Leverly

Compliance / HIPAA

Does your answering service need to be HIPAA compliant?

The honest answer: it depends on how your practice bills. But your callers never check your billing before they speak, and what they volunteer doesn't wait for the legal analysis.

Callers don't follow scripts

Picture a routine rescheduling call. The assistant asks nothing about health. The caller says:

"I need to move my appointment. My dialysis schedule changed."

That sentence now exists in a recording, a transcript, and a database. Attached to a name and a phone number, it's protected health information, whether or not anyone asked for it. Every system holding it either protects it properly or exposes the practice that took the call.

This is why "we only do scheduling, so HIPAA doesn't apply" fails. Scheduling-only describes what the vendor asks. It says nothing about what callers volunteer, and callers volunteer everything. Federal guidance is clear that vendors regularly handling this information on your behalf can't wave it off as data that merely passes through.

What a BAA is, from zero

When a vendor handles patient information on your behalf, HIPAA requires a signed contract called a Business Associate Agreement. It makes the vendor legally responsible for protecting that information: security safeguards, breach notification, limits on use, the works.

The one-question vendor test

Ask any answering service that will touch your calls: "Will you sign a BAA?" Some can't, because their software runs on tools that can't be covered by one. No BAA means every call they answer is your exposure, not theirs. Watch how they answer. A yes should arrive in writing before you have to ask twice.

Who HIPAA actually covers

HIPAA applies to "covered entities" and the vendors who serve them. Whether that's you mostly comes down to how you bill:

  • Dental and medical practices that bill insurance electronically. Covered, full stop. Every vendor touching patient information needs a BAA.
  • Cash-pay clinics and med spas. It depends. A practice that never bills insurance electronically may fall outside HIPAA's definition, while a physician-owned or insurance-billing operation is usually inside it. Most owners have never checked. Two minutes looking at how you bill answers it.
  • Life insurance agencies. Not covered by HIPAA at all, even when callers describe their health directly. Different laws regulate those answers: insurance privacy and data-security statutes with real penalties behind them.

Here's our position either way: whether the statute technically binds you, your callers assume that standard. So every Leverly client's calls get the same handling. Encrypted, separated, access-logged, retained. The law is the floor, not the design.

There's no such thing as "HIPAA certified"

No government certification for HIPAA compliance exists. No badge, no seal, no accrediting body. Any vendor displaying one is telling you something, and it isn't reassuring.

What exists instead is evidence: signed agreements, named safeguards, documented practices you can ask about. The five questions below surface it in a single phone call, with any vendor.

The five questions to ask any answering service

1

Will you sign a Business Associate Agreement?

The contract that makes them legally responsible for protecting your callers' information.

A good answer: "Yes, here's our standard BAA," offered in writing, unprompted.

2

Where are call recordings stored, and who holds the encryption keys?

"In the cloud" is not an answer. You want named storage, encryption in transit and at rest, and keys the vendor manages deliberately.

A good answer: names the storage, the encryption, and how your callers' data stays separate from every other client's.

3

How long are recordings kept?

Your retention rules depend on your regulator: state record-keeping laws for practices, CMS timelines for Medicare work. A vendor who quietly deletes after 30 days leaves you unable to produce a call when a complaint lands.

A good answer: a stated retention policy matching your rules, in locked storage that prevents early deletion.

4

Who can see my callers' information, and is every access logged?

If the vendor can't say who has access, neither can you when a patient asks.

A good answer: role-limited access, multi-factor sign-in, and an audit trail they can show you.

5

What happens to my data if we part ways?

If leaving means losing your call history, you never owned it.

A good answer: export in standard formats, then certified deletion, written into the agreement.

How Leverly answers all five

We sign a BAA with every healthcare client. Recordings live in per-client encrypted storage under keys we manage, retained to your regulator's timeline with early deletion locked out. Access is role-limited, multi-factor, and logged. Export and deletion terms are written into the agreement.

Compliance is shared. We handle our side and show you exactly what stays on yours, starting with a five-minute checklist at onboarding.

Talk to us about your setup 15 minutes. Real answers, no script. Or see how we handle sensitive caller information across every client.