HIPAA Compliant Answering Service: What to Check
A signed BAA is only the first requirement. What voicemail scripts, texting, and after-hours escalation still need to get right for real HIPAA compliance.
Is it right for you?
Your checks are saved on this device only — they reset if you clear browser data or switch devices.
A signed BAA is required, not a nice-to-have
Under 45 CFR 164.502(e), any vendor that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity is a business associate, and a phone answering service that takes a patient's name, symptom, and callback number every time it picks up the line fits that definition without much room for debate. The Business Associate Agreement is the contract that makes the vendor legally accountable for protecting that information the same way the practice itself is; without one, every patient call routed through the service is technically an unauthorized PHI disclosure, regardless of how careful the vendor's agents actually are on the phone.
The counter-argument some vendors and even some practices lean on is the HIPAA "conduit exception," the idea that a service merely passing a message along, the way the U.S. Postal Service passes along a sealed envelope, doesn't need a BAA at all. HHS draws the line on whether access to the information is transient or persistent: "The conduit exception is limited to transmission-only services for PHI (whether in electronic or paper form), including any temporary storage of PHI incident to such transmission. Any access to PHI by a conduit is only transient in nature. In contrast, [a vendor] that maintains ePHI for the purpose of storing it will qualify as a business associate, and not a conduit... the difference between a conduit and a business associate is the transient versus persistent nature of the opportunity to access protected health information" [HHS.gov, FAQ 2077, checked 2026-09-16]. A vendor that takes down a caller's symptoms, holds that message until an on-call provider checks in, and relays it by voicemail or text has persistent access to the content, not the fleeting pass-through the conduit exception was written for. That reading is consistent across the compliance guidance written specifically for medical practices evaluating answering services, not just this site's interpretation of the rule.
In practice, that means the BAA question isn't a judgment call a practice gets to make on its own. If the answering service handles any call where a caller might mention a symptom, a medication, or a reason for calling, treat the BAA as a precondition for using the service at all, and get it before the first call routes through, not after a compliance officer asks about it during an audit.
Generalist receptionist services vs. medical-specialty answering services
Two different categories of vendor both advertise HIPAA-compliant call handling, and they are not interchangeable. Ruby and Posh, reviewed in detail elsewhere on this site, are generalist live-receptionist services that also serve law firms, home-services companies, and other client types; medical accounts are one vertical among several. MAP Communications and notifyMD, by contrast, are answering services built specifically around medical and physician-group workflows, on-call rotation schedules, pharmacy callback routing, and message triage tiers baked into the product rather than configured after the fact.
| Vendor | Category | HIPAA / BAA status | Built-in medical workflow |
|---|---|---|---|
| Ruby | Generalist live receptionist | BAA available as a free opt-in; Ruby sends the agreement to sign on request [ruby.com, checked 2026-09-16] | No native on-call rotation or pharmacy callback routing |
| Posh | Generalist live receptionist | Markets HIPAA-compliant handling for medical/dental/behavioral-health accounts; specific BAA process not detailed on public pages, confirm directly [posh.com industry pages, checked 2026-09-16] | No native on-call rotation or pharmacy callback routing |
| MAP Communications | Medical-specialty answering service | Signed BAA before PHI changes hands, with flow-down agreements to subcontractors; SOC 2 and HITRUST certified [mapcommunications.com, checked 2026-09-16] | Physician on-call scheduling built into the service, customizable per office |
| notifyMD | Medical-specialty answering service | Signs a BAA, uses HIPAA-compliant VoIP with encrypted storage; HITRUST certified [notifymd.com, checked 2026-09-16] | Integrates with EHR platforms including Epic, Athenahealth, and eClinicalWorks for scheduling |
The practical difference shows up after hours, not during a routine daytime call. A generalist service can take a message competently regardless of vertical, but it typically has no built-in concept of which physician is on call this week, which calls need to interrupt someone's evening versus wait until morning, or how to route a pharmacy's callback about a prescription question to the right person. A medical-specialty service treats that routing logic as the core product, not an add-on, which is also why it tends to cost more per minute: the price difference is largely the cost of that workflow, not just the HIPAA paperwork.
HITRUST certification, which both MAP Communications and notifyMD hold, is worth distinguishing from a BAA. A BAA is a contract; HITRUST is a third-party security assessment (the HITRUST CSF framework) that a vendor pays to be independently audited against, covering things like encryption standards, access logging, and incident response, considerably more rigorous than the self-attestation most "HIPAA-compliant" marketing pages amount to. Neither Ruby's nor Posh's public pages mention HITRUST certification for their standard service. Both MAP Communications and notifyMD separately market themselves as the first answering service to reach HITRUST certification, a claim this article can't adjudicate between them; what's independently confirmable is that both currently hold it.
