47.66° N 117.43° W Summit · Profitable Growth
Medical Practice Marketing · Compliance limits
Do I need a BAA with my call tracking provider?
If the calls come from patients, assume yes until your compliance officer says otherwise. Call tracking receives the caller's number, the recording, and often a transcript, all attached to somebody contacting a healthcare provider. Most providers offer a business associate agreement only on a specific paid tier, so being a customer is not the same as being covered.
I am a marketer, not a lawyer, and nothing here is legal advice. Whether your practice needs a particular agreement is a decision for your counsel or compliance officer. This is what I check before wiring call tracking into a practice’s ad account.
Why call tracking is the exposure people miss
A practice will interrogate its electronic records vendor for months and then install call tracking in an afternoon, because call tracking reads as a marketing tool rather than a clinical one.
Look at what it receives. The caller’s phone number. The time they called. Which ad and which keyword brought them. Frequently the recording, and increasingly a machine transcript of the whole conversation. A patient describing their symptoms to a receptionist, transcribed and stored on a vendor’s servers, indexed and searchable.
That is the combination the HIPAA definition turns on, an identifier alongside the seeking of care, and then a verbatim account of the reason. It is among the most sensitive data the practice’s marketing stack touches, and it arrives through the tool nobody reviewed.
Being a customer is not being covered
This is the part that catches practices, and it catches them quietly.
Most call tracking vendors do offer a business associate agreement. Almost none of them offer it on the entry plan. It sits on a healthcare tier or an enterprise tier, usually at a meaningfully higher monthly cost, and it has to be requested, executed, and countersigned. A practice that signed up on the standard plan two years ago and assumed the vendor “does healthcare” has no executed agreement to point to.
The failure mode is silent. Nothing in the product changes. The dashboard looks the same, the calls still record, no warning appears. The only way to know is to go and look for the executed agreement, and if nobody can produce it, it doesn’t exist.
Three things to establish, in writing:
Does this vendor sign a BAA at all. Some won’t, and that’s a straight answer you can act on.
Is the plan you are on the one it covers. Ask explicitly. “We are on plan X, does the BAA apply to plan X” is the question, not “are you HIPAA compliant.”
What does enabling it change. This is the one people skip, and it has real consequences.
What a healthcare mode usually turns off
Vendors implement their covered configuration by restricting features, and the restrictions are the part that breaks an existing setup.
Expect some or all of these: personal data stripped out of notification emails, so the alert your front desk relies on arrives with the fields blank. Outbound webhooks to arbitrary URLs disabled, because an unsecured endpoint is an uncontrolled disclosure. Some integrations turned off entirely. Data retention shortened. Access to call audio restricted, sometimes while the transcript stays available through the API, sometimes not.
That last distinction matters more than it sounds. A practice that planned to review recordings may find the audio withheld while the text remains reachable, or the reverse. It decides whether any downstream review or scoring is possible at all, and it’s worth getting in writing from the vendor’s support team before you design anything on top of it.
The notification-email change is the one that reliably causes a fight two weeks after go-live. The front desk was reading the enquiry details out of that email. Now the email says a lead came in and nothing else, and someone has to log into a portal instead. Plan for it, or you will get a complaint that reads like the tracking is broken when it’s working exactly as intended.
Recording adds a second question that has nothing to do with HIPAA
Call recording is governed separately by state wiretapping law, and the rules differ by state. Some require only one party to consent. Others require all parties. A practice with two offices can sit in one regime, and a patient calling from across a state line can sit in another.
The practical answer is an announcement at the start of the call, every call, both directions. That is a decision for the practice rather than for whoever configures the tool, and it should be made before recording is switched on rather than discovered afterwards.
The second hop nobody maps
The agreement with the call tracking vendor covers the call tracking vendor. It doesn’t cover whatever the data flows into next.
Trace it. The vendor receives the call. Who else gets it? A CRM. A spreadsheet. An email to three staff members and, in most practices I have looked at, at least one person who is a contractor rather than an employee. A reporting tool. Possibly a transcription service the vendor subcontracts to.
Each hop is its own question, and the one that surprises practices is the staff list. Whether an outsourced scheduler or a virtual receptionist sits inside the practice’s workforce for policy purposes is a real question with a real answer, and it’s worth resolving before their address is on a notification list rather than after.
What this means for the ad account
None of this stops you running call tracking, and I wouldn’t run paid search for a practice without it. In the practices I have looked at, most bookings arrive by phone rather than by form. An account that can’t see calls is optimizing against the minority of its own results.
What it changes is sequencing. Get the agreement executed and the covered configuration enabled before the campaigns scale, not after, because the covered configuration will break something downstream and you want to find that out at low volume.
Then build the measurement on what survives. The architecture for a business that books by phone, including how the call outcome gets back to the ad platform without carrying anything it should not, is The Lead Quality Stack, and the practice-specific version is in how to track booked patients without sending PHI.
Tools for this diagnosis
Related questions
-
Can a medical practice run remarketing or Customer Match ads?
Google blocks the audiences you build for restricted health advertising, and Meta bars health data in audience criteria. What that closes, and what stays open.
Read the answer
-
Can a medical practice use Google Ads conversion tracking without violating HIPAA?
A practice can run conversion tracking, but not the default install. Which vendors need an agreement, what may leave your systems, and which audiences stay off.
Read the answer
-
Can I record and score patient phone calls for marketing?
Call scoring shows which keywords produce real appointments. What recording requires, why the transcript beats the audio, and where the model should run.
Read the answer
-
How do you track which ads produce booked patients without sending PHI?
Form fills are not patients. How offline conversion import closes the gap using hashed identifiers, a value, and nothing that says why they called.
Read the answer
Back to the full medical practice marketing: the compliance library
Want this diagnosed in your account?
Same diagnosis,
run on your account.
Thirty minutes on the phone. I look at your spend, your tracking, and your search-term reports before the call. You walk out with a clear list of what is leaking and what to fix first.