Short version

HIPAA compliant call center services are outsourced phone and messaging teams that handle protected health information for a covered entity or another business associate under a signed Business Associate Agreement, applying the safeguards in 45 CFR Part 164. Call Force Global delivers those teams from five nearshore countries at $12 to $18 per agent hour all-in, live in 7 days, month to month. Our agents handle administrative patient contact. Anything that needs a clinical or professional license stays with your own licensed staff, and the agent warm transfers to them.

The buying problem

Every vendor in this category says the same four words, HIPAA compliant call center, and shows a badge next to them. The badge is not a thing. What protects you is a contract with specific clauses, a documented risk analysis, and a vendor who can tell you which safeguards it implemented and which ones it decided against and why. This page shows you where those live in the regulation so you can ask for them by name, whether or not you end up hiring us.

What we run, and what stays with you

Call Force Global staffs the administrative half of patient contact. Scheduling, intake, verification, follow-up, billing questions and message handling sit with our agents. Clinical judgment and licensed activity sit with yours. The line is drawn in the call flow before launch, so an agent never has to work out where it falls in the middle of a call.

Work our agents handle on healthcare programs:

  • Appointment scheduling, rescheduling, reminder calls and no-show recovery
  • New patient intake and registration, including demographic and insurance capture
  • Insurance eligibility and benefit verification against payer portals
  • Referral coordination and chasing prior authorization status with payers
  • Billing and statement questions, payment plan setup, and routing disputes to your revenue cycle team
  • Patient portal support, password resets and onboarding walkthroughs
  • Prescription refill request intake, captured and routed to the prescriber without any clinical decision
  • After-hours message taking with an escalation script your clinical staff wrote
  • Recall and gap-in-care outreach, survey follow-up, and cancellation backfill

Work that stays on your side of the line:

  • Clinical triage, symptom assessment and any nurse-line function
  • Anything a nursing, medical, pharmacy or behavioral health license covers
  • Licensed insurance sales, plan recommendation and enrollment
  • Final decisions on releasing records, on medical necessity, and on anything a patient escalates for clinical reasons

Why the split is worth insisting on: a vendor whose scope stops at a clean, written boundary is a vendor whose liability perimeter your compliance team can actually draw. Vagueness here is the risk, not the boundary.

What a business associate agreement actually obligates a call center to do

A BAA is a contract, not a certificate. Under 45 CFR 164.502(e) a covered entity may only let a vendor create, receive, maintain or transmit protected health information once it has satisfactory assurances that the vendor will safeguard it, and those assurances have to be documented in a written agreement. Section 164.504(e)(2) then lists what the agreement has to say.

Read the list once and vendor sales copy starts sounding different. A compliant BAA has to provide that the business associate will:

  1. Not use or further disclose the information except as the contract permits or the law requires
  2. Use appropriate safeguards and, for electronic PHI, comply with the Security Rule at subpart C
  3. Report to you any use or disclosure the contract does not provide for, including breaches under 164.410
  4. Make sure any subcontractor handling your PHI agrees to the same restrictions and conditions
  5. Make PHI available so you can meet a patient's right of access under 164.524
  6. Make PHI available for amendment, and incorporate amendments, under 164.526
  7. Provide the information you need to produce an accounting of disclosures under 164.528
  8. Where it carries out one of your obligations, comply with the rules that would apply to you doing it
  9. Make its internal practices, books and records available to the Secretary for a compliance determination
  10. Return or destroy the PHI at termination where that is feasible, and extend the protections to anything it cannot return

Two clauses in the same section rarely come up in vendor conversations and both are worth raising. The agreement has to establish the permitted and required uses and disclosures, which means an open-ended "for business purposes" clause is not doing its job. And under 164.504(e)(1)(ii) and (iii), a party that knows about a pattern of violation by the other side has to take reasonable steps to cure it, then terminate if that fails. The BAA is the enforcement mechanism, so what it says matters more than any logo on a vendor's footer.

HHS publishes both the business associate guidance and a set of sample BAA provisions free of charge. They are a starting point rather than a finished contract, because a call center BAA needs specifics that the sample cannot know: which call types touch PHI, where recordings live, how long they are kept, and how fast a breach reaches you.

Call Force Global signs the BAA before onboarding starts. We will work from your template or supply ours, and we would rather spend a week on your redlines than start a program on an unsigned draft.

Required and addressable safeguards, and why this gets fumbled

Encryption is not required by HIPAA. Encryption at rest and encryption in transit are both addressable implementation specifications under 45 CFR 164.312. Addressable does not mean optional. It means you assess whether the safeguard is reasonable and appropriate in your environment, implement it if it is, and if it is not, document why and put an equivalent alternative measure in place.

