A HIPAA compliant answering service is one that handles a practice's protected health information under a signed business associate agreement and supports that agreement with concrete safeguards: encryption of calls and messages, access controls that limit who can view patient data, audit logging that records who accessed what, and written retention rules for how long recordings and messages are kept. Compliance is a property of the deployment and its controls, not a label a vendor can self-apply. Because a medical answering service creates, receives, and stores patient information on the practice's behalf, HIPAA treats the vendor as a business associate with direct legal duties. This guide covers what HIPAA actually requires of a medical answering service and the specific questions to ask a vendor before you sign.
What is a HIPAA compliant answering service?
A HIPAA compliant answering service answers a practice's calls, takes messages, and routes urgent calls while protecting the patient information it touches to the standard HIPAA sets. The distinction matters because the calls an answering service handles routinely involve protected health information: a caller's name tied to the fact that they are a patient of a given clinic is already PHI, before any clinical detail is shared. That means the service is not just answering phones, it is processing regulated data on the practice's behalf. HIPAA classifies such a vendor as a business associate, and the U.S. Department of Health and Human Services describes the safeguards a business associate must apply in its summary of the HIPAA Security Rule, which calls for administrative, physical, and technical protections for electronic PHI. A compliant service can show how it meets each of those, rather than asserting compliance as a slogan.
What does HIPAA require of a medical answering service?
Medical answering service compliance rests on a short list of concrete controls, each of which you can ask a vendor to demonstrate. First, encryption: calls, recordings, and messages should be encrypted both in transit and at rest, so intercepted or stolen data is unreadable. Second, access controls: only authorized operators should be able to view patient data, each with a unique login, and access should be scoped to what the role requires. Third, audit logging: the service should record who accessed which record and when, so access can be reviewed after the fact. Fourth, retention and disposal: recordings and messages should be kept only as long as a written policy allows and then deleted on a schedule. The HHS Security Rule summary groups these under administrative, physical, and technical safeguards for electronic PHI, and a compliant vendor maps its controls to those categories rather than treating compliance as a single checkbox.
Does an answering service need a business associate agreement?
Yes. A business associate agreement, or BAA, is the contract HIPAA requires before a covered entity shares protected health information with a vendor that will handle it. Since an answering service takes calls and stores messages containing PHI on the practice's behalf, it is a business associate, and the practice must have a signed BAA in place first. The agreement is not a formality: it defines what the service is permitted to do with the data, requires the service to apply safeguards, obligates it to report breaches, and extends the same duties to any subcontractor it uses. HHS publishes sample business associate agreement provisions that outline the permitted uses, required safeguards, breach reporting, and termination terms a signed agreement should cover. If a service will not sign a BAA, it cannot lawfully handle your patient calls, and that answer alone should end the evaluation.
See where an AI agent fits in your operation.
Book a demoWhat should you ask a HIPAA answering service vendor?
When you evaluate a HIPAA answering service, ask questions that force specific answers rather than reassurances. Start with the BAA: will you sign one, and does it cover subcontractors such as your telecom or cloud provider? On encryption, ask how calls and messages are protected in transit and at rest, and where recordings are stored. On access, ask whether each operator has a unique login, how access is limited by role, and whether staff receive HIPAA training. On audit logging, ask whether the system records who accessed each record and how long those logs are kept. On retention, ask for the written schedule that governs how long recordings and messages live before deletion. Finally, ask for evidence: an independent report such as SOC 2, or a written summary of safeguards, carries more weight than a compliance badge. For a broader view of how these controls apply to automated phone handling, see our HIPAA-compliant AI phone systems guide.
How does Flexbone run a HIPAA compliant answering service?
Flexbone runs AI voice agents that answer patient calls, and it operates as a business associate under a signed business associate agreement with each practice. The controls map to the requirements above rather than to marketing language. Calls, recordings, and messages are encrypted in transit and at rest. Access to patient data is limited by role and tied to individual accounts. Calls are transcribed and logged, so there is an audit trail of what was handled and, where applicable, who reviewed it. Retention follows a defined schedule agreed with the practice. The approach is audit-first: the agent's handling of calls is transcribed and available for review rather than opaque, and the control set is aligned with SOC 2. Flexbone does not claim that AI removes compliance obligations; it applies the same safeguards a compliant human service would and keeps a person in the loop for anything outside the agent's defined scope. To see how the agent handles inbound and after-hours calls in practice, read how we run healthcare calls.
How do you verify an answering service stays compliant over time?
Compliance is not a one-time check at signing, because staff, systems, and subcontractors change. Verify it on an ongoing basis by treating the BAA as a living document and revisiting it when the vendor adds subcontractors or changes where data is stored. Ask for a current independent report, such as an annual SOC 2, rather than a one-time attestation, and confirm the vendor runs its own access reviews and retention deletions on schedule. Keep your own record of which vendor holds what PHI, so a breach on their side maps quickly to your notification duties. The point is to confirm the controls still operate, not just that they were promised once. If you want to see an AI voice agent handle your patient calls under a signed BAA with encryption, access controls, and audit logging in place, book a demo.