HIPAA and dental answering services require a relationship-specific review. If a vendor creates, receives, maintains, or transmits protected health information on behalf of a covered dental practice, the vendor may be a business associate and a written business associate agreement may be required. A signed BAA is important, but it does not by itself prove that the service, configuration, or practice workflow is compliant.
Use this checklist to organize due diligence with qualified privacy and legal advisers. It is educational, not legal advice or a compliance certification.
Map the service before reading the contract
Draw the actual information path:
- caller reaches the practice number;
- carrier or phone system routes the call;
- answering service receives audio and caller metadata;
- service creates a recording, transcript, summary, message, or request;
- notifications reach staff;
- records are viewed, exported, corrected, retained, backed up, or deleted;
- subcontractors provide hosting, telephony, analytics, support, or AI functions.
For each step, record the entity, system, data, purpose, location, access roles, retention, and transfer method. A vendor cannot be evaluated only by its dashboard because protected information may exist in telephony logs, notifications, support tools, and backups.
The AI receptionist privacy checklist provides a broader technical review. This article focuses on the business associate relationship and agreement.
Determine the relationship
HHS defines a business associate as a person or entity that performs certain functions or services for a covered entity involving access to protected health information. Business associates can also include subcontractors that create, receive, maintain, or transmit PHI on behalf of another business associate.
Do not decide based on a vendor's marketing label. Ask what the service actually does and whether it handles PHI on behalf of the practice. A service that only acts as a transient conduit may be treated differently from a service that records, stores, processes, summarizes, or makes information available later.
HHS notes that cloud service providers maintaining electronic PHI generally are business associates even when the data is encrypted and the provider lacks the decryption key. Have counsel apply the rules to the exact arrangement.
Review the permitted purpose
The agreement and service configuration should match the approved job. Define:
- call conditions the service receives;
- information it may collect;
- general facts it may state;
- messages or requests it may create;
- staff roles that receive them;
- recordings or transcripts, if any;
- analytics and quality review;
- prohibited uses;
- whether data may be used to train or improve models;
- whether de-identified or aggregated data is used and under what standard;
- retention and deletion.
A broad clause allowing any use “to improve services” deserves careful review when call data may contain PHI. The practice should understand what is optional, what is required for service delivery, and what survives termination.
Check required contract themes
HHS provides sample BAA provisions, but the final agreement must fit the relationship. Review with counsel whether it addresses:
- permitted and required uses and disclosures;
- prohibition on uses outside the contract or law;
- appropriate safeguards;
- reporting of impermissible uses or disclosures;
- Security Rule incident reporting obligations where applicable;
- access to and amendment of designated record set information when applicable;
- accounting support when applicable;
- availability of records to HHS;
- subcontractor obligations;
- return or destruction at termination when feasible;
- conditions for termination after material breach.
Do not assume a generic online BAA covers recordings, transcripts, AI processing, notifications, or every subcontractor in the actual service.
Ask about subcontractors
Request a current list of entities that may create, receive, maintain, or transmit call data. For each, ask:
- function provided;
- data received;
- country or region of processing and storage;
- retention;
- access and support model;
- contractual safeguards;
- notice process for additions or changes;
- incident responsibilities;
- deletion and return obligations.
Clarify whether the practice can object to a material change and what happens if it does. A contract that requires downstream protections is not the same as evidence that the current chain has been identified and assessed.
Review safeguards and access
Ask for evidence appropriate to the risk, including:
- unique user accounts and role-based permissions;
- authentication controls;
- logging of access and administrative changes;
- encryption and key management;
- secure transmission;
- backup and recovery;
- vulnerability and patch management;
- workforce access and training;
- support access controls;
- notification privacy;
- retention enforcement;
- account closure and data export.
HHS describes risk analysis as a foundational process covering the confidentiality, integrity, and availability of all electronic PHI an organization creates, receives, maintains, or transmits. The dental practice needs its own risk analysis; a vendor report can inform but not replace it.
Apply minimum necessary controls
Reduce the information the service requests, displays, and sends to the amount reasonably needed for the approved purpose. Review:
- intake fields;
- transcript and summary visibility;
- notification previews;
- shared inbox membership;
- manager and support access;
- exports;
- quality-review samples;
- retention periods;
- reports.
The HHS minimum necessary standard has exceptions, including certain treatment disclosures, but it generally requires reasonable efforts and policies appropriate to the entity's circumstances. Let privacy advisers determine application; do not use the phrase as a substitute for analysis.
The dental office communication policy can help translate roles into daily channel rules.
Define incident communication
Ask what the vendor reports, to whom, through which channel, and within what contractual timeframe. Separate:
- service outage;
- security incident;
- impermissible use or disclosure;
- suspected breach;
- confirmed breach;
- inaccurate answer or operational defect;
- lost or delayed request.
The agreement should not force the practice to discover critical facts through a status page or routine report. Identify an incident contact on both sides and keep it current.
Ask what evidence the vendor preserves: affected systems, dates, data types, people, access logs, containment actions, subcontractors, and corrective measures. Legal advisers should determine notification duties.
Plan termination before launch
Document:
- how forwarding is disabled;
- how open requests are reconciled;
- data export format;
- return or deletion process;
- backup and residual-data treatment;
- administrator and support access removal;
- number ownership;
- subcontractor deletion;
- certification or evidence of completion;
- records the practice must retain;
- survival of contractual obligations.
Test the administrative export before depending on it. The practice should not learn at termination that request history is readable only inside a closed account.
Keep product boundaries explicit
Missed Calls Dental captures requests from eligible missed calls and makes them available for front desk follow-up. It does not book or change appointments, verify benefits, provide clinical advice, diagnose, triage, integrate with a PMS, or replace the practice's compliance responsibilities.
Use the missed-call workflow guide to separate automated capture from staff-owned actions.
Make a defensible decision record
Keep:
- approved use case and exclusions;
- data-flow diagram;
- relationship analysis from qualified advisers;
- executed BAA and service agreement;
- subcontractor list;
- risk assessment and remediation;
- access-role approvals;
- retention decision;
- test evidence;
- incident and termination contacts;
- review date and change triggers.
Revisit the review when the service adds a new data type, AI function, subcontractor, integration, region, retention policy, or operating scope.
A BAA is a control inside a larger system. The safest owner decision connects the contract to the real call path, the narrow approved job, daily access, staff handoff, risk management, incident response, and an orderly exit.



