Patient Access

HIPAA Compliant Answering Service Requirements

A HIPAA compliant answering service is one that handles a practice's protected health information under a signed business associate agreement and supports that agreement with concrete safeguards: encryption of calls and messages, access controls that limit who can view patient data, audit logging that records who accessed what, and written retention rules for how long recordings and messages are kept. Compliance is a property of the deployment and its controls, not a label a vendor can self-apply. Because a medical answering service creates, receives, and stores patient information on the practice's behalf, HIPAA treats the vendor as a business associate with direct legal duties. This guide covers what HIPAA actually requires of a medical answering service and the specific questions to ask a vendor before you sign.

What is a HIPAA compliant answering service?

A HIPAA compliant answering service answers a practice's calls, takes messages, and routes urgent calls while protecting the patient information it touches to the standard HIPAA sets. The distinction matters because the calls an answering service handles routinely involve protected health information: a caller's name tied to the fact that they are a patient of a given clinic is already PHI, before any clinical detail is shared. That means the service is not just answering phones, it is processing regulated data on the practice's behalf. HIPAA classifies such a vendor as a business associate, and the U.S. Department of Health and Human Services describes the safeguards a business associate must apply in its summary of the HIPAA Security Rule, which calls for administrative, physical, and technical protections for electronic PHI. A compliant service can show how it meets each of those, rather than asserting compliance as a slogan.

What does HIPAA require of a medical answering service?

Medical answering service compliance rests on a short list of concrete controls, each of which you can ask a vendor to demonstrate. First, encryption: calls, recordings, and messages should be encrypted both in transit and at rest, so intercepted or stolen data is unreadable. Second, access controls: only authorized operators should be able to view patient data, each with a unique login, and access should be scoped to what the role requires. Third, audit logging: the service should record who accessed which record and when, so access can be reviewed after the fact. Fourth, retention and disposal: recordings and messages should be kept only as long as a written policy allows and then deleted on a schedule. The HHS Security Rule summary groups these under administrative, physical, and technical safeguards for electronic PHI, and a compliant vendor maps its controls to those categories rather than treating compliance as a single checkbox.

Does an answering service need a business associate agreement?

Yes. A business associate agreement, or BAA, is the contract HIPAA requires before a covered entity shares protected health information with a vendor that will handle it. Since an answering service takes calls and stores messages containing PHI on the practice's behalf, it is a business associate, and the practice must have a signed BAA in place first. The agreement is not a formality: it defines what the service is permitted to do with the data, requires the service to apply safeguards, obligates it to report breaches, and extends the same duties to any subcontractor it uses. HHS publishes sample business associate agreement provisions that outline the permitted uses, required safeguards, breach reporting, and termination terms a signed agreement should cover. If a service will not sign a BAA, it cannot lawfully handle your patient calls, and that answer alone should end the evaluation.

See where an AI agent fits in your operation.

Book a demo

What should you ask a HIPAA answering service vendor?

When you evaluate a HIPAA answering service, ask questions that force specific answers rather than reassurances. Start with the BAA: will you sign one, and does it cover subcontractors such as your telecom or cloud provider? On encryption, ask how calls and messages are protected in transit and at rest, and where recordings are stored. On access, ask whether each operator has a unique login, how access is limited by role, and whether staff receive HIPAA training. On audit logging, ask whether the system records who accessed each record and how long those logs are kept. On retention, ask for the written schedule that governs how long recordings and messages live before deletion. Finally, ask for evidence: an independent report such as SOC 2, or a written summary of safeguards, carries more weight than a compliance badge. For a broader view of how these controls apply to automated phone handling, see our HIPAA-compliant AI phone systems guide.

How does Flexbone run a HIPAA compliant answering service?

Flexbone runs AI voice agents that answer patient calls, and it operates as a business associate under a signed business associate agreement with each practice. The controls map to the requirements above rather than to marketing language. Calls, recordings, and messages are encrypted in transit and at rest. Access to patient data is limited by role and tied to individual accounts. Calls are transcribed and logged, so there is an audit trail of what was handled and, where applicable, who reviewed it. Retention follows a defined schedule agreed with the practice. The approach is audit-first: the agent's handling of calls is transcribed and available for review rather than opaque, and the control set is aligned with SOC 2. Flexbone does not claim that AI removes compliance obligations; it applies the same safeguards a compliant human service would and keeps a person in the loop for anything outside the agent's defined scope. To see how the agent handles inbound and after-hours calls in practice, read how we run healthcare calls.

How do you verify an answering service stays compliant over time?

Compliance is not a one-time check at signing, because staff, systems, and subcontractors change. Verify it on an ongoing basis by treating the BAA as a living document and revisiting it when the vendor adds subcontractors or changes where data is stored. Ask for a current independent report, such as an annual SOC 2, rather than a one-time attestation, and confirm the vendor runs its own access reviews and retention deletions on schedule. Keep your own record of which vendor holds what PHI, so a breach on their side maps quickly to your notification duties. The point is to confirm the controls still operate, not just that they were promised once. If you want to see an AI voice agent handle your patient calls under a signed BAA with encryption, access controls, and audit logging in place, book a demo.

FT
Flexbone Team

Frequently asked questions

An answering service is HIPAA compliant when it handles protected health information under a signed business associate agreement and backs that agreement with real safeguards. Those safeguards include encryption of calls and messages, access controls that limit who can see patient data, audit logging of who accessed what, and defined retention rules. Compliance depends on the deployment and the controls, not on a badge or a claim on a website.

Yes. Because the service creates, receives, or stores protected health information on the practice's behalf, HIPAA treats the vendor as a business associate, and a covered entity must have a signed business associate agreement in place before sharing that information. The agreement sets the permitted uses of the data, the required safeguards, and the breach reporting duties.

Yes, recording is allowed, but the recordings are protected health information and must be protected like any other PHI. That means the recordings are encrypted, access to them is limited and logged, and they are kept only as long as the retention policy allows. Ask the vendor where recordings are stored, who can play them back, and when they are deleted.

HIPAA does not set a single fixed retention period for the messages themselves, but it does require a documented policy and requires certain compliance records to be kept for six years. State medical record laws and the practice's own policy often drive the actual retention window. Confirm the vendor follows a written retention and deletion schedule that matches your policy.

Ask whether they will sign a business associate agreement, how they encrypt calls and messages in transit and at rest, how they control and log staff access to patient data, and how long they retain recordings and messages. Ask for evidence such as a SOC 2 report or a summary of their safeguards. A vendor that cannot answer these clearly is a compliance risk.

Start with an audit.

We'll study your operations and show you exactly where AI fits.

Book an Audit