FLUXATHThe Dispatch

Compliance · Complete guide

HIPAA, TCPA & Call Compliance for Service Businesses

Plain-language guide to compliance hipaa, TCPA, and call rules for local service businesses — what matters, what doesn't, and what it costs to get wrong.

The $1.9 Million Reason to Read This Page

A national HVAC franchise paid $1.9 million to settle a TCPA class action in 2022. Their crime: texting opted-in customers promotional messages after those customers had specifically replied “STOP.” The franchise thought their software handled opt-outs automatically. It didn’t. Eleven thousand customers, $1,500 per willful violation, one bad vendor integration.

That’s not a scare tactic. It’s the actual math. The Telephone Consumer Protection Act was written to have teeth, and plaintiffs’ attorneys have built a cottage industry finding businesses that didn’t know they had a compliance gap. HIPAA violations carry their own fine schedule — up to $1.9 million per violation category per year at the highest tier.

This guide cuts through the confusion. It covers what HIPAA actually covers (it’s narrower than most people think), what TCPA actually prohibits (it’s broader than most people think), and what local service businesses — HVAC, plumbing, dental, roofing, law firms, med spas, pest control, and everyone in between — need to do today to stop operating blind.


What HIPAA Actually Covers — and What It Doesn’t

Start here because roughly 70% of local service businesses worry about HIPAA when they don’t need to, and the ones who do need to worry often don’t.

HIPAA — the Health Insurance Portability and Accountability Act — applies to covered entities and their business associates. That’s it.

Covered entities are:

  • Healthcare providers who transmit health information electronically (doctors, dentists, chiropractors, therapists, hospitals, urgent care)
  • Health plans (insurers, HMOs, Medicare/Medicaid)
  • Healthcare clearinghouses

Business associates are vendors and contractors who handle protected health information (PHI) on behalf of a covered entity — billing companies, answering services, IT vendors who touch patient records, cloud storage providers used for records.

PHI is any individually identifiable information related to a patient’s health condition, care, or payment for care: name + diagnosis, appointment reason, prescription details, treatment history, insurance information.

If you run an HVAC company, a roofing business, a pest control operation, or an auto repair shop — HIPAA doesn’t apply to you. Full stop. Your customer calls are not PHI. You can use any phone system, any CRM, any AI receptionist without a HIPAA compliance framework.

If you run a dental office, med spa, plastic surgery practice, therapy group, or any practice that takes appointments for health-related services and maintains records of those services — HIPAA applies to you at every touchpoint, including your phone system.

For the dental and med spa operators reading this, the compliance obligations run deep enough to warrant their own detailed treatment. The HIPAA compliance requirements for dental offices and med spas using AI phone receptionists covers the specific questions you need to ask any vendor before signing.


TCPA: The Law That Bites Everyone

The Telephone Consumer Protection Act, unlike HIPAA, applies to nearly every business that uses a phone. It governs:

  • Autodialed calls and texts to cell phones
  • Pre-recorded voice messages
  • Fax marketing (yes, still on the books)
  • Do Not Call Registry compliance

The key distinctions:

Type of communication Consent required? DNC Registry applies?
Manual one-off call to a lead who contacted you No written consent needed Yes — check the Registry
Automated text to a customer with prior business relationship Prior express consent (may be implied by giving their number) Yes
Promotional text to a cold prospect Prior express written consent Yes
Pre-recorded voicemail drop to cell phone Prior express written consent Yes
Live call to a landline for non-promotional purposes No consent requirement Yes

The most common trap for local service businesses isn’t the bulk campaign they intentionally ran — it’s the automated follow-up sequence their CRM or marketing platform sent without proper consent capture.

Say your website has a “Get a Free Quote” form. A visitor fills it out. Your platform immediately fires off an automated text: “Hi, this is Mike’s HVAC — we got your request! Reply YES to schedule.” That’s an autodialed text to a cell phone number. Under the FCC’s 2024 one-to-one consent rule (effective January 2025), that text requires prior express written consent specifically naming your business as a sender. The form checkbox saying “I agree to receive communications from partners” doesn’t cut it anymore.

The TCPA compliance requirements for local businesses running missed-call follow-up systems goes deeper on the mechanics — consent language, opt-out handling, and what “express written consent” actually looks like in a form.


The Business Associate Agreement Chain

If you’re a healthcare-adjacent business, you need to understand BAAs before you buy any phone technology.

A Business Associate Agreement is a contract between a covered entity and any vendor that might handle PHI. Without a signed BAA, a covered entity cannot legally share PHI with that vendor. Using an answering service, AI receptionist, or CRM without a BAA — when that tool touches patient information — is a direct HIPAA violation.

The chain looks like this:

  • Your dental office (covered entity) → answering service (business associate) → answering service’s cloud storage vendor (sub-business associate)

Each link in the chain needs a BAA. If your answering service uses Amazon Web Services to store call recordings, AWS needs a BAA with the answering service, who needs a BAA with you.

Most established enterprise vendors (AWS, Google Cloud, Microsoft Azure) readily provide BAAs. The gap is usually at the mid-tier: small answering services, off-the-shelf AI receptionist tools marketed to general businesses, and CRMs not built for healthcare.

