PhoneAgent.ai
Healthcare

HIPAA Compliant Voicemail: Scripts, Examples and Limits

HIPAA does not ban leaving voicemails for patients. It limits what the message may contain. Here is what a compliant message actually sounds like, four scripts you can use as written, and the results question that trips up front desks.

By the PhoneAgent.ai team

July 2026 · 8 min read

The Front Desk
What kind of business?
AI disclosed Calendar checked Appointment booked
Live call Inbound · answered 24/7 · booking

Hear it answer to watch the AI disclose, qualify the caller, check the calendar and book the appointment.

Appointment card

Live

Confirmation text sent

.

What PhoneAgent did

AI-disclosed Consent-aware TCPA-aware

Live, interactive · AI disclosed · no card needed

Appointment booked Caller routed · logged to CRM

Your agent answers like this, tuned to your hours, services, and calendar.

A HIPAA compliant voicemail is one that says as little as possible: your practice name, a callback number, and only what is needed to get the patient to call you back. HHS guidance is explicit that the Privacy Rule does not prohibit leaving messages on answering machines, so the rule is not "never leave a voicemail." It is the minimum necessary standard at 45 CFR 164.502(b), applied to a message that somebody other than the patient may well hear. Leave the reason for the call out of it, leave clinical detail out of it, and honor any request the patient has made about where and how you contact them.

That is the whole rule in three sentences. What follows is what a compliant message actually sounds like, four scripts you can use as written, the one question that trips up front desks more than any other, and where voicemail quietly costs a practice money even when it is perfectly compliant.

Is voicemail HIPAA compliant?

Voicemail is permitted. This surprises people, because the folklore in a lot of medical offices is that HIPAA banned leaving messages, and staff end up hanging up on answering machines to be safe.

HHS addressed this directly. The Privacy Rule permits covered entities to communicate with patients about their care, and it does not prohibit leaving messages on an answering machine. What it requires is that you reasonably safeguard the patient's privacy by limiting the amount of information disclosed. HHS suggests a covered entity may want to consider leaving only its name and number, plus other information necessary to confirm an appointment, or simply asking the individual to call back.

The reason for the limit is practical rather than technical. Answering machines are heard by whoever is in the room. Household members, roommates, an ex-partner, a teenager's parent, a colleague standing near a desk phone. HIPAA does not assume the person who dialed is the only person who will hear you, so the message has to be safe if the wrong person plays it.

What is a HIPAA compliant voicemail?

It is a message that would cause no harm and reveal nothing if a stranger heard it. Concretely, it contains four things at most:

  • The name of the practice, or in sensitive specialties, just a first name and a callback number
  • A callback number
  • A request to call back, or a bare appointment confirmation with date and time
  • Nothing else

What makes a message non-compliant is almost always the reason for the call. "Calling about your biopsy results" identifies a condition. "Your prescription for the anxiety medication is ready" identifies a diagnosis and a medication. "Confirming your appointment at the fertility clinic on Thursday" identifies a course of treatment. In each case the caller thought they were being helpful, and in each case the message discloses more than getting a callback required.

The practice name itself deserves a moment of thought. For a general practice, saying the name is fine and usually helpful. For a practice whose name announces the specialty, an addiction treatment center, a psychiatric practice, an infectious disease clinic, the name alone can be the disclosure. Those practices commonly leave a first name and a number instead.

What does a HIPAA compliant voicemail look like?

Here are four messages you can use as written. They are deliberately short, because length is where detail creeps in.

1. Generic callback request, safe for any specialty:

Hello, this message is for Jordan Reyes. This is Alex calling from Lakeside Medical. Please call us back at 555-0147 at your convenience. Thank you.

2. Appointment confirmation, the one case where detail is allowed:

Hello, this message is for Jordan Reyes. This is Lakeside Medical calling to confirm your appointment on Tuesday, August 11 at 2:15pm. If you need to change it, call us at 555-0147. Thank you.

3. Sensitive specialty, practice name withheld:

Hello, this message is for Jordan Reyes. This is Alex returning your call. Please reach me at 555-0147. Thank you.

4. Results are in, and the patient must call:

Hello, this message is for Jordan Reyes. This is Lakeside Medical. We have something to discuss with you, so please call us back at 555-0147. Thank you.

Notice what is missing from all four: no reason for the call beyond a confirmation, no condition, no medication, no department name, no urgency language that implies bad news. "We have something to discuss" is deliberately flat, because "please call us urgently about your results" tells a listening household member roughly as much as naming the condition would.

Can a doctor's office leave test results on voicemail?

Not as a default, and not without the patient having agreed to it. Test results are clinical information, and leaving them on a machine that anyone in a household can play back is the exact disclosure the minimum necessary standard is meant to prevent. The safe pattern is the fourth script above: say you need to speak with them and give a number.

There is a real exception worth knowing. A patient can ask you to leave results on voicemail, and many do, because they are tired of phone tag over a routine cholesterol panel. If a patient has requested it and you have documented that request, leaving the result is defensible. What is not defensible is a front desk deciding case by case that this particular result seems harmless enough. Document the preference, store it where whoever makes the call can see it, and default to no results on voicemail for everybody else.

How do you leave a HIPAA compliant voicemail?