Where compliance actually breaks: voicemail and texting
A signed BAA covers the vendor's legal accountability for PHI; it does not automatically make every downstream message channel compliant. Voicemail is the most common place this goes wrong. HIPAA's minimum-necessary standard means a message left for a provider or a patient should include only a name, a callback number, and a general reason for the call, never a diagnosis, a medication name, a lab result, or a condition-revealing word like "oncology" or "behavioral health" unless the patient has specifically authorized more detail. A voicemail box that a covered entity doesn't control (a personal cell phone's carrier voicemail, for instance) is also a weaker point of the chain than an encrypted, access-logged system, since the practice can't verify who else might access it.
Texting carries a sharper version of the same problem. Standard SMS is not encrypted end-to-end and does not include the access controls, audit trails, or authentication HIPAA expects for transmitting PHI, so sending a patient's appointment details or symptom summary through a vendor's plain consumer texting line is a compliance gap even if the answering service itself has signed a BAA. The two accepted fixes are an encrypted SMS gateway, which wraps the standard SMS channel in an encrypted layer end to end, or a dedicated secure-messaging app with built-in encryption, authentication, and audit logs. Before turning on any texting feature a vendor offers, ask specifically which of those two models it uses, and don't assume "we text you the message" means the same thing as "we text you the message securely."
This is also where the earlier BAA-versus-marketing-claim distinction matters most in practice: a vendor can have a fully signed BAA in place and still route messages through a texting or voicemail channel that isn't itself built to the same standard. The BAA makes the vendor accountable if that happens; it doesn't prevent it from happening. Confirming the actual delivery channel, not just the contract, is the step a lot of practices skip.
After-hours triage: what a generic answering script does not cover
A general-purpose live receptionist script, of the kind covered in our answering service pricing breakdown, is built to route a call, take a message, or book an appointment. A medical after-hours triage script has to do something more specific: sort every incoming call into an urgency tier, decide whether it needs to interrupt an on-call provider immediately, wait for a scheduled callback window, or get routed to 911 or the nearest emergency department instead of held for a callback at all. Getting that triage wrong in either direction has a real cost, a delayed urgent call is a patient-safety problem, and an over-triggered urgent escalation on every routine refill request burns out the on-call rotation fast.
This is the piece that's hardest to verify from a vendor's marketing page and the one worth asking about directly before signing: what specific criteria does the service use to decide a call is urgent, how is that on-call physician actually reached (a direct transfer, a page, a text with acknowledgment required), and what happens if the on-call provider doesn't respond within a set window. A medical-specialty service should have a documented answer to all three; a generalist service may improvise a version of it per account, which is worth confirming rather than assuming.
Frequently asked questions
What is the cheapest HIPAA-compliant phone service?
No single vendor holds that title, since the final bill tracks call volume and whether a practice wants a person or an automated system picking up. Ruby's opt-in compliance path costs nothing extra on top of its regular plan, which puts it near the low end for a solo practitioner; a physician group leaning on dedicated on-call routing and outside security audits should expect a steeper per-minute rate for that extra machinery.
How much does it cost to hire an answering service?
Expect metered pricing, per minute or per call, rather than one flat number, and expect most vendors serving this niche to push you toward a custom quote instead of a sticker price. Base that request on your practice's real monthly call log, including seasonal swings, rather than a hypothetical average, before you stack quotes side by side.
Are voicemails HIPAA compliant?
Nothing about a voicemail box makes it compliant on its own; the outcome depends on what gets said into it. Stick to identifying details a caller would need for a callback, who's calling and a number to reach them, and leave anything about a specific condition or prescription out unless that patient has already given the green light to share it.
Which texting service is HIPAA compliant?
The default text message app on a phone doesn't clear the bar, since it skips the login controls and audit trail the rule expects for PHI in transit. Compliance only shows up once a vendor wraps SMS in its own encryption layer or hands the job to a purpose-built secure app, so get a straight answer on which of the two a prospective vendor actually runs before trusting it with a patient's information.
Can a general answering service like Ruby or Posh handle medical calls instead of a dedicated medical answering vendor?
It can, once you have the signed agreement in hand rather than a marketing claim, and that's usually enough for a single-provider office without complicated coverage needs. Once a group has several physicians rotating call duty and pharmacies phoning back about prescriptions, the extra spend on a vendor built around that exact workflow tends to pay for itself in fewer dropped handoffs.