The Unseen HIPAA Mistake Most Practices Don't Know They're Making
Updated: Aug 24

Key Takeaways:
A HIPAA violation doesn't require a data breach. Simply operating without a required compliance agreement is a violation on its own, and it can carry real financial penalties.
HIPAA compliance doesn't automatically extend to every connected vendor, including phone systems and answering services.
Any outside vendor handling patient health information on a practice's behalf, including an answering service or nurse line, is legally required to have its own signed Business Associate Agreement (BAA).
A genuinely HIPAA-compliant answering service has its own BAA, its own safeguards, and a secure connection into the practice's EHR.
What would happen when a patient calls your practice at 6 p.m. with a question about post-procedure symptoms, and no one picks up?
Your office is closed, the call rolls to voicemail, and by the time a nurse can call back the next morning, the patient has already searched for urgent care nearby or worse, they have waited out the night unsure whether to worry.
This scenario repeats itself across specialty and primary care practices every evening, weekend, and even on holidays. And this is why more practice leaders are re-examining whether their existing after-hours answering service still fits how patients are now expecting to reach them.
In this article, we will not discuss whether after-hours coverage matters because they surely do. Instead, we will help you determine whether the current coverage you have is still the right one.
How confident are you that your answering service is HIPAA-compliant?
Most practices, in fact, feel confident about their HIPAA compliance. The EHR is certified, the staff have been trained, and the practice has a privacy policy on file. By every internal measure, the compliance looks handled well.
But what if a patient’s attorney requests a full account of how a nurse-line message about chest pain was received, documented, and routed to the on-call provider? Who specifically took the call, what was said, and where that information is stored? The EHR record is complete and properly documented, but the call itself didn't originate in the EHR. Instead, it came through an outside answering service that was not initially reviewed for HIPAA compliance.
Many medical practices assume that compliance travels automatically from a certified EHR to every vendor connected to it. It actually doesn't, and the phone system answering a practice's very first patient call is usually where that assumption is tested first.
The HIPAA Assumption Most Practices Make
The belief is understandable. If the EHR vendor has done the compliance work, it feels reasonable to assume every tool feeding into that system inherits the same protection.
But HIPAA doesn’t work that way.
Compliance is a set of obligations that applies separately to each vendor handling protected health information (PHI) on a practice's behalf, and it does not pass down from one compliant system to the next. Any person or entity outside a covered entity's own workforce that performs functions involving the use or disclosure of PHI is defined as a business associate under HIPAA's Privacy Rule. An EHR being compliant says nothing about whether the answering service routing calls into it meets that same HIPAA standard.
This is exactly where the problems tend to arise.
Picture a practice using an outsourced, general-purpose answering service for after-hours calls or nurse-line messages. A patient calls describing symptoms, leaves a callback number, and asks a scheduling question. That conversation is considered protected health information (PHI) the moment the patient starts sharing.
Medical answering services that take calls from patients and record messages containing health information qualify as business associates, because receiving that information is a core part of the service they provide. They are vendors handling protected data; therefore, there must be a signed Business Associate Agreement (BAA) on file, documented safeguards, and a clear structure for how message data is stored and who can access it before it reaches staff. The moment an answering service operator takes a call containing patient health information, they have received PHI on the practice's behalf, and every call handled without a signed BAA in place has been a HIPAA violation.
The Cost of a HIPAA Violation for Medical Practices
A HIPAA violation doesn't require a breach.
Missing business associate agreements are among the most commonly cited HIPAA violations, and the Office for Civil Rights (OCR) has issued a penalty of as low as $31,000 to as much as $750,000 for a missing BAA alone. In 2016, Raleigh Orthopaedic Clinic in North Carolina agreed to pay $750,000 and a robust corrective action plan after turning over the X-ray films and related health information of 17,300 patients to a company with no BAA in place. In another case two years later, Advanced Care Hospitalists, a Florida contractor physician group, paid $500,000 and adopted a substantial corrective action plan after sharing patient information with a medical billing vendor without ever executing a BAA. In both cases, no breach needed to occur; the missing agreement was the violation itself.
While neither case involved a medical answering service, the same standard still applies just as strictly. OCR’s enforcement pattern applies to any vendor that creates, receives, maintains, or transmits PHI on a practice’s behalf — regardless of what that vendor does or how it integrates with the practice’s systems. A medical answering service can even be entirely disconnected from a practice's EHR and still be squarely within HIPAA's reach the moment it takes a call containing patient information. In other words, a practice using an outsourced answering service for after-hours or nurse-line calls also carries the exact same exposure as the abovementioned practices in the settlements.

What A HIPAA-Compliant Answering Service Looks Like
A genuinely HIPAA-compliant answering service satisfies a defined, verifiable standard:
It signs a Business Associate Agreement (BAA) establishing its legal responsibility for any patient information it receives.
It encrypts calls and messages both at rest and in transit, so information can't be intercepted or accessed if a device or system is compromised.
It maintains access audit logs, creating a record of who viewed or handled a given message and when, which matters if a practice ever needs to demonstrate exactly what happened with a patient's information.
It provides secure messaging for relaying PHI back to on-call staff, rather than routing patient details through unencrypted text or personal email.
It applies a minimum-necessary standard, collecting only what's needed to route the call correctly, such as a name, callback number, and brief description of the concern.
It trains its staff on HIPAA requirements annually, so the team training the AI voice agent understands the obligations and boundaries around patient information.
A HIPAA-compliant answering service should be the baseline standard for any medical practice handling patient calls. Practices that confirm this proactively avoid a far more difficult conversation later — one prompted by an incident, an audit, or a records request.
Closing the Gap
Overlooking a medical answering service’s compliance status reflects a wrong assumption from most practices — that HIPAA compliance extends automatically from the EHR to every connected vendor. A brief review of current phone and nurse-line infrastructure against this standard can close an exposure that may have existed for years, unnoticed until now.
To see what a HIPAA-compliant answering service looks like when it's built specifically for medical and mental health practices, visit Aidion Health or schedule a demo with an expert to walk through how it applies to your practice.
Frequently Asked Questions (FAQs)
1. Does a medical answering service need a Business Associate Agreement (BAA)?
Yes. Any answering service that receives patient information during a call is a business associate under HIPAA and must have a signed BAA with the practice before handling that information.
2. Can a practice be penalized for a missing BAA even if no data was ever breached?
Yes. OCR treats a missing BAA as a violation on its own, independent of whether a breach occurs. Settlements for this exact issue have ranged from $31,000 to $750,000.
3. Does an answering service need to be HIPAA-compliant if it's not connected to the practice's EHR?
Yes. The BAA requirement is triggered by handling PHI (creating, receiving, maintaining, or transmitting it), not by whether the vendor connects to the EHR. A phone system can be entirely separate from the EHR and still fall under HIPAA.
4. What should a practice check to confirm its answering service is HIPAA-compliant?
Confirm the vendor has a signed BAA on file, encrypts calls and messages, limits data collection to the minimum necessary, and trains its staff on HIPAA requirements annually.
5. Who enforces HIPAA violations related to missing BAAs?
The HHS Office for Civil Rights (OCR) is responsible for investigating and penalizing HIPAA violations, including cases where a required BAA was never executed.
.png)


