HIPAA Compliant Answering Service: What to Verify Before You Sign
Compliance comes down to what you verify before signing, from the business associate agreement clauses to where the operators sit and who reports a breach.
Written by the Commure Agents Team
Published: September 19, 2026
•
13 min read
What You Need to Know About a HIPAA Compliant Answering Service
- A HIPAA compliant answering service signs a business associate agreement (BAA) and documents the safeguards covering every recording, transcript and message it holds.¹
- In March 2026, the HHS Office for Civil Rights (OCR) settled with a patient communication business associate over an unreported breach affecting 15 million individuals.²
- Before signing, read the agreement against the sample BAA provisions HHS publishes, then confirm where the operators sit and who reports a breach.³
What makes a HIPAA compliant answering service, and is it a business associate?
A HIPAA compliant answering service signs a business associate agreement and documents the safeguards covering every recording, transcript and message it holds. Any service that takes messages, records calls or stores transcripts maintains protected health information (PHI) on the practice's behalf. HHS guidance treats a vendor that maintains PHI for a covered entity as a business associate rather than a conduit.⁴
HHS draws the line at storage
HHS guidance on cloud service providers (CSPs) settles the point for a vendor that never reads what it holds. Lacking an encryption key "for the encrypted data it receives and maintains does not exempt a CSP from business associate status."⁴ The guidance applies to answering services by close analogy, since both hold PHI for a covered entity.
The conduit exception reaches transmission only
HHS limits it to "transmission-only services for PHI," including temporary storage incident to that transmission.⁴ Its FAQ describes a conduit as an entity that "transports information but does not access it other than on a random or infrequent basis."⁵
A service that keeps a message log, a call recording or a transcript holds information rather than moving it. That places the vendor outside the conduit exception and inside the BAA requirement.
Under 45 CFR 164.502(e)(1)(i), a covered entity may disclose PHI only after obtaining satisfactory assurance that the business associate will safeguard it.¹ The BAA is where that assurance is written down, so read the contract before relying on a vendor's compliance claim.
A business associate must obtain the same assurances from any subcontractor that handles protected health information on its behalf.¹ An answering service that sends audio to a transcription provider must cover that relationship with its own agreement.
A caller's name, phone number and reason for calling, held by a vendor working for a provider, is protected health information. The recording of that call and the transcript generated from it are the same information in two more formats.
Ask a prospective vendor what it holds, where that data sits, and what the agreement says about both.
How does patient information move through an answering service call?
Protected health information enters a HIPAA compliant answering service call the moment a caller gives a name and a reason for calling. It then comes to rest in four places, and a breach can begin at any of them.
- The message. What the operator writes down, and how much of the call it captures.
- The delivery channel. Whatever carries the message out of the vendor's system to on-call staff.
- The recording or transcript. The audio, and the text generated from it.
- The retention store. Everything the vendor still holds from calls that were resolved months ago.
The intake script sets the size of the exposure
The minimum necessary standard at 45 CFR 164.502(b) requires reasonable efforts to limit protected health information to the minimum necessary for the intended purpose.¹ An intake script that collects a full clinical history to book a follow-up widens exposure without improving the booking.
A message reaches on-call staff by text, email, secure app or a callback to a personal phone. Each of those routes can leave a record outside the vendor's system. Find out which one the vendor uses by default, and whether the practice can require another.
HHS guidance says providers "should take care to limit the amount of information disclosed on the answering machine."⁶ The safe pattern is a name, a callback number and a request to return the call. Automated and prerecorded calls to a patient's wireless number carry separate conditions under the Telephone Consumer Protection Act.⁷
Minimum necessary exempts the clinical handoff
A practice can pass a caller's symptom description to the on-call physician. The standard excludes disclosures to a health care provider for treatment.¹ The constraint sits on what the vendor collects, keeps and stores around that handoff.
Confirmations and clinical questions are different calls
HHS treats appointment reminders as part of treatment, so they "can be made without an authorization."⁸ A caller describing a symptom needs an escalation path the practice agreed in advance, which means deciding what counts as urgent before the phone rings. Settling that alongside answer-speed targets and call logging is one of the healthcare call center best practices worth fixing before a contract starts.