The mechanics are set out in 164.306(d). Where a standard carries a required implementation specification, you implement it. Where it carries an addressable one, you have to do three things: assess it against its likely contribution to protecting electronic PHI, implement it if it is reasonable and appropriate, and if it is not, document why and implement an equivalent alternative measure if that in turn is reasonable and appropriate. The rule also tells you what to weigh, at 164.306(b): your size and capabilities, your existing technical infrastructure, the cost of the measure, and the probability and criticality of the risk.

So "addressable" is a documented decision with a paper trail behind it. A vendor that cannot produce that paper trail has not addressed anything. And a vendor that tells you encryption is required by HIPAA has not read 164.312, which is a small thing that tells you something real about how carefully they read everything else.

Selected HIPAA Security Rule safeguards, their citation, and whether they are required or addressable
Safeguard Citation Designation
Risk analysis 164.308(a)(1)(ii)(A) Required
Risk management 164.308(a)(1)(ii)(B) Required
Sanction policy 164.308(a)(1)(ii)(C) Required
Information system activity review 164.308(a)(1)(ii)(D) Required
Termination procedures, removing access when someone leaves 164.308(a)(3)(ii)(C) Addressable
Password management 164.308(a)(5)(ii)(D) Addressable
Facility security plan 164.310(a)(2)(ii) Addressable
Workstation use and workstation security 164.310(b) and 164.310(c) Standard, no implementation specification
Disposal of ePHI and the media holding it 164.310(d)(2)(i) Required
Media re-use, wiping before reissue 164.310(d)(2)(ii) Required
Unique user identification 164.312(a)(2)(i) Required
Emergency access procedure 164.312(a)(2)(ii) Required
Automatic logoff 164.312(a)(2)(iii) Addressable
Encryption and decryption, data at rest 164.312(a)(2)(iv) Addressable
Audit controls 164.312(b) Standard, no implementation specification
Transmission security, guarding ePHI moving over a network 164.312(e)(1) Standard, both its specifications addressable
Encryption, data in transit 164.312(e)(2)(ii) Addressable

Three rows are worth a second look. Audit controls at 164.312(b) and workstation security at 164.310(c) carry no implementation specification at all, so there is no addressable escape hatch: you implement mechanisms that record and examine activity, and you physically restrict the workstations that reach ePHI. Transmission security at 164.312(e)(1) is the interesting one, because the standard is mandatory and both of the mechanisms named under it, integrity controls and encryption, are addressable. You have to guard PHI moving across a network. How you do it is the documented decision. Meanwhile the two encryption entries, the things most people picture when they hear "HIPAA requirement", are the addressable ones. The rule is less about technology than the marketing suggests and much more about decisions you can evidence.

For the record, Call Force Global encrypts protected health information in transit and at rest on healthcare programs, and enforces automatic logoff. We are naming the designations to make a point about vendor claims, not to argue for weaker controls. The full text of all three safeguard sections is at 164.308, 164.310 and 164.312, and HHS keeps its own Security Rule guidance current.

How Call Force Global runs a HIPAA program day to day

Six operational controls carry most of the weight on a healthcare program: what gets recorded, who can log in, what is allowed at the desk, what agents are trained and sanctioned on, how fast a problem reaches you, and who else touches the work. Here is our answer on each.

Recording and what actually gets captured

Recording is a configuration decision, and it is yours. You tell us which call types are recorded, whether payment card capture is masked, how long recordings are kept, and who on your side may request one. Recordings live in the program's storage with role-based retrieval, and every retrieval is logged against a named user with a reason. Agents cannot record locally, cannot export audio, and cannot email a recording anywhere. If your retention policy is shorter than our default, yours wins.

Access control

Every agent has a unique login. There are no shared credentials and no generic team accounts, because unique user identification at 164.312(a)(2)(i) is one of the required specifications and because shared logins make an audit trail worthless. CRM, EHR and payer portal permissions are scoped to the fields the call type actually needs, which is the minimum necessary standard at 164.502(b) expressed as screen configuration. When an agent comes off the program, access is revoked the same day and the removal is logged.

Screen and workspace policy

Healthcare programs run from dedicated, badge-controlled floor space, not from home. Personal phones and personal storage devices stay out of the PHI-handling area. There is no paper and no pens at those desks, so nothing walks out in a pocket. Screens lock on step-away, and monitors face away from walkways. Visitors are logged and escorted. None of this is exotic. It is worth asking every vendor on your list where their agents physically sit, because the answer varies more than the marketing does.

