The moment a patient says why they're calling, your phone line is handling protected health information. Most offices have never examined what that means — for voicemail, for the answering service, or for anything with AI in the name.
Three things generally need to be true of any system that answers your practice's phone:
Most practices have never checked all three.
The front-desk phone is usually the least-examined system in a medical or dental office. The charts live in a certified records system with logins and audit trails. The imaging is locked down. The email has been through at least one security conversation. And then there's the phone — which takes in more raw patient information on a given Tuesday than anything else in the building, and which nobody has looked at since it was installed.
This isn't negligence. It's just that a phone doesn't feel like a database. But the compliance question doesn't care how it feels.
Protected health information isn't confined to charts. It's any health information tied to an identifiable person. So the moment a caller says "this is David Alvarez, I cracked a molar and I'm in a lot of pain, can someone see me today," you are holding PHI. It doesn't matter that it arrived as sound rather than a form.
That has a practical consequence. Anything that captures, stores, or passes along that call — a voicemail box, an answering service operator, a transcription tool, an AI receptionist — is handling PHI on your behalf. And under HIPAA, that generally makes them a business associate, not just a vendor.
A Business Associate Agreement is the contract that says a vendor understands it's handling PHI, will protect it, will limit who can see it, and will tell you if something goes wrong. It is the single clearest test of whether a phone vendor has actually thought about healthcare, or is simply selling you a general-purpose product that happens to have clinics as customers.
This is where a lot of setups quietly fail. Many traditional answering services are built to handle plumbers, law firms, and dental offices with the same operators and the same software. Many mainstream voicemail-to-text and call-transcription tools are consumer or general-business products. Some will sign a BAA. Plenty won't, or have never been asked.
The uncomfortable version of the question: if a patient's recorded description of their symptoms is sitting in a vendor's system right now, do you have a signed agreement covering it? If you don't know, that's the finding.
People often collapse "is it HIPAA compliant" and "can I record this call" into one issue. They're different. HIPAA governs how health information is protected. Recording consent is governed by state wiretap law, and it varies.
Some states require only one party to consent — meaning the practice can record its own calls. Others, including Massachusetts, are all-party consent states: everyone on the call needs to be aware. In practice, that's why you hear "this call may be recorded" at the start of so many calls. It's not a formality; it's how consent is established before anything sensitive is said.
If your practice operates across New England, this deserves an actual look rather than an assumption, because your callers may be in a different state than your office.
There's a newer question layered on top: if the voice answering the phone isn't human, should the caller be told?
Our position is that they should — plainly, at the start, in the first breath of the call. Not because it's clever, but because a patient deciding whether to describe a health problem deserves to know who or what they're describing it to. It's also the direction regulation has been moving. An AI receptionist that lets a patient believe they're talking to a person at the front desk is solving the practice's problem by creating the patient's.
Catchsera's agent identifies itself as an AI assistant and notes that the call may be recorded, at the top of the call. It's the first thing it does.
A call handled compliantly and then dumped into an unprotected inbox isn't handled compliantly. The tail end of the process deserves the same scrutiny:
This is the part most phone setups never address, because a voicemail box has no concept of access control and a message pad on the counter has no audit log.
You don't need a consultant to find the obvious gaps. Five questions:
If several of those produce a shrug, that's not unusual — it's the normal state of a phone system nobody has revisited. It's also very fixable.
This article is general information from a vendor that builds phone reception for clinics — it is not legal advice, and we are not your attorneys. Recording law and HIPAA obligations depend on your state, your specific setup, and facts we don't have. Use this to ask better questions, then confirm your obligations with qualified counsel.
If the voicemail contains a patient's identity and health situation, it contains PHI. The format doesn't grant an exemption. The same is true of a transcription emailed to the front desk.
Absence of a known incident isn't the same as compliance. The question isn't whether something has gone wrong; it's whether you have the agreement, the disclosure, and the access controls in place if it does.
Not inherently — it depends entirely on how it's built. A purpose-built clinical system with a BAA, disclosure at the start, controlled access, and logging can be more defensible than an unexamined general-purpose service. The technology isn't the variable; the design and the paperwork are.
Catchsera answers every call for your practice with a HIPAA-compliant setup, a BAA on every account, clear AI and recording disclosure, and a live dashboard where your team — and only your team — sees what came in.
Get a free demo →