<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Tahir Almas</title>
    <description>The latest articles on DEV Community by Tahir Almas (@tahiralmas).</description>
    <link>https://dev.to/tahiralmas</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3911307%2F77d2f227-47d5-42ea-87e2-5d4abeb9b2cd.png</url>
      <title>DEV Community: Tahir Almas</title>
      <link>https://dev.to/tahiralmas</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/tahiralmas"/>
    <language>en</language>
    <item>
      <title>Your Upstream Carrier Just Became Your Problem: The FCC's Next Robocall Move</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Wed, 29 Jul 2026 06:58:48 +0000</pubDate>
      <link>https://dev.to/tahiralmas/your-upstream-carrier-just-became-your-problem-the-fccs-next-robocall-move-1o96</link>
      <guid>https://dev.to/tahiralmas/your-upstream-carrier-just-became-your-problem-the-fccs-next-robocall-move-1o96</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://www.ictbroadcast.com/fcc-upstream-provider-vetting-outbound-calling/" rel="noopener noreferrer"&gt;ictbroadcast.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The FCC's robocall strategy has quietly changed shape. Instead of chasing the people placing bad calls, it is putting pressure on the providers who carry them, and asking those providers to look at whoever handed them the traffic in the first place. If you run outbound campaigns on your own &lt;strong&gt;call center software&lt;/strong&gt;, that shift reaches you through your carrier, not through a new rule aimed at you.&lt;/p&gt;

&lt;p&gt;Reply comments on the numbering proceeding closed on 7 July 2026, so this is live policy rather than speculation. The direction is clear enough to plan around even before the final text lands.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the FCC is proposing
&lt;/h2&gt;

&lt;p&gt;The core idea is that a voice service provider should know the upstream providers it accepts traffic from, in a specific and documented way. The proposal spells out what that looks like: confirm the upstream provider has a filing in the Robocall Mitigation Database, actually read that filing and its mitigation plan for completeness, confirm the provider holds a Service Provider Code token where it claims full or partial STIR/SHAKEN implementation, and check whether the provider appears on certain national security or enforcement related lists.&lt;/p&gt;

&lt;p&gt;Read that list again and notice what it is not. It is not a technical standard. It is a due diligence obligation, closer to what a bank does before opening an account than anything in a SIP specification.&lt;/p&gt;

&lt;p&gt;Signing your own traffic was the old bar. Vetting who hands you traffic is the new one.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this reaches your call center software even though it targets carriers
&lt;/h2&gt;

&lt;p&gt;Most outbound teams read "provider obligation" and assume it is somebody else's paperwork. That assumption held for a few years. It is getting weaker.&lt;/p&gt;

&lt;p&gt;Carriers that are told to vet upstream sources will pass that scrutiny down, because the cheapest way to satisfy a regulator is to tighten who you accept. Wholesale voice is a chain, and every link that gets squeezed squeezes the next one. In practice that means the questions on your next carrier onboarding form get longer, and the tolerance for vague answers gets shorter.&lt;/p&gt;

&lt;p&gt;The other reason it reaches you is that the Commission has been willing to cut providers off entirely rather than fine them. Losing a route with no notice is an operational problem, not a legal one, and no compliance budget fixes a dialer that suddenly cannot complete calls. If your campaigns run through a single upstream, that is concentration risk you can measure today.&lt;/p&gt;

&lt;p&gt;Teams running a self-hosted stack have a real advantage here, because the call detail records and campaign logs sit on hardware you control. Producing six months of evidence is a query rather than a support ticket. That is not a small thing when someone asks you to prove what you sent and when.&lt;/p&gt;

&lt;h2&gt;
  
  
  The four checks, and the part people skip
&lt;/h2&gt;

&lt;p&gt;If you resell, aggregate, or hand traffic to anyone downstream of you, the four checks below are the ones the proposal describes. Even if you only buy termination and never sell it, running them on your own carrier is a reasonable way to judge whether that carrier is about to have a bad year.&lt;/p&gt;

&lt;p&gt;Four checks, four artefacts. The artefact is the half people forget.&lt;/p&gt;

&lt;p&gt;The part people skip is the evidence. Checking the Robocall Mitigation Database takes two minutes and leaves no trace unless you deliberately keep one. A dated screenshot and a three line review note, filed somewhere you can find it in eighteen months, is the difference between having done the work and being able to show it. I would treat that filing habit as the actual deliverable here.&lt;/p&gt;

&lt;p&gt;One honest caveat: none of this is a substitute for the consent and suppression work you already owe. Vetting your carrier does nothing for a campaign calling numbers it should not. Our &lt;a href="https://www.ictbroadcast.com/autodialer-laws-and-regulations-tcpa-compliant-auto-dialer/" rel="noopener noreferrer"&gt;guide to autodialer laws and regulations&lt;/a&gt; covers that side, and it has not become less important.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to do in the next month
&lt;/h2&gt;

&lt;p&gt;Start by writing down which upstream providers your traffic actually touches. A surprising number of operators cannot answer that quickly, especially where a reseller sits in the middle. You cannot vet a chain you have not drawn.&lt;/p&gt;

&lt;p&gt;Then check your own filing. If you appear in the Robocall Mitigation Database, reread what you filed. Plans written two or three years ago often describe a system that no longer matches how the business runs, and an out of date plan reads worse than a modest one that is accurate.&lt;/p&gt;

&lt;p&gt;After that, look at attestation levels on your own outbound. If your calls are going out with anything less than full attestation, find out why. Sometimes the answer is a number the carrier does not believe you own, which is fixable in an afternoon and quietly costs you answer rate every day it stays broken.&lt;/p&gt;

&lt;p&gt;Finally, add a second termination route if you only have one. Not because your current carrier is doing anything wrong, but because enforcement in this area is fast and does not care about your campaign calendar.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where this is heading
&lt;/h2&gt;

&lt;p&gt;My read is that STIR/SHAKEN has stopped being a caller ID feature and become the paperwork trail for an accountability regime. The signature was never the point on its own. The point is that a signature ties a call to a provider, and a provider to a filing, and a filing to a name somebody can act against.&lt;/p&gt;

&lt;p&gt;For legitimate outbound operations that is mostly good news, because the traffic it squeezes is the traffic that has been degrading answer rates for everyone. The cost is a bit more diligence and a lot more record keeping. That is a trade most serious teams should take, and the ones who set up the record keeping early will find the next rule change much less disruptive than the ones who wait for a carrier to demand it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does this apply to me if I am not a carrier?
&lt;/h3&gt;

&lt;p&gt;The obligations described in the proposal sit with voice service providers. If you only originate your own campaigns, you are not the direct target, but your carrier's new diligence will show up as tougher onboarding and faster disconnection for accounts that look risky.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the Robocall Mitigation Database in plain terms?
&lt;/h3&gt;

&lt;p&gt;It is the FCC's public register where providers state how far they have implemented caller ID authentication and describe the steps they take to prevent illegal robocalls on their networks. Anyone can look up an entry, which is what makes it usable as a vetting tool.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is a Service Provider Code token?
&lt;/h3&gt;

&lt;p&gt;It is the credential a provider needs in order to sign calls under STIR/SHAKEN. Claiming implementation without holding one is exactly the mismatch the FCC wants downstream providers to catch, which is why confirming the token appears as a separate check.&lt;/p&gt;

&lt;h3&gt;
  
  
  Will full attestation stop my calls being labelled as spam?
&lt;/h3&gt;

&lt;p&gt;Not by itself. Attestation tells the terminating carrier who vouched for the call, but analytics engines also weigh complaint rates, call duration patterns and how many numbers you rotate through. Good attestation with bad calling behaviour still gets labelled.&lt;/p&gt;

&lt;h3&gt;
  
  
  How long should I keep vetting records?
&lt;/h3&gt;

&lt;p&gt;Longer than feels necessary. Investigations look backwards, and the useful answer is usually about a relationship that ended a year ago. Keeping dated evidence for the life of the relationship plus a couple of years is a sane default.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictbroadcast.com/autodialer-laws-and-regulations-tcpa-compliant-auto-dialer/" rel="noopener noreferrer"&gt;Autodialer laws and regulations for TCPA compliant calling&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictbroadcast.com/country-wise-regulations-about-auto-dialers/" rel="noopener noreferrer"&gt;Country wise regulations about auto dialers&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictbroadcast.com/custom-caller-id-with-personalized-name/" rel="noopener noreferrer"&gt;Custom caller ID with a personalised name&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictbroadcast.com/voice-broadcast/" rel="noopener noreferrer"&gt;Voice broadcasting with ICTBroadcast&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictbroadcast.com/packages/" rel="noopener noreferrer"&gt;ICTBroadcast editions and pricing&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Compliance gets easier when the records live on your own server instead of a vendor's. ICTBroadcast is &lt;a href="https://www.ictbroadcast.com/free-asterisk-based-auto-dialer/" rel="noopener noreferrer"&gt;an Asterisk based auto dialer&lt;/a&gt; you host yourself, with campaign and call detail data you can query directly. Have a look at the &lt;a href="https://www.ictbroadcast.com/packages/" rel="noopener noreferrer"&gt;available editions&lt;/a&gt; if you are weighing a move off a hosted platform.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>1.5 Million Servers, One Header: What CVE-2026-41940 Means for Your Fax Host</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Wed, 29 Jul 2026 06:55:30 +0000</pubDate>
      <link>https://dev.to/tahiralmas/15-million-servers-one-header-what-cve-2026-41940-means-for-your-fax-host-55nk</link>
      <guid>https://dev.to/tahiralmas/15-million-servers-one-header-what-cve-2026-41940-means-for-your-fax-host-55nk</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://www.ictfax.org/cve-2026-41940-cpanel-fax-server-risk/" rel="noopener noreferrer"&gt;ictfax.org&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Short version: a critical flaw in cPanel and WHM, tracked as CVE-2026-41940, lets an unauthenticated attacker become root by sending one malformed header. Around 1.5 million instances were exposed when it went public. If you run &lt;strong&gt;open source fax server software&lt;/strong&gt; on a box that also runs the hosting panel, that flaw reaches your fax spool without needing a second exploit.&lt;/p&gt;

&lt;p&gt;That last sentence is the part most write-ups skip. Plenty of coverage explains the bypass. Very little of it asks the follow-up question a fax operator cares about, which is what an attacker actually walks away with once they are root on your server.&lt;/p&gt;

&lt;h2&gt;
  
  
  What actually broke
&lt;/h2&gt;

&lt;p&gt;The bug sits in &lt;code&gt;cpsrvd&lt;/code&gt;, the daemon behind the cPanel and WHM login. Its basic authentication handler took the value from the HTTP Authorization header and wrote it into a session file without stripping carriage returns and newlines. Raw &lt;code&gt;\r\n&lt;/code&gt; characters in a header therefore became new lines in the session file.&lt;/p&gt;

&lt;p&gt;Once you can write new lines into a session file, you can write new properties into it. Attackers inserted &lt;code&gt;user=root&lt;/code&gt; and &lt;code&gt;hasroot=1&lt;/code&gt;, tampered with the &lt;code&gt;whostmgrsession&lt;/code&gt; cookie so the per-session encryption step got skipped, then reloaded the session. The server read its own file back and concluded the visitor was an authenticated administrator.&lt;/p&gt;

&lt;p&gt;No credentials. No user interaction. Network reachable. It scored 9.8 on CVSS, which is about as high as these things go, and honestly the score feels earned rather than inflated for once.&lt;/p&gt;

&lt;p&gt;The path from a malformed header to a readable fax spool, with no second exploit required.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this hits open source fax server software harder than most apps
&lt;/h2&gt;

&lt;p&gt;A compromised web app usually leaks whatever that app can reach. A fax server is different, because of what it leaves lying around on disk.&lt;/p&gt;

&lt;p&gt;Every received fax gets written as an image file before anything else happens to it. Cover sheets, recipient lists and job metadata sit alongside it. Trunk credentials live in configuration files the service has to read at startup. None of that is protected by an application login, so root does not need to guess a password or open a database. Root just reads files.&lt;/p&gt;

