Signal without a Business Associate agreement to handle PHI would be either be considered limited/incidental or as a conduit and not on the hook for PHI data going through them incidentally the risk would stay with the entities using it not Signal itself (and certainly not absolved).
Secondly it doesn't matter if data was only "in flight" when leaked and not stored. I.e. the availability of the protected information is what is regulated.
Thirdly Signal DOES store user data for up to quite a long time as it proxies the delivery of messages, just in an encrypted form (a plus for meeting requirements though) it's not supposed to be able to read and supposedly deletes it after it no longer needs to hold onto it.
Finally if someone hacked the Signal servers and a bug in the encryption was found or you forgot to check the conversation verification code and were being MITMd then it's still a violation anyways. That is you're good until you aren't - the encryption only protects you while it worked not because you tried (though if it is found you didn't have any encryption on some data that in itself is a fineable offense).
[1] https://www.cms.gov/Regulations-and-Guidance/Administrative-...