HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this wholly insecure connection? Who cares! Just don't let the auditor near our PBX.
Sadly, the HTTPS and IPv6 anti-vaxxer crowd is strong in the VOIP community, if it isn't severely painful to the VOIP company themselves, they aren't going to secure it. Not that they'd secure it properly anyway, even if their livelihoods depended on it...