All articles
Compliance 9 min read

The HIPAA-Compliant Answering Service: What to Require Before You Sign

A vintage switchboard console and headset on a dark desk at night, a sealed glass tube curving away from it carrying glowing envelopes toward a lit doorway

Short answer: An answering service that handles patient calls is a business associate, so it must sign a BAA before it takes a single message. Operators should collect the minimum necessary — name, callback number, urgency — and every message must land inside a covered system, not in a personal inbox or an unsecured text to the on-call provider.

Most practices buy an answering service the way they buy a fire extinguisher: quickly, under pressure, after something went wrong. Somebody missed an urgent call on a Saturday, the practice signed up on Monday, and nobody asked the compliance questions because the sales page said "HIPAA compliant" in the header.

That phrase is not a certification. There is no government body that inspects answering services and issues a HIPAA badge — the vendor is simply telling you they believe they can meet the requirements. Sometimes that is true. Sometimes it means they bought an encrypted portal and never trained the overnight operators. The difference lands on you, because when a business associate mishandles your patients' information, it is still your practice's breach to report.

This is the compliance half of the after-hours decision. The cost half — what answering services, voicemail, and AI answering actually charge, per resolved call — is in our after-hours answering comparison. The full channel-by-channel rulebook lives in the HIPAA-compliant communications guide.

Your answering service is a business associate

This is the one structural fact that generates every requirement below. A business associate is any outside party that creates, receives, maintains, or transmits protected health information on your behalf. An answering service that picks up your patients' calls does all four in the first thirty seconds of its first shift.

So the sequence is not negotiable: the signed BAA comes before the first forwarded call, not after the trial. A vendor that wants to run a two-week pilot on live patient calls while legal reviews the agreement is asking you to route PHI to an uncovered third party for two weeks. The answer is that they can have the pilot after the signature, or you can pilot with internal test calls.

One question practices routinely forget to ask: who else touches the data? Answering services subcontract — overflow centers during peak hours, offshore night desks, transcription tools, the cloud platform the message portal runs on. Business associates are required to bind their own subcontractors to equivalent protections, and you are entitled to ask what that chain looks like. "We handle everything in house" is a fine answer. So is a clear list. A vendor that cannot describe its own subcontractors has not thought about this.

What an operator may actually write down

This is the question practices most often ask and vendors most often answer vaguely: what is the person on the overnight desk allowed to collect about a patient?

The governing idea is the same minimum-necessary standard that shapes every other channel. The operator's job is to route the call correctly, not to document the visit. Almost every message can be handled well with four fields.

  • Caller's name and callback number. The two fields that make everything else recoverable. Get the number twice.
  • Whether the caller is the patient, and if not, who they are. This decides what the returning clinician may discuss when they call back — the rules for that conversation are in who am I allowed to talk to?
  • Urgency, by your script's categories — not by the operator's medical judgment. "Caller says chest pain" is a routing fact; "caller is probably having a cardiac event" is a clinical opinion an answering service should never render.
  • A short reason for the call, in the caller's words. Enough for the on-call provider to prioritize, not a symptom narrative. "Question about medication started yesterday" beats three paragraphs.

The corollary matters as much: operators should not be prompting for detail the practice does not need. A well-designed script does not ask for a date of birth, an insurance ID, a medication list, or a symptom history, because collecting those creates a store of sensitive information sitting in a vendor's system to serve no routing purpose. If a caller volunteers all of it anyway — and they will — that is fine and unavoidable. The test is whether the script solicits it.

Ask to see the actual intake script before you sign, and ask to change it. A vendor that treats its script as fixed is telling you the same script serves an HVAC company and a psychiatry practice, which is exactly the problem.

Where the message goes is the whole ballgame

You can run a perfectly disciplined intake script and still fail here, and this is where most real incidents happen. The message gets taken correctly, then delivered carelessly.

  • Plain SMS to a provider's personal cell. The most common after-hours pattern in medicine, and the least defensible. Patient information now lives on a personal device with no access control, no wipe capability, and no way to retrieve it when that provider leaves the practice.
  • Email to a personal or non-covered inbox. Same failure, longer retention. Messages forwarded to a personal address are outside the boundary and effectively permanent.
  • A portal nobody opens. The compliant option that fails operationally. If the on-call provider has to log into a web portal at 2 AM, they will ask the service to text them instead within a week, and your compliant architecture quietly reverts to the one above.
  • A secure notification that pulls the provider into a covered app. This is the pattern that survives contact with real humans: the alert contains no PHI, the content lives inside the platform, and the callback goes out through the business number so the provider's personal number is never exposed. Our cloud voice handling works this way.

