Notes
HIPAA-Compliant Call Tracking: What Can Leave Your Systems
Call tracking is used in a HIPAA-compliant way when the vendor signs a business associate agreement, recordings and transcripts are limited and access-controlled, and nothing from the call travels to an ad platform except a click identifier, a neutral stage name and a time. The number-swapping itself is not the risk. What the vendor stores and who can hear it is.
Key takeaways
- Half of serious clinic enquiries arrive by phone, so a practice without call tracking is measuring half its marketing.
- The vendor becomes a business associate the moment a caller describes a symptom. It needs an agreement.
- Recording is the highest-risk setting, and often unnecessary for attribution.
- Transcripts and AI summaries are separate features and may sit outside the agreement.
- The click identifier is not health data and should still reach the CRM.
Contents
Your front desk answers the phone all day, and none of those conversations appear in your Google Ads reports. Call tracking closes that gap, which is why every agency recommends it. In a clinic, it also creates a vendor that hears patients describe why they are calling.
I am a marketing consultant and not a lawyer. This is a sourced map for your privacy officer, written by the person who has to make the phone half of attribution work.
Is call tracking HIPAA compliant?
Call tracking can be used compliantly when the vendor has signed a business associate agreement covering the features you use, recordings and transcripts are restricted and retained briefly, access is limited to named users and logged, and only non-health identifiers are forwarded to advertising platforms. No vendor is compliant by default, and HHS sets out the contract requirement under business associates.
Where the risk actually sits
The number swap is mechanical: the visitor sees a tracking number, the call is routed to your real line, and the vendor logs which source produced it. Nothing about that requires health information.
The risk begins at the next three settings. Whether the call is recorded. Whether it is transcribed, and by what. And who in your organisation, or the vendor's, can open it. A recorded call in which someone describes a symptom is protected health information sitting on a third party's servers.
Seven checks for any vendor
| # | Check | A pass looks like |
|---|---|---|
| 1 | BAA on the plan you are buying | Signed before go-live, not promised after |
| 2 | Call recording | Off by default, or on with consent and a short retention |
| 3 | Transcripts and AI features | Named individually as covered, or switched off |
| 4 | Access control | Named users, roles and an audit log |
| 5 | Retention | You set it, and it is measured in days |
| 6 | Click ID passthrough | The identifier reaches the CRM record |
| 7 | Where data lives | A named region, encrypted in transit and at rest |
I am not publishing a table of vendor verdicts. Several call tracking companies offer healthcare plans, and their terms change. Use these seven questions on whichever one your agency proposes, and ask for the agreement before the demo.
What the ad platform should receive
Three fields: the click identifier, a neutral conversion action name, and the time. Not the caller's number, not the recording, not a transcript, not a summary.
That is the same design as the web side, described in click-ID-only conversion feeds, and it is what makes phone demand measurable without disclosing anything about the caller. The loop from call to CRM to platform is in call tracking and the CRM, and the dental-specific version in dental call tracking without breaking HIPAA.
What goes wrong
| Cause | What actually happens | Hidden cost | What you see | Risk level |
|---|---|---|---|---|
| Recording on by default | Symptom descriptions stored indefinitely | The largest exposure in the stack | Every call has an audio file | High |
| Transcripts outside the agreement | PHI processed by an uncovered feature | A gap inside a covered product | AI summaries nobody approved | High |
| One shared login | No way to say who listened | The audit log is meaningless | Everyone uses the same account | Medium |
| Caller number sent to the ad platform | An identifier leaves your systems | A disclosure created by an integration | A phone field in the upload | High |
| No click ID passthrough | Phone demand is invisible to bidding | Half your marketing unmeasured | Calls logged as direct | Medium |
| Indefinite retention | Yesterday's convenience is next year's breach | Exposure grows monthly | No retention setting configured | Medium |
What it costs
Market figures were checked in September 2026. They are ranges, not quotes. Vendor subscription prices are not listed here because they change by seat and volume; ask for the price of the plan that includes the agreement.
| Route | Typical cost | Time to a defensible setup | What it depends on |
|---|---|---|---|
| Reconfigure your current vendor | Staff time | Days | Whether they sign on your plan |
| Switch vendor | Subscription plus setup | Days to weeks | Number of tracking numbers and integrations |
| Developer work on passthrough | Upwork lists tag manager specialists at $20 to $49 an hour, median $30; senior US consultants at $85 to $175 | Days | CRM and form stack |
| I set up the phone half of attribution | Audit at $500 per ad account with a 90-day plan, credited toward the first month | Scoped in the audit | Entry points, CRM, sign-off |
The audit covers your ad account, the tracking and the path from enquiry to booked patient, and ends with a 90-day plan. It is credited toward the first month if you continue with me.
You work with me directly. There are no account managers and no juniors.
Test one call end to end
Call your own tracking number from a page you opened with a test click ID, then follow that call through the vendor, the CRM and the upload. Five minutes tells you whether the phone half of your marketing is measurable and whether anything is leaking on the way. If you want it built properly, start with the audit, or see HIPAA-compliant conversion tracking.
Frequently asked questions
Is call tracking allowed under HIPAA?
Yes, with a business associate agreement and appropriate controls. The number swap itself is not the issue; recordings, transcripts and access are.
Do we have to record calls?
No, and for attribution you usually do not need to. Recording is a front-desk training decision, and it carries the highest risk in this stack.
Are call transcripts and AI summaries covered by the agreement?
Sometimes not. Ask for them to be named explicitly in the covered services list, or switch them off.
Can the caller's phone number be sent to Google?
It should not be. Send the click identifier, a neutral stage name and the time. Nothing about the caller.
Does a tracking number hurt local SEO?
Not if your main number stays consistent on your Business Profile and citations, and the tracking number is swapped dynamically for paid visitors.
What about consent for recording?
State law varies, and several require all parties to consent. That is a legal question for your counsel, separate from HIPAA.
Who does the work if I hire you?
I do: the passthrough, the CRM connection and the feed. Vendor agreements stay with you and your compliance partner.
How do I verify it myself?
Place one test call from a page opened with a hand-typed click identifier. Check three things: the CRM record carries that identifier, the upload log shows the call, and the ad platform received no caller details.