A practice that outsources patient calls is handing protected health information to a third party. That is permitted, routine, and done by practices of every size. It is only safe when a specific set of arrangements is in place before the first call is answered, and the arrangements are not complicated once you know what they are.

This article sets out what to require and what to ask, in the order the questions come up. It is general information about vendor selection, written by an outsourcing provider that handles this work, and it is not legal advice. Confirm your obligations with your own counsel or compliance adviser before signing anything.

Who counts as a business associate

A covered entity is the practice, plan or clearinghouse that HIPAA applies to directly. A business associate is any person or organisation that creates, receives, maintains or transmits protected health information on a covered entity's behalf. An answering service that takes patient messages, a scheduling team that reads the appointment book, a billing team that sees claims and a support team that verifies a caller's identity against a record are all business associates.

The test is whether the vendor handles the information, not how much of it or how briefly. A team that only takes names and callback numbers without any clinical context may sit outside the definition, but that line is narrow and easy to cross, and most practices treat any vendor touching patient contact as a business associate to be safe. Subcontractors of a business associate that handle the information are business associates too.

The business associate agreement comes first

A signed business associate agreement is required before a business associate touches protected health information. It is not a formality to complete during onboarding. It is the document that sets out what the vendor may do with the information, the safeguards it must maintain, how it reports incidents to you, what happens with subcontractors, and what happens to the data when the contract ends.

A vendor who is unfamiliar with the term, or who offers to sign whatever you send over without review, is telling you they have not done healthcare work before. A vendor who has done it will have a standard agreement, will expect yours to differ in places, and will be able to explain each clause. Ask for their standard one, ask whether it flows down to every subcontractor, and read it.

Be cautious with the phrase HIPAA certified. HIPAA compliance is demonstrated through the agreement, the documented safeguards and the practices behind them, not through a certificate. Ask what stands behind any certification claim rather than accepting the label.

Ask whether the vendor will sign a BAA and ask to see their standard one. Anything other than an immediate yes ends the conversation.

Minimum necessary, applied to the role and the access

The minimum necessary standard means using, disclosing and requesting only the protected health information needed for the task. For an outsourced team, that translates into role design: an agent who confirms appointments needs the schedule and a way to verify identity, not the chart. An agent who takes after-hours messages needs to record the caller's details and the reason for the call, not to read the history.

Write the roles down before access is granted. For each role, list the systems, the screens within those systems and the fields the agent may see, and note what they may not. This document is what the vendor uses to configure access and what you use to audit it later. It is also the basis for the scripts, because an agent who cannot see a result cannot be tempted to read it out.

Then specify the access precisely. Agents should reach exactly the systems the role requires and nothing more. That means named accounts rather than shared logins, permissions scoped to the function, access provisioned through a documented process and revoked the same day someone leaves, and session logging you can review. A vendor that cannot describe its offboarding process in specifics has not thought about the risk that matters most. Decide where the work is done and on whose systems, too. Agents working inside your practice management system through your accounts, with your logging, are easier to audit than agents working in a vendor's copy of your data. Where the vendor must hold data, the agreement should say what, where and for how long.

The three categories of safeguards

HIPAA's security requirements are grouped into administrative, physical and technical safeguards, and a good vendor can describe what it does under each heading without being prompted.

Administrative safeguards are the policies and people: a named security officer, risk analysis, workforce training, sanctions for violations, access management procedures, and a contingency plan. Ask who owns security at the vendor, when the last risk analysis was done, and how a policy violation is handled.

Physical safeguards cover the premises and the devices: who can enter the floor where calls are taken, whether personal phones are allowed at the desk, what happens to paper, how workstations are positioned and locked, and how equipment is disposed of. For remote or home-based agents, ask how the same controls are applied outside an office.

Technical safeguards cover the systems: unique user accounts, automatic logoff, encryption in transit and at rest, audit logs of who accessed what and when, and integrity controls that show whether a record has been altered. Ask to see how access is provisioned and how quickly it is revoked when someone leaves the programme.

Recording, retention and what agents may say

Three rules need writing down explicitly. What may be recorded, and whether recordings capture protected health information. How long recordings and notes are retained, and how they are destroyed. What an agent may read back, write down or repeat to a caller who cannot be verified.

That last one causes more real-world problems than the other two combined. A family member calling about a patient is a routine situation with a non-routine answer, and agents need a scripted response rather than judgement in the moment. The script should cover identity verification steps, what may be confirmed to a verified caller, what may be said to an unverified one, and how to take a message without disclosing anything. Recording consent rules also vary by state, so the announcement wording needs confirming with counsel.

Offshore processing, decided deliberately

HIPAA does not prohibit processing protected health information outside the United States, and plenty of practices use offshore delivery for medical billing and patient support and do it well. What changes offshore is that enforcement and recourse become practically harder, so the contractual and technical controls carry more weight.

If you go offshore, be deliberate. Confirm the business associate agreement extends to every subcontractor. Establish exactly which country processes and stores the data. Confirm your own state law, your payer contracts and your cyber insurance do not impose a stricter requirement than HIPAA does. Some do, and finding out after launch is expensive.

Workforce training, not a policy document

Every agent touching protected health information needs training on it, and you should ask what that training actually consists of, how often it repeats, and how it is verified. A statement that all staff complete HIPAA training means nothing without those three details. Ask to see the material, ask how a new agent is assessed before taking live calls, and ask how a refresher is triggered when a script or a rule changes.

Training also needs to be specific to your programme, not generic. An agent who has learned the general rules but not your verification script, your message-taking template and your escalation path will improvise, and improvisation is where disclosures happen.

Incident reporting, agreed in advance

A business associate is required to report to the covered entity when protected health information has been used or disclosed in a way the agreement does not permit, including breaches. The agreement should say how quickly the vendor must notify you, in what form, who investigates, what evidence you receive, and who handles any further notification obligations. Decide all of it before launch. A vendor learning your expectations during an actual incident is the worst possible time.

Ask what the vendor's incident process looks like in practice: who is called first, how the affected records are identified, how access is suspended, and what the written report contains. Ask whether they have run it before. A rehearsed process is a different thing from a paragraph in a contract.

The vendor checklist

Nine questions. A vendor that answers all nine specifically has done this before. One that answers in reassurances has not.

Documented handling is the difference between outsourcing that reduces your risk and outsourcing that increases it. Our HIPAA medical answering service page describes how patient call handling is scoped, how access and scripts are agreed, and what documents a practice should expect from us before launch. The healthcare outsourcing page covers the wider programme. Once again, this is general information, and your counsel or compliance adviser should confirm what applies to your practice.

  • Whether they will sign a BAA, and whether it flows down to subcontractors
  • Which systems agents will access, with what permissions, and how the minimum necessary is applied
  • How access is provisioned, logged and revoked
  • What is recorded, how long it is retained and how it is destroyed
  • Where data is processed and stored, physically
  • What agent HIPAA training consists of, how often it repeats and how it is verified
  • What they do under each of the administrative, physical and technical safeguard headings
  • How and how quickly they report an incident to you
  • What happens to your data when the contract ends