Short answer: an answering service handling patient information is a HIPAA business associate. Compliance means a signed BAA plus real technical safeguards — encryption in transit and at rest, access controls, audit logging, workforce training and breach procedures. It does not mean a certificate, because no official HIPAA certification exists.
Start here: "HIPAA certified" is not a thing
The U.S. Department of Health and Human Services does not certify, endorse or approve any vendor as HIPAA compliant. When a service advertises itself as "HIPAA certified," it's referring to a third-party assessment or its own internal attestation — which may be meaningful, but is not a federal credential.
What actually protects your practice is documentary and technical: a signed agreement plus safeguards you can verify. Treat "certified" as marketing and ask for the substance instead.
The BAA is non-negotiable
A Business Associate Agreement is a contract that binds the vendor to protect PHI, restricts how they may use and disclose it, requires them to report breaches to you, and obligates them to flow the same terms down to their own subcontractors.
Under the HITECH Act, business associates are directly liable for HIPAA violations — but that doesn't transfer your exposure. Disclosing PHI to a vendor without an executed BAA is itself a violation. Get it signed before any patient data moves.
Safeguards to verify
Technical
- Encryption of PHI in transit and at rest
- Role-based access controls with unique user IDs
- Audit logging — who accessed what, and when
- Automatic session termination
- Secure message delivery (not plain SMS or unencrypted email)
Administrative
- Documented workforce training on PHI handling
- A designated security/privacy officer
- Breach-notification procedures and timelines
- Subcontractor management (their vendors need BAAs too)
- Data-retention and secure-destruction policies
Organizational
- Independent security attestation — SOC 2 Type II is the common one, and it demonstrates controls operating over time rather than at a single moment
- Clear documentation of where data is stored and processed
The "minimum necessary" principle
HIPAA's minimum necessary standard means collecting and disclosing only the PHI required for the task. In practice this shapes your call script: an appointment booking needs a name, callback number and reason for visit — it does not need a detailed symptom history. A well-configured answering service should let you control exactly what gets captured.
Questions to ask any vendor
- Will you sign a BAA, and can I review it before onboarding?
- Is PHI encrypted at rest as well as in transit?
- Do you maintain audit logs, and can I access them?
- Do you hold a SOC 2 Type II attestation? Can I see the report or a summary?
- Where is data stored, and for how long? How is it destroyed?
- Do your subcontractors have BAAs with you?
- What is your breach-notification process and timeline?
- How are call recordings and transcripts secured and access-controlled?
Red flags
- Reluctance to sign a BAA, or "we'll handle that later"
- Claims of official "HIPAA certification" from the government
- Message delivery over unencrypted email or plain SMS
- No audit logging, or no ability to show you access records
- Vague answers about where data lives or who can see it
- Marketing that implies the AI performs clinical triage or gives medical advice
Where we stand
AutomateNexus Voice is SOC 2 Type II, and HIPAA is available under a signed BAA for practices handling PHI. Encryption in transit and at rest, access controls and audit logging are standard, and you control exactly what the agent captures on each call.
Frequently asked questions
Is there an official HIPAA certification for vendors?
No. HHS does not certify or endorse vendors. Third-party attestations such as SOC 2 Type II are useful evidence of controls, but they are not a government HIPAA certification.
Do I need a BAA with my answering service?
Yes, if the service handles PHI on your behalf — which any medical answering service does. The BAA must be executed before PHI is shared.
Are call recordings PHI?
If a recording or transcript contains identifiable patient information, it is PHI and must be protected accordingly — encrypted, access-controlled, retained per policy and securely destroyed.
Is an AI answering service HIPAA compliant?
It can be, on the same terms as a human service: a signed BAA plus verifiable safeguards. The technology being AI doesn't change the requirements — it changes who you're contracting with, not what HIPAA demands.
The bottom line
Ignore certification badges. Ask for the BAA, the SOC 2 report, and a straight answer on encryption and audit logs. A vendor that answers those three easily is far more likely to be genuinely compliant than one leading with a logo.
More context in the complete medical answering service guide, or see our medical answering service.
This article is general information about answering services and HIPAA, not legal or compliance advice. Consult your privacy officer or counsel before choosing a vendor that will handle protected health information.
Related reading
After-Hours Medical Answering Service: On-Call Routing Without Voicemail
Patients don't get sick on a schedule. Here's how after-hours medical answering should work — protocol-driven urgency routing, on-call escalation, and no surcharge for nights.
Medical Answering Service: The Complete 2026 Guide
A medical answering service handles patient calls your front desk can't. Here's what one costs, what HIPAA actually requires, and how AI answering compares for practices in 2026.
Answering Service Pricing Models: Per-Minute vs Per-Call vs Flat-Rate
The pricing model matters more than the rate. Here's how per-minute, per-call, dedicated-agent and flat-rate answering services compare — and which one wins at your call volume.
Never miss another call.
Join 500+ businesses capturing every lead with an AI receptionist that's live in under 20 minutes.