- Identify what sensitive information it handles.
- Review who can access it.
- Test what happens during an outage.
- Document the controls.
- Reassess when your business changes.
That approach supports HIPAA compliance efforts, GLBA and FTC Safeguards Rule obligations, law firm cybersecurity, accounting firm IT, and practical business continuity.
A qualified managed service provider can help connect telephony with the rest of your environment: Microsoft 365, identity governance, endpoint protection, network security, backup, disaster recovery, and helpdesk support. That creates accountability instead of another isolated technology purchase.
See how A PC of Mind’s managed IT services and cybersecurity services can support a more secure technology foundation.
Where to Start
Your next step does not have to be a full phone replacement tomorrow. Start with a focused assessment:
- Inventory every phone platform, PBX, voicemail system, recording tool, and mobile application.
- Identify whether calls or voicemails contain PHI, NPI, financial information, or confidential client data.
- Document where recordings and voicemails are stored.
- Review MFA, encryption, access controls, and audit logging.
- Examine forwarding rules and personal-device usage.
- Test carrier failure, internet failure, and office closure scenarios.
- Review vendors and contracts.
- Create a prioritized modernization roadmap.
A broader IT assessment can help place telephony within your overall risk picture.
Important: HIPAA, GLBA, and FTC Safeguards Rule applicability depends on your organization, services, data, and business activities. Technology controls support compliance but do not replace advice from qualified legal or compliance professionals.
Final Word
Your phone system is part of your security perimeter.
If it stores sensitive information, connects to cloud services, routes remote employees, or keeps your firm available during an emergency, it deserves the same scrutiny as email, endpoints, and file storage.
The best business phone system for 2026 is not simply the one with the clearest audio or the lowest monthly price. It is the one that helps you protect confidential information, maintain reliable operations, produce meaningful evidence, and give your staff a secure way to communicate.
Do not wait for the PBX to fail, or for a regulator, insurer, client, or incident investigator to discover the gap first.
Modernize your telephony on your terms.