At 2:14 in the morning a patient calls the practice number and gets a live operator three states away. She gives her name, her date of birth, the medication she took, and the symptom that scared her enough to call. The operator types it up and sends it to the on-call physician. Four pieces of protected health information have just been created, received, and transmitted by a company the patient has never heard of.
That company is a business associate under HIPAA. Not "sort of," not "if the contract says so": by definition. OCR (the HHS Office for Civil Rights) has enforced against business associates since at least 2016. Its list includes a $650,000 settlement over a business associate's failure to safeguard nursing home residents' PHI (June 29, 2016), a $2.3 million settlement with a business associate over a breach affecting over 6 million individuals (September 23, 2020), a $350,000 settlement with MedEvolve over disclosure of PHI on an unsecured server (May 16, 2023), and a March 5, 2026 settlement with MMG Fusion, a software business associate that, per OCR's announcement, had no accurate and thorough risk analysis and failed to notify the covered entities whose data was exposed.
This guide is written for both sides of the phone: the answering service that needs to understand its own obligations, and the practice that needs to know what to demand from the service. It covers business associate status, what P.H.I. (Protected Health Information) looks like in a call center, the violations that recur, how a service builds its program, the practice's vetting checklist, and the proposed Security Rule update.
HIPAA Compliance for Medical Answering Services: Business Associate Status and Everything That Follows
45 CFR 160.103 defines a business associate as a person who, on behalf of a covered entity and "other than in the capacity of a member of the workforce," "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter." An answering service receives PHI on every call, creates it in the message, maintains it in the call log and recording, and transmits it to the on-call clinician. It hits all four verbs. The practice cannot contract around that status, and the service cannot disclaim it.
Three consequences follow directly from the regulation:
- The Security Rule applies to the service directly. 164.302 states that "a covered entity or business associate must comply with the applicable standards" of the Security Rule. Risk analysis, security official, workforce training, access controls, audit controls, transmission security: all of it, in the service's own name, not the client's.
- The service must report breaches to each affected client. 164.410(b) requires a business associate to notify the covered entity "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." A service that handles calls for 40 practices and suffers one intrusion owes 40 notifications, each identifying the affected individuals as 164.410(c) requires. The MMG Fusion settlement turned in part on exactly that failure.
- The service may use PHI only as the contract allows. 164.502(a)(3) limits a business associate to uses and disclosures "permitted or required by its business associate contract." Training a new operator on real messages, sharing a memorable call with a colleague, or keeping recordings after a client leaves are all outside that permission unless the contract says otherwise.
Practices carry the mirror-image duty. 164.502(e)(1) and 164.308(b) forbid a covered entity from letting a business associate handle PHI without "satisfactory assurances" documented in a written contract that meets 164.504(e). OCR's list includes a settlement titled simply "No Business Associate Agreement? $31K Mistake" (April 20, 2017). The BAA guide lists what the contract must say.
What PHI Looks Like in an Answering Service
- Live calls. Name, callback number, date of birth, provider name, reason for the call, symptoms, medications, and often the pharmacy.
- Typed messages. The relay to the on-call provider, whether by app, secure message, email, or SMS.
- Call recordings. 160.103 defines PHI to include information "transmitted or maintained in any other form or medium." The same section's definition of electronic media carves out a live voice call "if the information being exchanged did not exist in electronic form immediately before the transmission." That carve-out covers the call while it is happening. The moment the platform records it, the recording is ePHI (electronic P.H.I.) stored on a server, and the Security Rule attaches.
- On-call schedules and escalation rosters. Not PHI by themselves, but they show who receives it and are part of the access-control picture.
- Operator screens and account scripts. Instructions that say "Dr. Patel's oncology patients: transfer immediately" reveal diagnoses by routing.
- Reports back to the client. Nightly message logs, usually emailed as attachments.
Common HIPAA Violations in Answering Services
Relaying messages by ordinary SMS. 164.312(e)(1) requires "technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network." Carrier SMS offers none. The texting rules guide covers what a compliant relay looks like; a secure messaging app under a BAA, or a callback-only relay, are the common answers.
No risk analysis in the service's own name. 164.308(a)(1)(ii)(A) requires the business associate itself to conduct an "accurate and thorough" risk analysis. Many services point to the telephony vendor's security whitepaper instead. That is the vendor's analysis, not the service's, and it does not cover the operator laptops, the home offices, or the message archive. The business associate risk assessment guide explains what the analysis must cover.
Operators working from home with no policy. Remote operators are the industry norm. 164.310(b) and (c) require workstation use and workstation security policies that specify "the physical attributes of the surroundings" and restrict the machine to authorized users. A shared family computer running the operator console fails both. The remote work rules guide covers the setup.
Collecting more than the message needs. 164.502(b) applies the minimum necessary standard to business associates by name. A script that asks every caller for a full medication list and an insurance ID, when the on-call physician only needs a callback number and the chief complaint, collects PHI the service then has to protect for no reason.
Keeping everything forever. 164.504(e)(2)(ii)(J) requires the contract to provide that the business associate will, at termination, "return or destroy all protected health information" it still holds, if feasible. Recordings and logs for a client who left three years ago are a liability with no matching revenue.
