A healthcare organization evaluating a HIPAA-compliant answering service should examine much more than a vendor's marketing claim. When a vendor acts as a business associate and handles protected health information, buyers should evaluate the business associate agreement, permitted uses, access controls, message delivery, subcontractors, safeguards and incident procedures.
What HIPAA Compliance Means in Answering Workflows
HIPAA does not create a single government certification badge for answering services.
The practical question is how the service interacts with protected health information and what obligations apply to the parties.
HHS explains that a business associate is generally an outside person or organization performing certain functions or services for a covered entity that involve PHI, and that covered entities may disclose PHI to business associates when required contractual safeguards are in place.
https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
Protected Health Information
Answering-service workflows can involve information about patients, appointments, providers or the reason someone is seeking care.
Buyers should map what information the service will:
- receive
- create
- store
- transmit
- access
- disclose
That exercise is more useful than simply asking whether the vendor "does HIPAA."
Business Associate Agreements
When a vendor is acting as a business associate, the parties generally use a business associate agreement defining permitted and required uses and disclosures and requiring appropriate safeguards.
HHS provides guidance and sample provisions for these contracts.
The existence of a BAA does not, by itself, prove that every operational control is adequate.
Access Controls
Ask how agents access patient information.
Evaluate:
- role-based access
- authentication
- administrative privileges
- termination of access
- workstation controls
- remote-work practices
- auditability
Access should generally be limited to what the workflow actually requires.
Message Handling
Understand how messages move from the caller to the healthcare organization.
Questions include:
- Is information sent by secure portal, app, email, text or phone?
- Is message data stored?
- For how long?
- Can supervisors view it?
- Are recordings retained?
- Which subcontractors process the data?
Escalation
Urgent medical messages require clear routing instructions.
The answering service should follow the healthcare organization's escalation rules, not make independent clinical judgments.
Buyer Due-Diligence Checklist
| Area | Question to ask |
|---|---|
| BAA | Will the provider execute an appropriate agreement when required? |
| PHI | What information will agents access? |
| Security | How is information protected in storage and transit? |
| Staff | How are agents trained? |
| Subcontractors | Which third parties may access data? |
| Access | How are user permissions controlled? |
| Incidents | What notification/escalation procedures exist? |
| Retention | How long are messages and recordings stored? |
| Workflow | How are urgent and routine calls separated? |
Limitations
A vendor cannot make the buyer's entire healthcare operation HIPAA compliant.
Compliance depends on the arrangement, the parties, their respective obligations and how the service is actually configured and used.
Call Center Magic provides educational information and does not certify vendors or provide individualized legal advice.