What is HIPAA?

HIPAA
HIPAA is the US law protecting health information held by providers, health plans and the vendors working for them. It runs on a compliance regime, not on a certificate anyone can issue.

What HIPAA means in practice

Two parts matter for a phone system. The Privacy Rule covers how health information may be used and shared. The Security Rule covers how it is kept safe when held on a computer.

Your practice is the covered entity and stays responsible for PHI. A vendor handling it on your behalf is a business associate.

The mechanism that makes that lawful is a signed business associate agreement between the two of you.

What people get wrong

What one rescheduling call leaves behind

Say a patient calls a dental office to move an appointment. All the assistant needs is her name, her current slot and a new time. But people talk, and she says, "I need to move my root canal on the 14th, I'm starting blood thinners next week and my cardiologist wants me to wait."

In one sentence she's volunteered a procedure, a medication and the existence of a heart condition. That sentence now sits in a transcript, and possibly in a recording and a summary too. It also passed through every system that processed the call along the way. Nobody asked for it. This is why "we only do scheduling" doesn't settle the question by itself, and why the questions about what's stored, where, for how long, and who can delete it matter more than any badge on a vendor's homepage.

"Minimum necessary" on a phone line

HIPAA has a principle called minimum necessary: use and share only as much health information as the task requires. You can apply that idea to a phone setup whatever vendor you choose, and it shrinks the problem before any contract is signed.

Start with what the assistant asks. "What's the reason for your visit?" invites clinical detail. "Is this for a new or existing patient, and which provider do you see?" gets you what scheduling needs. When a caller begins describing symptoms, the instruction can be to offer a transfer to clinical staff.

Then look at what's kept. Transcripts without audio hold less than both together. Shorter retention holds less than indefinite retention. A summary that says "reschedule request, moved to the 21st" holds less than one that repeats the caller's medical reasons.

None of this makes a setup compliant, and GreetKeeper makes no HIPAA claim. It does mean your compliance adviser is reviewing a smaller pile.

How GreetKeeper handles it

GreetKeeper makes no HIPAA claim and holds no certification of any kind. We would rather say that here than have you discover it during a risk assessment.

Healthcare setups scope themselves to inquiry and scheduling data: who called, what they wanted, when they are coming in. Treatment detail belongs in your practice-management system.

Ask us what the system stores for your configuration and take that answer to whoever advises you, rather than to a comparison table.

HIPAA questions

Is a caller's name and number PHI?

In a healthcare provider's hands, identifying information tied to seeking treatment generally is. That is why keeping the phone record narrow shrinks the whole question.

Does SOC 2 cover HIPAA?

No. SOC 2 audits controls against trust services criteria. It can be useful evidence and it is not a BAA, so it does not make PHI handling lawful on its own.

What if a caller volunteers medical detail?

They will, which is why the storage and retention answers matter more than any badge. Ask what happens to that audio and that transcript, and how you delete both.

Hear it take one of your calls

Two minutes, your own scenario, no card.