Training and the sanction policy

HIPAA training and a passing test come before an agent joins a healthcare program, not after. Training covers the Privacy Rule, the Security Rule, minimum necessary, what counts as PHI on a phone call, and what to do the moment something looks wrong. Refresh is annual. There is a written sanction policy, which the rule requires at 164.308(a)(1)(ii)(C), and it runs up to removal from the program. We would rather lose an agent than argue about a disclosure later.

Breach reporting

Under 45 CFR 164.410, a business associate has to notify the covered entity following discovery of a breach of unsecured PHI, without unreasonable delay and no later than 60 calendar days after discovery. The section also defines discovery broadly: a breach counts as discovered on the first day it is known to any employee or agent other than the person who caused it, or would have been known with reasonable diligence. Sixty days is the legal ceiling. We contract to a shorter internal escalation and name the contacts on both sides during onboarding, and the notification content follows what 164.410(c) requires so your own patient notice is not held up waiting for detail from us. HHS keeps a plain-language summary of the Breach Notification Rule if you want the full chain of obligations.

Who else touches the work

Nobody. Call Force Global does not subcontract agent labor. Every agent on your program is our employee on our floor, which means there is no downstream chain of subcontractor BAAs for your team to audit. That matters because 164.502(e)(1)(ii) pushes the same obligations down to subcontractors, and each additional layer is another set of assurances someone has to obtain and verify.

Send us your BAA and your call types

We will come back inside one business day with the redlines we would raise, the seat count the volume needs, and a line-item rate. No slide deck.

Get my 24-hour quote

Or book a 20-minute discovery call if you would rather talk it through.

Where the fronter-only model applies in healthcare

Call Force Global does not supply licensed agents of any kind. On any scope that needs a license, our agents work as fronters: they gather, verify, schedule and route, then warm transfer to your own licensed staff at the moment the conversation crosses the line. We say this plainly because buyers keep discovering it late with other vendors, and late is expensive.

In healthcare that plays out in three places:

  • Clinical calls. A patient describing symptoms gets a warm transfer to your nurse line or clinical staff. Our agent does not assess, advise or prioritize by acuity. The handoff script is written with your clinical lead before launch and tested during calibration.
  • Health plan sales and enrollment. Our agents qualify and schedule. Plan comparison, recommendation and enrollment stay with licensed producers on your side. This is the same structure we run on Medicare programs and across insurance, where we hold no producer license and no AHIP certification and say so on those pages too.
  • Anything a state license covers. If your compliance team is unsure whether a task falls inside a licensed scope, we treat it as licensed and route it to you. That default costs a few extra transfers, and we think that is the right side to be wrong on.

The upside for you is a scope boundary you can put in a policy document. The downside is real too: if you want a single vendor to run the licensed close as well, we are not that vendor and we will tell you on the first call.

What HIPAA compliant call center services cost in 2026

Call Force Global charges $12 to $18 per agent hour all-in for nearshore healthcare programs. Our estimate of the equivalent US onshore loaded cost is $35 to $48 per hour. Where each program lands inside those two bands decides the saving, which works out at roughly 49 to 75 percent.

Start with the published wage. The Bureau of Labor Statistics puts the row it labels Customer service representatives at an hourly mean of $22.40 and an annual mean of $46,590 across 2,595,750 people employed in the occupation, in the May 2025 Occupational Employment and Wage Statistics release. That is the wage before an employer has paid anything else.

Then add what employment costs on top. BLS Employer Costs for Employee Compensation for March 2026 puts total compensation for private industry workers at $46.60 per hour worked, of which wages and salaries are $32.60 and benefits are $14.01, so benefits account for 30.1 percent of the total. Expressed as a markup on wages rather than a share of the total, that is about 43 percent. Apply it to the customer service wage and pay and benefits alone land near $32 per hour, before a single dollar of supervision, floor space, technology, recruiting or QA. That is how we get to an estimate of $35 to $48 per hour for a loaded onshore seat. It is our arithmetic on two published sources, not a quoted market price. The working is on our US agent loaded cost index if you want to check it.