&lt;p&gt;For a healthcare deployment that is the whole ballgame. Those image files are protected health information the moment they land. Under the Security Rule you are expected to be able to say what was accessed and when, and if the attacker had root, they could also edit the logs you would use to answer that question. Losing the ability to prove scope is often worse than the access itself.&lt;/p&gt;

&lt;p&gt;There is a fair counterpoint here, and it applies to self-hosting generally: the same property that makes a self-hosted &lt;a href="https://www.ictfax.org/ictfax-free-open-source-fax-over-ip-foip-solution/" rel="noopener noreferrer"&gt;fax over IP setup&lt;/a&gt; attractive, which is that the documents never leave your infrastructure, also means nobody else is watching that infrastructure for you. Self-hosting moves the risk. It does not delete it.&lt;/p&gt;

&lt;h2&gt;
  
  
  The two months nobody talks about
&lt;/h2&gt;

&lt;p&gt;The patch is the easy part of this story. Fixed builds shipped across seven branches: 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5, and WP Squared 136.1.7. Everything released after version 11.40 is affected, so "we are on an older stable branch" is not a defence.&lt;/p&gt;

&lt;p&gt;The uncomfortable part is the timeline. Exploitation was observed in the wild from late February 2026, roughly two months before a patch existed. That gap changes what patching means. Applying the update stops future exploitation, but it tells you nothing about whether someone was already inside during those two months.&lt;/p&gt;

&lt;p&gt;So patch first, then treat the box as suspect until you have looked. I would not skip that second step even on a server you consider low value, because fax hosts tend to hold a lot more sensitive material than their owners remember.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to check on the fax host today
&lt;/h2&gt;

&lt;p&gt;Assuming you have patched, here is the order I would work through. It should take under an hour on a single server.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Confirm the running build, not the one in your notes. Version drift between what you think is deployed and what is actually deployed is common on servers that were built once and left alone.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Pull the WHM access log and look for successful administrative sessions that have no matching login event. A session that appears fully authenticated without a preceding login is the signature here.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;List every WHM and cPanel user account and API token, then remove anything you cannot personally account for. Persistence usually looks boring.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Check whether the panel ports are reachable from the public internet at all. If they are, that is a configuration choice you can reverse this afternoon.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Rotate the SIP and trunk credentials your fax service uses. They were readable, so treat them as read.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If step two turns up something you cannot explain, stop and preserve the disk before you clean anything. Tidying up first is the most common way teams destroy the evidence they later need.&lt;/p&gt;

&lt;h2&gt;
  
  
  The layout change worth making
&lt;/h2&gt;

&lt;p&gt;Patching closes this specific hole. It does not close the next one, and control panels are a recurring source of these. The structural fix is to stop letting a hosting panel and a fax service share a root account.&lt;/p&gt;

&lt;p&gt;Same flaw, two layouts. Separation is what decides whether a panel bug becomes a data breach.&lt;/p&gt;

&lt;p&gt;In practice that means the fax server gets its own machine or its own virtual machine, the hosting panel gets a different one, and the panel is reachable over a VPN or a bastion rather than the open internet. Encrypt the spool at rest and ship the audit log somewhere the fax host cannot rewrite. That last detail is underrated. An audit trail stored on the machine being investigated is not really an audit trail.&lt;/p&gt;

&lt;p&gt;Is one extra virtual machine worth it? For a hobby setup, probably not. For anything carrying patient documents, the extra machine costs less per year than a single breach notification exercise costs in staff time alone. Our &lt;a href="https://www.ictfax.org/ictfax-installation-guide/" rel="noopener noreferrer"&gt;installation guide&lt;/a&gt; assumes a dedicated host for exactly this reason, and the &lt;a href="https://www.ictfax.org/technologies/" rel="noopener noreferrer"&gt;technology stack behind ICTFax&lt;/a&gt; is built to run without a hosting panel anywhere near it.&lt;/p&gt;

&lt;p&gt;One more thing worth saying plainly: if you inherited a server and have never audited what else runs on it, do that before you worry about tuning anything. Most fax hosts I have seen accumulate services nobody remembers installing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does CVE-2026-41940 affect ICTFax itself?
&lt;/h3&gt;

&lt;p&gt;No. The vulnerability is in cPanel and WHM, not in the fax software. It matters to fax operators only because the two so often share a server, and root on that server means read access to the fax spool.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do I know if my server was already compromised?
&lt;/h3&gt;

&lt;p&gt;Look for authenticated WHM sessions with no corresponding login event, unfamiliar administrative users or API tokens, and changes to the panel configuration you did not make. Exploitation predates the patch by about two months, so a clean current version does not rule out earlier access.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is a self-hosted fax server less safe than a cloud fax service?
&lt;/h3&gt;

&lt;p&gt;Not inherently, but the responsibility sits with you. A cloud provider patches its own control plane while you accept that your documents live on someone else's disks. Self-hosting reverses both halves of that trade. Neither option removes risk, so pick the one whose failure mode you can actually manage.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should I remove the hosting panel from my fax server?
&lt;/h3&gt;

&lt;p&gt;If the server exists to run fax, yes. A fax host needs a mail transfer agent, a SIP stack and the fax application. It does not need a graphical hosting panel, and every panel you remove is an attack surface you stop having to patch.&lt;/p&gt;

&lt;h3&gt;
  
  
  What should I rotate after patching?
&lt;/h3&gt;

&lt;p&gt;SIP and trunk credentials first, since they sit in readable configuration files. Then panel passwords, API tokens, and any credentials stored in cron jobs or deployment scripts on the same box.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/ictfax-installation-guide/" rel="noopener noreferrer"&gt;ICTFax installation guide&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/open-source-faxing-software-based-on-t-38-protocol/" rel="noopener noreferrer"&gt;Open source faxing software based on the T.38 protocol&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/ictfax-admin-guide/" rel="noopener noreferrer"&gt;ICTFax administrator guide&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/download-ictfax/" rel="noopener noreferrer"&gt;Download ICTFax&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/support/" rel="noopener noreferrer"&gt;ICTFax support&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Running fax on hardware you control is still the right call for anyone handling sensitive documents. Just make sure the machine underneath it is doing one job. &lt;a href="https://www.ictfax.org/download-ictfax/" rel="noopener noreferrer"&gt;Download ICTFax&lt;/a&gt; and follow the &lt;a href="https://www.ictfax.org/ictfax-installation-guide/" rel="noopener noreferrer"&gt;installation guide&lt;/a&gt; for a clean, panel-free build.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Branded Calling Just Went Live in the UK, Canada and Germany. Your US Playbook Won't Port</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Tue, 28 Jul 2026 09:19:46 +0000</pubDate>
      <link>https://dev.to/tahiralmas/branded-calling-just-went-live-in-the-uk-canada-and-germany-your-us-playbook-wont-port-5bep</link>
      <guid>https://dev.to/tahiralmas/branded-calling-just-went-live-in-the-uk-canada-and-germany-your-us-playbook-wont-port-5bep</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://www.ictdialer.com/branded-calling-uk-canada-germany-auto-dialer-software/" rel="noopener noreferrer"&gt;ictdialer.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Branded calling has entered public beta in Canada, Germany and the UK, and the vendor released Q1 2026 numbers alongside it: an 80.6 percent average answer rate for calls carrying a branded display name against 65.2 percent for unbranded ones. If you run &lt;strong&gt;auto dialer software&lt;/strong&gt; that touches those three markets, the interesting part is not the headline. It's that almost nothing you built for STIR/SHAKEN compliance transfers.&lt;/p&gt;

&lt;p&gt;Same feature, three markets, three very different payoffs.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the Q1 2026 numbers actually say
&lt;/h2&gt;

&lt;p&gt;Break the average apart and it stops being one story. Canada went from 82.5 percent unbranded to 92.8 percent branded. The UK moved 62.9 to 75.8. Germany, the most reserved of the three, went 63.0 to 70.4. So the lift ranges from about seven points to nearly thirteen depending on which border your call crosses.&lt;/p&gt;

&lt;p&gt;Two caveats before anybody builds a forecast on this. First, it is vendor-published data drawn from their own customer base, which skews toward businesses already organized enough to register a brand. Second, an answer is not a conversation, and it is definitely not a sale. I would treat these as directionally honest and plan against the low end.&lt;/p&gt;

&lt;p&gt;For context on why any of this moves at all: Hiya's State of the Call research this year put 87 percent of consumers in the camp of unlikely to answer a number they don't recognize. That is the wall. Branded calling is the first mechanism in a while that goes at it directly rather than just trying to avoid a spam label.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why STIR/SHAKEN work doesn't carry over for auto dialer software abroad
&lt;/h2&gt;

&lt;p&gt;US caller reputation work is a signing problem. Your carrier attests to the fact that you have the right to use a number, that attestation rides along with the call, and analytics engines fold it into a score that decides whether a handset says Scam Likely. The 2026 TNS Robocall Report has authentication running at roughly 85 percent of voice traffic between Tier-1 carriers, so at this point being signed is table stakes rather than an advantage.&lt;/p&gt;

&lt;p&gt;Branded calling solves a different problem. Nobody is verifying that you own the number in order to display your name. You register a brand, it gets vetted, and it gets tied to your numbers so the handset can render something a human recognizes. One process proves a call is not spoofed. The other tells the person on the other end who is ringing them.&lt;/p&gt;

&lt;p&gt;That distinction has a practical consequence teams keep missing. Your US attestation status, your carrier relationships, your remediation history with the analytics providers: none of it follows you to Frankfurt. You register separately, per country, and you budget separately.&lt;/p&gt;

&lt;p&gt;Two programs, two registrations, one shared prerequisite you can't skip.&lt;/p&gt;

&lt;h2&gt;
  
  
  Uneven gains should change where you dial first
&lt;/h2&gt;

&lt;p&gt;Here's the operational read. Canada already answers the phone. Starting from 82.5 percent, the ten point gain lands on a base that was healthy to begin with, so branding there is optimization rather than rescue. The UK is where I'd spend first: a thirteen point jump off a 62.9 percent base is the difference between a campaign that pays for itself and one that doesn't.&lt;/p&gt;

&lt;p&gt;Germany is the one to model carefully. Seven points is real, but it is the smallest lift of the three, and German outbound has its own consent culture and regulatory temperament sitting behind the number. If your German list quality is shaky, a display name is not going to carry the campaign.&lt;/p&gt;

&lt;p&gt;Consider a twelve-agent outbound team splitting effort across all three markets. Reallocating dials toward the UK for a quarter, purely because the branding lift is biggest there, is a cheaper experiment than adding headcount and it answers a question you'll need answered anyway.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to change in your dialer this quarter
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Freeze your caller ID set per country. Brand registration ties a name to specific numbers, so a dialer that rotates DIDs aggressively will undo the thing you just paid for.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Split reporting by destination country. A blended answer rate across three markets will hide exactly the differences shown above.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Check handset and carrier coverage before promising results internally. Display name support is not universal, and a share of your dials will land on devices that show nothing.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Keep pacing conservative while you measure. Abandoned calls raise complaint rates, and complaints are the fastest way to lose a brand registration you just earned.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Re-baseline before you switch anything on. Without two weeks of clean unbranded data per country you'll have no way to prove the lift.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Confirm your local consent basis separately. Branding changes whether people answer, not whether you were allowed to dial.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Most of that is configuration rather than engineering. An open source stack helps here mainly because per-country caller ID rules and campaign-level reporting are things you can change yourself instead of filing a feature request. The &lt;a href="https://www.ictdialer.com/ictdialer-the-ultimate-freeswitch-based-open-source-auto-dialer-software-for-call-automation-solution/" rel="noopener noreferrer"&gt;FreeSWITCH-based architecture behind ICTDialer&lt;/a&gt; exists partly for that reason.&lt;/p&gt;

&lt;h2&gt;
  
  
  What branded calling won't fix
&lt;/h2&gt;

