« Back To All Blog Articles

What makes an answering service HIPAA compliant? Checklist

| Greetmate

What makes an answering service HIPAA compliant? Checklist

When a practice hands its phones to an outside service, HIPAA still treats every patient call as the practice's responsibility. You can outsource the ringing; you keep the liability for what happens on those calls. Picking a HIPAA compliant answering service is due diligence the covered entity cannot skip.

The stakes are not abstract. Business associates are involved in roughly one in three reported healthcare breaches, and third-party involvement in those breaches doubled from 15% to 30% in a single year. Separately, operating without a required BAA is itself a HIPAA violation, breach or no breach.

Most of what ranks for this topic was written by the medical answering services themselves: four bullets about encryption, then a pitch. This guide is written from the practice's side of the table. It covers what to verify before signing: the BAA, the subcontractor chain, and how PHI moves through texts, voicemail, and recordings. It ends with ten questions you can copy into an email or read straight into a vendor call.

Key Takeaways:

  • If a service touches patient information on your behalf, it is a business associate. A signed BAA is required before it takes a single call.
  • A BAA does not shift your liability to the vendor. The practice answers for the vendors it chooses.
  • Standard texting is not banned, but it is not automatically compliant either.
  • Every subcontractor in the chain — telephony, hosting, transcription — needs its own downstream BAA.
  • Vetting continues after signing: re-review the BAA annually, request access logs, and run test calls.

Table of Contents

Does your answering service even need to be HIPAA compliant?

Yes, with one carve-out that will not help you. If your answering service takes messages with patient names, routes calls about appointments, or stores any patient information on your behalf, it is a business associate under HIPAA. A signed BAA is required before it handles a single call, and the practice keeps responsibility for how that vendor handles PHI.

HIPAA has a narrow conduit exception for services that move data without accessing or storing it, such as postal mail or an internet provider. Answering services do not qualify. They read messages, keep transcripts, route calls based on what callers say, and often store recordings. That persistent access to patient information is what makes the vendor a business associate.

In practice the question settles itself fast. The moment a message pairs a patient name with an appointment reason, a callback number tied to a chart, or a question about a refill, protected health information is in the vendor's hands. Even a service that claims to take "just names and numbers" usually handles PHI, because the context makes the information identifiable.

A BAA is the entry ticket: here's what should be inside it

Every vendor page says "we'll sign a BAA." That is the entry ticket, and it is the bare minimum. What separates a real agreement from a signature page is what the document obligates the vendor to do. Four things belong in it:

Permitted uses, spelled out. The BAA should list exactly what the vendor may do with PHI: answer calls, take messages, relay them to your staff, support scheduling. Anything not listed is off-limits. Watch for language like "as needed to provide services."

Subcontractor flow-down. Your BAA with the vendor does not automatically bind the vendor's own vendors. The terms do not travel down the chain on their own — a separate downstream agreement must exist before any subcontractor touches PHI. Your BAA should require the vendor to maintain those agreements and notify you when the list changes.

A breach notification window with a number in it. A practice must notify affected patients within 60 days of discovering a breach. Well-drafted contracts put the vendor's obligation at 24 to 48 hours so your team has room to run that clock. If the draft says the vendor will notify you "promptly," push for hours, not adjectives.

Termination and PHI Destruction. The BAA should state what happens to message logs, transcripts, and recordings when the contract ends: return or certified destruction of all PHI, on a stated timeline, with written confirmation.

A practice administrator reading a printed business associate agreement at her desk, pen in hand

A signed BAA does not move your liability to the vendor. Business associates are directly liable for their own violations, but the covered entity answers for choosing and overseeing them — and regulators have treated a missing or inadequate BAA as a violation on its own, even when nothing was breached.

OCR's enforcement record shows what that costs. Raleigh Orthopaedic paid $750,000, North Memorial paid $1.55 million, Cottage Health paid $3 million, and Pagosa Springs paid $111,400 in enforcement actions where BAAs were missing or inadequate. In each case the fine landed on the practice or the health system. The BAA was the covered entity's job.

How PHI actually moves: messages, texts, voicemail, and recordings

Who answers the call is one question. What the call leaves behind is another, and each channel carries its own rules.

Text messages

Standard SMS is not banned, but it is not automatically compliant either. Texting patient information takes a service covered by a BAA, a setup configured for how the PHI will be used, and in many cases affirmative opt-in from the patient. When a vendor says "we text confirmations, it's fine," ask which of those three they have.

