Your Call Recording Vendor Is a Business Associate. Its AI Subprocessor Is a Subcontractor.
Your call recording vendor is a business associate. The AI service it routes transcripts to is a subcontractor — and HIPAA requires that link to be papered too.
Your Call Recording Vendor Is a Business Associate. Its AI Subprocessor Is a Subcontractor.
Most healthcare operators can produce a signed business associate agreement with their call recording vendor in under a minute. Far fewer can name the AI model provider that vendor routes transcripts to, and almost none can produce the agreement between those two parties.
Under the HIPAA rules, that second agreement is not optional and it is not your vendor's private business. It is a required link in a chain that runs from you all the way down, and the regulation says so in plain terms.
How the chain is actually constructed
Start with the disclosure rule. 45 CFR 164.502(e)(1)(i) permits a covered entity to disclose protected health information to a business associate, or to let a business associate create, receive, maintain, or transmit PHI on its behalf, only if the covered entity "obtains satisfactory assurance that the business associate will appropriately safeguard the information."
The next clause is the one people miss. Section 164.502(e)(1)(ii) applies the identical requirement one level down: a business associate may disclose PHI to a subcontractor only if it obtains satisfactory assurances that the subcontractor will appropriately safeguard the information. And 164.502(e)(2) requires those assurances be "documented through a written contract or other written agreement or arrangement."
Then the contract rule fills in the terms. 45 CFR 164.504(e)(2)(ii)(D) requires a business associate agreement to obligate the business associate to "ensure that any subcontractors that create, receive, maintain, or transmit protected health information on behalf of the business associate agree to the same restrictions and conditions that apply to the business associate." Section 164.504(e)(5) makes clear these requirements apply to business associate–subcontractor arrangements the same way they apply to covered entity–business associate arrangements.
The Security Rule runs a parallel track. 45 CFR 164.308(b) requires the same satisfactory assurances for electronic PHI, documented in a written contract meeting 164.314(a).
Two consequences follow, and they cut in opposite directions.
First, you do not sign an agreement with the subcontractor. Both 164.502(e) and 164.308(b) are explicit that a covered entity is not required to obtain satisfactory assurances directly from a subcontractor. Your paper runs to your vendor. That is correct and it is the design.
Second, that does not make the subcontractor your vendor's private matter. Your BAA is required to obligate your vendor to bind its subcontractors to equivalent terms. Whether your vendor actually did so is a question about your agreement's performance, which makes it squarely a question you are entitled to ask and answer.
Laid out as a chain, it looks like this:
| Layer | Example | Status under HIPAA | Who papers it |
|---|---|---|---|
| 1 | Your agency | Covered entity | — |
| 2 | Call recording / call intelligence vendor | Business associate | You, per 164.502(e)(1)(i) |
| 3 | Speech-to-text or model provider the vendor calls | Subcontractor | Your vendor, per 164.502(e)(1)(ii) |
| 4 | Infrastructure, storage, or logging under that provider | Subcontractor | Layer 3, same rule again |
The rule recurses. There is no depth at which it stops applying, and no layer at which "we only pass it through" is a recognized exemption.
Where the AI layer breaks the assumption
A traditional call recording vendor was mostly a storage business. The PHI went in, sat encrypted, and came out when someone pulled a call. The subcontractor list was short and boring: a cloud provider, maybe a backup service.
A vendor doing transcription, summarization, sentiment scoring, or automated compliance flagging is a different animal. The audio moves. It may go to a speech-to-text service, then to a language model provider, then to an embedding or vector store, then to a monitoring or observability tool that logs request payloads. Each of those handlers, if it creates, receives, maintains, or transmits PHI on the vendor's behalf, is a subcontractor under 164.502(e)(1)(ii).
The regulation does not care whether the model is hosted, whether the vendor calls it an "API integration" rather than a subcontractor, or whether the data is described as being used only transiently. What matters is whether PHI is created, received, maintained, or transmitted.
Three questions that surface the truth quickly
- "Name every third party that touches call audio, transcripts, or derived text, including logging and observability tooling." The word "including" matters. Logging pipelines are where transcripts leak into systems nobody put on the BAA list.
- "For each, confirm you hold a signed agreement binding them to the same restrictions and conditions that apply to you." This is 164.504(e)(2)(ii)(D) read back to them. A vendor who cannot answer it has not read their own BAA.
- "Is any PHI used to train, fine-tune, or improve a model — yours or a third party's?" Ask for the answer in the contract, not in an email.
