Every practice owner who considers outsourcing phones eventually asks the same question, usually late at night: is this even allowed? It is — HIPAA was written with outsourcing in mind. The Privacy Rule's entire business-associate framework exists so covered entities can hand work involving protected health information (PHI) to outside companies under defined safeguards. Thousands of answering services, billing firms, and call centers operate legally inside that framework every day.
"Allowed" and "safe," though, are separated by diligence. This article is the checklist we would want a prospective client to run on us — or on any vendor. It reflects how we operate our own healthcare call center, and it pairs with our HIPAA compliance overview and security practices pages.
Can you legally outsource patient calls under HIPAA?
Yes. A company that answers calls, schedules appointments, or takes messages involving your patients is a business associate — an outside entity performing functions on your behalf that involve PHI. HIPAA permits the relationship on two conditions: a compliant Business Associate Agreement (BAA) is in place, and the vendor applies the required administrative, physical, and technical safeguards. Since the HITECH Act, business associates are also directly liable for their own HIPAA violations — the responsibility genuinely binds both sides, not just yours.
What is a BAA, and why is it non-negotiable?
The BAA is the contract that makes the whole arrangement lawful. It defines what PHI the vendor may use and for what purposes, requires safeguards, obligates the vendor to report security incidents and breaches within stated timelines, flows the same duties down to any subcontractors, and requires PHI to be returned or destroyed when the relationship ends. Two hard rules follow. First, the BAA is signed before any PHI flows — not after the pilot, not "once we scale." Second, a vendor that hesitates, stalls, or claims it does not need one has answered your safety question for you. Walk away.
The HIPAA outsourcing checklist
Run every item. A trustworthy vendor can evidence each one on request — not just nod at it.
- Signed BAA before go-live, covering permitted uses, safeguards, breach notification timelines, subcontractors, and data return or destruction at termination.
- Documented HIPAA training for every agent on your account — initial and refresher — with records the vendor can produce, not just a policy PDF.
- Minimum-necessary access. Agents see only the systems and fields their role requires; an appointment scheduler does not need clinical notes.
- Unique logins and audit trails. Named accounts per agent, no shared passwords, activity logs that can answer "who accessed what, when."
- Encryption in transit and at rest for any system storing or moving PHI, including call recordings.
- Secure messaging channels. PHI never travels over personal email, personal phones, or consumer chat apps; message relay uses agreed secure methods.
- Workstation and environment controls — locked-down machines, screen privacy, clean-desk rules, and defined controls for any remote agents.
- A written incident-response process: how incidents are detected, contained, investigated, and reported to you within the BAA's timeline.
- Subcontractor transparency. The vendor names any subcontractors touching PHI and holds BAAs with each — the chain of agreements cannot have missing links.
- Sanction policy. Defined consequences for agents who violate privacy rules, actually enforced.
- Termination hygiene. Access revoked same-day when agents leave the account; PHI returned or destroyed when the contract ends.
- Periodic review rights. You can ask for training records, an updated subcontractor list, and security summaries annually — and the contract says so.
Want to see how we answer this checklist?Free operations audit — our compliance answers in writing within 1 business day.
Get My Free AuditWhat questions should you ask a vendor before signing?
- Will you sign our BAA — or provide yours — before any patient data is shared?
- How are agents trained on HIPAA, how often, and can you show completion records?
- Who exactly will have access to our systems, and how is that access scoped and logged?
- What happens, step by step, if an agent mishandles patient information?
- Do any subcontractors touch our calls or data? Under what agreements?
- How do agents relay messages containing PHI to our on-call staff?
- What happens to our data — recordings, messages, notes — if we leave?
Score the answers on specificity. "We're fully HIPAA compliant" is a slogan; "new agents complete training before touching a live call, refreshers run annually, and here are the records" is an operating practice.
What are the red flags?
Reluctance about the BAA is the loudest. Others: leaning on a "HIPAA certified" badge instead of substance (no official certification exists — see the FAQ), shared logins "for convenience," vagueness about where agents work and who employs them, no named process for incidents, and contracts silent on data return. None of these guarantees a breach; all of them tell you compliance is a brochure rather than a habit. And one boundary worth stating plainly: a non-clinical call team should never give medical advice — clinical questions must route to your licensed staff per your protocol. A vendor that does not volunteer that boundary has not thought hard about your risk.
What should happen when something goes wrong?
Even good operations have incidents — a misdirected message, a lost device. What separates safe vendors is the response: contain immediately, assess what PHI was involved and the probability of compromise, notify you within the BAA's timeline with facts rather than reassurances, document everything, and implement a corrective action so the same failure cannot repeat quietly. Ask a prospective vendor to walk you through their last incident drill or real event in exactly those terms. A vendor who has never thought about the question is more dangerous than one who candidly describes handling a small one well.
Frequently asked questions
Is there an official HIPAA certification for call centers?
No. The US government does not issue a HIPAA certification for vendors. Companies claiming to be "HIPAA certified" have, at best, completed third-party training or audits — which can be meaningful, but is not an official credential. Evaluate the substance: the BAA, training records, access controls, and incident process, not the badge.
Does HIPAA allow offshore or global teams to handle patient calls?
HIPAA itself does not prohibit business associates from operating outside the US — the same BAA, safeguard, and breach-notification obligations apply wherever the work happens. However, some state Medicaid programs and specific payer or broker contracts add their own restrictions on offshore handling of certain data, so check the contracts you operate under before signing.
Who is liable if an outsourced agent causes a breach?
Potentially both parties. Business associates are directly liable under HIPAA for their own violations, and the covered entity retains breach-notification duties to patients and regulators. The BAA allocates responsibilities — who investigates, who notifies, and within what timelines — which is exactly why the incident-response section of the BAA deserves close reading before signing.
Do you need a BAA with an answering service that only takes messages?
Almost certainly yes. If the service hears or records a caller's name together with any health context — symptoms, appointments, medications, even the fact that they are your patient — it is handling protected health information and functioning as a business associate. Message-taking is not an exemption; sign the BAA before the first call is routed.