Five steps, in order, every time:

  1. Check the patient's contact preferences before dialing. If they have asked to be reached only at work, or asked that no message be left at home, that request governs.
  2. Confirm you dialed the number in the chart, not one scribbled on a message pad.
  3. Ask for the patient by name, so a wrong-number recipient knows immediately the message is not for them.
  4. Give your first name, the practice name if the practice name is not itself a disclosure, and the callback number. Say the number twice.
  5. Stop. Do not explain why you are calling.

The fifth step is the one that fails. Staff want to be helpful, and "just so you know, it's about your lab work" feels kind in the moment. Write the script down, tape it near the phone, and train to it, because a rule that lives only in someone's memory gets improvised at 4:55pm on a Friday.

What about the voicemail greeting on your own office line?

Your outgoing greeting has a different risk profile, and one specific trap. The greeting itself discloses nothing about any individual, so it is not a privacy problem. The problem is what it invites patients to say.

A greeting that says "leave your name, number and the reason for your call" is asking patients to record protected health information onto whatever system holds your voicemail. That is fine if the system is covered by your safeguards and, where a vendor holds it, by a signed Business Associate Agreement. It is not fine if messages land in a consumer mailbox forwarded to a personal cell phone, which is a more common arrangement in small practices than anyone likes to admit.

Two things worth fixing. First, know where the recordings physically live and who can play them, and if a vendor is involved, get the BAA in writing before patients start talking. Our page on what to require of a HIPAA compliant answering service sets out the full checklist, and the deeper vendor guide is in what to actually check in a HIPAA compliant answering service. Second, if you record calls as well as messages, note that recording consent is a separate question governed by state wiretapping law rather than by HIPAA, and roughly a dozen states require every party to consent. That is worked through in state call recording consent laws.

Practices with real compliance programs tend to handle this by tracking the obligation and the control in the same place they track everything else, rather than leaving the phone line as the one system nobody has mapped to a written control. A missing BAA with a phone vendor is precisely the sort of gap a risk analysis exists to surface, and an incomplete or missing risk analysis was the most frequently cited deficiency in OCR enforcement actions in 2025.

What if a patient asks you not to leave messages at home?

You generally have to accommodate it. Under 45 CFR 164.522(b), individuals have the right to request that you communicate with them by alternative means or at an alternative location, and covered entities must accommodate reasonable requests. HHS gives examples of what counts as reasonable: mail in a closed envelope rather than a postcard, mail to a post office box rather than a home address, calls to a work number rather than a home number. Absent extenuating circumstances, those are reasonable requests.

The compliance failure here is rarely a refusal. It is that the request gets made to one person at the front desk, written on a sticky note, and never reaches the person who makes the callback three weeks later. The request has to live in the chart, in a field that surfaces before anyone dials.

This matters more than it used to. Civil monetary penalties are adjusted for inflation annually, and after the January 28, 2026 adjustment they run from $145 per violation at the lowest tier to an annual cap of $2,190,294 at the willful neglect, uncorrected tier. OCR resolved 21 settlements and civil monetary penalties in 2025, its second highest annual total on record, collecting $8,330,066.

Where compliant voicemail quietly costs you patients

Here is the part nobody writes about. Every rule above pushes you toward saying less, which is correct for privacy and terrible for getting anything resolved. A perfectly compliant message triggers a callback, that callback reaches your voicemail, and now two parties are trading messages that neither is allowed to make useful.

Meanwhile the calls that need answering most are the ones arriving when the front desk is gone. A patient calling at 7pm to move Thursday's appointment does not need a clinician and does not need to disclose anything sensitive. They need somebody to open the calendar. If that call lands in voicemail, some of them simply do not call back, and a no-show costs the practice a slot it could have refilled.

The structural fix is to stop routing the routine calls into a mailbox at all. An AI receptionist for a medical practice answers at any hour, books and reschedules directly into the calendar, and answers the non-clinical questions about hours, parking, insurance and what to bring, none of which requires a diagnosis or creates a privacy exposure. Anything clinical routes straight to your nurse line by your rules. The medical answering service page covers how that compares on price to live operator services, which commonly bill $1.00 to $2.00 per minute, and after-hours answering covers the evening and weekend window specifically.

The privacy logic works in your favor here, which is the counterintuitive bit. A front desk scoped to booking and routing needs a name, a callback number and a visit type. It never needs the reason a patient is worried, so there is far less protected health information in the system than a mailbox full of patients explaining their symptoms to a machine.

The one sentence version

Leaving a voicemail for a patient is allowed, so long as the message contains only a name, a callback number and at most an appointment confirmation, never the reason for the call or any clinical detail, and so long as you honor any request the patient has made about where to reach them. Write the script down, keep results off the machine unless the patient asked for them, know who holds the recordings, and move the routine scheduling calls somewhere they can actually be resolved instead of leaving them to bounce between two mailboxes.

This is general information, not legal advice. HIPAA obligations depend on your specific situation, so confirm the details with a qualified professional.

Hear PhoneAgent.ai answer and book

The AI receptionist answers every call 24/7, greets callers in your business name, books appointments into your calendar and texts missed callers back. Flat fee, no per-minute meter, AI disclosed on every call.

Never miss another call

PhoneAgent.ai answers every call 24/7, greets callers in your business name, books appointments into your calendar and texts missed callers back. Flat fee, no per-minute meter, AI disclosed on every call.

AI disclosed · Recording consent-aware · Books appointments

AI disclosed on every call · recording consent-aware · TCPA-aware.