Subcontractors with no agreement. The telephony platform, the SMS gateway, the overflow call center, and the cloud host are all subcontractors under 160.103, and 164.502(e)(1)(ii) requires the service to obtain satisfactory assurances from each of them. A breach at the platform is the service's breach as far as its clients are concerned.
Building the Program: The Service's Side
Name a security official under 164.308(a)(2). In a 15-seat service this is usually the owner or the operations manager.
Do the risk analysis and write down the fixes. Inventory the phone platform, the message app, the recording storage, the operator devices, the home networks, and the client-reporting email path. Then treat what the analysis finds under 164.308(a)(1)(ii)(B).
Give every operator a unique login and log what they touch. 164.312(a)(2)(i) makes unique user identification Required; 164.312(b) requires audit controls. The audit log is also how the service answers a client who asks who accessed a particular message.
Train, and sanction. 164.308(a)(5) requires security awareness training for the whole workforce; 164.308(a)(1)(ii)(C) requires a sanction policy. Operators handle the most sensitive calls a practice receives, at the least supervised hour of the day.
Write the breach procedure with the 60-day clock and the client list in it. 164.308(a)(6) requires security incident procedures; 164.410 sets the notification duty. The procedure should name who calls which client, in what order, with what information.
Sign a BAA with every client and every subcontractor, and keep them in one register with dates.
Vetting Checklist: The Practice's Side
A practice choosing an answering service should be able to check every line below before the first call is routed.
| Question for the service | What the answer should be | Rule |
|---|---|---|
| Will you sign our BAA, or provide yours? | Yes, before go-live, with the 164.504(e)(2) terms | 164.502(e), 164.308(b) |
| How are messages relayed to on-call staff? | Secure app or encrypted channel, never carrier SMS or plain email | 164.312(e) |
| Are calls recorded, where are recordings stored, and for how long? | Named platform, encrypted storage, defined retention, destroyed at termination | 164.310(d), 164.504(e)(2)(ii)(J) |
| Do operators work remotely, and under what policy? | Written workstation policy, dedicated devices, no shared machines | 164.310(b), (c) |
| When did you last complete a risk analysis? | A date within the last year, in the service's own name | 164.308(a)(1)(ii)(A) |
| Which subcontractors touch our messages, and do they have BAAs? | A list, with agreements | 164.502(e)(1)(ii) |
| How fast will you tell us about a breach? | A number of days, well inside 60, written into the BAA | 164.410(b) |
| Can you limit what operators collect for our account? | Yes, to a script the practice approves | 164.502(b) |
The business associate agreement mistakes guide lists the clauses practices most often get wrong in these contracts.
The Proposed Security Rule Update
HHS published a proposed Security Rule overhaul in January 2025. It has not been finalized and OCR is not enforcing it. As proposed, it would apply to business associates exactly as it applies to covered entities, and would require encryption of ePHI at rest and in transit, multifactor authentication, a written asset inventory and network map, automated vulnerability scans at least every six months, and penetration testing at least every 12 months. For an answering service the practical effect would be to make the telephony platform's encryption and the operators' MFA mandatory rather than Addressable. Services that adopt those controls now will have nothing to change if the rule is finalized. The Security Rule delay article tracks the timeline.
---
FAQ
Is a medical answering service a business associate under HIPAA?
Yes. 45 CFR 160.103 defines a business associate as a person who creates, receives, maintains, or transmits protected health information on behalf of a covered entity, outside the covered entity's workforce. Taking and relaying patient messages does all four.
Does the HIPAA Security Rule apply to the answering service directly?
Yes. 164.302 applies the Security Rule to business associates in their own name. The service needs its own risk analysis, security official, policies, training, access controls, and audit controls, separate from anything its clients have done.
Can operators text messages to the on-call doctor?
Not by ordinary carrier SMS. 164.312(e)(1) requires technical measures to guard ePHI in transit, and plain SMS has none. A secure messaging application under a business associate agreement, or a callback-only relay, meets the standard.
Are call recordings protected health information?
Yes. PHI includes information maintained in any form or medium. The live call itself falls under a carve-out in the electronic media definition, but a stored recording is ePHI on a server and is subject to the Security Rule.
What happens if the answering service has a breach?
164.410 requires the service to notify each affected covered entity without unreasonable delay and no later than 60 calendar days after discovery, identifying the individuals involved. Each practice then handles its own patient notifications under 164.404.
Conclusion
Whether the reader runs the answering service or hires one, the fix is the same: a signed B.A.A., a risk analysis that covers the phone platform, and a message workflow that does not leak. One Guy Consulting's Full-Scope plan covers business associates as well as practices, with the risk analysis, policies, vendor register, and training sized to the operation. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.103 (definitions: business associate, subcontractor, protected health information, electronic media)
- 45 CFR 164.302 (Security Rule applicability)
- 45 CFR 164.308 (administrative safeguards)
- 45 CFR 164.310 (physical safeguards)
- 45 CFR 164.312 (technical safeguards)
- 45 CFR 164.410 (breach notification by a business associate)
- 45 CFR 164.502 (general rules, business associate uses, minimum necessary)
- 45 CFR 164.504 (business associate contract terms)
- HHS OCR resolution agreements and civil money penalties
- HHS press release: OCR settlement with MMG Fusion, LLC (March 5, 2026)
- HIPAA Security Rule NPRM, 90 FR 898 (January 6, 2025)
Related Reading