The July 2026 Issue

Why Your Medical Answering Service Needs to Be HITRUST Certified



HIPAA tells you what the law requires. HITRUST proves you’re actually doing it.

By Clay McElroy, MBA

Picture this. A patient calls their physician’s office at 11:47 p.m. with chest pain. The call rolls to the practice’s after-hours answering service. The agent collects the patient’s name, date of birth, current medications, and a brief description of symptoms, then dispatches the on-call physician. Routine. Forty thousand times a night, somewhere in the country, this exact sequence plays out.

Now picture the same call eight months later, when the patient’s protected health information shows up on a dark web forum because the answering service vendor had inadequate access controls and never noticed the intrusion until ransomware locked down their phone system. The practice’s name is in the breach notification. Patients learn about it from a letter. The plaintiff’s bar is already lining up.

This is not hypothetical. In 2025 alone, more than 642 large healthcare data breaches were reported to the HHS Office for Civil Rights, exposing the protected health information of nearly 57 million Americans.

Roughly one-third of those breaches originated with business associates — the vendors, contractors, and outsourced services that sit downstream of the covered entity. A medical answering service is, by every legal definition, a business associate.

The question for any healthcare practice, hospital system, or specialty group choosing an answering service is no longer whether their vendor is ”HIPAA compliant.”  Every reputable vendor will claim that. The real question is whether the vendor can prove it — independently, repeatedly, and against a control framework rigorous enough to actually move the needle on risk. That is what HITRUST certification provides, and increasingly, it is what discerning healthcare buyers are demanding.

HIPAA Is the Floor. HITRUST Is the Ceiling.

HIPAA is a federal law. It defines what covered entities and business associates must do to protect PHI, but it is famously non-prescriptive about how. There is no HIPAA certificate, no annual stamp of approval, no inspector who walks through your call center and signs off. Any vendor can claim HIPAA compliance, and almost all of them do. Self-attestation is the industry default.

HITRUST is different. The HITRUST CSF — now in version 11.7 as of late 2025 — is a comprehensive control framework that harmonizes HIPAA, NIST 800-53, ISO 27001, SOC 2, PCI DSS, and dozens of other standards into a single auditable set of requirements. There are three certification tiers. The r2, or Risk-Based 2-Year certification, is the most rigorous. It is tailored to the organization’s specific risk profile and typically evaluates 300 to 400 controls across policy, procedure, and implementation. It requires an independent external assessor and a quality review by HITRUST itself before the certificate is issued.

Recertification happens every two years with an interim assessment at the twelve-month mark. In other words, HIPAA tells you what the law requires. HITRUST proves, on a recurring basis and through third-party validation, that you are actually doing it. The framework is updated quarterly to reflect emerging threats. The 2025 HITRUST Trust Report found that fewer than one percent of HITRUST- certified environments reported a data breach in the previous year — a statistic that, when set against the industry’s broader breach numbers, is not a coincidence.

“HIPAA compliant” is a claim. HITRUST-certified is a verdict. In healthcare, the difference shows up the moment something goes wrong.

What Happens When Your Answering Service Isn’t Certified

The risks of contracting with a non-certified vendor fall into four categories, and each one compounds the others when an incident occurs.

Direct liability flows uphill. Under the HIPAA Omnibus Rule, a covered entity can be held liable for the HIPAA violations of its business associate if the covered entity “knew, or by exercising reasonable diligence, should have known” of a pattern of non-compliance. Translation: when your answering service is breached, the OCR investigates you, too. Your due diligence file had better be thicker than a stack of vendor self-attestations.

The penalties are not theoretical. OCR collected nearly $7.9 million across 18 HIPAA enforcement actions in 2025 alone, with civil monetary penalties scaling up to $25,000 per violation category per year. IBM’s 2025 Cost of a Data Breach Report measured the average healthcare breach at $7.42 million, the highest of any industry. Add downtime costs — hospitals can lose up to $900,000 per day when systems are offline — and the math gets ugly fast.

Breach notification cascades are expensive and public. Under the HIPAA Breach Notification Rule, breaches affecting 500 or more individuals must be reported to OCR within 60 days, posted to the HHS “Wall of Shame,” and disclosed to local media. When the breach originates with your answering service, your practice name is on that list. Patients learn about it. So does your competition. So do plaintiffs’attorneys, who treat the OCR breach portal as a lead list.

Cyber insurance is harder and more expensive to get. The cyber insurance market has hardened considerably. Insurers are now routinely denying coverage or pricing it punitively for healthcare entities that cannot demonstrate a formal security framework like HITRUST. Certified organizations report premium discounts of up to 25 percent — and, more importantly, they get coverage at all.

The Regulatory Floor Is Rising

Two near-term developments make this conversation more urgent. First, the long-anticipated HIPAA Security Rule overhaul takes effect in May 2026, with mandatory multi-factor authentication, universal PHI encryption, 24-hour breach reporting for certain incidents, and annual penetration testing. HITRUST CSF v11.7 already maps to these new mandates, which means organizations already in an r2 program will satisfy a substantial portion of the new requirements by default. Vendors who have been coasting on self-attested HIPAA compliance will not.

