A practice that outsources patient calls is handing protected health information to a third party. That is permitted, routine, and done by practices of every size—but it is only safe when a specific set of arrangements is in place before the first call is answered.

This is what to require, and what to ask.

The business associate agreement comes first

Any vendor that creates, receives, maintains, or transmits protected health information on your behalf is a business associate, and a signed business associate agreement is required before they touch it. This is not a formality to complete during onboarding—it is the document that establishes their obligations and your recourse.

A vendor who is unfamiliar with the term, or who offers to sign “whatever you send over” without review, is telling you they have not done healthcare work before.

The disqualifying question:“Will you sign a BAA, and can I see your standard one?” Anything other than an immediate yes ends the conversation.

Least-privilege access, specified precisely

Agents should reach exactly the systems the role requires and nothing more. That means named accounts rather than shared logins, permissions scoped to the function, access provisioned through a documented process and revoked the same day someone leaves the programme, and session logging you can review.

Ask to see how access is granted and removed. A vendor that cannot describe its offboarding process in specifics has not thought about the risk that matters most.

Recording, retention, and what agents may repeat

Three rules need writing down explicitly. What may be recorded— and whether recordings capture PHI. How long recordings and notes are retained, and how they are destroyed. What an agent may read back, take down, or repeat to a caller who cannot be verified.

That last one causes more real-world problems than the other two combined. A family member calling about a patient is a routine situation with a non-routine answer, and agents need a scripted response rather than judgment in the moment.

Offshore processing is allowed—decide it deliberately

HIPAA does not prohibit processing protected health information outside the United States. Plenty of practices use offshore delivery for medical billing and patient support and do it well.

What changes offshore is that enforcement and recourse become practically harder, so the contractual and technical controls carry more weight. If you go offshore, be deliberate: confirm the BAA extends to every subcontractor, establish exactly which country processes the data, and confirm your own state law and payer contracts do not impose a stricter requirement than HIPAA does.

Workforce training, not a policy PDF

Every agent touching PHI needs training on it, and you should ask what that training actually consists of, how often it repeats, and how it is verified. “All staff complete HIPAA training” is an answer that means nothing without those three details.

Incident response, agreed in advance

Decide before launch what happens if something goes wrong: how quickly the vendor must notify you, who investigates, what evidence you receive, and who handles notification obligations. Breach notification timelines are unforgiving, and a vendor learning your expectations during an actual incident is the worst possible time.

Agree the incident process while everyone is calm. It is the one part of the contract you hope never to use and cannot afford to improvise.

The vendor checklist

Will you sign a BAA, and does it flow down to subcontractors? Which systems will agents access, with what permissions? How is access provisioned and revoked? What is recorded, how long is it retained, and how is it destroyed? Where is data processed, physically? What does agent HIPAA training consist of and how often does it repeat? What is your breach notification timeline to me? What happens to my data when the contract ends?

Eight questions. A vendor that answers all eight specifically has done this before. One that answers in reassurances has not.

Getting the setup right

Documented handling is the difference between outsourcing that reduces your risk and outsourcing that increases it. Our HIPAA medical answering service page covers how patient call handling is set up in practice, and the healthcare outsourcing page covers the wider programme.

This article is general information about vendor selection, not legal advice. Confirm your obligations with your own counsel or compliance advisor before signing anything.