&lt;p&gt;A name on the screen raises the odds someone picks up. It does nothing about what happens next. If your list is stale, if the agent takes four seconds to start talking, or if the offer is wrong for that market, a higher answer rate just means more people hearing a bad pitch.&lt;/p&gt;

&lt;p&gt;There's a reputational edge to this too. Getting recognized more often cuts both ways, because now the calls people resent are attached to your brand instead of an anonymous number. Teams running heavy volume with thin targeting should probably fix targeting first. That's not the advice a vendor blog usually gives, but it's the one I'd want.&lt;/p&gt;

&lt;p&gt;The dull prerequisites still decide most outcomes: consistent numbers, sane pacing, clean data, and agents who are ready when the call connects. Our roundup of &lt;a href="https://www.ictdialer.com/10-best-open-source-auto-dialer-software-solutions/" rel="noopener noreferrer"&gt;open source auto dialer options&lt;/a&gt; goes through how different platforms handle those basics, and the &lt;a href="https://www.ictdialer.com/webrtc/" rel="noopener noreferrer"&gt;WebRTC agent setup&lt;/a&gt; matters more than people expect once answer rates climb and connect times start mattering.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What is branded calling?
&lt;/h3&gt;

&lt;p&gt;It's a program that displays your verified business name on the recipient's handset during an inbound ring. You register the brand, it gets vetted, and it gets associated with the numbers you dial from. It is separate from caller name lookup services and separate from call authentication.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is branded calling the same as STIR/SHAKEN?
&lt;/h3&gt;

&lt;p&gt;No. STIR/SHAKEN is a US framework for cryptographically signing calls so carriers can tell whether a number is being spoofed. Branded calling adds identity for the person answering. You can be fully authenticated and still show up as an unknown number.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does branded calling work in every country?
&lt;/h3&gt;

&lt;p&gt;Not yet. The current public beta covers Canada, Germany and the UK, with availability depending on the recipient's carrier and device. Coverage keeps expanding, so check per market rather than assuming a global rollout.&lt;/p&gt;

&lt;h3&gt;
  
  
  How much does the answer rate actually improve?
&lt;/h3&gt;

&lt;p&gt;Q1 2026 data put the branded average at 80.6 percent against 65.2 percent unbranded, but the country split ran from about seven points in Germany to nearly thirteen in the UK. Model the low end and measure your own baseline before committing budget.&lt;/p&gt;

&lt;h3&gt;
  
  
  Will branded calling stop my calls being marked as spam?
&lt;/h3&gt;

&lt;p&gt;Not on its own. Spam labelling is driven by complaint rates and calling patterns. A registered brand can be withdrawn if your behaviour looks abusive, so the underlying discipline around pacing and consent still does the heavy lifting.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I need to change my dialer to support it?
&lt;/h3&gt;

&lt;p&gt;Usually not at the code level. What matters is operational: a stable set of registered numbers per country, per-country reporting, and pacing controls tight enough to keep complaints low.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictdialer.com/10-best-open-source-auto-dialer-software-solutions/" rel="noopener noreferrer"&gt;10 best open source auto dialer software solutions&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictdialer.com/ictdialer-the-ultimate-freeswitch-based-open-source-auto-dialer-software-for-call-automation-solution/" rel="noopener noreferrer"&gt;ICTDialer: FreeSWITCH-based open source auto dialer&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictdialer.com/webrtc/" rel="noopener noreferrer"&gt;WebRTC agent interface&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictdialer.com/free-auto-dialer-software-the-best-free-dialers-for-outbound-sales/" rel="noopener noreferrer"&gt;Free auto dialer software for outbound sales&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictdialer.com/10-best-open-source-unified-communications-software-solutions/" rel="noopener noreferrer"&gt;10 best open source unified communications platforms&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Run outbound on a stack you can actually tune
&lt;/h2&gt;

&lt;p&gt;Per-country caller ID rules, campaign-level pacing and reporting you can split by destination are configuration problems, and they're much easier when you own the platform. ICTDialer is an open source predictive dialer built on FreeSWITCH, covering voice, SMS, fax and email campaigns from one system. Take a look at &lt;a href="https://www.ictdialer.com/" rel="noopener noreferrer"&gt;what ICTDialer does&lt;/a&gt;, or read the &lt;a href="https://www.ictdialer.com/ictdialer-the-ultimate-freeswitch-based-open-source-auto-dialer-software-for-call-automation-solution/" rel="noopener noreferrer"&gt;platform overview&lt;/a&gt; if you're weighing a migration. For deployment questions, reach our team through the &lt;a href="https://service.ictvision.net/submitticket.php" rel="noopener noreferrer"&gt;support desk&lt;/a&gt;.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>The HIPAA Security Rule Slipped to 2027. Your Fax Server Still Has an August Problem</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Tue, 28 Jul 2026 09:15:55 +0000</pubDate>
      <link>https://dev.to/tahiralmas/the-hipaa-security-rule-slipped-to-2027-your-fax-server-still-has-an-august-problem-5d7c</link>
      <guid>https://dev.to/tahiralmas/the-hipaa-security-rule-slipped-to-2027-your-fax-server-still-has-an-august-problem-5d7c</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://www.ictfax.org/hipaa-security-rule-delay-open-source-fax-server/" rel="noopener noreferrer"&gt;ictfax.org&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;HHS has pushed final action on its HIPAA Security Rule overhaul to July 2027, more than a year past the May 2026 date it was aiming for. If you run &lt;strong&gt;open source fax server software&lt;/strong&gt; that carries protected health information, that delay buys you planning time and nothing else. The Privacy Rule update is still expected in August, and it lands closer to your fax queue than the security overhaul ever did.&lt;/p&gt;

&lt;p&gt;Two rules, two very different clocks. Only one of them slipped.&lt;/p&gt;

&lt;h2&gt;
  
  
  What actually moved in the federal agenda
&lt;/h2&gt;

&lt;p&gt;The Office for Civil Rights had its proposed Security Rule rewrite sitting in the final rule stage, with final action pencilled in for May 2026. The updated agenda moves it into long-term actions instead. That reclassification is the part worth reading twice. Long-term actions is where rules go when nobody expects them inside the next twelve months, and a Davis Wright Tremaine read of the agenda flagged the same signal.&lt;/p&gt;

&lt;p&gt;The proposal itself was not shy. It would have taken a pile of specifications that are currently addressable, meaning you can document why you skipped them, and made them flatly required: encryption of electronic PHI at rest and in transit, multi-factor authentication, a maintained asset inventory, network segmentation, and annual penetration testing. For a lot of small healthcare IT teams that was a genuine budget event. You can see why the comment file got heavy.&lt;/p&gt;

&lt;p&gt;So the pressure came off, right? Not really. Here is the part that gets lost in the headlines.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why the delay changes nothing for open source fax server software today
&lt;/h2&gt;

&lt;p&gt;The Security Rule that exists right now is still enforced exactly as written. OCR did not suspend anything. It postponed replacing one rule with a stricter one, which means the current requirements, including the risk analysis obligation that shows up in a striking share of enforcement actions, are still the standard you get measured against if a breach lands on your desk.&lt;/p&gt;

&lt;p&gt;There is a second reason to ignore the new date. Most of what the proposal wanted was already what any competent auditor expects to see. Encrypted disks. Accounts with real authentication in front of them. A list of the machines you own. If your hardening roadmap had July 2027 written at the top of it, that roadmap was wrong before the delay and it is still wrong now.&lt;/p&gt;

&lt;p&gt;My honest read: the delay helps organizations that were going to be caught short on pen testing budgets, and it helps almost nobody else. A self-hosted fax server that handles PHI sits in the same risk bucket today that it sat in last month.&lt;/p&gt;

&lt;h2&gt;
  
  
  August is the deadline that should worry fax teams
&lt;/h2&gt;

&lt;p&gt;While the security overhaul drifted, OCR kept the Privacy Rule update on the calendar for August, along with further rulemaking on health IT interoperability and certification. The stated goals are strengthening a patient's right to access their own records, improving information sharing for care coordination, and widening family and caregiver involvement during emergencies.&lt;/p&gt;

&lt;p&gt;Read that through a fax lens and it gets concrete fast. Access rights come with turnaround clocks, and a large share of records requests still move over fax because that is what the requesting clinic or attorney's office can receive. When a request arrives, somebody has to find the document, confirm it went to the right number, and prove all of it later. A records clerk at a mid-sized clinic who needs three days to pull a transmission log is the whole problem in one sentence.&lt;/p&gt;

&lt;p&gt;Interoperability rulemaking points the same direction. The agencies want data moving with fewer barriers, and fax keeps being the bridge between systems that were never designed to talk. That is not nostalgia, it is just what the install base looks like. Our take on &lt;a href="https://www.ictfax.org/open-source-faxing-software-based-on-t-38-protocol/" rel="noopener noreferrer"&gt;fax over IP using the T.38 protocol&lt;/a&gt; goes deeper on how that bridge holds up on modern networks.&lt;/p&gt;

&lt;p&gt;Self-hosting hands you four layers. That is control and liability in the same move.&lt;/p&gt;

&lt;h2&gt;
  
  
  The four layers you own when you self-host
&lt;/h2&gt;

&lt;p&gt;Run your own fax server and the transport is yours to configure. You choose whether SIP signaling rides TLS, whether media is protected, and which carrier terminates the call. T.38 is worth being precise about here, because it solves reliability for fax over packet networks, not confidentiality. It is an error-correction story, not an encryption story, and teams conflate the two constantly.&lt;/p&gt;

&lt;p&gt;Storage is the layer people underestimate. Every received fax becomes an image file and a database row, sitting on a disk you provisioned, under a retention policy you either wrote or forgot to write. Nobody sends you a reminder about the second one.&lt;/p&gt;

&lt;p&gt;Access and audit round it out. You decide what sits in front of the login, and you keep the full transmission history rather than filing a support ticket to ask a vendor for it. During an access request or a breach investigation, being able to export your own logs the same afternoon is worth more than most feature comparisons will ever tell you.&lt;/p&gt;

&lt;h2&gt;
  
  
  A short list worth clearing before August
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Put SIP signaling behind TLS and protect the media path. Unencrypted signaling on a network segment that touches PHI is the easiest finding an auditor will ever write up.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Turn on full-disk encryption wherever fax images and the database live, then write down where the keys are held.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Add multi-factor authentication at the reverse proxy or OS layer for anyone who can open a received fax.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Decide your retention period, then actually enforce deletion. Old faxes you never needed are pure breach surface.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Test a log export end to end and time it. If it takes longer than an afternoon, fix that before somebody asks under pressure.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Re-read the BAA with your fax carrier. The delay does not touch business associate obligations at all.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Refresh the risk analysis and date it. This is the single most cited gap in enforcement actions.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of that requires the 2027 rule to exist. Most of it is a weekend of work for one competent sysadmin, and the &lt;a href="https://www.ictfax.org/ictfax-installation-guide/" rel="noopener noreferrer"&gt;ICTFax installation guide&lt;/a&gt; covers the base setup those controls layer on top of.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where the self-hosting pitch deserves pushback
&lt;/h2&gt;

&lt;p&gt;Self-hosting is not automatically the safer choice, and I would rather say that plainly than sell past it. An unpatched fax box in a wiring closet, running a kernel from three years ago, with one shared admin password, is worse than a cloud provider that employs people to think about this full time. Control is only an advantage when somebody exercises it.&lt;/p&gt;

&lt;p&gt;The version of this that works looks boring: a documented owner, a patch cadence, monitored logs, and a restore you have actually tested. If your team can commit to that, owning the stack genuinely reduces the number of third parties standing between you and the PHI. If it cannot, be honest about it and buy the service instead. Teams building automated workflows on top usually start with the &lt;a href="https://www.ictfax.org/fax-api-tutorial/" rel="noopener noreferrer"&gt;fax API tutorial&lt;/a&gt;, which is also where retention and logging decisions tend to get made by accident.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does the delay mean HIPAA encryption requirements are cancelled?
&lt;/h3&gt;

