How Leverly handles sensitive caller information
Your callers don't check which privacy law applies before they speak. They assume what they say is protected. We build every part of the platform as if they're right, whether the statute behind them is HIPAA, Medicare marketing rules, insurance data-security law, or your state's privacy act.
One standard for every call
Different clients answer to different regulators. A dental office is covered by HIPAA. A Medicare agency answers to CMS. A life insurance agency answers to state insurance privacy and data-security law. Rather than build to each floor separately, Leverly runs one standard across all of them:
- ✓Written agreements. A Business Associate Agreement for every healthcare client, and equivalent written data-protection terms where HIPAA doesn't apply.
- ✓Encryption everywhere. Calls, recordings, and records are encrypted in transit and at rest, under encryption keys we manage deliberately, not platform defaults.
- ✓Client-by-client separation. Your callers' recordings and records are stored separately from every other client's, with access controls to match.
- ✓Access that's limited and logged. Named roles, multi-factor sign-in, and an audit trail of every touch.
- ✓Retention that matches your rules. Recordings are kept to the timeline your regulator requires, in locked storage that prevents early deletion, then removed on schedule.
- ✓A clean exit. If we part ways, your records are returned in standard formats and then deleted, with written confirmation. It's in the agreement, not a promise on a call.
Which rules apply to you
Most vendors wave one acronym at every prospect. The honest answer is that the law that governs your calls depends on what you do. Here's the map:
| If you are | What governs your calls | What it demands |
|---|---|---|
| A dental or medical practice | HIPAA | A signed BAA with every vendor that touches patient information, plus security safeguards and access controls. |
| A Medicare agent or agency | CMS marketing rules | Sales and marketing calls recorded and kept at least six years; enrollment records for ten. Strict scripts and disclosures. |
| A med spa or cash-pay clinic | HIPAA, sometimes; state privacy law, always | Whether HIPAA binds you depends on how you bill. Your patients' expectations don't. State law increasingly fills the gap. |
| A life insurance agency | Insurance privacy and data-security law | Health answers aren't HIPAA-protected here, but they are regulated insurance information: restricted use, vendor safeguards, breach duties. |
Cutting across all four: recording-consent laws in all-party-consent states, telemarketing consent rules for outbound calls, and licensing lines an automated assistant must never cross. Our assistants schedule and connect. They don't recommend coverage, quote, or screen anyone by health history.
Does your answering service need to be HIPAA compliant?
If the map put you in the first or third row, this is the question that decides your vendor shortlist. We wrote the plain-English answer: who HIPAA actually covers, why "we only do scheduling" is not a safe harbor, and the five questions that surface the truth about any answering service.
The HIPAA guide for practices and clinics Who's covered, what a BAA is from zero, why "HIPAA certified" doesn't exist, and the five questions to ask any vendor. Read the HIPAA guide →Next guide: texting and calling your leads — the consent rules.
Compliance is shared. Here's the line.
Any vendor who says "sign with us and compliance is handled" is telling you something isn't right. The law splits responsibility between you and every vendor you use. We keep our side in order and show you exactly what stays on yours, starting with a short checklist at onboarding.
What Leverly handles
- Written agreement — BAA or equivalent
- Encrypted storage under managed keys
- Per-client separation of records
- Role-limited, logged access
- Retention to your regulator's timeline
- Carrier registration for business texting
- Recorded-line disclosure on every call
What stays on your side
- Your own vendor agreements — we'll show you which
- Consent language on your lead forms
- Your policies, training, and notices
- What your licensed staff say on calls
- Documenting consent for outbound outreach
Ask us the hard questions
Bring your compliance questions to a real conversation. We'll tell you which rules apply to your calls, what we handle, and what stays with you. If we're not the right fit, we'll say so.
Talk to us about your setup 15 minutes. Real answers, no script.