Any answering service taking calls for a healthcare practice handles protected health information. Here is what that obligates, what a BAA does and does not cover, and what to verify before go-live.
The desk is a business associate, not a bystander
If an outside answering service takes calls for a covered healthcare practice, it is handling protected health information the moment a patient says why they are calling. Under HIPAA that makes the service a business associate, and the relationship requires a business associate agreement. This is not a formality that can be added later — it is the instrument that defines what the service may do with the information and what happens if something goes wrong.
The practical point for a practice manager is simple: you remain accountable. Choosing a vendor does not transfer the obligation, and a breach at the desk is a breach involving your patients.
What a BAA does and does not do
A signed BAA establishes the legal relationship and the permitted uses and disclosures. What it does not do is make the operation compliant on its own. A provider that offers a BAA readily and cannot describe its access controls, its logging, or how it trains agents is offering paperwork rather than protection. The agreement is necessary and nowhere near sufficient.

The controls worth verifying
- Minimum necessary access. An agent booking an appointment does not need a clinical history. Access should be scoped to the role and demonstrably so.
- Named accounts and audit logging. Shared logins make it impossible to establish who saw what, which defeats the point of logging at all.
- Message delivery. How does a message reach the on-call clinician? Unencrypted SMS and personal email are the common weak points, and they are usually invisible until someone asks.
- Call recording and retention. If calls are recorded, where do the recordings live, who can play them, for how long are they kept, and how are they destroyed?
- Agent training and turnover. Training at induction is table stakes. Ask what happens when an agent leaves, and how quickly access is revoked.
- Where the work is performed. Remote agents are not automatically a problem, but the answer should be a policy rather than a shrug.
Where practices usually get caught out
The recurring gap is not the answering service at all — it is the handoff. A desk with tightly controlled systems that then texts patient details to a clinician's personal phone has moved the information outside every control it just demonstrated. Trace the whole path, from the caller to the person who acts on it, and look for the point where the information leaves a managed system.
The second recurring gap is scope creep. A desk set up to book appointments gradually starts taking symptom descriptions, medication questions and test-result inquiries because patients volunteer them. Decide deliberately what the desk handles and what it routes, and revisit it once the program has been running.
What agents must never do
No clinical advice, ever, and the boundary needs training rather than a note in a script, because patients push on it constantly and often anxiously. Agents support access to care — booking, routing, message capture, urgency triage against your written protocol — and every predictable clinical question has an approved response that captures the facts and routes the call.
This article describes how programs are commonly structured and is not legal advice. Confirm your own obligations with your counsel and privacy officer before an outside team handles patient information.
See how a medical answering desk is structured, or read the wider healthcare support model.
Messages and recordings are records too
The control conversation usually focuses on the call itself, and the exposure more often sits in what the call leaves behind. A message containing a patient name and a symptom is protected health information. So is a call recording, a screen capture, an agent's note and the delivery mechanism that carries the message to the practice.
Delivery is where practices are most often caught out. Plain email and standard SMS are not appropriate channels for message content, and a portal notification that includes the detail in its preview has the same problem. The workable pattern is a notification that carries no clinical content plus a secure portal where the message is retrieved, with access logged. Then apply retention deliberately: messages and recordings need a defined retention period, automatic deletion at the end of it, and a documented answer to who can retrieve them meanwhile. A service that keeps everything indefinitely because storage is cheap has created an obligation on your behalf.

Verification without disclosure
Confirming who you are speaking to is where well-designed scripts quietly fail. A verification step that reads information back to the caller has disclosed it to whoever is on the line, before establishing that they are entitled to it. The rule is that the caller supplies the identifiers and the agent confirms or declines — never the reverse.
Family members are the hardest case and the most common. Someone calling about a relative is usually sincere and often urgent, and an agent with no rule will help. Define in advance who may receive what: whether a spouse or parent is authorised, how that authorisation is recorded and checked, what may be said to an unauthorised caller (that a message will be passed on, and nothing else), and how to handle a caller who becomes distressed at being declined. Rehearse that last one, because it is where disclosure actually happens.
Incidents, and what you must be able to show
Compliance is judged in retrospect, usually after something went wrong, and the difference between a manageable incident and a serious one is whether the evidence exists. Assume you will need to show, for a given date: who had access to what and on what basis, the training record of the person who handled the contact, the retention and deletion status of the associated records, and the access log for anyone who retrieved them.
Agree the incident path in writing before you need it: what the service must tell you, within what period, and who notifies whom. A business associate agreement establishes the relationship; it does not by itself give you a notification timeline you can rely on. Ask what the provider's most recent incident was and how it was handled — an operator with real controls answers; one with none has never looked. Our PCI guide covers the equivalent discipline where payment data is involved.
Frequently asked questions
Does every answering service handling our calls need a BAA?
If it creates, receives, maintains or transmits protected health information on your behalf, yes — and taking a patient call almost always meets that description, because the caller identifies themselves and says why they are calling. The exception people reach for is a service that only takes a name and number, but in practice patients volunteer clinical detail immediately. Treat the BAA as a precondition of go-live rather than something to sort out afterwards, and confirm the position with your privacy officer.
Is call recording allowed?
Recording is common in healthcare answering and is not prohibited by HIPAA in itself, but recordings containing protected health information are subject to the same safeguards as any other record — access control, encryption, retention and destruction. State wiretapping and consent laws apply separately and vary, including two-party consent states. The practical questions are where recordings are stored, who can retrieve them, and how long they are kept, and those should have documented answers.
Can agents text messages to our on-call doctor?
Only through a channel that is actually secured, and standard SMS to a personal phone generally is not. This is the most common gap we see, because it is invisible until somebody traces the path: a desk with tightly controlled systems that then sends patient details over an unmanaged channel has undone its own controls at the last step. Look at how messages are delivered and confirm the arrangement with your privacy officer.
What happens if the service has a breach?
The BAA should set out notification obligations and timing, and you should know what they are before you need them rather than reading the clause during an incident. Ask what the provider's incident response process looks like, who is notified and how quickly, and what forensic detail you would receive. A provider that cannot describe this concretely has probably not rehearsed it, and an unrehearsed process is the one that costs you the reporting deadline.
Answering services
Keep reading
The rest of this cluster, for the question you are actually working through.
- Answering Service vs Call Center: Which One Do You Need?
- What Drives Answering Service Cost (And What to Ask Before You Buy)
- After-Hours Answering: Designing Coverage That Pays for Itself
- 24/7 Live Answering Service | A Person Answers, Every Hour of Every Day
- Home Services Answering Service | 24/7 Dispatch for Every Trade
- IT Answering Service | 24/7 Live Intake and Ticketing for MSPs