Second, state-level requirements are stacking up. Texas SECURETexas explicitly names HITRUST as the statutory foundation for its safe harbor provisions. New York’s SHIN-NY mandates HITRUST for all Qualified Entities. NYDFS issued an industry letter in October 2025 citing HITRUST as the preferred standard under 23 NYCRR Part 500. Enterprise payers and health systems are following suit — for a growing number of large contracts, HITRUST is no longer a preference. It is a procurement prerequisite.

If your answering service vendor is not on a certification path today, they are not going to be ready when your hospital system’s vendor risk management team comes asking next year.

What to Ask Before You Sign a BAA

Procurement teams evaluating a medical answering service should require documentary evidence — not marketing language — across the following areas:

• Current HITRUST certification status. Ask which tier (e1, i1, or r2), what the certification date is, and whether the next interim or recertification assessment is scheduled. r2 is the gold standard.

• Scope of the certification. Some vendors certify a narrow slice of their environment and trade on the certification across the entire business. Confirm that the operations actually handling your PHI are in scope.

• Subcontractor management. Where are calls answered? Where are recordings stored? Who handles after-hours overflow? Each subcontractor is its own risk surface.

• Workforce model and training. Outsourced or offshored agents who have not been HIPAA-trained, background-checked, and access-controlled are the single most common failure modes of incident response and breach notification procedures. Ask to see the actual playbook. If they cannot produce one, that is the answer.

The Bottom Line

Healthcare runs on trust. When a patient gives their date of birth and medication list to an after-hours operator, they are extending the same trust they extend to the physician’s office during business hours.

The fact that the call is being handled by an outsourced vendor is invisible to them — and legally irrelevant. When something goes wrong, the practice’s name is on the breach letter, not the vendor’s. HITRUST r2 certification is not a marketing badge. It is third-party, recurring, evidence-based proof that the controls protecting your patients’  information have been independently validated and are continuously maintained. For medical answering services in 2026, it is fast becoming the difference between a vendor your compliance officer can approve and a vendor your compliance officer cannot.

The cost of choosing right is a procurement question. The cost of choosing wrong is a breach notification, an OCR investigation, and a headline you will be explaining for years.

About the Author: Clay McElroy, MBA, is Director of Client Engagement at TAS United, a healthcare-exclusive medical answering service and AI agent platform founded in 1984. TAS United holds HITRUST r2 certification, and serves physician practices, hospital systems, behavioral health groups, and pharmaceutical clients across the U.S. and Puerto Rico. Headquartered in Lubbock, Texas with operations in Guaynabo, Puerto Rico, the company provides bilingual live agents, AI-Integrated Agent hybrid services and the Nurse on Demand triage product line.


News

Peter Lyle DeHaan Releases Book Offering 60 Prescriptions for Healthcare Call Center Excellence
The Healthy Medical Call Center Now Available in Multiple Formats to Help Leaders Boost Staff Retention, Quality Service, and Patient Satisfaction.

Acclaimed call center author Peter Lyle DeHaan announced the release of The Healthy Medical Call Center: 60 Prescriptions for Leadership, Quality, and Patient Satisfaction, the fifth installment in his much-admired Call Center Success Series. The book is now available in ebook, audiobook, paperback, and hardcover formats.

The Healthy Medical Call Center offers sixty proven prescriptions specifically designed for healthcare call center leaders who face the daily challenges of staff retention, quality service, and patient satisfaction. This comprehensive guide provides a practical roadmap for operational excellence in today’s demanding healthcare communication environment.

The book is directly applicable to a wide range of healthcare contact centers and medical call centers, including hospital switchboards, telephone triage operations, medical answering services, and healthcare insurance call centers. Written for call
center directors, operations managers, supervisors, and aspiring leaders, DeHaan’s latest work addresses the unique pressures and opportunities within medical communication settings.

“Healthcare call centers are the critical first point of contact between patients and care providers,” said Peter Lyle DeHaan. “This book provides actionable strategies that leaders can implement immediately to improve their operations, support their teams,
and ultimately enhance patient satisfaction.”

Drawing on his extensive experience in the call center industry, DeHaan delivers practical, field-tested advice that healthcare communication leaders can apply to transform their operations. Each prescription addresses real-world challenges with
clear, implementable solutions.

As the fifth, and final, book in the Call Center Success Series, The Healthy Medical Call Center continues DeHaan’s mission to equip call center professionals with the tools and insights they need to excel in an increasingly complex industry.

About Peter Lyle DeHaan
Peter Lyle DeHaan is a seasoned business author specializing in the call center industry. Through his Call Center Success Series and other works, he has established himself as a trusted resource for call center professionals seeking to improve their operations and leadership capabilities. For more information about Peter Lyle DeHaan, visit https://peterlyledehaan.com/about-peter-dehaan/.

Book Details
The Healthy Medical Call Center: 60 Prescriptions for Leadership, Quality, and Patient Satisfaction is now available in ebook, audiobook, paperback, and hardcover.

Send us your healthcare call center articles and news for the next issue of Medical Call Center News.


A Thought for Today

“Show up every day. Work hard. Do it with joy. Care more about others than we do ourselves.” – Mike Deegan, paraphrased