Answering365

Does Your Answering Service Need a Business Associate Agreement?

August 23, 2026 22 min readAnswering365 Team
Does Your Answering Service Need a Business Associate Agreement? | Answering365

Practices comparing answering services usually ask whether the provider is HIPAA compliant. It is the right question, but on its own it is not sufficient, because compliance is something a provider asserts and a Business Associate Agreement is something they sign.

If an answering service handles protected health information on your behalf — and any service taking patient calls does — HIPAA treats that service as a business associate, and the relationship is expected to be governed by a written agreement. Here is what that means in practice.

This is general information about how the arrangement usually works, not legal advice. Confirm the specifics with your own counsel or compliance officer before you sign anything.

What makes an answering service a business associate

A business associate, broadly, is a person or company that performs a function on behalf of a covered entity and handles protected health information in doing it. An answering service taking calls for a medical practice fits that description straightforwardly.

It is worth noticing how little it takes. Protected health information is not only diagnoses and test results. A message recording that a named patient called about a specific appointment, or that a particular person is seeking treatment from your practice at all, is information about that individual's care. Operators handle that from the first call onward.

So the question is rarely whether a BAA is appropriate. It is whether the provider has one, will sign it, and can describe what sits behind it.

What the agreement covers

A BAA sets out the terms under which the service may handle information on your behalf. In general terms it addresses:

  • The permitted uses — what the service may do with the information, and what it may not.
  • Safeguards the service will maintain to protect it.
  • What happens if there is a breach or unauthorized disclosure, including how and how quickly you are notified.
  • Whether and how subcontractors may be involved, and that they are bound by equivalent terms.
  • What happens to the information when the relationship ends.
  • Your ability to satisfy yourself that the terms are being met.

The value is less in the document existing than in what it forces both parties to have decided in advance.

Questions to ask before you sign

A provider set up for medical work will answer all of these specifically. Vagueness on any of them is the finding, not an inconvenience.

About the agreement itself

  1. 1Will you sign a BAA, and can we see it before committing?
  2. 2Will you sign ours, or do you require your own form?
  3. 3Who at your organization is responsible for compliance, and how do we reach them?

About what actually happens to the information

  1. 1Where are messages stored, and for how long?
  2. 2Who can access them, and how is that access removed when someone leaves?
  3. 3How are operators trained on handling patient information, and how often is it refreshed?
  4. 4Are calls recorded? If so, where do the recordings live and who can hear them?
  5. 5Do any subcontractors touch our messages at any point?
  6. 6How would we be told about a breach, and within what timeframe?

The storage and access questions are the ones that reveal most. A provider that can describe retention periods and access controls without checking has thought about this; one that answers only in adjectives has not.

Compliance is training and process, not a badge

A logo on a website is not a compliance program. What actually protects patient information is mundane and operational: how operators are trained, how systems control access, how long records are kept, what happens when staff change, and how message delivery works.

Message delivery deserves particular attention, because it is where information leaves the provider's systems and enters yours. Ask how urgent messages reach your on-call clinician and whether that route is appropriate for the information it carries. A protocol designed only for speed can end up sending detail somewhere it should not go.

Our guide to HIPAA-compliant answering services covers the operational side in more detail.

Where this applies beyond a doctor's office

Practices sometimes assume this only concerns physicians. In reality the same considerations arise anywhere patient information reaches an operator — dental practices, mental health and therapy practices, home health and hospice providers, clinics, and research centers screening candidates for a study.

Trial recruitment is a case worth flagging, because callers are not yet your patients and people assume the rules are looser. Screening calls collect health information from members of the public, which is precisely when confidentiality deserves the most attention — see cutting clinical trial costs by outsourcing recruitment calls.

One boundary that belongs in the protocol

Separate from the agreement, make sure the clinical line is written down. An operator classifies urgency against rules a clinician wrote and routes the call accordingly. An operator never interprets symptoms and never advises a patient on what to do.

That boundary protects patients, staff, and the operator, and any provider vague about it is describing a service no practice should use — whatever paperwork they are willing to sign.

What a "HIPAA compliant" claim does and does not tell you

There is no government body that certifies an answering service as HIPAA compliant. No agency inspects providers and issues a badge. So when a provider describes itself that way, it is making a self-assessment — which may be entirely accurate, but is not the same as an external verification.

That is not a reason for cynicism; it is a reason to ask what sits underneath the claim. A provider genuinely set up for medical work will welcome the questions, because answering them is how they differentiate from a general message-taking service that has added a line to its website.

The practical test is specificity. Ask how long messages are retained and you should get a period, not a reassurance. Ask who can access them and you should get a description of roles, not the word "authorized".

Common mistakes practices make

  • Assuming a BAA is in place because compliance was discussed. The agreement is a document; confirm it exists and that you have a copy.
  • Signing without reading the breach notification terms, which are the clauses you will care about most if they are ever needed.
  • Overlooking message delivery. Information is at its most exposed as it travels from the service to your team, and the route is often chosen for speed alone.
  • Forgetting to revisit it. Staff change, systems change, and an agreement signed years ago may not describe how either party now works.
  • Treating recorded calls as separate from the rest. A recording of a patient call is a record of a patient interaction.

None of these is exotic. They are the ordinary consequences of treating compliance as a procurement checkbox rather than an operating arrangement.

Answering365 provides US-based, bilingual medical answering services with fully HIPAA-compliant processes and systems. To discuss how patient calls would be handled for your practice, call 888-588-9800 or get in touch.

Never miss another call.

See how Answering365 captures every lead with live, 24/7 US-based operators.

Ready to never miss another call?

Get your first week free. No long-term contracts — just a friendly, professional voice for your business 24/7/365.

Call UsSchedule a CallGet Started