← Back to BlogCompliance

When a Third Party Answers Your Patient Calls, HIPAA Has Already Started

VoxBrook Team · 5 min read

Practices tend to think of HIPAA as something that governs the EHR and the fax machine. It also governs the phone — specifically, what happens when someone outside the practice answers it.

The answering service is a business associate

Protected health information isn't just diagnoses and lab results. A person's name, connected to the fact that they are a patient of your practice, is PHI on its own. An answering service that takes a call, hears "this is Jane Smith, I'm a patient of Dr. Lee, and I need to reschedule" has received PHI.

Under the HIPAA Privacy Rule, a person or company that creates, receives, maintains, or transmits PHI to perform a function on behalf of a covered entity is a business associate (45 CFR 160.103). An answering service doing intake, scheduling, or after-hours triage fits that definition. There is no exception for low call volume, and no exception for "they only take messages."

A signed BAA has to come first

HIPAA requires a covered entity to obtain satisfactory assurances, in the form of a written business associate agreement, that the business associate will appropriately safeguard PHI — before disclosing PHI to it (45 CFR 164.502(e), 164.504(e)).

In practice: the BAA is signed before calls start routing, not backfilled after go-live. If a service can't produce a BAA for your review during the evaluation, that's the end of the evaluation.

The required elements of a BAA are set by regulation. Among other things, it must establish the permitted uses and disclosures of PHI, require the business associate to use appropriate safeguards, require it to report any use or disclosure not provided for by the contract (including breaches), require it to ensure any subcontractors agree to the same restrictions, and require return or destruction of PHI when the arrangement ends. HHS publishes sample provisions covering all of it.

The subcontractor question is where "US-based" becomes a compliance issue

If the answering service uses any subcontractor that could encounter PHI — an overflow partner, an offshore team, a vendor that stores call recordings — HIPAA requires the service to have its own BAA with that subcontractor, on terms at least as protective as yours (45 CFR 164.308(b)).

This is a concrete question to ask, not a philosophical one: Does any call, recording, or message ever reach a person or system outside the United States? If so, what BAA covers them? A vague answer is an answer.

Minimum necessary applies to the script

HIPAA's minimum-necessary standard means the service should collect and transmit only the PHI the task requires. A message that a patient called about a billing question doesn't need their diagnosis attached. This is a reason to design your intake script with the service rather than accept a generic one — the script is where minimum-necessary either gets built in or doesn't.

What to actually verify

  • A signed BAA, in place before any call routes, reviewed against the HHS required-elements list.
  • Written confirmation the service holds BAAs with every subcontractor that could touch PHI.
  • A clear answer on whether PHI ever leaves the US.
  • Encryption of call recordings and message logs, at rest and in transit.
  • Access controls and access logging for your account's data.
  • A breach-notification timeline in the BAA that meets or beats the 60-day regulatory maximum.
  • A configurable retention period for call recordings — indefinite retention of recorded PHI is a liability, not a feature.

The takeaway

The moment a third party answers a patient call, you've made a disclosure of PHI. HIPAA treats that as a formal relationship with paperwork attached. Getting the BAA and the subcontractor chain right before go-live is straightforward; discovering the gap during a complaint investigation is not.


This is general information, not legal advice — confirm specifics with your compliance counsel. VoxBrook signs BAAs for healthcare clients and puts one in place before any call routes. See our HIPAA + TCPA vendor checklist or talk to our team.

Free Resource
The HIPAA + TCPA Answering-Service Vendor Checklist
What a healthcare practice has to verify before a third party answers its patient calls — and the two federal rules that decide it.
Read it →

Losing calls you shouldn't be?

Tell us about your call volume and we'll put together a quote.

Get a Quote

Or read more about Medical & Dental Practices.