Before you sign with any phone vendor, ask two questions:

  1. Will you sign a HIPAA Business Associate Agreement?
  2. Do all your subprocessors who may touch our call recordings or transcripts have BAAs in place?

If the vendor stalls, says “we’re HIPAA-compliant” without offering to sign a BAA, or doesn’t know what a subprocessor is — that’s your answer.

The full guide on whether your answering service needs a HIPAA BAA walks through what the agreement must contain and how to vet a vendor’s subprocessor chain.


Call Recording: The State Law Trap

Federal law and a majority of states operate under one-party consent: if you’re a participant in a call, you can record it without notifying the other party.

A meaningful number of states require all-party consent — every person on the call must be informed before recording begins.

All-party consent states (as of 2026):

  • California
  • Florida
  • Illinois
  • Maryland
  • Massachusetts
  • Michigan
  • Montana
  • Nevada
  • New Hampshire
  • Oregon
  • Pennsylvania
  • Washington

If you operate in any of these states, or if your callers might be in any of these states, your call recordings require disclosure. The fix is simple: include a short statement in your phone greeting. “This call may be recorded for quality and training purposes” covers you. Skipping it in California or Florida — where statutory damages run $5,000 per recorded call — doesn’t.

Most cloud phone systems (RingCentral, Twilio, Vonage) can be configured to play a recording disclosure automatically at call start. If you’re using an AI receptionist, verify that the greeting includes a disclosure or that you can add one.


Attorney-Client Privilege: A Word for Law Firms

Law practices deal with a different compliance framework entirely. The ethical obligations under attorney-client privilege and state bar rules of professional conduct apply from the first ring.

A prospective client calling your firm may disclose sensitive information — a DUI, a custody dispute, a business fraud — before they’ve formally retained you. That disclosure is still privileged. The call handling system you use must be able to demonstrate confidentiality: no third-party access to transcripts, no data used for training without consent, no shared infrastructure that puts client conversations next to other businesses’ data.

The confidentiality requirements for law firm intake and AI receptionists covers what your state bar likely expects and what questions to ask before deploying any automated intake tool.


The Cost of Getting It Wrong

Compliance failures aren’t just fines. They’re operational disruptions, reputation damage, and the distraction of managing litigation while trying to run a business.

Violation type Per-incident exposure Class action risk
TCPA — negligent text without consent $500 High (50+ plaintiffs = $25,000+)
TCPA — willful violation $1,500 High
HIPAA — unknowing violation $100–$50,000 Low (OCR enforcement, not civil)
HIPAA — willful neglect, uncorrected Up to $1,900,000/year per category Low
State recording law — per call (CA) $5,000 Moderate

The TCPA exposure is what catches most local businesses off guard. One automated text platform sending to 500 unverified cell numbers can generate $250,000 in statutory liability before any attorney fees.

The practical fix for most non-healthcare businesses is a one-time audit of their automated communication flows: every text, every automated call, every voicemail drop. Map each one to a consent event. Where there’s no consent, pause the sequence until consent language is added to the original contact form.


When Compliance Is Overkill — And When It Isn’t

Not every local business needs a compliance attorney, a BAA, or a specialized HIPAA-ready phone system.

You probably don’t need HIPAA infrastructure if:

  • You’re a trade contractor (HVAC, plumbing, electrical, roofing, landscaping, pest control)
  • You’re a general auto repair shop, towing company, or cleaning service
  • You don’t collect or store any information about customers’ health conditions, treatments, or insurance

You do need HIPAA-grade vendor selection if:

  • You’re a dental or orthodontic practice
  • You’re a med spa, plastic surgery center, or any practice that performs or books medical procedures
  • You’re a mental health provider, therapist, or counselor
  • You’re a chiropractic office, physical therapy practice, or any provider who bills health insurance

Everyone who sends automated texts needs TCPA compliance. This isn’t optional and it isn’t tiered by industry. If your marketing platform, CRM, or AI follow-up tool sends automated texts to cell phones, you need written consent, a functional opt-out mechanism, and records of both.

An honest look at the comparison between AI receptionists and human answering services for medical practices shows that the compliance burden isn’t a reason to avoid AI tools — it’s a reason to evaluate vendors more carefully.


What a Compliant Phone System Looks Like in Practice

For a non-healthcare trade business (HVAC, plumbing, roofing, garage door):

  • Any AI receptionist product works from a HIPAA standpoint — you’re not a covered entity
  • Add a call recording disclosure to your greeting (“This call may be recorded…”)
  • Audit your automated text follow-up for TCPA consent: does your contact form include explicit consent language naming your business?
  • Register your business number with the Free Caller Registry and consider 10DLC registration if you send texts at scale
  • Check the National Do Not Call Registry before any outbound campaign

For a dental office, med spa, or healthcare-adjacent practice:

  • Any AI receptionist or answering service vendor must sign a HIPAA BAA
  • The vendor’s subprocessors (cloud hosting, transcription services) must also have BAAs
  • Call recordings and transcripts are PHI — they must be stored with encryption at rest and in transit
  • Staff training on HIPAA minimum-necessary standard applies to phone intake
  • Text follow-up for appointment reminders requires consent — most standard patient intake forms include this, but verify
  • Consider a HIPAA-focused compliance review before deploying any new phone technology

The Honest Conversation About Cost

Compliance isn’t free. Here’s what the realistic picture looks like.