&lt;p&gt;No. The proposed overhaul that would have made encryption explicitly required is what slipped. The existing Security Rule still applies, and encryption remains an addressable specification you must either implement or document a defensible alternative for.&lt;/p&gt;

&lt;h3&gt;
  
  
  When is the HIPAA Security Rule overhaul now expected?
&lt;/h3&gt;

&lt;p&gt;Final action has been pushed to at least July 2027, and the rulemaking was moved from the final rule stage into long-term actions. Treat July 2027 as the earliest plausible date rather than a commitment.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is changing in the Privacy Rule this August?
&lt;/h3&gt;

&lt;p&gt;OCR still intends to finalize an update strengthening patient access rights, improving information sharing for care coordination, and expanding family and caregiver involvement during emergencies, with separate rulemaking planned on interoperability and certification.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is open source fax server software HIPAA compliant?
&lt;/h3&gt;

&lt;p&gt;Software by itself is never compliant or non-compliant. Compliance depends on how you deploy it: encryption, access control, audit logging, retention, a current risk analysis, and a signed BAA with any carrier that touches the traffic. Self-hosting gives you the ability to satisfy those, not a guarantee that you have.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does T.38 encrypt fax transmissions?
&lt;/h3&gt;

&lt;p&gt;It does not. T.38 exists to carry fax reliably across IP networks with error correction. Confidentiality has to come from the layers around it, typically TLS for signaling and a protected media path.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should we wait for the 2027 rule before hardening?
&lt;/h3&gt;

&lt;p&gt;Waiting is the expensive option. Nearly every control in the proposal is something auditors already look for, and the current rule is enforced today. Doing the work now spreads the cost and removes the deadline scramble later.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/ictfax-installation-guide/" rel="noopener noreferrer"&gt;ICTFax installation guide&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/open-source-faxing-software-based-on-t-38-protocol/" rel="noopener noreferrer"&gt;Open source faxing software based on the T.38 protocol&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/ictfax-software-feature/" rel="noopener noreferrer"&gt;ICTFax software features&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/fax-api-tutorial/" rel="noopener noreferrer"&gt;Fax API tutorial&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://www.ictfax.org/download-ictfax/" rel="noopener noreferrer"&gt;Download ICTFax&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Own the stack that carries your PHI
&lt;/h2&gt;

&lt;p&gt;ICTFax is an open source fax server you install on your own infrastructure, which keeps the transport, storage, access and audit layers inside your risk analysis instead of somebody else's. Start at the &lt;a href="https://www.ictfax.org/" rel="noopener noreferrer"&gt;ICTFax project home&lt;/a&gt;, or go straight to &lt;a href="https://www.ictfax.org/download-ictfax/" rel="noopener noreferrer"&gt;the download page&lt;/a&gt; and stand up a test server before the August rule lands. Questions about a healthcare deployment can go to our team through the &lt;a href="https://service.ictinnovations.com/submitticket.php" rel="noopener noreferrer"&gt;support desk&lt;/a&gt;.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Therapy's Front Door Moved Online, and the Latest Research Says That's Working</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Sat, 25 Jul 2026 16:16:49 +0000</pubDate>
      <link>https://dev.to/tahiralmas/therapys-front-door-moved-online-and-the-latest-research-says-thats-working-2ghe</link>
      <guid>https://dev.to/tahiralmas/therapys-front-door-moved-online-and-the-latest-research-says-thats-working-2ghe</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://roshni.online/online-mental-health-front-door-research/" rel="noopener noreferrer"&gt;roshni.online&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For decades, getting mental health support started with the hardest possible step: telling someone face to face. Find a clinic, travel there, sit in a waiting room where a neighbor might see you. Research published this month adds to a picture that's been forming for a while now: that path has been replaced. A study of people using AI-supported therapy apps found roughly 80% reported meaningful improvement within six weeks. Teletherapy keeps matching in-person outcomes for anxiety and depression in controlled comparisons. The front door to care has moved online, and the evidence says the new door works.&lt;br&gt;
The old path lost most people before they arrived. The new one starts the week you notice.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Starting Early Beats Starting Perfectly
&lt;/h2&gt;

&lt;p&gt;Buried in most outcome studies is a finding that doesn't get headlines: the strongest predictor of improvement isn't which therapy modality you pick. It's whether you start, and how early. Anxiety and low mood respond far better in their first months than after years of quiet compounding, when they've had time to reshape sleep, work, and relationships.&lt;/p&gt;

&lt;p&gt;The old path failed precisely on this measure. Every barrier, distance, cost, the fear of being seen, pushed the start date later, and for most people it pushed it to never. What online support changed isn't the therapy itself. It's the start date. A first conversation the same week you notice something is wrong, from your own room, with nobody watching you walk in.&lt;/p&gt;

&lt;p&gt;That's also the honest way to read the 80%-in-six-weeks result. It isn't evidence that an app replaces a therapist. It's evidence that accessible, structured support, available at the exact moment someone is ready to reach for it, moves the needle for most people who use it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Stepped Care: The Structure Behind the Numbers
&lt;/h2&gt;

&lt;p&gt;The systems getting good results share a shape that clinicians call stepped care: start with the lightest support that could help, and step up only when needed.&lt;br&gt;
Four steps, and most people only ever need the bottom two.&lt;br&gt;
The first step is an always-available assistant. Roshni's free AI assistant exists for exactly this rung: it's anonymous, it's awake at 3 a.m. when the hard thoughts are loudest, and it helps you talk through what's happening and decide whether you want more. We've written before about &lt;a href="https://roshni.online/ai-chatbots-crisis-reach-real-support/" rel="noopener noreferrer"&gt;what AI chat support can and can't do&lt;/a&gt;, and the boundary matters: it's a starting point and a bridge, not a replacement for human care.&lt;/p&gt;

&lt;p&gt;The second step is scheduled sessions with a counselor, by video or chat, and this is where most anxiety and depression care now happens. The research comparing it to in-person therapy keeps landing in the same place: for common conditions, outcomes match. Our guide to &lt;a href="https://roshni.online/online-mental-health-support-how-it-helps/" rel="noopener noreferrer"&gt;how online mental health support helps&lt;/a&gt; walks through what those sessions actually look like.&lt;/p&gt;

&lt;p&gt;The third step recognizes something the neat clinical categories miss: a lot of distress arrives tangled with practical problems. A marriage under strain, workplace harassment, an inheritance dispute eating a family alive. Talking to a counselor helps; sometimes you also need to know your options. That's why Roshni pairs mental health support with &lt;a href="https://roshni.online/online-legal-consultation-trusted-guidance-from-home/" rel="noopener noreferrer"&gt;online legal consultation&lt;/a&gt;, because the anxiety and the legal question are often the same problem wearing two coats.&lt;/p&gt;

&lt;p&gt;The fourth step is the one any honest platform has to name: crisis. Online support has limits, and urgent risk belongs with crisis lines and local in-person care immediately, not with an app. A system that doesn't say this clearly isn't a care system; it's a product hoping nothing goes wrong.&lt;/p&gt;

&lt;h2&gt;
  
  
  What This Means If You've Been Waiting
&lt;/h2&gt;

&lt;p&gt;If you've been circling the idea of getting support, the research this month is really about you. The tools at the bottom of the ladder are free or close to it, they're private, and the evidence says most people who engage with them feel meaningfully better within weeks. You don't have to commit to therapy to start. You have to start to find out whether therapy is what you need.&lt;/p&gt;

&lt;p&gt;Open a conversation with the assistant tonight if tonight is hard. Book a session if the conversation tells you there's more to work through. The &lt;a href="https://roshni.online/pricing/" rel="noopener noreferrer"&gt;session options&lt;/a&gt; are built to be a smaller obstacle than the problem you're carrying. The front door moved. It's closer than it has ever been.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does online therapy actually work as well as in-person?
&lt;/h3&gt;

&lt;p&gt;For the most common concerns, anxiety and depression, controlled studies keep finding comparable outcomes between video-based therapy and in-person sessions. What matters most is starting early and attending consistently, both of which online formats make easier.&lt;/p&gt;

&lt;h3&gt;
  
  
  What did the new AI therapy research find?
&lt;/h3&gt;

&lt;p&gt;A study published this month of people using AI-supported therapy apps found around 80% reported meaningful improvement within six weeks. The result reflects accessible, structured support reaching people early, not AI replacing human therapists.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is an AI assistant a substitute for a counselor?
&lt;/h3&gt;

&lt;p&gt;No. It's a first step: a private space to put what you're feeling into words, learn coping basics, and decide whether to book a human session. Anything involving urgent risk, or persistent symptoms, belongs with a counselor or crisis service.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is stepped care?
&lt;/h3&gt;

&lt;p&gt;A way of organizing support so you start with the lightest effective help, an always-on assistant or self-guided tools, and step up to scheduled counseling, specialist support, or in-person care only as needed. It keeps early help cheap and immediate while keeping serious care available.&lt;/p&gt;

&lt;h3&gt;
  
  
  When should someone skip the app and seek immediate help?
&lt;/h3&gt;

&lt;p&gt;If there are thoughts of self-harm, harm to others, or a safety risk at home, contact a crisis line or local emergency services right away. Online platforms, including this one, are built for support and early care, not emergencies.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://roshni.online/online-mental-health-support-how-it-helps/" rel="noopener noreferrer"&gt;Online Mental Health Support: How It Helps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://roshni.online/ai-chatbots-crisis-reach-real-support/" rel="noopener noreferrer"&gt;AI Chatbots: Crisis Reach and Real Support&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://roshni.online/online-legal-consultation-trusted-guidance-from-home/" rel="noopener noreferrer"&gt;Online Legal Consultation from Home&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://roshni.online/pricing/" rel="noopener noreferrer"&gt;Session Pricing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://roshni.online/about-us/" rel="noopener noreferrer"&gt;About Roshni&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
    <item>
      <title>Everyone Says the VoIP Market Is Too Crowded. For White-Label Resellers, That's the Opportunity</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Sat, 25 Jul 2026 16:13:39 +0000</pubDate>
      <link>https://dev.to/tahiralmas/everyone-says-the-voip-market-is-too-crowded-for-white-label-resellers-thats-the-opportunity-1hom</link>
      <guid>https://dev.to/tahiralmas/everyone-says-the-voip-market-is-too-crowded-for-white-label-resellers-thats-the-opportunity-1hom</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://www.ict.vision/crowded-voip-market-white-label-reseller-opportunity" rel="noopener noreferrer"&gt;ict.vision&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A theme kept surfacing in this month's telecom trade coverage: the VoIP and UCaaS market has become brutally crowded. Hundreds of providers, near-identical feature lists, and buyers who can't tell one hosted phone offer from the next. Commentators frame this as bad news. It is, for vendors trying to out-feature each other. For a different player, the local reseller running white-label ICT software under their own brand, a crowded market is the best news in years. Confusion is a product opportunity, and trust is the scarce good.&lt;br&gt;
The same crowding that squeezes vendors creates the reseller's opening.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Crowding Kills Feature Competition
&lt;/h2&gt;

&lt;p&gt;When forty providers offer auto attendants, mobile apps, call recording, and now AI answering, the feature list stops being a reason to choose anyone. Features commoditize within a quarter of shipping. Price becomes the only visible difference, and price competition in a commodity market is a race everyone loses slowly.&lt;/p&gt;

&lt;p&gt;Buyers respond to this the way people always respond to overwhelming choice: they stop evaluating and start looking for someone to trust. A small business owner comparing their fourteenth hosted PBX tab doesn't want a fifteenth. They want a person, ideally nearby, ideally recommended, who will pick the right system, install it, brand the invoice clearly, and answer the phone when something breaks.&lt;/p&gt;

&lt;p&gt;That person is the reseller. And the reseller's economics only work if the software underneath carries their brand, not somebody else's.&lt;/p&gt;

&lt;h2&gt;
  
  
  The White-Label Difference, in Cold Terms
&lt;/h2&gt;

