“HIPAA-compliant” should not be treated as a product badge. Compliance depends on the covered entity, the vendor relationship, contracts, safeguards, configuration, staff behavior, subcontractors, and ongoing risk management.
This checklist helps a U.S. medical practice ask better questions before an answering service creates, receives, maintains, or transmits protected health information (PHI). It is not a legal conclusion about any provider, including OneSpec.
Determine Whether the Vendor Is a Business Associate
HHS defines a business associate based on the functions performed and access to PHI, not the vendor's marketing label. When a service handles PHI on behalf of a covered entity, the parties generally need a written business associate contract that defines permitted uses, safeguards, reporting, subcontractors, and what happens to PHI at termination.
Confirm the relationship with qualified counsel or the practice's privacy officer. Do not assume that every healthcare phone call, every practice, or every vendor arrangement has identical obligations.
Review the Business Associate Agreement
A BAA is necessary in many business-associate relationships, but signing one does not by itself make the complete workflow compliant. Review whether the agreement addresses:
- permitted and required uses and disclosures
- appropriate safeguards
- security incidents and breach reporting
- access to information needed for individual rights
- subcontractors that handle PHI
- return or destruction of PHI at termination
- termination rights for a material violation
HHS publishes sample provisions, but warns that the sample alone may not be sufficient for a binding contract or state-law compliance.
Map the Data Flow
Ask the provider to show where PHI can travel during a call:
- telephony carrier and call routing
- live operator or voice-processing system
- recordings and transcripts
- scheduling, CRM, or practice-management integrations
- notifications by text, email, or app
- backups, logs, analytics, and support tools
- subcontractors and cloud infrastructure
For each step, document who can access the data, why access is needed, where it is stored, how long it is retained, and how it is deleted.
Evaluate Safeguards, Not Marketing Terms
The HIPAA Security Rule requires regulated entities to use reasonable and appropriate administrative, physical, and technical safeguards for electronic PHI. A due-diligence review should cover:
- risk analysis and risk-management process
- workforce access and training
- authentication and role-based access
- audit and incident records
- transmission and storage protections
- backups, availability, and contingency procedures
- security evaluation and documentation
HIPAA does not reduce to one encryption algorithm or certificate. Ask how each control fits the risk and workflow, and request evidence appropriate to the decision.
Apply Minimum-Necessary Thinking
For uses and disclosures where the HIPAA minimum-necessary standard applies, collect and expose only the information reasonably needed for the task. A scheduling request may not require a detailed symptom history. Limit fields, scripts, permissions, notifications, and transcript access accordingly.
Minimum necessary has exceptions, including certain treatment disclosures. Have the practice define the correct rule for each call type rather than asking the answering service to improvise.
Plan for Incidents and Failures
Test what happens when:
- a caller reaches the wrong practice or patient record
- a notification goes to the wrong destination
- a user account is compromised
- an integration is unavailable
- a caller describes an urgent or emergency situation
- a patient asks to access or correct information
- the contract ends
The workflow should identify who is notified, which records are preserved, how access is contained, and how legal notification decisions are made. Do not copy a generic “60-day” statement into an internal incident target; contractual reporting to the covered entity may need to be much faster, while legal deadlines depend on the facts and applicable rule.
Questions to Ask an Answering-Service Provider
- Will you sign a BAA appropriate to this service and data flow?
- Which subprocessors can create, receive, maintain, or transmit PHI?
- Is customer data used to train shared AI models?
- Which recordings, transcripts, logs, and backups are retained, and for how long?
- How are access, authentication, audit records, and support access controlled?
- How and when are security incidents reported to us?
- What happens when the service cannot safely complete a call?
- How are data returned or destroyed at termination?
- What evidence supports your answers?
Sources and Limitations
- HHS overview of current Security Rule requirements: Summary of the HIPAA Security Rule.
- HHS explanation and sample provisions for business associate contracts: Business Associate Contracts.
- HHS guidance on limiting certain uses, disclosures, and requests to the minimum necessary: Minimum Necessary Requirement.
- HHS overview of business associates' direct liability for specific HIPAA requirements: Direct Liability of Business Associates.
- This checklist is general information, not legal or compliance advice. It does not certify OneSpec or any other vendor as compliant. Requirements depend on the parties, data, configuration, jurisdiction, and use case.
A credible review produces a written data map, contract, risk decision, test record, and owner for ongoing oversight. A claim on a landing page is not a substitute for that work.