HIPAA call center staffing models compared on rate and what the rate includes
Staffing model Rate per agent hour What is inside the rate
US in-house or domestic BPO $35 to $48 per hour (Call Force Global estimate) Wages and benefits per BLS, plus supervision, facility, technology and recruiting. Compliance tooling is often a separate line.
Call Force Global nearshore $12 to $18 per hour all-in Wages, employer costs, supervision, workstation and dialer seat, recording storage, HIPAA training, QA, signed BAA. No setup fee.
Per-minute answering service Priced by the minute, by vendor Suits low, spiky after-hours volume. Costs turn against you once volume is steady, and scripting depth is limited. We compare the options on our medical answering service roundup.

What moves a program toward the top of our band: overnight or weekend coverage, bilingual Spanish and English staffing, deep EHR or practice management integration, revenue cycle work that needs coding familiarity, and small teams where supervision cannot spread across many seats. What pulls it down: steady daytime volume, a single call type, a stable script, and teams above roughly 15 seats.

If you want to test the operating model before committing to a program, the Pilot Month runs two dedicated agents for one live month at $3,840 flat, with every recording and QA scorecard yours to keep. There is no money-back guarantee anywhere in our terms. The risk reversal is structural instead: a small paid pilot, month-to-month terms after it, no annual prepay, and a fast agent swap if someone is not working out.

Twelve questions to ask any vendor before you sign

Use these in vendor selection whether or not Call Force Global is on your shortlist. Each one maps to a specific paragraph of the regulation, which makes a vague answer easy to spot.

  1. Will you sign our BAA as written, or do you require yours? Either answer is fine. A vendor that hesitates on the question itself is not.
  2. When was your last risk analysis and who performed it? Risk analysis is a required specification at 164.308(a)(1)(ii)(A). A date more than a year old, or an answer that describes a checklist rather than an assessment, tells you something.
  3. Which addressable specifications did you decide not to implement, and where is that documented? This is the single best question on the list. Under 164.306(d)(3) that documentation has to exist. If nobody can produce it, nothing was addressed.
  4. Does every agent have a unique login, and can you show me an access report for one agent for one day? Unique user identification is required at 164.312(a)(2)(i) and activity review at 164.308(a)(1)(ii)(D). If both exist, the report is a two-minute request.
  5. How fast is access revoked when an agent leaves the program? Termination procedures are addressable at 164.308(a)(3)(ii)(C), so ask what they actually do and how it is evidenced.
  6. Where do call recordings live, who can retrieve them, and is retrieval logged? Section 164.312(b) makes audit controls a standard with no addressable option, so there is no version of this answer that begins with "we assessed it".
  7. What is the policy on phones, paper and personal storage at desks that handle PHI? Workstation use and workstation security sit at 164.310(b) and (c). Ask whether anyone works from home.
  8. What breach notification deadline will you contract to? The regulatory ceiling is 60 calendar days at 164.410(b). Most buyers want considerably less, in writing.
  9. Do you subcontract any part of the agent labor, and who holds those BAAs? Subcontractor obligations flow down under 164.502(e)(1)(ii) and 164.504(e)(1)(iii). Every layer is another thing to verify.
  10. What minimum necessary controls exist in the tools agents use, and who configured the field permissions? The standard is at 164.502(b) and it lands as screen and field configuration, not as a policy PDF.
  11. What is in the training curriculum, and what does the sanction policy actually do? Training sits at 164.308(a)(5) and the sanction policy is required at 164.308(a)(1)(ii)(C). Ask whether it has ever been used.
  12. Are you HIPAA certified? The correct answer is no. HHS states that it does not certify any person or product as HIPAA compliant, and that its Office for Civil Rights does not endorse private consultants, seminars, materials or systems. It says so in its own notice on misleading marketing claims. A confident yes to this question should send you back to questions two and three.

A note on badges: third-party attestations such as a SOC 2 report or an independent HIPAA readiness assessment can be genuinely useful, and they are not what HHS is warning about. The warning is about anyone implying that HHS or OCR blessed them. Read what the attestation actually covers and which systems were in scope, because a badge on a marketing page rarely tells you.

Nearshore delivery and HIPAA

HIPAA does not prohibit outsourcing outside the United States. HHS has said that storing or processing electronic PHI outside the country can introduce distinct risks that belong in the covered entity's risk analysis and risk management, which means location is an input to the analysis rather than a yes or no gate.

HHS makes the point directly in its guidance on ePHI held on servers outside the United States: the rules do not bar it, and the outsourcing arrangement has to be assessed like any other risk, including practical questions about enforceability. So the honest framing for any vendor outside the US, including us, is that geography changes what belongs in your risk analysis. It does not settle the question either way.

Call Force Global delivers from five countries: Jamaica, Saint Lucia, Trinidad and Tobago, Belize and Colombia. That is the complete list. All five sit inside or within a few hours of US time zones, so patient-facing phone work runs during US business hours without a night shift, and a caller at 2pm Eastern gets an agent who speaks English as a first language partway through a normal working day.

