PhoneAgent.ai

HIPAA compliant answering service for medical offices and 24/7 phone answering

Most practices ask a phone vendor the wrong question. "Are you HIPAA compliant?" invites a yes from everybody and tells you nothing, because HIPAA does not certify, approve or license anyone. The question that separates a serious vendor from a marketing page is narrower: will you sign a Business Associate Agreement, and what happens to the recordings.

Answer 24/7 · disclose AI · qualify · book the appointment

The Front Desk
What kind of business?
AI disclosed Calendar checked Appointment booked
Live call Inbound · answered 24/7 · booking

Hear it answer to watch the AI disclose, qualify the caller, check the calendar and book the appointment.

Appointment card

Live

Confirmation text sent

.

What PhoneAgent did

AI-disclosed Consent-aware TCPA-aware

Live, interactive · AI disclosed · no card needed

Appointment booked Caller routed · logged to CRM

Your agent answers like this, tuned to your hours, services, and calendar.

The short answer

A HIPAA compliant answering service is one that has signed a Business Associate Agreement before it handles a single patient call. Under 45 CFR 164.504(e) a vendor that creates, receives, maintains or transmits protected health information on your behalf is a business associate, and the BAA is required rather than optional. There is no government HIPAA certification and no official seal, so "HIPAA certified" on a vendor site describes an internal audit at best. What you can actually verify is narrow and checkable: a signed BAA, encryption in transit and at rest, named access controls and audit logs, a written retention limit on recordings, and call scripts that keep every disclosure to the minimum necessary under 45 CFR 164.502(b). PhoneAgent.ai is built for scheduling, routing and non-clinical questions rather than storing clinical records, it answers 24/7 at a flat $89 to $399 a month, and it discloses that it is an AI on every call.

Last updated July 2026

This page sets out what HIPAA actually requires of a service that answers patient calls, what a front desk may and may not say to a caller, and what the two options cost. It applies whether the phone is answered by live operators or by software. The rule does not care which, it cares about the safeguards around the protected health information either one touches. PhoneAgent.ai answers in your practice's name 24/7, books visits into your calendar, routes clinical callers to your nurse line by your rules, and is scoped so it never needs a diagnosis to do its job.

AI DISCLOSED CONSENT-AWARE TCPA-AWARE

Flat fee no per-minute surprises

Answers 24/7 never to voicemail

Why it works

What your team gets with a HIPAA compliant answering service

Scoped to the minimum

The agent takes a name, a callback number and a visit type. It does not ask for a diagnosis, so there is far less protected health information to protect.

Consistent on every call

Software follows the same script every time. Most small privacy slips come from ordinary human variability, not malice.

Disclosed and consent-aware

The AI identifies itself on every call and recording prompts follow the caller's state, which is a separate rule from HIPAA.

What it handles

Answered, disclosed and booked on autopilot

The AI receptionist answers every call 24/7, discloses it is your AI assistant, qualifies and routes the caller, answers your FAQs, and books the appointment straight into your calendar, then texts a confirmation and logs the contact to your CRM.

  • Answers patient calls 24/7 in your practice's name
  • Books and reschedules visits directly into your calendar
  • Answers non-clinical questions such as hours, location, parking and what to bring
  • Routes clinical callers and urgent symptoms to your nurse line by your rules
  • Collects only the fields you configure, never a diagnosis
HOW A CALL RESOLVES Never voicemail
Caller wants an appointment
Caller asks a question you answer often
Call is urgent by your rules Routed
Confirmation texts sent · AI disclosed Transcript on every call

Why PhoneAgent.ai

One AI receptionist that handles the whole call

Not a voicemail box, not a phone tree, and not a message-only answering service. Answer, disclose, qualify, route and book in one place, honest with every caller.

Answers every call

It answers on the first ring, 24/7, discloses it is your AI assistant, and holds a natural conversation, so no caller is ever sent to voicemail.

Honest and consent-aware

It tells callers it is an AI, recording is optional and consent-aware per state, and outbound texts are TCPA-aware with opt-outs honored.

Books the appointment

Callers get booked straight into your calendar, texted a confirmation and logged to your CRM, so the appointment is on the books before you check.

