Free Resource

The HIPAA + TCPA Answering-Service Vendor Checklist

What a healthcare practice has to verify before a third party answers its patient calls — and the two federal rules that decide it.

When an answering service takes calls for a medical or dental practice, it is almost always handling protected health information — a patient's name tied to the fact that they're a patient is PHI on its own. That makes the answering service a business associate under HIPAA, and it triggers a specific set of requirements before the first call is ever routed.

Separately, if the answering service places calls or sends texts on the practice's behalf — appointment reminders, callbacks, dispatch confirmations — the Telephone Consumer Protection Act applies to how and when that contact happens.

This checklist walks the questions a practice should ask, grouped by which rule drives them. The free sections cover when a BAA is required and what it has to say. The rest covers TCPA, the security questions behind the BAA, and the contract terms that matter.

1. A business associate agreement is required, not optional

HIPAA requires a covered entity to have a written business associate agreement in place before disclosing PHI to a business associate. An answering service that hears patient names, reasons for calling, or appointment details is a business associate. There is no small-volume exception and no 'they only take messages' exception.

The BAA has to be signed before calls start routing, not backfilled later. If a service can't produce a BAA for your review during evaluation, that is the end of the evaluation.

The required elements of a BAA are specified by regulation — it must, among other things, establish the permitted uses of PHI, require the business associate to safeguard it, require reporting of any breach or improper use, and require return or destruction of PHI when the arrangement ends.

Verify
Ask each service you're evaluating to send their standard BAA. Read it against the HHS list of required elements linked in the sources.

2. The BAA has to bind the service's own subcontractors

If the answering service uses any subcontractor that will encounter PHI — an overflow partner, an offshore team, a software vendor that stores call recordings — HIPAA requires the service to have its own BAA with that subcontractor, on terms at least as protective as yours.

This is where 'US-based' matters as a compliance question and not just a quality one. Ask directly: does any call, recording, or message ever reach a person or system outside the US, and if so, what BAA covers them.

Verify
Ask: 'List every subcontractor that could encounter our patients' information, and confirm you hold a BAA with each.' A vague answer is an answer.

3. Minimum necessary applies to what the agent collects and passes on

HIPAA's minimum-necessary standard means the answering service should collect and transmit only the PHI needed for the task. A message that a patient called about a billing question doesn't need their diagnosis in it.

This should show up in how your intake script is written — it's a reason to design the script with the service rather than accept a generic one.

3 more sections

Keep reading — no download required

The rest of this — the remaining sections, the full checklist, and the sources — opens right here on the page. One email, no PDF, no mailing list.

One email to open the rest of this page. We won't add you to a mailing list or share it — see our privacy policy.

Rather have someone run the phones instead of writing the protocol? That's what we do.

Medical & Dental Practices answering · Talk to our team

This resource references dated regulatory material. Last reviewed against its sources for the 2027-02-28 revision cycle.