What we do about location-specific risk, so your risk analysis has something concrete to record: dedicated badge-controlled floors rather than home working, no personal devices in PHI areas, agents employed directly by us with no labor subcontracting, contractual jurisdiction agreed in the BAA, and the same access and audit controls across every site. If your privacy officer wants a site-level write-up for a specific country, ask and we will produce it during procurement. We compare the delivery models honestly in our breakdown of nearshore, offshore and onshore outsourcing, and there is a fuller build-out of the healthcare offer on our healthcare call center page and healthcare BPO page.

Frequently asked questions

Is encryption required by HIPAA?
No. Encryption at rest under 45 CFR 164.312(a)(2)(iv) and encryption in transit under 164.312(e)(2)(ii) are both addressable implementation specifications, not required ones. Addressable means the covered entity or business associate has to assess whether the safeguard is reasonable and appropriate in its environment, implement it if it is, and if it is not, document why and put an equivalent alternative measure in place. That is a documented decision, not a free pass. Call Force Global encrypts protected health information in transit and at rest on every healthcare program and does not use the addressable route to skip it.
Does a call center need a business associate agreement?
Yes, whenever it creates, receives, maintains or transmits protected health information for a covered entity or another business associate. Under 45 CFR 164.502(e) the covered entity has to obtain satisfactory assurances first, documented in a written contract, and 164.504(e)(2) sets out what that contract has to say. Call Force Global signs the agreement before any protected health information reaches an agent, and will work from your paper or ours.
How fast does a call center have to report a breach?
A business associate must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured protected health information. That deadline sits at 45 CFR 164.410(b). Sixty days is the outer limit set by the rule, not a target, and buyers routinely negotiate something much shorter into the agreement. Call Force Global will contract to a shorter window and name the escalation contacts during onboarding.
Is any call center HIPAA certified?
No, and a vendor claiming otherwise is worth a second look. The Department of Health and Human Services states that it does not certify any person or product as HIPAA compliant, and that its Office for Civil Rights does not endorse private consultants, seminars, materials or systems. Ask for the date of the last risk analysis, the sanction policy, evidence of unique user identification, and the written record of which addressable specifications the vendor chose not to implement.
What do HIPAA compliant call center services cost in 2026?
Call Force Global charges $12 to $18 per agent hour all-in for nearshore healthcare programs. That covers wages, employer costs, supervision, the workstation and dialer seat, recording storage, HIPAA training and QA. Our own estimate for the equivalent US onshore loaded cost is $35 to $48 per hour, built on Bureau of Labor Statistics wage and benefit data. Depending on where each program lands inside the two bands, that is a saving of roughly 49 to 75 percent.
Can Call Force Global agents do clinical triage or sell health plans?
No. Call Force Global does not supply licensed agents of any kind. Our agents handle administrative patient contact such as scheduling, intake, eligibility verification, billing questions, referral coordination and message taking, then warm transfer anything that needs a clinical or professional license to your own licensed staff. We write that boundary into the call flow before launch so an agent never has to judge it live.
Which countries does Call Force Global deliver from?
Five: Jamaica, Saint Lucia, Trinidad and Tobago, Belize and Colombia. All five sit inside or within a few hours of US time zones, so patient-facing phone work runs during US business hours without a night shift. Agents work from dedicated floors with badge access and a controlled desk policy, not from home.

Sources

Regulation text read directly from the eCFR on September 4, 2026: 45 CFR Part 164, 164.306, 164.308, 164.310, 164.312, 164.410, 164.502 and 164.504. HHS guidance on business associates, sample BAA provisions, the Security Rule, the Breach Notification Rule, ePHI stored outside the United States and misleading marketing claims. Wage and employer cost figures from the BLS Occupational Employment and Wage Statistics and Employer Costs for Employee Compensation releases. Rates, program inclusions and the onshore cost estimate are Call Force Global's own.

Ready when you are

Start with the BAA, not the sales deck

Send us your agreement and a description of the calls. We come back with redlines, a seat count and a line-item rate inside one business day. Call 1-844-287-9234 or send us the scope.

No commitment required. A senior ops manager replies, not a form autoresponder.

Program terms

BAA signed before onboarding Live in 7 days, no setup fee Month to month, no annual prepay Warm transfer to your licensed staff
HIPAA trained Nearshore, US time zones $12-18/hr all-in Non-licensed scope, stated up front