The enforcement posture is not theoretical
OCR has been settling business associate cases directly, and the failures it names are the unglamorous ones.
On March 5, 2026, OCR announced a settlement with MMG Fusion, LLC, a business associate, over a breach affecting approximately 15 million individuals following a December 2020 unauthorized system infiltration. OCR found the entity had failed to conduct an accurate and thorough risk analysis, impermissibly disclosed PHI, and failed to notify affected covered entities without unreasonable delay. The monetary settlement was $10,000; the corrective action plan runs three years and requires risk analysis, written policies, workforce training, audit controls, authentication mechanisms, and encryption of ePHI in transit and at rest.
The dollar figure is small. The operational point is not. As OCR Director Paula M. Stannard put it in the announcement, "When a breach occurs, business associates must notify affected covered entities without unreasonable delay and within 60 calendar days of discovery."
Read that as an operator. If your AI vendor's model subprocessor is breached, your ability to meet your own notification obligations depends on a notice traveling up a chain you have never inspected. If the bottom link does not know it is a subcontractor, the notice does not travel.
The clause most operators never invoke
There is a provision in the contract rule that gets almost no attention. Under 164.504(e)(1)(iii), a business associate is out of compliance if it "knew of a pattern of activity or practice of a subcontractor that constituted a material breach or violation" of the subcontractor's obligations, unless it took reasonable steps to cure or terminate the arrangement.
Structurally, the same standard applies to you regarding your business associates. Knowledge is not a shield. Once you have reason to believe your vendor's subprocessor chain is not properly papered, "we assumed they handled it" stops being an available position.
What to do this week
- List every vendor that touches call audio or transcripts. Include the phone system, the recorder, the QA tool, the CRM integration, and anything doing transcription or analytics. Twenty minutes with your IT lead.
- For each, confirm a current signed BAA and locate the subcontractor clause. You are looking for language tracking 164.504(e)(2)(ii)(D). If it is missing, that is a contract defect, not a technicality.
- Send one email per vendor asking for the current subprocessor list. A vendor operating properly can produce this same-day. A vendor that treats the request as unusual has told you something.
- Check your BAAs for change notification. If a vendor can swap model providers without telling you, your subprocessor inventory is accurate only on the day you built it.
- Confirm the breach notification path in writing. Specifically: how a subcontractor breach reaches your vendor, and how it reaches you, within a timeline that lets you meet your obligations.
Where this sits in vendor diligence
The subprocessor question belongs in the same conversation as the rest of your security review, not in a separate legal track that happens after selection. We have a broader list in the security questions you should ask any healthcare SaaS vendor before signing, and the recording-specific ground is covered in our HIPAA call recording compliance guide.
The category, briefly
Any AI-based call intelligence platform serving healthcare is a business associate with a subprocessor chain, and the honest ones will hand you that chain without being pushed. SurfacerIQ operates in that category; the diligence questions above are the ones we would expect a buyer to ask us.
This post is general information about the HIPAA rules, not legal advice — consult counsel on your specific agreements and vendor arrangements.
If you want a second read on your call vendor's subprocessor chain, talk to us.
Keep exploring
Related resources
Compliance monitoring →
Flag policy and regulatory issues on every call, not a sample.
Home care & healthcare →
Purpose-built for regulated call handling in home care and health.
HIPAA at SurfacerIQ →
How SurfacerIQ handles PHI, BAAs, and audit trails.
More from Compliance & HIPAA
- Minimum Necessary Applies to Your QA Team, Not Just Your Firewall8 min
- 42 CFR 484.50(e): You Must Document That a Complaint Existed — and How It Ended7 min
- HIPAA Does Not Require You to Keep Call Recordings for Six Years7 min
See SurfacerIQ in action
Calls in. Tickets out. Automatically. See how it works on a real call.
Keep reading
Minimum Necessary Applies to Your QA Team, Not Just Your Firewall
Your QA team can play any recording from any patient. The Privacy Rule has an opinion about that, and it is not the one your encryption vendor answered.
42 CFR 484.50(e): You Must Document That a Complaint Existed — and How It Ended
The CoP does not just require you to investigate complaints. It requires you to document that they existed and how they ended. Where that quietly breaks.
HIPAA Does Not Require You to Keep Call Recordings for Six Years
The six-year figure lives in HIPAA's administrative documentation rule, not in a call recording mandate. Here is what actually binds a home health agency.