Recordings and transcripts outlive the message they came from. A message is resolved when the callback happens, and the audio behind it can sit in a vendor's storage for years.
The vendor's default retention period applies to messages, recordings and transcripts unless the practice sets its own schedule. Get three answers in writing:
- The retention period that applies to each of the three.
- The disposal method at the end of that period.
- What happens to the archive when the contract ends.
How long the vendor keeps call audio drives the breach math, because the population at risk is everyone in the store rather than everyone who called last week.
With Commure AI Call Center Agents, the practice can view full call transcripts in its dashboard, and the agreement covering them is signed before any patient data moves.
What has to be in the BAA, and which safeguards should you require?
The business associate agreement behind a HIPAA compliant answering service must contain the ten elements HHS lists, and HHS publishes sample provisions for them.³ The Security Rule adds technical safeguards on top of them, some required and others addressable.⁹
Five clauses to read closely, and the one to check first
HHS's ten required elements include these five. Read the vendor's agreement against the sample provisions in this order:
- Permitted uses and disclosures. The agreement states what the vendor may do with the information and nothing broader.
- Safeguards. The vendor agrees to use appropriate safeguards and to comply with Subpart C of the Security Rule for electronic protected health information.
- Reporting. The vendor reports impermissible uses or disclosures, security incidents, and breaches of unsecured protected health information under 45 CFR 164.410.
- Subcontractor flow-down. The vendor requires the same obligations of every subcontractor that creates, receives, maintains or transmits protected health information on its behalf.
- Termination. The covered entity can terminate if the vendor violates a material term of the agreement.
Check subcontractor flow-down first, because it decides whether the vendor's telephony carrier, transcription engine and storage provider are covered. An answering service can run on several other companies' infrastructure.
Required and addressable both carry obligations
The Security Rule sorts its technical safeguards into two kinds, and the difference changes what evidence a practice should ask for. 45 CFR 164.312 makes unique user identification a required implementation specification.⁹ The specification requires an individual identifier for every operator who touches the system, rather than a shared login. Encryption and decryption, transmission encryption and integrity controls are addressable.⁹
Addressable means the vendor must assess whether the measure is reasonable and appropriate.¹⁰ The vendor then either uses it or documents why not, and adopts an equivalent alternative where one is reasonable and appropriate. The assessment is part of meeting the standard, so ask for the document itself.
Permitted-use and termination clauses can follow standard language that vendors reuse. The reporting and subcontractor clauses are more likely to be drafted vendor by vendor, so read those in full.
What stays with the practice
The practice keeps its own obligations after a BAA is signed, and its own risk analysis has to account for the calls it has outsourced.
The reporting clause connects the vendor's compliance program to the practice's, and 45 CFR 164.410 governs the breach notification a business associate owes.³ Set the notification window inside the agreement, name the person who receives the notice, and require reporting of security incidents rather than confirmed breaches alone.
Access control, audit controls and person or entity authentication complete the technical standards.⁹ A practice can ask for evidence of each one. The same technical standards govern HIPAA compliant AI note taking, so a group buying both can run one set of questions.
Which requirements catch practices off guard before they sign?
Four requirements can surface late in HIPAA compliant answering service contracts: the location of the operators, the vendor's own breach exposure, recording consent, and the pending Security Rule rewrite. Put each one on the diligence list before signing, and get each answer in writing.
Offshore operators are allowed, and they change your paperwork
HIPAA applies the same rules wherever protected health information is stored, with no separate offshore requirement.¹¹ HHS notes that "the risks to such ePHI may vary greatly depending on its geographic location."¹¹ HIPAA therefore permits offshore operators, and their location belongs in the risk analysis. Where operators sit is one of the terms to settle when healthcare call center outsourcing is scoped and contracted.