&lt;p&gt;There are two ways to resell communications services. In the agent model, you sell a big platform's brand for a commission, and the platform owns the customer, sets the price, and trims your margin whenever its investors need a better quarter. In the white-label model, the platform is invisible: your brand on the portal, your name on the invoice, your relationship, your pricing.&lt;/p&gt;

&lt;p&gt;The second model has a structural property that matters more as markets crowd: the customer relationship is an asset you own. When renewal pressure comes, the customer's loyalty attaches to you, the party who answered the phone at 6 p.m., not to a logo they've never seen. In a market where trust is the differentiator, giving the trust away to an upstream brand is giving away the business.&lt;br&gt;
One brand across four product lines, on multi-tenant platforms with fixed cost.&lt;/p&gt;

&lt;h2&gt;
  
  
  One Brand, a Whole Portfolio
&lt;/h2&gt;

&lt;p&gt;The other advantage crowding hands to resellers is breadth. A vendor fights to win one product category. A reseller with a white-label portfolio sells whatever this particular customer needs: a &lt;a href="https://www.ict.vision/ict-pbx" rel="noopener noreferrer"&gt;hosted PBX&lt;/a&gt; for the law office, a &lt;a href="https://www.ict.vision/ict-broadcast" rel="noopener noreferrer"&gt;broadcasting and auto-dialing platform&lt;/a&gt; for the collections agency, digital &lt;a href="https://www.ict.vision/ict-fax" rel="noopener noreferrer"&gt;fax over IP&lt;/a&gt; for the clinic that lives under compliance rules. Same brand, same bill, same trusted person across all of it.&lt;/p&gt;

&lt;p&gt;Multi-tenancy is what makes the math work. These platforms run every customer as a tenant on infrastructure you control, so the software cost is fixed while the tenant count grows. Compare that to per-seat reseller margins, which vendors compress year after year, and the difference compounds: the white-label reseller's margin grows with each customer added, instead of shrinking with each contract renewal.&lt;/p&gt;

&lt;p&gt;My honest advice to anyone weighing this: the hard part isn't the technology, it's committing to the service relationship. White-label reselling is a service business wearing a software costume. If you don't want to answer the 6 p.m. call, stay an agent. If you do, the crowded market is currently manufacturing overwhelmed buyers faster than resellers are absorbing them.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where ICT Vision Fits
&lt;/h2&gt;

&lt;p&gt;ICT Vision exists for exactly this play: a white-label B2B portfolio, PBX, contact center, broadcasting, fax, CRM, built on &lt;a href="https://www.ict.vision/ict-core" rel="noopener noreferrer"&gt;ICTCore&lt;/a&gt; and delivered multi-tenant so resellers and service providers can launch under their own brand without building a platform first. The crowding that's making headlines is the demand side of that equation. The supply side is a portfolio, a brand of your own, and the willingness to be the person a confused buyer trusts.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What does white label mean in ICT software?
&lt;/h3&gt;

&lt;p&gt;The software runs under your brand: your logo on the portal, your domain, your invoices, your pricing. Customers see your company as the service provider, while the underlying platform stays invisible to them.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why is a crowded VoIP market good for resellers?
&lt;/h3&gt;

&lt;p&gt;Crowding overwhelms buyers, and overwhelmed buyers stop comparing features and start seeking a trusted local party to choose and manage the service for them. Resellers monetize that trust; vendors competing on feature lists can't.&lt;/p&gt;

&lt;h3&gt;
  
  
  What's the difference between an agent and a white-label reseller?
&lt;/h3&gt;

&lt;p&gt;An agent sells the platform's brand for a commission and the platform owns the customer. A white-label reseller owns the brand, the pricing, and the customer relationship, and pays for the platform instead of surrendering the relationship to it.&lt;/p&gt;

&lt;h3&gt;
  
  
  How does multi-tenant software improve reseller margins?
&lt;/h3&gt;

&lt;p&gt;One platform installation serves every customer as a separate tenant, so the software and infrastructure cost stays roughly fixed while revenue scales with tenants. Margin per customer grows as the base grows, unlike per-seat commission models.&lt;/p&gt;

&lt;h3&gt;
  
  
  What services can a white-label ICT reseller offer?
&lt;/h3&gt;

&lt;p&gt;A typical portfolio covers hosted PBX for business phone systems, contact center software, voice and SMS broadcasting, digital fax for regulated industries, and CRM, all under one brand and one bill.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.ict.vision/ict-pbx" rel="noopener noreferrer"&gt;ICT PBX: White Label Hosted PBX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ict.vision/ict-broadcast" rel="noopener noreferrer"&gt;ICT Broadcast: Voice and SMS Broadcasting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ict.vision/ict-fax" rel="noopener noreferrer"&gt;ICT Fax: Fax over IP Platform&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ict.vision/ict-core" rel="noopener noreferrer"&gt;ICTCore: The Platform Underneath&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ict.vision/ict-crm" rel="noopener noreferrer"&gt;ICT CRM&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
    <item>
      <title>Half Your Team Isn't Coming Back to the Desk. Size Your PBX for That</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Sat, 25 Jul 2026 16:10:33 +0000</pubDate>
      <link>https://dev.to/tahiralmas/half-your-team-isnt-coming-back-to-the-desk-size-your-pbx-for-that-1j54</link>
      <guid>https://dev.to/tahiralmas/half-your-team-isnt-coming-back-to-the-desk-size-your-pbx-for-that-1j54</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ictpbx.com/hybrid-work-half-remote-pbx-sizing/" rel="noopener noreferrer"&gt;ictpbx.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The hybrid work argument is over, and the data called the winner. Workplace surveys through mid-2026 keep landing on the same picture: roughly half of remote-capable employees now work hybrid, splitting each week between home and office, and the loudest return-to-office campaigns barely moved that number. Offices adapted with booking apps and hot desks. The business phone system, in a lot of companies, did not. Desk phones still ring at empty desks on Tuesdays, and customers still end up saved in contacts under someone's personal mobile number.&lt;br&gt;
The work pattern stabilized; the office PBX still assumes an office.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Mismatch, Concretely
&lt;/h2&gt;

&lt;p&gt;Walk through what half-remote does to a phone system designed for full-office. An inbound customer call hits reception, reception transfers to a desk extension, and the desk is empty because it's a home day. The call bounces to voicemail, the customer calls the salesperson's mobile instead, and now a business relationship lives on a personal SIM that walks out the door if the employee does.&lt;/p&gt;

&lt;p&gt;Meanwhile nobody can see availability. Reception doesn't know whether the support lead is at home and reachable or on the school run. Ring groups built around physical departments ring rooms instead of people. The company is effectively running two phone systems, the PBX for the office half of the week and an unmanaged mess of mobiles for the other half, and the seam between them is exactly where customers fall through.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a Half-Remote Phone System Looks Like
&lt;/h2&gt;

&lt;p&gt;The fix isn't exotic; it's a set of defaults that assume location is variable. One extension per person, registered simultaneously to the desk phone, a browser softphone, and a mobile app, so extension 204 is the person, wherever they sit. Presence everyone can see: office, home, on a call, off shift. And outbound business caller ID from every device, so the customer sees the company number whether the call started at a desk or a kitchen table.&lt;/p&gt;

&lt;p&gt;The browser softphone deserves special mention because it quietly solves the worst hybrid problem: the home machine. Installing and maintaining SIP clients on personal laptops is a support burden and a security question. A &lt;a href="https://ictpbx.com/webrtc-softphone-browser-calling-ictpbx/" rel="noopener noreferrer"&gt;WebRTC softphone&lt;/a&gt; needs nothing installed: the extension lives in a browser tab, encrypted end to end, and disappears when the tab closes. ICTPBX ships this as standard, which is one reason half-remote deployments lean on it heavily.&lt;br&gt;
Four sizing decisions that make Monday morning work.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sizing It: Four Decisions
&lt;/h2&gt;

&lt;p&gt;First, count people, not desks. Per-user licensing with multi-device registration means 40 staff need 40 extensions, full stop. If a quote prices desk phones and mobile apps as separate line items, you're being charged twice for the same person.&lt;/p&gt;

&lt;p&gt;Second, make WebRTC the default endpoint and desk phones the exception. Buy hardware for the roles that genuinely live at a desk, reception, maybe a shared warehouse phone, and let everyone else run browser and mobile. Most companies discover they need a third of the handsets they thought.&lt;/p&gt;

&lt;p&gt;Third, route by presence and schedule, not by location. "In the office" no longer predicts availability, so ring groups and IVR targets should follow who's on shift and free. Time-based routing that follows the working day, wherever it's happening, beats any floor plan.&lt;/p&gt;

&lt;p&gt;Fourth, split your infrastructure budget correctly: bandwidth for the office, security for the homes. The office link needs capacity for concurrent calls; the home endpoints need TLS signaling and SRTP media so calls stay private on domestic Wi-Fi. We covered the hardening side in our &lt;a href="https://ictpbx.com/multi-tenant-pbx-security-best-practices-2026/" rel="noopener noreferrer"&gt;multi-tenant PBX security guide&lt;/a&gt;, and it applies doubly when half your endpoints live outside the office firewall.&lt;/p&gt;

&lt;p&gt;One opinion from watching these deployments: companies overthink the technology and underthink the directory. The half-remote PBX works when presence is accurate, and presence is accurate when it updates itself from devices and calendars instead of relying on humans toggling a status. Ask any vendor how presence gets set, and be suspicious of answers that start with "users simply remember to."&lt;/p&gt;

&lt;h2&gt;
  
  
  The Monday Morning Test
&lt;/h2&gt;

&lt;p&gt;Here's the acceptance test for any system you evaluate, including &lt;a href="https://ictpbx.com/software-pbx/" rel="noopener noreferrer"&gt;ICTPBX's hosted PBX software&lt;/a&gt;: Monday, 9 a.m., half the team at home, half in the office. A customer calls the main number. Does the call reach the right available person on the first attempt, with the company's caller ID on every callback? If yes, your phone system matches how your company actually works now. If no, you're still running a 2019 phone system in a 2026 company, and your customers are the ones absorbing the difference.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How common is hybrid work now?
&lt;/h3&gt;

&lt;p&gt;Surveys through mid-2026 consistently show around half of remote-capable employees working hybrid, with a smaller share fully remote and the rest fully on-site. The pattern has held steady for over a year despite return-to-office pushes.&lt;/p&gt;

&lt;h3&gt;
  
  
  What PBX features matter most for hybrid teams?
&lt;/h3&gt;

&lt;p&gt;Multi-device registration under one extension, a WebRTC browser softphone, mobile apps with business caller ID, visible presence, and time or presence-based routing. Together they make location irrelevant to reachability.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do remote employees need VPNs for the phone system?
&lt;/h3&gt;

&lt;p&gt;Not with a properly configured hosted PBX. WebRTC softphones connect over TLS and SRTP directly, so calls are encrypted without VPN clients on personal machines. That removes both a support burden and a common failure point.&lt;/p&gt;

&lt;h3&gt;
  
  
  How much bandwidth do concurrent calls need?
&lt;/h3&gt;

&lt;p&gt;Plan roughly 100 kbps per concurrent call in each direction with common codecs, plus headroom. A 20-person office rarely has 20 simultaneous calls; measuring your real concurrency for a week beats guessing.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can hybrid teams keep their existing business numbers?
&lt;/h3&gt;