Voicemail

PHI should not be left on a patient's voicemail without the patient's consent. The vendor's script should show how agents handle it: name and callback number only, or full details once the caller says it is okay to leave them.

Call recordings

If the vendor records calls for quality or training, state recording and consent laws apply on top of HIPAA. Some states require one party to consent; others require everyone on the call. A vendor recording calls from multiple states needs to meet the strictest rule that applies to your callers.

A small local service and a large HIPAA compliant call center face the same obligations on texts, voicemail, and recordings. The channel sets the rules.

The subcontractor chain: who else touches your calls

Signing with an answering service means signing with its stack. One call can pass through a telephony carrier, a cloud host that stores the messages, a transcription or AI vendor that summarizes the call, and in some services an agent pool in another country. Any of those companies that touches PHI is a subcontractor business associate, and a downstream BAA must be in place before access happens.

Ask for two things. First, a current list of subcontractors with PHI access, including where they operate. Offshore processing is not prohibited, but it changes the risk picture and can change your notification obligations if something breaks. Second, written confirmation that downstream BAAs exist for every company on that list, and that your vendor must tell you when the list changes.

This is where newer AI answering services most often fall short. The voice model, the telephony layer, the storage, and the analytics dashboard are frequently four different companies. If the vendor you are evaluating cannot name them, write that down as a due-diligence finding and keep shopping.

People and access: training, controls, and what happens after a breach

A signed agreement does not control what a live agent does at 2 a.m. with a message about a patient's refill. Three areas to probe:

Training. Agents who handle PHI should be trained on HIPAA basics at hire and refreshed on a schedule. Ask how the training is documented and what happens when an agent mishandles a message.

Access controls. Not every agent needs to see every message. Solid vendors limit access by client and role, log who opens what, and can produce those logs on request. "All our agents are background-checked" is a statement about hiring. It is not an access control.

Breach response. Get the incident process in writing: who investigates, who notifies you, and how fast. Your 60-day patient notification clock does not pause while you chase a quiet vendor.

The enforcement climate explains the scrutiny. OCR closed 2025 with 21 settlements, the second-highest annual total on record, and IBM puts the average healthcare data breach at $7.42 million. Most practices cannot absorb that, which makes the ten questions below worth asking before the contract, not after an incident.

10 questions to ask before you sign

These are written to be copied into an email or read straight into a call. Each comes with what a good answer sounds like and what a bad one sounds like. Run them before you talk pricing. If you want the pricing side of the decision, we broke down what medical answering service quotes usually hide.

An office manager on a phone call with a vendor, a printed checklist and handwritten notes on her desk

1. "Can we review your standard BAA before we sign, including the subcontractor, notification, and termination clauses?" Good: they send it unprompted, and it already contains the four terms above. Bad: "our legal team handles that during onboarding."

2. "Which subcontractors will have access to our patients' information, and where are they located?" Good: a current, named list (telephony, hosting, transcription) with locations and downstream BAAs confirmed. Bad: "we handle all of that internally."

3. "How is your text messaging set up, and how do you capture patient opt-in?" Good: messages run through a BAA-covered setup, opt-in is recorded, and message content stays minimal. Bad: "we use regular texting, it's fine."

4. "Do you record calls, and under which consent rules?" Good: a written recording policy built around the strictest state consent rule that applies to your callers. Bad: "we record for quality," with no answer on consent.

5. "What will your agents leave on a patient's voicemail?" Good: a scripted policy of name and callback number only, unless the patient has agreed to more. Bad: "the agent uses judgment."

6. "How is your staff trained on PHI handling, and how is it documented?" Good: training at hire, refreshers on a schedule, aggregate records they can share. Bad: "our agents are experienced."

7. "Who inside your company can see our messages, and can you produce access logs?" Good: access limited by client and role, with logs available on request. Bad: "everyone here is trusted."

8. "How many hours after discovering a breach will you notify us, and is that number in the contract?" Good: a number, typically 24 to 48 hours, written into the BAA. Bad: "immediately," with no number anywhere in the agreement.

9. "When the contract ends, what happens to our PHI, and on what timeline?" Good: certified return or destruction within a stated window, confirmed in writing. Bad: "data is deleted per our retention policy," with no timeline you can hold.