Medicare Advantage contracting adds a second obligation. The Centers for Medicare & Medicaid Services (CMS) requires plans to file an offshore subcontractor attestation. It covers each offshore subcontractor that "receives, processes, transfers, handles, stores, or accesses Medicare beneficiary PHI." CMS applies it to "first tier, downstream, and related entities."¹²
That phrase reaches entities below the plan, which can include a practice's answering service. The requirement binds plans, and it reaches providers through their plan contracts.¹² CMS states it in the CY2027 application.
Several states add their own limits, so check each state where the practice operates. Have the vendor name every country where its operators and its data sit, and put the answer in the contract rather than in an email.
The vendor's breach becomes your notification problem
Enforcement actions show what a practice inherits when the vendor holding its call data fails. In March 2026, OCR settled with MMG Fusion, a patient communication software business associate.² The breach affected about 15 million individuals.² OCR cited a failure to conduct an accurate and thorough risk analysis, and a failure to notify the covered entities it served.²
Business associates must notify affected covered entities "without unreasonable delay and within 60 calendar days of discovery."² A practice that learns of a breach on day 59 has lost the time it needed to warn its own patients. Set the contractual notification window inside that outer limit.
State law decides recording consent
Consent to record sits outside HIPAA, which is why a review built around the BAA alone can miss it. State wiretapping law decides whether a call may be recorded, and some states require consent from every party. Confirm the rule in every state patients call from, as well as the state the practice sits in.
Three questions settle whether a vendor's recording practice holds up:
- Where the disclosure sits in the call flow, and whether every caller hears it.
- How a caller's response to that disclosure is captured.
- Whether the vendor can retrieve the consent record for one named call.
A vendor that discloses recording only in its terms of service leaves all three unanswered.
The Security Rule is being rewritten
One requirement on this list is still moving, so write the agreement to follow it. HHS published a proposed update to the Security Rule in January 2025.¹³ The rule sits under long-term actions in HHS's regulatory agenda, with final action listed for July 2027.¹⁴ The current Security Rule applies today. The proposal would make encryption and every other implementation specification required, with limited exceptions.¹³
Require the vendor to comply with the Security Rule as amended and to give notice of material changes to its safeguards. An agreement written that way can hold up without renegotiation.
How do you verify a HIPAA compliant answering service before you sign?
Verifying a HIPAA compliant answering service is a document review: ask for the business associate agreement, the risk analysis, the encryption assessment and a sample audit log. A vendor that produces all four in a week is running a compliance program, while a certificate alone documents none of them.
Run the table below against any HIPAA compliant answering service, whether the operators are people, software, or both.
Price the compliance work alongside the per-minute rate
A cheaper vendor that cannot produce a risk analysis costs more once the practice has to build the documentation itself. Comparing medical answering service pricing on cost per resolved call rather than per minute makes that difference visible. These vendor checks are one part of the wider program a HIPAA compliance checklist lays out.
The subcontractor flow-down and retention rows also apply to the HIPAA compliant answering service already in place. Both clauses can drift after an agreement is signed, because both change when the vendor changes its own suppliers.
Split the review between two roles so the vendor decision does not wait on one reviewer's calendar. The practice administrator or patient access lead collects the four documents. The privacy or compliance officer reviews the agreement and the risk analysis against the table.
A vendor's refusal to name its subcontractors or share the encryption assessment is evidence about its documentation. Record the refusal, because what a practice could not verify belongs in its risk analysis too.
The fourteen sources cited here are government and regulatory primary documents, because peer-reviewed research on answering-service HIPAA compliance is scarce.
How do Commure AI Call Center Agents handle after-hours and overflow calls?
Every row in the verification table applies to an AI answering layer on the same terms as a human one.
Commure AI Call Center Agents cover the administrative share of after-hours and overflow calls for multi-location groups. The scope is frequently asked questions, intent routing, intake, and appointment confirmation, scheduling, rescheduling and cancellation within configured rules. They work in English and Spanish, on inbound calls, and route clinical or urgent calls to the on-call provider.
One agreement covers the whole path. A BAA is signed before any patient data moves. The dashboard holds call activity, call success status and the full call transcripts a compliance review needs. Write-back reaches eClinicalWorks, athenahealth, Epic, ModMed, MEDITECH and AdvancedMD; other EHRs can be scoped as well. That agreement covers the answering layer, the transcript store and the electronic health record (EHR) write-back. A practice maintains one risk analysis and tests one notification chain instead of owning the seams between vendors. Retention and escalation rules are agreed during scoping.