HIPAA-ready AI receptionist: Vendors that offer BAA-signed, HIPAA-compliant phone answering typically charge a premium. At FLUXATH, the Starter plan ($297/month, no setup fee) is designed for standard trade businesses. Healthcare-adjacent practices considering the Pro tier ($497/month, no setup fee) or Enterprise ($797/month, no setup fee) should confirm BAA availability at the plan level — the Enterprise tier is where full compliance infrastructure (custom data handling, subprocessor chain documentation) is negotiable.

Against that cost, run the math on missed calls. Studies of small-business call handling consistently find that more than half of calls to local service businesses go unanswered during peak hours. Say your average HVAC service call is $350 and you answer 60% of inbound calls. Recovering 10 more calls per month is $3,500 in revenue. The receptionist pays for itself before you factor in the compliance benefit.

Legal review: If you’re a healthcare-adjacent practice deploying new phone technology, budget $500–$2,000 for a one-hour review with a healthcare attorney. It’s not optional, and it costs far less than a single HIPAA investigation.

TCPA audit: If you’ve been running automated text campaigns without auditing your consent capture, a compliance attorney can typically review your flows in 2–4 hours. The cost is negligible compared to a class action defense.

When this doesn’t pencil out: if you take fewer than 20 inbound calls per month and send no automated texts, neither an AI receptionist nor a formal compliance review is a priority right now. Get back to it when call volume picks up.


What to Do Next

The compliance picture for local service businesses splits into two tracks. Figure out which one you’re on.

Track one — trade or non-healthcare service business:

  1. Add a call recording disclosure to your phone greeting if you record calls
  2. Audit your automated texts: do you have written consent for each sequence?
  3. Verify your outbound numbers are Do Not Call compliant before any campaign
  4. If you’re adding an AI receptionist, pick any vendor that meets your call quality bar — HIPAA isn’t in play

Track two — dental, med spa, law firm, or any healthcare-adjacent practice:

  1. List every vendor who touches patient call data: phone system, CRM, voicemail, transcription service
  2. Confirm each has signed a BAA or will sign one
  3. Pull your current patient intake form and verify it includes explicit text consent language
  4. Have a healthcare or telecom attorney review your setup before you add any new automated tool

The goal isn’t perfect legal certainty — it’s closing the obvious gaps that turn small oversights into six-figure problems. Most businesses reading this are one consent form update and one vendor call away from a much cleaner position.

If you want to see what a compliant AI receptionist setup looks like for your specific business type, FLUXATH offers a working demo at +1 (858) 358-7270. You can hear how the intake flow sounds and ask vendor-specific compliance questions before committing to anything.

Frequently asked questions

Does HIPAA apply to my HVAC or plumbing business?
Almost certainly not. HIPAA applies to covered entities — doctors, dentists, hospitals, health insurers — and their business associates. If you don’t handle protected health information (diagnoses, prescriptions, treatment records), you’re not a covered entity. Dental offices and med spas are a different story: see the dedicated HIPAA guide for healthcare-adjacent practices.
What does TCPA actually require when I call a missed lead back?
For the return call itself — one call back to a number that rang your line — you’re on solid ground. The TCPA’s restrictions bite hardest on autodialed or pre-recorded outbound campaigns, and on texts. If you’re using an automated system to send follow-up texts or drop pre-recorded voicemails, you need prior written consent. Our TCPA basics article walks through what your missed-call follow-up system must get right.
Does an AI receptionist need a HIPAA Business Associate Agreement?
If the AI receptionist takes calls at a dental office, med spa, or any practice that handles protected health information, yes — the vendor must sign a BAA. If you’re an HVAC shop, plumber, or roofer, this question doesn’t apply to you. Read the full breakdown in our guide on whether your answering service needs a HIPAA BAA.
What's the fine for a TCPA violation?
The statutory penalty is $500 per violation, trebled to $1,500 per willful violation. A single unauthorized text blast to 10,000 contacts can produce a $5–15 million exposure before any class action multiplier. Plaintiffs’ firms specifically hunt for these cases because the math works in their favor.
Can I record calls without telling the caller?
It depends on the state. Federal law and most states allow one-party consent — meaning you can record a call you’re a party to without notifying the other person. California, Florida, Illinois, Washington, and a handful of others require all-party consent. If you record calls (for training, QA, or CRM notes), your greeting should say so. ‘This call may be recorded’ is the standard fix.
What's the first thing I should actually do after reading this guide?
Figure out which bucket you’re in: (1) a healthcare-adjacent practice that handles PHI, or (2) a standard trade/service business. If you’re in bucket one, your first call is to your malpractice or business attorney to get your BAA chain in order. If you’re in bucket two, the highest-ROI move is auditing your automated follow-up texts for TCPA consent gaps — that’s where the real litigation risk lives for most local businesses.