&lt;p&gt;Yes. Numbers port to the hosted platform and ring every registered device. Callers dial the same number they always have; where it rings is what changes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://ictpbx.com/software-pbx/" rel="noopener noreferrer"&gt;ICTPBX Hosted PBX Software&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ictpbx.com/webrtc-softphone-browser-calling-ictpbx/" rel="noopener noreferrer"&gt;WebRTC Softphone: Browser Calling in ICTPBX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ictpbx.com/multi-tenant-pbx-security-best-practices-2026/" rel="noopener noreferrer"&gt;Multi-Tenant PBX Security Best Practices&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ictpbx.com/ictpbx-sms-ai-voice-agent-enterprise-edition/" rel="noopener noreferrer"&gt;ICTPBX SMS and AI Voice Agent: Enterprise Edition&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ictpbx.com/ucaas-market-growth-2026-hosted-pbx-providers/" rel="noopener noreferrer"&gt;UCaaS Market Growth and Hosted PBX Providers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
    <item>
      <title>AI Flags, Humans Decide: Why Hybrid Proctoring Won the Online Exam Debate</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Sat, 25 Jul 2026 16:07:24 +0000</pubDate>
      <link>https://dev.to/tahiralmas/ai-flags-humans-decide-why-hybrid-proctoring-won-the-online-exam-debate-2im6</link>
      <guid>https://dev.to/tahiralmas/ai-flags-humans-decide-why-hybrid-proctoring-won-the-online-exam-debate-2im6</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://www.ictlms.net/hybrid-proctoring-ai-flags-human-review/" rel="noopener noreferrer"&gt;ictlms.net&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The online proctoring argument is settling, and neither extreme won. Fully automated AI proctoring kept losing appeals when false positives punished anxious test takers. Pure human proctoring never scaled past a few dozen simultaneous candidates. The model that's actually spreading, reflected in this month's industry coverage, is hybrid: AI watches every exam and flags events, humans review the flags and make every judgment call. Roughly 78% of institutions now run some form of it for high-stakes assessments, and programs pairing the two layers report up to 60% fewer confirmed integrity incidents.&lt;br&gt;
The division of labor: AI never sleeps, humans never get overruled.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why AI-Only Proctoring Lost
&lt;/h2&gt;

&lt;p&gt;The automated-only approach had a seductive pitch: no scheduling, no proctor payroll, infinite scale. Its failure mode was equally simple. An algorithm that flags a gaze shift can't tell cheating from a candidate glancing at their crying toddler, and when the flag itself becomes the verdict, the false positives land on the people least equipped to fight them: anxious students, disabled test takers, anyone whose test environment isn't a silent private office.&lt;/p&gt;

&lt;p&gt;Appeals boards noticed. So did courts and regulators in several countries. The pattern across integrity disputes has been consistent: automated evidence with no human judgment attached doesn't hold up. An unreviewed AI accusation is a liability, not a safeguard.&lt;/p&gt;

&lt;p&gt;Human-only proctoring failed in the opposite direction. Live proctors watching video walls miss things after twenty minutes, cost real money per session, and cap how many candidates you can examine at once. A certification body running 5,000 exams a quarter can't staff that honestly.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the Hybrid Split Looks Like in Practice
&lt;/h2&gt;

&lt;p&gt;The working model gives each layer the job it's good at. During the exam, AI monitors everyone simultaneously: gaze patterns, additional faces in frame, tab switches, audio anomalies, copy-paste attempts. It records flagged moments with timestamps and context. Crucially, it decides nothing.&lt;/p&gt;

&lt;p&gt;After the exam, a human reviewer works through the flagged clips. Most get dismissed in seconds: a pet walked past, a candidate stretched, someone read the question aloud to themselves. The few that survive review become integrity cases with actual evidence attached: the clip, the timestamp, the reviewer's reasoning. Cases built that way survive appeals, which is the entire point.&lt;/p&gt;

&lt;p&gt;This is the architecture behind &lt;a href="https://www.ictlms.net/ai-online-exam-software/" rel="noopener noreferrer"&gt;ICT Exam's AI online exam platform&lt;/a&gt;: automated flagging during the session, a review queue afterward, and evidence bundled with every decision. We wrote about the integrity mechanics in more depth in our &lt;a href="https://www.ictlms.net/ai-proctoring-exam-integrity-2026/" rel="noopener noreferrer"&gt;AI proctoring and exam integrity&lt;/a&gt; piece; the short version is that the AI's job is attention, not judgment.&lt;br&gt;
Four decisions to make before your next exam window.&lt;/p&gt;

&lt;h2&gt;
  
  
  Running Hybrid Well: Four Decisions
&lt;/h2&gt;

&lt;p&gt;First, classify exams by stakes. Weekly quizzes don't need proctoring at all, and pretending they do wastes reviewer hours while irritating students. Save the full pipeline for finals, certifications, and admissions tests.&lt;/p&gt;

&lt;p&gt;Second, tune flag sensitivity to your review capacity, not to some ideal of total coverage. If your team can review 200 flags within 48 hours, configure thresholds that produce roughly 200 flags. An unreviewed flag is worse than no flag: it's an accusation nobody examined, sitting in a log, discoverable later.&lt;/p&gt;

&lt;p&gt;Third, publish exactly what's monitored before exam day. Candidates who know the system flags second voices will warn their families; candidates surprised by it generate false positives and file appeals. Transparency is cheap and it works. My own view: this step matters more than any threshold tuning, because most "integrity events" in anxious cohorts are really communication failures.&lt;/p&gt;

&lt;p&gt;Fourth, store evidence with verdicts. Clip, timestamp, reviewer decision, in one record. When an appeal arrives eight months later, the institution that kept the bundle wins in a week; the one that kept only a "flagged: yes" boolean settles.&lt;/p&gt;

&lt;p&gt;The market context says this gets bigger, not smaller. Online proctoring is heading toward $1.8 billion as certification and hiring assessments keep moving online. Institutions choosing platforms now should be asking one question above the feature list: when the AI flags something, who decides what happens next? If the answer isn't "a person, with the evidence in front of them," keep looking. The &lt;a href="https://www.ictlms.net/features/" rel="noopener noreferrer"&gt;ICT Exam feature set&lt;/a&gt; was built around that answer.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What is hybrid proctoring?
&lt;/h3&gt;

&lt;p&gt;A two-layer model for online exam monitoring: AI observes all candidates during the exam and flags suspicious events, then human reviewers examine each flag and decide whether it's a genuine integrity incident. The AI provides attention at scale; humans provide judgment.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why not use AI-only proctoring?
&lt;/h3&gt;

&lt;p&gt;Automated flags misread ordinary behavior, glances, background noise, nervous habits, as cheating, and those false positives disproportionately hit anxious and disabled test takers. Integrity decisions based on unreviewed AI output also fare poorly in appeals and legal challenges.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does hybrid proctoring actually reduce cheating?
&lt;/h3&gt;

&lt;p&gt;Programs pairing AI flags with human review report up to 60% fewer confirmed incidents. Part is deterrence: candidates take monitoring more seriously when they know flags are actually reviewed. Part is precision: reviewed cases stick, so consequences are real.&lt;/p&gt;

&lt;h3&gt;
  
  
  What should candidates be told before a proctored exam?
&lt;/h3&gt;

&lt;p&gt;Exactly what is monitored (camera, audio, screen activity), what triggers flags, who reviews them, and how to appeal. Publishing this before exam day reduces anxiety-driven false positives and cuts appeal volume.&lt;/p&gt;

&lt;h3&gt;
  
  
  How much human review capacity do we need?
&lt;/h3&gt;

&lt;p&gt;Plan for reviewing every flag within 48 hours, and tune AI sensitivity to match that capacity. A typical setup produces a handful of flags per hundred exam sessions once thresholds are calibrated to your cohort and exam format.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.ictlms.net/features/" rel="noopener noreferrer"&gt;ICT Exam Features&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictlms.net/ai-online-exam-software/" rel="noopener noreferrer"&gt;AI Online Exam Software&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictlms.net/ai-proctoring-exam-integrity-2026/" rel="noopener noreferrer"&gt;AI Proctoring and Exam Integrity in 2026&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictlms.net/packages/" rel="noopener noreferrer"&gt;ICT Exam Packages&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictlms.net/integrations/" rel="noopener noreferrer"&gt;LMS Integrations (LTI 1.3)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
    <item>
      <title>AI Answering Is Now a Checkbox on VoIP Plans. Service Providers Need a Stack Answer, Not a Vendor</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Sat, 25 Jul 2026 16:04:12 +0000</pubDate>
      <link>https://dev.to/tahiralmas/ai-answering-is-now-a-checkbox-on-voip-plans-service-providers-need-a-stack-answer-not-a-vendor-1419</link>
      <guid>https://dev.to/tahiralmas/ai-answering-is-now-a-checkbox-on-voip-plans-service-providers-need-a-stack-answer-not-a-vendor-1419</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://ictinnovations.com/ai-default-voip-feature-open-source-stack/" rel="noopener noreferrer"&gt;ictinnovations.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Something shifted in VoIP product pages this month, and it's easy to miss because it looks like marketing noise. Residential and business VoIP providers started listing AI answering, the virtual receptionist that takes a call, answers questions, and books the appointment, as a standard plan feature. Not an enterprise pilot, not a paid add-on. A checkbox next to voicemail. Surveys back the shift up: roughly 81% of telecom operators now use AI somewhere in their stack. For service providers, the question stopped being whether to have an AI story and became which layer of your stack it lives in.&lt;br&gt;
Two years ago AI was differentiator pricing. Now it's checkbox pricing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why the Checkbox Matters More Than the Feature
&lt;/h2&gt;

&lt;p&gt;When a capability moves from premium add-on to default expectation, the economics around it flip. Customers stop paying extra for it and start penalizing its absence. That's where AI answering is heading in VoIP: renewal conversations now include "where's your AI receptionist?" in the same breath as per-minute rates and trunk capacity.&lt;/p&gt;

&lt;p&gt;For the operators and resellers we work with, this lands on top of an older squeeze. Carrying calls has been commodity margin for a decade; the money migrated to the software wrapped around the calls: PBX features, campaign tools, analytics, portals. AI is simply the newest floor of that building, and it's being added fast enough that providers without it lose deals to providers with it, even at higher prices.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Stack Answer: Own What Lasts, Swap What Churns
&lt;/h2&gt;

&lt;p&gt;Here's the trap in responding to this with a vendor contract: the AI layer is the least stable layer in the whole stack. Models get cheaper and better quarterly. The speech-to-text engine that was state of the art in January is mid-pack by June. Weld your service to one vendor's AI and you've bolted the fastest-changing component to the slowest-changing contract.&lt;br&gt;
Four layers, two you own permanently, one you swap freely, and the data underneath it all.&lt;br&gt;
The structure that works looks like this. At the bottom, an open source telephony engine, FreeSWITCH or Asterisk, owns the SIP trunks and media. This layer barely changes year to year, which is exactly why you want to own it. We've compared the options in our &lt;a href="https://www.ictinnovations.com/comparative-analysis-of-various-open-source-sip-servers" rel="noopener noreferrer"&gt;analysis of open source SIP servers&lt;/a&gt; if you're choosing now.&lt;/p&gt;

&lt;p&gt;Above it, the application layer: the unified communications platform, dialer, PBX, or fax service your customers log into. This is your product and your billing relationship. Open source options here are mature, our roundup of &lt;a href="https://www.ictinnovations.com/open-source-voip-software-top-ip-telephony-application" rel="noopener noreferrer"&gt;open source VoIP software&lt;/a&gt; covers the field, and ICT Innovations builds its product line (ICTBroadcast, ICTDialer, ICTFax, ICTPBX) on exactly this pattern.&lt;/p&gt;

&lt;p&gt;Then the AI layer, and this is the one to keep swappable by design. Speech-to-text, the language model, text-to-speech, each behind an API boundary so that switching providers is a configuration change. The providers shipping AI receptionists as checkbox features are mostly doing it this way internally; the mistake would be building your version any other way.&lt;/p&gt;

&lt;p&gt;Underneath everything sits the layer people forget until it's gone: the data. Recordings, transcripts, call detail records. Keep them on your own infrastructure and every future AI improvement can be tuned on your actual traffic. Hand them to a platform vendor and you've given away the asset that would have differentiated you. That, more than license fees, is the strongest argument for the open source route here.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to Do This Quarter
&lt;/h2&gt;

