HIPAA-Compliant Customer Support: What a BPO Can and Cannot Claim

If a vendor tells you it is "HIPAA certified", stop. The Department of Health and Human Services does not recognize any HIPAA certification, public or private, and says plainly that such certifications do not prevent a finding of non-compliance. What a contact center can legitimately be is a business associate that meets its obligations and can prove it.

What a business associate actually has to do

What "HIPAA-compliant call center" should mean

That the vendor will sign your BAA before go-live, has trained agents and can show the records, enforces role-based access inside your EHR or practice management system rather than copying PHI into its own, logs sessions, controls its facilities, and can hand your compliance officer a documented set of safeguards and a risk analysis on request. Anything less is marketing.

Questions to ask

  1. Will you sign our BAA, and how quickly?
  2. Where does PHI live during a call? (The right answer: in our systems, via role-based access.)
  3. How are agents trained, how often, and can we see the completion records?
  4. What is logged, and for how long?
  5. What is your incident response process and notification timeline?
  6. Who owns compliance on your side, and can we talk to them?

How we answer them

RC Business Solutions runs every healthcare program under a signed BAA, trains agents before go-live and annually, keeps PHI in client systems through role-based access, logs sessions, and has our CIO walk your compliance team through the safeguards under NDA. Details are on our HIPAA-compliant call center and security and compliance pages.

← Back to insights

Ready to scale your support?

See how a dedicated nearshore team in Jamaica cuts customer service costs by 30 to 45 percent.

Get a Free Quote