Compare

What to require of a HIPAA compliant answering service

Every row is something you can ask for in writing and verify before go-live, with the part of the rule it comes from.

What to require What it means in practice Where it comes from
A signed BAA before go-live The vendor signs a Business Associate Agreement covering calls, messages and recordings, and you hold a copy before the first patient call 45 CFR 164.504(e)
Minimum necessary scope The agent collects a name, callback number and visit type, and never reads clinical detail back to whoever is on the line 45 CFR 164.502(b) and 164.514(d)
Encryption in transit and at rest Recordings, transcripts and messages are encrypted on the wire and in storage, and the vendor can describe how Security Rule, 45 CFR 164.312
Access controls and audit logs Named roles on the vendor side, a documented business need for access, and logs you can request 45 CFR 164.308 and 164.312(b)
A written retention limit A stated retention period for recordings and transcripts, and a deletion path when the contract ends 45 CFR 164.504(e)(2)(ii)
Confidential communication requests honored When a patient asks to be reached only at work, or asks that no message be left at home, the phone workflow can actually do it 45 CFR 164.522(b)
No "HIPAA certified" claim There is no government certification program, so a certification badge is an internal or paid audit, not an approval No such program exists under HIPAA

HIPAA does not certify, approve or license vendors. This is general information rather than legal advice, so confirm the specifics for your practice with a qualified professional.

What makes an answering service HIPAA compliant?

Three things, and none of them is a badge.

The first is the Business Associate Agreement. An answering service that takes patient messages is creating, receiving and maintaining protected health information on your behalf, which makes it a business associate under the Privacy Rule. The BAA is the contract that binds it to safeguard that information and to report breaches to you, and 45 CFR 164.504(e) requires it. Without a signed BAA in place, every disclosure of patient information to that vendor is a violation on your side, not just theirs. Ask for it before go-live and read the retention and subcontractor clauses rather than skimming to the signature line.

The second is the minimum necessary standard at 45 CFR 164.502(b). Protected health information should not be used or disclosed when it is not needed for the purpose at hand. On a phone line this is mostly a design question. A front desk that books an appointment and routes a clinical caller needs a name, a callback number and a visit type. It does not need symptoms, a diagnosis or a medication list, and a service that collects those anyway has manufactured risk for no benefit. The smaller the scope, the smaller the exposure.

The third is the Security Rule safeguards around whatever is collected: encryption in transit and at rest, access limited to people with a documented business need, audit logs, and a retention period that ends. Worth knowing where the rule currently stands: the proposed overhaul of the Security Rule was published in the Federal Register on January 6, 2025 and the comment period closed on March 7, 2025, but it has not been finalized, and the federal agenda now targets July 2027 for final action. So the standard you are held to today is the existing Security Rule, not the proposal. Our fuller vendor checklist lives in the guide to a HIPAA compliant answering service, and the general evaluation questions are in questions to ask an AI receptionist vendor.


What a HIPAA compliant answering service can and cannot say to a patient

The operating principle that keeps a phone line clean is simple: capture and route, do not interpret or confirm. A front desk that follows it will rarely have a privacy problem, because it never holds enough to cause one.

  • Can: give hours, location, parking, directions, insurance plans accepted and what to bring to a first visit
  • Can: book, reschedule and cancel appointments, and send a confirmation text
  • Can: take a name, a callback number and the reason for the call in the caller's own words
  • Can: route a clinical question or an urgent symptom straight to your nurse line or on-call provider
  • Cannot: give medical advice, triage symptoms, or tell a caller whether something sounds serious
  • Cannot: confirm or deny that a named person is a patient to whoever happens to be calling
  • Cannot: read back test results, diagnoses, medications or visit history
  • Cannot: leave clinical detail on a voicemail, which is a separate trap covered in our guide to a <a href="/blog/hipaa-compliant-voicemail">HIPAA compliant voicemail</a>

What it costs, and what getting it wrong costs

Live medical answering services are the most expensive category in the industry, and HIPAA obligations are part of why. Published US rates commonly run $1.00 to $2.00 per minute with monthly minimums around $50 to $150, and a practice with real after-hours volume can land between $400 and $1,500 or more in a month. Per-minute billing also has an awkward property for a medical line: the calls you most want answered, the long ones from an anxious patient at 9pm, are the ones that cost the most.