10. "After we go live, how do we verify all of this is still true?" Good: they expect the question (annual BAA review, access audits on request, a named compliance contact). Bad: they treat the signature as the last compliance conversation you will ever need.

If you are comparing AI-powered options alongside live-agent services, these questions apply to both, and it is fair to ask an AI vendor how its own stack stays compliant. Greetmate belongs on that list: it is HIPAA-ready, with a BAA available, and its phone workflows are scoped, built, and tested with a practice before go-live. Nobody hands you software and walks away.

Vetting doesn't stop at the signature

A signed BAA is a snapshot, and vendors change. They add subcontractors, migrate platforms, get acquired, and swap telephony providers, usually without telling clients, because the average contract does not require them to. Four habits keep the file current:

  • Re-review the BAA every year. Confirm the subcontractor list, notification window, and destruction terms still match how the service actually runs.
  • Run test calls each quarter. Call after hours, ask to book, and check what lands in voicemail and how the message is stored and relayed.
  • Request access logs annually. If logs were promised during vetting, collect them and read them.
  • Watch your own numbers. Call volume, message delivery times, how often patients say they called and heard nothing back.

That last habit runs into a blind spot: most traditional answering services report little beyond a message count. Ask about reporting during vetting, because leadership should be able to see what came in, what it produced, and where handoffs stalled. Greetmate treats that as part of the product: every workflow generates reporting on call activity, outcomes, and items that need staff action. The annual check becomes a report you read instead of a call you make. The platform page shows what that looks like.

Frequently asked questions about HIPAA compliant answering services

Do I actually need a HIPAA compliant answering service?

If the service handles patient information on your behalf (names, appointment details, messages), yes. It is a business associate, and a BAA is required before it takes a single call. Even a service that only records names and callback numbers usually qualifies, because the context makes the information identifiable.

What does a HIPAA compliant answering service do differently?

Operationally, quite a lot: it signs BAAs up and down its chain, trains agents on PHI handling, limits who can see messages, scripts what gets left on voicemail, configures texting properly, puts a breach notification window in the contract, and destroys PHI when the contract ends. A vendor that describes compliance as a badge instead of those specifics is asking you to skip the checklist.

Why are some AI answering services not HIPAA compliant?

Many consumer-grade voice tools were never built for patient information. The common failures: no BAA offered at all, call data used to improve models, no downstream agreements with the telephony, model, and storage providers, and transcripts stored without access controls. AI services can be compliant (the same ten questions apply), but the burden of proof sits with the vendor. We go deeper in our review of HIPAA-compliant voice AI agents and our ranking of HIPAA-compliant voice AI receptionists.

If the answering service leaks patient information, who carries the liability?

Both sides can. The vendor is directly liable for its own violations, and the practice is liable for failing to vet and oversee it. The practice also owns the patient notification duty and the 60-day clock. That shared exposure is why the BAA, the subcontractor chain, and the questions above matter before signing.

The responsibility stays with the practice

Everything above reduces to one fact: the phone stays the practice's responsibility no matter who answers it. The BAA, the subcontractor chain, the texting setup, and the access logs all exist because HIPAA holds the covered entity accountable for the vendors it chooses.

That is also why implementation support matters as much as the technology. Greetmate is healthcare voice and SMS infrastructure, delivered as a tech-enabled service: the team scopes each workflow, builds it, connects it to the systems the practice already runs, and tests it before go-live. Greetmate is HIPAA-ready, with a BAA available.

Bring the ten questions to every vendor you evaluate, including us. Book a demo and ask each one.

How Greetmate Transforms Healthcare Phone Operations:
Inbound Call Automation

Handle patient calls around the clock — including after-hours and overflow — so your front desk can focus on in-office care.

Appointment & Follow-Up Workflows

Automate appointment scheduling, patient follow-ups, and reactivation outreach through workflow-driven voice communication.

EHR & System Integrations

Connect with your existing EHR, scheduling tools, and operational systems for seamless, end-to-end patient communication.

See Greetmate in Action.
Healthcare voice AI infrastructure — live in hours.


More Blog Articles

Find helpful articles in our blog that are all about business, customer service and AI technology.

What makes an answering service HIPAA compliant

Your practice keeps the compliance responsibility even after the vendor signs. A five-point checklist and ten questions that separate vendors that can show you specifics from vendors that repeat the word compliant.

Blog Post Image for What makes an answering service HIPAA compliant