&lt;p&gt;If you're a service provider, three moves cover most of the ground. Audit your plans against the new baseline: if competitors in your market list AI answering as standard and you don't, that gap is costing renewals now. Pick your API boundaries: decide where speech, language, and voice synthesis plug into your stack, and write the integration so the vendor name is a config value. And start logging with AI in mind: transcripts and outcomes captured cleanly today are the tuning data for whatever you deploy next year.&lt;/p&gt;

&lt;p&gt;The checkbox era of VoIP AI rewards the boring virtues: owning your telephony, keeping your data, and staying free to chase the best model each quarter. Open source has been the right answer to the first two for twenty years. It turns out to be the right answer to the third one too.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is AI answering really standard on VoIP plans now?
&lt;/h3&gt;

&lt;p&gt;Increasingly, yes. Multiple providers rolled AI receptionist features into standard business and even residential plans this year, and industry surveys put AI adoption at roughly 81% of telecom operators. It's following the same path voicemail transcription took: premium first, checkbox next.&lt;/p&gt;

&lt;h3&gt;
  
  
  What does an AI receptionist actually do?
&lt;/h3&gt;

&lt;p&gt;It answers inbound calls, handles routine questions like hours and directions, books or reschedules appointments, takes structured messages, and routes callers to humans when the request falls outside its scope. All of it runs on the same SIP infrastructure as ordinary calls.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why keep the AI layer swappable?
&lt;/h3&gt;

&lt;p&gt;Because it changes faster than any other layer. Model pricing and quality shift quarterly, so an API boundary that makes switching providers a configuration change protects you from paying last year's premium for last year's model.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can open source VoIP platforms support AI features?
&lt;/h3&gt;

&lt;p&gt;Yes. Open source engines like FreeSWITCH and Asterisk handle the call media, and AI services connect through standard APIs for speech recognition, language processing, and synthesis. The open platform approach is what keeps each piece replaceable.&lt;/p&gt;

&lt;h3&gt;
  
  
  What data should service providers keep for AI?
&lt;/h3&gt;

&lt;p&gt;Call recordings (where consent allows), transcripts, call detail records, and outcome labels like resolved or escalated. Stored on your own infrastructure, this becomes the tuning and evaluation data for every future AI feature you ship.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.ictinnovations.com/open-source-voip-software-top-ip-telephony-application" rel="noopener noreferrer"&gt;Open Source VoIP Software: Top IP Telephony Applications&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictinnovations.com/comparative-analysis-of-various-open-source-sip-servers" rel="noopener noreferrer"&gt;Comparative Analysis of Open Source SIP Servers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictinnovations.com/five-open-source-sip-libraries" rel="noopener noreferrer"&gt;Five Open Source SIP Libraries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictinnovations.com/Top-ICT-Innovations-in-2026-Transforming-Communication" rel="noopener noreferrer"&gt;Top ICT Innovations in 2026&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictinnovations.com/selecting-a-wholesale-voip-provider-for-your-buisness-needs" rel="noopener noreferrer"&gt;Selecting a Wholesale VoIP Provider&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
    <item>
      <title>CMS Says Dropping Paper Fax Saves $782 Million a Year. Paper Is the Problem, Not Fax</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Sat, 25 Jul 2026 16:01:01 +0000</pubDate>
      <link>https://dev.to/tahiralmas/cms-says-dropping-paper-fax-saves-782-million-a-year-paper-is-the-problem-not-fax-hl2</link>
      <guid>https://dev.to/tahiralmas/cms-says-dropping-paper-fax-saves-782-million-a-year-paper-is-the-problem-not-fax-hl2</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://www.ictfax.org/cms-paper-fax-phase-out-782-million-open-source/" rel="noopener noreferrer"&gt;ictfax.org&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;CMS put a price tag on paper this month: $781.98 million per year. That's what the agency projects taxpayers save as its new rule phases fax machines and postal mail out of Medicare administrative workflows. Plenty of headlines compressed that into "CMS kills the fax," which makes good copy and bad analysis.&lt;/p&gt;

&lt;p&gt;Read the rule and a different picture shows up. The target is paper: physical machines printing protected health information into open mailrooms, envelopes crossing the country for two weeks, staff re-keying faxed forms into billing systems. Digital fax, the kind an open source fax server handles as PDFs over T.38, is a different animal entirely, and it isn't going anywhere.&lt;br&gt;
CMS is retiring paper workflows; the fax protocol itself is a separate question.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why an Open Source Fax Server Survives the Paper Purge
&lt;/h2&gt;

&lt;p&gt;The healthcare system still runs an enormous volume of document exchange over fax, and the reason is stubborn: fax is the one channel every provider, payer, pharmacy, and lab can receive. FHIR APIs and EDI rails are growing, but until the last regional clinic and the last small imaging center are on them, fax remains the universal fallback. CMS knows this, which is why the rule pushes electronic alternatives rather than banning the channel.&lt;/p&gt;

&lt;p&gt;A digital fax server sits comfortably on the compliant side of that push. Documents arrive as PDFs, never touch paper, land in a queue with sender, timestamp, page count, and delivery result logged. Outbound faxes go from email, a web portal, or a &lt;a href="https://www.ictfax.org/fax-api-tutorial/" rel="noopener noreferrer"&gt;REST API&lt;/a&gt; straight into the recipient's machine or server. No mailroom, no toner, no PHI sitting in an output tray. The workflow CMS wants to eliminate simply doesn't exist in this setup.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Migration Path That Actually Works
&lt;/h2&gt;

&lt;p&gt;Most organizations can't flip to fully digital overnight, and honestly, they shouldn't try. The pattern that works runs in three stages.&lt;br&gt;
Analog to hybrid to digital: each stage keeps the fax number and drops some paper.&lt;br&gt;
Stage one is where most clinics sit today: fax machines on analog lines, paper everywhere. Stage two bridges the gap. An ATA (analog telephone adapter) lets the old machines keep working while a fax server starts receiving inbound faxes as PDFs. Staff who love the physical machine keep it; everyone else gets email delivery. Numbers stay the same, workflows change gradually.&lt;/p&gt;

&lt;p&gt;Stage three drops the analog lines entirely. Faxing runs over SIP trunks with &lt;a href="https://www.ictfax.org/open-source-faxing-software-based-on-t-38-protocol/" rel="noopener noreferrer"&gt;T.38&lt;/a&gt;, the protocol built specifically to carry fax reliably across IP networks. Per-line telco charges disappear, every page is logged, and the fax server integrates with the EHR through its API. At that point your "fax" is really a structured document pipeline that happens to speak a protocol every healthcare organization on earth can receive.&lt;/p&gt;

&lt;p&gt;Self-hosting matters more here than most write-ups admit. Cloud fax services work, but they put a third party and its BAA between you and your PHI. Run the server yourself and the documents never leave your infrastructure. For a small IT team, that's one less vendor risk assessment, one less breach-notification dependency, and no per-page fees scaling against you.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to Do Before the Deadlines Arrive
&lt;/h2&gt;

&lt;p&gt;The CMS rule pairs with the claims-attachment standards finalized earlier this year, and both point the same direction: electronic first, paper gone, everything auditable. If your fax estate is still analog, start the hybrid stage now while there's no deadline pressure. Port the numbers to SIP DIDs, stand up a fax server, and let the paper fade out one department at a time. Waiting until compliance letters arrive means doing the same migration on someone else's schedule.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is CMS banning fax machines?
&lt;/h3&gt;

&lt;p&gt;No. The rule phases paper-based fax and mail out of Medicare administrative workflows to cut costs, projected at $781.98 million per year. Electronic document exchange, including digital fax over T.38, remains fully acceptable.&lt;/p&gt;

&lt;h3&gt;
  
  
  What's the difference between paper fax and digital fax?
&lt;/h3&gt;

&lt;p&gt;Paper fax prints documents on physical machines over analog lines. Digital fax sends and receives the same transmissions as PDF files through a fax server over IP, with full logging and no paper output. The protocol is compatible; the workflow is completely different.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is a self-hosted fax server HIPAA compliant?
&lt;/h3&gt;

&lt;p&gt;It can be, and self-hosting simplifies the picture: PHI stays on your own server, so no third-party cloud fax vendor needs a BAA for the core fax path. You still need encryption in transit, access controls, and audit logging, which a properly configured server provides.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is T.38 and why does it matter?
&lt;/h3&gt;

&lt;p&gt;T.38 is the protocol for carrying fax over IP networks. Plain audio codecs mangle fax tones, causing failed pages. T.38 relays the fax data digitally, making fax over SIP trunks reliable enough to replace analog lines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I keep my existing fax numbers when moving to a fax server?
&lt;/h3&gt;

&lt;p&gt;Yes. Fax numbers port to SIP DIDs the same way voice numbers do. Inbound faxes then arrive at your server instead of an analog line, and senders notice nothing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.org/ictfax-installation-guide/" rel="noopener noreferrer"&gt;ICTFax Installation Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.org/open-source-faxing-software-based-on-t-38-protocol/" rel="noopener noreferrer"&gt;Open Source Faxing Software Based on T.38&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.org/fax-api-tutorial/" rel="noopener noreferrer"&gt;Fax API Tutorial&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.org/fax-services-email-to-fax-software-fax-to-email-server/" rel="noopener noreferrer"&gt;Email to Fax and Fax to Email Services&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.org/download-ictfax/" rel="noopener noreferrer"&gt;Download ICTFax&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
    <item>
      <title>The Claims Attachment Rule Is Final: E-Signature Standards, the 2028 Deadline, and Your Fax Workflow</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Sat, 25 Jul 2026 15:57:44 +0000</pubDate>
      <link>https://dev.to/tahiralmas/the-claims-attachment-rule-is-final-e-signature-standards-the-2028-deadline-and-your-fax-workflow-2hja</link>
      <guid>https://dev.to/tahiralmas/the-claims-attachment-rule-is-final-e-signature-standards-the-2028-deadline-and-your-fax-workflow-2hja</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://www.ictfax.com/hipaa-claims-attachment-rule-2028-fax-workflow/" rel="noopener noreferrer"&gt;ictfax.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The waiting is over. CMS published the final HIPAA claims attachment rule in the Federal Register on March 24, 2026, it took effect on May 26, and every covered entity now has until May 26, 2028 to comply. The rule sets national standards for electronic claims attachments and, for the first time, electronic signatures on those attachments. If your organization moves clinical documents by fax, this rule doesn't kill that workflow. It does raise the bar for what your fax platform has to prove.&lt;br&gt;
Publication, effective date, and the 2028 compliance deadline: two years of runway.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the Rule Actually Requires
&lt;/h2&gt;

&lt;p&gt;Claims attachments are the supporting documents payers request before adjudicating a claim: clinical notes, imaging reports, lab results, operative summaries. Until now there was no national standard for sending them electronically, so the industry defaulted to mail and fax, and payers pended millions of claims waiting on paper.&lt;/p&gt;

&lt;p&gt;The final rule names the X12 275 transaction and HL7 CDA templates as the standards for transmitting attachments, and it adopts e-signature standards so a payer can verify who signed a document and that nobody altered it afterward. Health plans, clearinghouses, and providers who transact electronically all fall under it.&lt;/p&gt;

&lt;p&gt;Here's the part that matters for fax users: the rule standardizes how attachments travel between systems that both speak X12. It doesn't outlaw other channels. A huge share of attachment requests will keep flowing to organizations that won't have 275 capability by 2028, and for those exchanges, secure digital fax remains the workhorse. What changes is the definition of acceptable. A fax machine spitting PHI into an open tray with no audit trail was always risky. After 2028, with payers auditing attachment workflows against the new standards, it becomes indefensible.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where HIPAA Compliant Fax Software Fits
&lt;/h2&gt;