The category overview is AI voice agents in healthcare, and the call-handling mechanics sit in voice AI for patient call automation.
Request a complimentary call center health analysis to see what your own call volume looks like. The analysis reviews a week of call transcripts and metadata under a signed BAA. It returns a volume breakdown by call type and outcome, plus a model quantifying the automation opportunity, in about a week.
Sources
- U.S. Department of Health and Human Services. (n.d.). 45 CFR 164.502: Uses and disclosures of protected health information: General rules. eCFR. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- U.S. Department of Health and Human Services. (2026, March 5). HHS' Office for Civil Rights settles HIPAA investigation of MMG Fusion, LLC breach affecting 15 million individuals. https://www.hhs.gov/press-room/ocr-mmg-fusion-hipaa-agreement.html
- U.S. Department of Health and Human Services. (2017, June 16). Business associate contracts: Sample business associate agreement provisions. https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html
- U.S. Department of Health and Human Services, Office for Civil Rights. (2016). Guidance on HIPAA & cloud computing. https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
- U.S. Department of Health and Human Services. (n.d.). FAQ 245: Are the following entities considered "business associates" under the HIPAA Privacy Rule: US Postal Service, United Parcel Service, delivery truck line employees and/or their management? https://www.hhs.gov/hipaa/for-professionals/faq/245/are-entities-business-associates/index.html
- U.S. Department of Health and Human Services. (n.d.). FAQ 198: May physician's offices or pharmacists leave messages for patients at their homes, either on an answering machine or with a family member, to remind them of appointments or to inform them that a prescription is ready? https://www.hhs.gov/hipaa/for-professionals/faq/198/may-health-care-providers-leave-messages/index.html
- Federal Communications Commission. (2021, February 25). Limits on exempted calls under the Telephone Consumer Protection Act of 1991. Federal Register. https://www.federalregister.gov/documents/2021/02/25/2021-01190/limits-on-exempted-calls-under-the-telephone-consumer-protection-act-of-1991
- U.S. Department of Health and Human Services. (n.d.). FAQ 286: Are appointment reminders allowed under the HIPAA Privacy Rule without authorizations? https://www.hhs.gov/hipaa/for-professionals/faq/286/are-appointment-reminders-allowed-under-hipaa-without-authorization/index.html
- U.S. Department of Health and Human Services. (n.d.). 45 CFR 164.312: Technical safeguards. eCFR. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
- U.S. Department of Health and Human Services. (n.d.). 45 CFR 164.306: Security standards: General rules. eCFR. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.306
- U.S. Department of Health and Human Services. (2022, December 28). FAQ 2083: Do the HIPAA Rules allow a covered entity or business associate to use a CSP that stores ePHI on servers outside of the United States? https://www.hhs.gov/hipaa/for-professionals/faq/2083/do-the-hipaa-rules-allow-a-covered-entity-or-business-associate-to-use-a-csp-that-stores-ephi-on-servers-outside-of-the-united-states/index.html
- Centers for Medicare & Medicaid Services. (n.d.). CY2027 Medicare Advantage Part C application, Section 3.17. https://www.cms.gov/files/document/cy2027-medicare-advantage-part-c-application.pdf
- U.S. Department of Health and Human Services, Office for Civil Rights. (2025, January 6). HIPAA Security Rule to strengthen the cybersecurity of electronic protected health information (Proposed rule, RIN 0945-AA22). Federal Register, 90 FR 898. https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information
- U.S. Department of Health and Human Services. (2026). HIPAA Security Rule to strengthen the cybersecurity of electronic protected health information (RIN 0945-AA22, long-term actions). Unified Agenda of Federal Regulatory and Deregulatory Actions. https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202604&RIN=0945-AA22
Try the #1 AI Scribe for Free
No Credit Card Required. Join 20,000 Clinicians.











