01
What to ask any answering service about HIPAA
If you're evaluating vendors, these questions separate real safeguards from marketing copy. We'll answer every one of them in writing.
- Will you sign our BAA, or yours, before handling PHI?
- Where are call recordings and transcripts stored, and are they encrypted at rest?
- Who at your company can access our patients' call data, and how is that logged?
- Can we set our own retention period and request deletion?
- Which subprocessors handle PHI, and do they have BAAs with you?
- How do you notify us in the event of a breach, and how quickly?