&lt;p&gt;Think of the post-2028 attachment landscape as two lanes. Lane one is the X12 275 rail between systems that both support it. Lane two is everything else, and lane two is where a modern fax server earns its keep.&lt;br&gt;
The attachment path from provider to payer, and what the fax layer must provide by May 2028.&lt;br&gt;
The requirements aren't mysterious. Encryption in transit, whether that's TLS on the SIP leg carrying T.38 or HTTPS on the API path. Encrypted storage at rest. A per-document audit trail that records who sent what, when, to whom, and whether it arrived. And integration hooks, because the rule's whole point is killing manual re-keying: your billing system should attach documents through an &lt;a href="https://www.ictfax.com/fax-rest-api-guide.html" rel="noopener noreferrer"&gt;API&lt;/a&gt;, not a staff member standing at a machine.&lt;/p&gt;

&lt;p&gt;ICTFax was built for exactly this shape of workflow. It's a &lt;a href="https://www.ictfax.com/freeswitch-based-fax-server/" rel="noopener noreferrer"&gt;FreeSWITCH based fax server&lt;/a&gt; that moves documents as PDFs over T.38, logs every transmission with timestamps and delivery results, and exposes a REST API so attachments flow programmatically from the systems that generate them. No paper stage, no output tray, no gap in the audit trail.&lt;/p&gt;

&lt;p&gt;My honest read on the two-year runway: it's generous, and that's a trap. The organizations that got burned by past HIPAA transaction deadlines were the ones that treated the runway as a snooze button. Mapping your attachment workflow takes a week. Doing it in 2026 means 2027 is for testing and 2028 is boring. Doing it in early 2028 means paying rush rates to consultants.&lt;/p&gt;

&lt;h2&gt;
  
  
  A Practical Checklist for the Next Six Months
&lt;/h2&gt;

&lt;p&gt;Start with an inventory. List every point where clinical documents leave your organization for a payer, and note the channel: portal upload, mail, fax, clearinghouse. Most groups find fax carries more volume than anyone guessed.&lt;/p&gt;

&lt;p&gt;Then grade the fax layer. Analog machines on POTS lines fail the audit-trail test outright. Cloud fax services pass technically but park your PHI with a third party. A self-hosted fax server passes the technical tests and keeps documents on your own infrastructure, which shortens the vendor-risk section of your next security review. You can &lt;a href="https://www.ictfax.com/demo/" rel="noopener noreferrer"&gt;try a live demo&lt;/a&gt; to see the logging and API side before committing anything.&lt;/p&gt;

&lt;p&gt;Finally, talk to your top five payers about their 275 timelines. If a payer that sends you a third of your attachment requests will support X12 275 by 2027, plan that integration. For the long tail that won't, make sure the fax path is encrypted, logged, and API-driven. That combination, not any single channel, is what compliance will look like.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What is the HIPAA claims attachment rule?
&lt;/h3&gt;

&lt;p&gt;It's the CMS final rule adopting national standards for electronic claims attachments (X12 275 with HL7 CDA documents) and electronic signatures. It was published March 24, 2026, took effect May 26, 2026, and sets a compliance deadline of May 26, 2028 for HIPAA covered entities.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does the rule ban fax for claims attachments?
&lt;/h3&gt;

&lt;p&gt;No. It standardizes electronic attachment transactions between systems that support them. Fax remains a lawful channel, but the practical expectation shifts to secure digital fax with encryption, audit logs, and delivery confirmation rather than paper machines.&lt;/p&gt;

&lt;h3&gt;
  
  
  What makes fax software HIPAA compliant?
&lt;/h3&gt;

&lt;p&gt;Encryption in transit and at rest, role-based access controls, per-document audit logging with delivery confirmation, and secure storage. Self-hosting adds control: PHI stays on your infrastructure instead of a cloud vendor's.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is an X12 275 transaction?
&lt;/h3&gt;

&lt;p&gt;It's the standard electronic envelope for sending additional documentation that supports a claim, carrying HL7 CDA clinical documents inside. The new rule makes it the named standard for attachment exchange between capable systems.&lt;/p&gt;

&lt;h3&gt;
  
  
  What should healthcare organizations do before May 2028?
&lt;/h3&gt;

&lt;p&gt;Inventory every attachment exit point, upgrade any analog fax to a logged digital fax server, ask major payers for their X12 275 timelines, and wire attachments into the billing system through an API so nothing depends on manual handling.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.com/freeswitch-based-fax-server/" rel="noopener noreferrer"&gt;FreeSWITCH Based Fax Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.com/fax-rest-api-guide.html" rel="noopener noreferrer"&gt;Fax REST API Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.com/packages-pricing/" rel="noopener noreferrer"&gt;Packages and Pricing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.com/user-guide/" rel="noopener noreferrer"&gt;ICTFax User Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictfax.com/demo/" rel="noopener noreferrer"&gt;Request a Demo&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
    <item>
      <title>The FCC's Revoke-All Waiver Won't Save You. Build Your Dialer's Opt-Out Logic for the Full Rule</title>
      <dc:creator>Tahir Almas</dc:creator>
      <pubDate>Sat, 25 Jul 2026 15:54:50 +0000</pubDate>
      <link>https://dev.to/tahiralmas/the-fccs-revoke-all-waiver-wont-save-you-build-your-dialers-opt-out-logic-for-the-full-rule-409e</link>
      <guid>https://dev.to/tahiralmas/the-fccs-revoke-all-waiver-wont-save-you-build-your-dialers-opt-out-logic-for-the-full-rule-409e</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://www.ictdialer.com/fcc-revoke-all-consent-auto-dialer-opt-out/" rel="noopener noreferrer"&gt;ictdialer.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A quiet piece of FCC housekeeping this year deserves more attention than it got. The agency's revoke-all consent rule, in force since April 2025, says that when a contact revokes consent in any reasonable way, that revocation applies broadly, across your campaigns and channels, and you have ten business days to honor it. Industry groups won a limited waiver on the trickiest cross-channel piece, and the FCC extended that waiver in January. Plenty of outbound teams read the extension as a reprieve. That's the wrong read. Waivers expire; architecture is forever. If your auto dialer's opt-out handling can't already do the full rule, the extension is the time you've been given to fix it.&lt;br&gt;
One revocation, any channel, ten business days: the rule in one picture.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Revoke-All Actually Demands
&lt;/h2&gt;

&lt;p&gt;Three parts of the rule bite hardest for anyone running dialing campaigns. First, revocation counts in "any reasonable manner." A texted STOP, a spoken "take me off your list" mid-call, an email reply, a message through your website. You don't get to insist people use your designated opt-out channel.&lt;/p&gt;

&lt;p&gt;Second, the revocation reaches sideways. A STOP reply to a text message doesn't just kill texts; under the rule's full scope it revokes consent for the calls tied to that same consent too. This cross-channel reach is exactly what the waiver temporarily softens, and exactly what returns when the waiver lapses.&lt;/p&gt;

&lt;p&gt;Third, the clock is short. Ten business days from revocation to suppression, everywhere. If your opt-outs travel from an SMS platform to a spreadsheet to a monthly list scrub, you're structurally unable to comply, and with TCPA statutory damages running $500 to $1,500 per violating call or text, a leaky opt-out pipeline is the most expensive plumbing problem in outbound calling.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Architecture That Passes an Audit
&lt;/h2&gt;

&lt;p&gt;The fix isn't a policy document. It's four layers of dialer plumbing, and they're all buildable today.&lt;br&gt;
Capture everywhere, store once, filter at dial time, log everything.&lt;br&gt;
Capture on every channel. Your IVR needs a press-to-opt-out branch on every outbound campaign. Your SMS side needs STOP keyword handling. Your agents need a one-click disposition code that means "revoked consent," because a verbal request buried in call notes is a lawsuit waiting for discovery.&lt;/p&gt;

&lt;p&gt;One global DNC store. This is where most setups fail. Opt-outs recorded per campaign leave the contact live in the other nine campaigns, which is precisely what revoke-all prohibits. Every capture path must write to a single suppression list that every campaign reads.&lt;/p&gt;

&lt;p&gt;Filter at dial time. Scrubbing lists at import isn't enough, because a contact who opts out on Tuesday morning is still sitting in the batch you imported Monday. The dialer should check the suppression store as it builds each calling batch, so revocations take effect in hours, not at the next import.&lt;/p&gt;

&lt;p&gt;Log with timestamps. When the revocation arrived, through which channel, and when suppression applied. In a TCPA dispute, that log is the difference between a dismissed claim and a settlement negotiation.&lt;/p&gt;

&lt;p&gt;This is a place where &lt;a href="https://www.ictdialer.com/10-best-open-source-auto-dialer-software-solutions/" rel="noopener noreferrer"&gt;open source auto dialer software&lt;/a&gt; holds a real edge. When the DNC logic is code you can read and extend, wiring every capture path into one suppression store is an afternoon of configuration, not a feature request in a vendor's backlog. ICTDialer's &lt;a href="https://www.ictdialer.com/ictdialer-the-ultimate-freeswitch-based-open-source-auto-dialer-software-for-call-automation-solution/" rel="noopener noreferrer"&gt;FreeSWITCH based architecture&lt;/a&gt; keeps campaign control, contact lists, and DNC handling in one platform, so the opt-out captured by the IVR is the same record the next dialing batch checks.&lt;/p&gt;

&lt;h2&gt;
  
  
  Do This Before the Waiver Lapses
&lt;/h2&gt;

&lt;p&gt;Run a simple drill this month. Text STOP to one of your own campaigns, then check how long that number stays dialable in your voice campaigns. If the answer is "until someone runs the monthly scrub," you've found your project. Then trace every place an opt-out can enter: SMS, IVR, agent, email, web form, and confirm each one lands in the same suppression store the dialer reads at batch time.&lt;/p&gt;

&lt;p&gt;The teams treating the waiver extension as extra runway to build are going to cruise through its expiration. The teams treating it as permission to wait are betting their margins on the FCC extending it forever. Regulators rarely do.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What is the FCC revoke-all consent rule?
&lt;/h3&gt;

&lt;p&gt;Effective April 2025, it requires callers to honor consent revocation made in any reasonable manner within ten business days, with the revocation applying across the campaigns and channels tied to that consent rather than just the one where it was received.&lt;/p&gt;

&lt;h3&gt;
  
  
  What did the FCC waiver change?
&lt;/h3&gt;

&lt;p&gt;The waiver, extended in January 2026, temporarily delays the cross-channel scope, the requirement that an opt-out on one channel revokes consent on others. The core rule still applies, and the full scope returns when the waiver expires.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I send a message asking what the person meant?
&lt;/h3&gt;

&lt;p&gt;Yes, one. The rule permits a single clarification message asking whether the revocation covers all message types, provided it contains no marketing. Silence means treat the revocation as covering everything.&lt;/p&gt;

&lt;h3&gt;
  
  
  How fast must an opt-out reach my dialer?
&lt;/h3&gt;

&lt;p&gt;Legally, within ten business days. Practically, aim for same-day: dial-time filtering against a global suppression list closes the gap between a morning opt-out and an afternoon call, which batch scrubbing can't.&lt;/p&gt;

&lt;h3&gt;
  
  
  What are the penalties for getting this wrong?
&lt;/h3&gt;

&lt;p&gt;TCPA claims carry statutory damages of $500 per violation, tripled to $1,500 for willful violations, per call or text. Class actions aggregate those quickly, which is why audit logs of revocation handling matter as much as the suppression itself.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.ictdialer.com/10-best-open-source-auto-dialer-software-solutions/" rel="noopener noreferrer"&gt;10 Best Open Source Auto Dialer Software Solutions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictdialer.com/ictdialer-the-ultimate-freeswitch-based-open-source-auto-dialer-software-for-call-automation-solution/" rel="noopener noreferrer"&gt;ICTDialer: FreeSWITCH Based Open Source Auto Dialer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictdialer.com/free-auto-dialer-software-the-best-free-dialers-for-outbound-sales/" rel="noopener noreferrer"&gt;Free Auto Dialer Software for Outbound Sales&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictdialer.com/webrtc/" rel="noopener noreferrer"&gt;WebRTC in ICTDialer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ictdialer.com/10-best-open-source-unified-communications-software-solutions/" rel="noopener noreferrer"&gt;10 Best Open Source Unified Communications Solutions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
    </item>
  </channel>
</rss>