PhoneAgent.ai is a flat $89, $199 or $399 a month with no per-minute meter, so a busy week does not change the invoice. It answers calls in parallel rather than queueing them behind one operator, which matters on a Monday morning when the whole panel calls at once.

The downside case is worth sizing too. Civil monetary penalties are set in tiers and adjusted for inflation each year; after the January 28, 2026 adjustment they run from $145 per violation at the lowest tier up to an annual cap of $2,190,294 at the willful neglect, uncorrected tier. Enforcement is not theoretical either: OCR resolved 21 settlements and civil monetary penalties in 2025, its second highest annual total on record, collecting $8,330,066, and an incomplete or missing risk analysis remained the most frequently cited deficiency. A missing BAA with a phone vendor is exactly the kind of gap a risk analysis is supposed to surface.

For the wider category view, the medical answering service page covers pricing and staffing for medical practices generally, AI receptionist for medical practices covers the workflow, and dental answering service and veterinary answering service cover the neighboring practice types. Call recording consent is a separate state-law question, worked through in state call recording consent laws.

Good questions

Questions about a HIPAA compliant answering service

It depends entirely on the arrangement, not on the vendor category. An answering service that takes patient messages is a business associate under HIPAA, so compliance requires a signed Business Associate Agreement, safeguards on the information it holds, and disclosures kept to the minimum necessary. No answering service is compliant by default, and none is officially certified, because HIPAA has no certification program.
Yes. If the service creates, receives, maintains or transmits protected health information on your behalf, 45 CFR 164.504(e) requires a Business Associate Agreement before that information reaches them. Taking a patient name, callback number and reason for calling is enough to trigger it. Get the BAA signed before go-live, not after the first patient call.
It is a phone service that has signed a BAA, encrypts recordings and messages in transit and at rest, limits access to staff with a documented business need, keeps audit logs, retains data for a stated period and no longer, and follows scripts that disclose only the minimum necessary. The badge on the website is not the thing. The signed contract and the safeguards behind it are.
Ordinary phone calls are permitted under HIPAA. The Privacy Rule was written to allow providers to treat patients, which includes talking to them by phone. What the rule governs is how much is disclosed, to whom, and what safeguards sit around any recording or message. A call itself is fine; a recording kept forever on an unencrypted system by a vendor with no BAA is not.
Yes, with a BAA in place, and it should take as little as the job requires. The minimum necessary standard at 45 CFR 164.502(b) means a service booking an appointment needs a name, a callback number and a visit type. Collecting symptoms or a diagnosis because the script asks for them creates risk without improving the booking.
The rule applies the same way to software as to human operators. Ask an AI vendor the same four questions: will you sign a BAA, is the data encrypted in transit and at rest, is our call data excluded from model training, and how long are recordings kept and who can access them. A vendor that answers those crisply in writing is serious. One that points at a compliance badge instead has told you something.
Live medical answering services commonly bill $1.00 to $2.00 per minute with a monthly minimum around $50 to $150, and practices with heavy after-hours volume often spend $400 to $1,500 or more per month. PhoneAgent.ai is a flat $89, $199 or $399 a month with no per-minute meter, so the invoice does not climb with a busy week.
Yes, within limits. HHS guidance confirms the Privacy Rule does not prohibit leaving messages on answering machines, but you should limit what is disclosed, typically to the practice name, a callback number and only what is needed to confirm an appointment. You also have to honor a patient's request under 45 CFR 164.522(b) to be contacted somewhere else, such as at work rather than at home.

Explore more

More ways businesses answer and book with PhoneAgent.ai

Stop sending customers to voicemail.

Forward your number and your AI receptionist answers every call, discloses it is an AI, qualifies and routes the caller, and books the appointment into your calendar. Flat monthly fee, honest with every caller.

See pricing

AI disclosed on every call · recording consent-aware per state · TCPA-aware texting