Test this before you sign, not after. Place a call to the service pretending to be an urgent patient, then look at exactly what arrives on the on-call phone and where it is stored. If the full message text appears in a plain SMS preview on a lock screen, you have your answer, and it does not matter what the contract says.

The recorded-line question

Most answering services record their calls for quality and dispute purposes. Those recordings contain everything the caller said, which is frequently far more than the four fields above. That is not automatically a problem, but it is a decision you should make deliberately rather than discover later.

Three things to establish in writing: how long recordings are kept, who at the vendor can replay them, and whether recordings are used to train staff or any automated system. The state-law layer on recording — one-party versus all-party consent, and the announcement your callers hear — is a separate regime from HIPAA with its own rules, and we walk through it in recording patient calls.

The eight questions, in writing

Send these to any answering service or AI answering vendor before signing. The point is less the answers than the response: a healthcare-ready vendor answers all eight in a day, and a vendor that treats the list as unusual has told you something useful.

  1. 1.Will you sign our BAA, unmodified, before any live patient calls route to you?
  2. 2.Which subcontractors, overflow centers, or platforms touch our messages, and are they bound to equivalent terms?
  3. 3.Can we see and edit the intake script your operators read for our account?
  4. 4.Exactly how is a message delivered to our on-call provider, and what appears on their phone before they authenticate?
  5. 5.Are calls recorded, how long are recordings and transcripts retained, and who can access them?
  6. 6.Are our calls, transcripts, or recordings used to train models or improve your product?
  7. 7.What access controls and audit logs exist, and can we get a report of who viewed our messages?
  8. 8.What is your breach notification process and timeline to us?

Question six deserves particular attention if you are evaluating an AI answering service rather than a human one. An AI receptionist hears everything a human operator hears and stores it in a form that is trivially searchable, so "is our patient data used for training" is not a theoretical question. The rest of the AI-specific diligence — what the system refuses to discuss, where transcripts live — is covered in the AI answering section of the communications compliance guide, and our own answer is on the healthcare page, including which plans carry a BAA.

What good looks like

A compliant after-hours setup for a practice is not exotic. Emergencies are told to hang up and dial 911 before anything else. Urgent clinical calls route to the on-call provider through the business number. Everything else — reschedules, hours, refill requests, which is most of the volume — is captured as a structured message or handled outright. Messages land inside one covered system, the same one your staff already uses in the morning. Nothing important depends on somebody remembering to forward something.

Notice that this is the same architecture that stops you missing calls in the first place. The compliance requirements and the revenue requirements point at the same design, which is the useful thing about this whole topic — the guide to the operational side is never miss a call again, and the voicemail scripts that sit underneath it are in HIPAA voicemail rules.

Two things sit outside this page's scope and are worth naming. If you are weighing an AI receptionist rather than a human service, the capability question — what these systems can actually resolve versus route — is covered by our sister company at AI voice agents for business. And the practice-wide compliance program that the answering service plugs into — risk assessments, EHR security, breach response — is IT territory: the HIPAA compliance guide for healthcare IT.

Frequently asked questions

Does an answering service need to sign a BAA?
Yes. An answering service that receives patient calls creates, receives, and transmits protected health information on the practice's behalf, which makes it a business associate. The agreement should be signed before any live patient calls are routed to the vendor.

What information can an answering service take from a patient?
The minimum needed to route the call: the caller's name and callback number, whether they are the patient, the urgency level per your script, and a brief reason in the caller's own words. Scripts should not solicit dates of birth, insurance identifiers, medication lists, or symptom histories, because none of that is needed to get the call to the right person.

Can the answering service text messages to my personal cell phone?
Plain text messages containing patient details to a personal device put PHI on an uncontrolled system with no access controls or remote wipe. The workable pattern is a notification containing no patient information that opens a covered app, with callbacks placed through the business number so personal numbers stay private.

Is an AI answering service HIPAA compliant?
It can be, on the same terms as a human service: a signed BAA, controlled and logged access to transcripts, a clear answer on whether patient data trains models, and defined limits on what the system will discuss rather than improvise. The technology is not the deciding factor; the contract and the data handling are.

Who is responsible if the answering service causes a breach?
Both parties have obligations, but the practice cannot outsource its accountability to patients or regulators. That is precisely why the diligence questions and the signed agreement matter before the first call, rather than being treated as paperwork to finish later.

The compliant after-hours setup and the one that stops losing patients are the same build. Our pricing is public, and the plans that carry a BAA are marked on the healthcare page.

Ready to stop overpaying for dial tone?

Get the whole platform — voice, text, video, AI — from $14.99 per user. Set up today, port your number free, cancel whenever. Talk is cheap; switching is even cheaper.