Any answering service taking calls for a healthcare practice handles protected health information. Here is what that obligates, what a BAA does and does not cover, and what to verify before go-live.
The desk is a business associate, not a bystander
If an outside answering service takes calls for a covered healthcare practice, it is handling protected health information the moment a patient says why they are calling. Under HIPAA that makes the service a business associate, and the relationship requires a business associate agreement. This is not a formality that can be added later — it is the instrument that defines what the service may do with the information and what happens if something goes wrong.
The practical point for a practice manager is simple: you remain accountable. Choosing a vendor does not transfer the obligation, and a breach at the desk is a breach involving your patients.
What a BAA does and does not do
A signed BAA establishes the legal relationship and the permitted uses and disclosures. What it does not do is make the operation compliant on its own. A provider that offers a BAA readily and cannot describe its access controls, its logging, or how it trains agents is offering paperwork rather than protection. The agreement is necessary and nowhere near sufficient.

The controls worth verifying
- Minimum necessary access. An agent booking an appointment does not need a clinical history. Access should be scoped to the role and demonstrably so.
- Named accounts and audit logging. Shared logins make it impossible to establish who saw what, which defeats the point of logging at all.
- Message delivery. How does a message reach the on-call clinician? Unencrypted SMS and personal email are the common weak points, and they are usually invisible until someone asks.
- Call recording and retention. If calls are recorded, where do the recordings live, who can play them, for how long are they kept, and how are they destroyed?
- Agent training and turnover. Training at induction is table stakes. Ask what happens when an agent leaves, and how quickly access is revoked.
- Where the work is performed. Remote agents are not automatically a problem, but the answer should be a policy rather than a shrug.
Where practices usually get caught out
The recurring gap is not the answering service at all — it is the handoff. A desk with tightly controlled systems that then texts patient details to a clinician's personal phone has moved the information outside every control it just demonstrated. Trace the whole path, from the caller to the person who acts on it, and look for the point where the information leaves a managed system.
The second recurring gap is scope creep. A desk set up to book appointments gradually starts taking symptom descriptions, medication questions and test-result inquiries because patients volunteer them. Decide deliberately what the desk handles and what it routes, and revisit it once the program has been running.
What agents must never do
No clinical advice, ever, and the boundary needs training rather than a note in a script, because patients push on it constantly and often anxiously. Agents support access to care — booking, routing, message capture, urgency triage against your written protocol — and every predictable clinical question has an approved response that captures the facts and routes the call.
This article describes how programs are commonly structured and is not legal advice. Confirm your own obligations with your counsel and privacy officer before an outside team handles patient information.
See how a medical answering desk is structured, or read the wider healthcare support model.
Frequently asked questions
Does every answering service handling our calls need a BAA?
If it creates, receives, maintains or transmits protected health information on your behalf, yes — and taking a patient call almost always meets that description, because the caller identifies themselves and says why they are calling. The exception people reach for is a service that only takes a name and number, but in practice patients volunteer clinical detail immediately. Treat the BAA as a precondition of go-live rather than something to sort out afterwards, and confirm the position with your privacy officer.
Is call recording allowed?
Recording is common in healthcare answering and is not prohibited by HIPAA in itself, but recordings containing protected health information are subject to the same safeguards as any other record — access control, encryption, retention and destruction. State wiretapping and consent laws apply separately and vary, including two-party consent states. The practical questions are where recordings are stored, who can retrieve them, and how long they are kept, and those should have documented answers.
Can agents text messages to our on-call doctor?
Only through a channel that is actually secured, and standard SMS to a personal phone generally is not. This is the most common gap we see, because it is invisible until somebody traces the path: a desk with tightly controlled systems that then sends patient details over an unmanaged channel has undone its own controls at the last step. Look at how messages are delivered and confirm the arrangement with your privacy officer.
What happens if the service has a breach?
The BAA should set out notification obligations and timing, and you should know what they are before you need them rather than reading the clause during an incident. Ask what the provider's incident response process looks like, who is notified and how quickly, and what forensic detail you would receive. A provider that cannot describe this concretely has probably not rehearsed it, and an unrehearsed process is the one that costs you the reporting deadline.
Answering services
Keep reading
The rest of this cluster, for the question you are actually working through.

