Compass listens to 100% of patient conversations across scheduling, intake, billing, triage, and patient relations, and produces the evidence OCR and accreditors ask for: who said what, when, and whether minimum necessary was honored. We sign a BAA before you send a single call.

Your week as a healthcare privacy or compliance leader is shaped by calls you never hear. A scheduler reads back a full date of birth in front of a waiting room. A billing rep talks to a spouse who is not on the authorization form. A home health intake nurse leaves a voicemail on a household line that names the diagnosis. An ambulatory front desk reroutes a records request through a fax form when the patient asked for electronic delivery. Any one of these can become an OCR complaint, and investigations rarely focus on the triggering call. They focus on whether you had reasonable safeguards across all of them.
The metrics that should tell you the program is working do not. A QA score says reps verified two identifiers on 94% of sampled calls. You cannot say the other thousand calls that week followed the same pattern. You have a right of access procedure on paper under 45 CFR 164.524, but you do not know how often patients call asking for records or whether the 30-day clock starts when the call ends or when the ticket is created. The 21st Century Cures Act information blocking rule sits on top of it. The rule applies to actors that include healthcare providers, and prohibited practices include interfering with access, exchange, or use of electronic health information. Patient phone calls are where many of those interferences first happen.
Volume compounds the problem. A regional hospital system runs six figures of patient calls a month. A multi-site physician group runs tens of thousands. A home health or hospice agency runs fewer but with higher exposure per call, because most reach a patient's home where a spouse, adult child, or hired caregiver might answer. Across all three settings, your QA team listens to a fraction of one percent. Retention is not evidence, and search is not understanding. When OCR, a Joint Commission surveyor, a CHAP reviewer, or your audit committee asks how you monitor minimum necessary, you need to answer across every call.
Sampling misses the calls that get you sued and the ones that get you fined. The QA team picks calls on a schedule: reps they have not heard from recently, calls a supervisor flagged, a random pull from a shift. They do not score every call where a caller said "my mother" or "my husband," every call where the rep volunteered information before verifying identity, or every outbound voicemail. The conversations most likely to involve impermissible disclosure, minimum necessary failure, or information blocking risk fall outside the frame.
Time pressure is where minimum necessary degrades. The standard at 45 CFR 164.502(b) limits uses and disclosures to the minimum necessary, with exceptions for treatment, the individual, and certain authorized disclosures. On a busy scheduling line, that becomes "everything in the chart that helps me find the right slot." A rep six hours into a shift reads visit reason out loud to confirm a referral. A registration rep recites insurance details to verify a spouse. A home health intake coordinator names a wound type to a caregiver who was never authorized. None of it shows up on a scorecard that has no question for it.
Right of access misses happen in the queue. A patient calls asking for records. The rep redirects them to a portal, tells them to fax a form, quotes a fee, or says imaging has to be picked up in person. Each response is potentially correct, and each is potentially a problem under the OCR Right of Access Initiative depending on what comes next. The 30-day clock at 45 CFR 164.524 starts when the request was made, not when it lands in the right queue. Patient experience sits in the same blind spot: the hold transfer that drops a patient back to the main menu, the pause after a death-in-the-family mention that the rep does not acknowledge, the scheduling handoff that loses the chief complaint. Not HIPAA failures, but the same calls drive complaints, repeat contacts, and patient experience scores.
OCR enforces the HIPAA Privacy and Security Rules under 45 CFR Parts 160 and 164. Resolution agreements show the office investigates impermissible disclosures to family members and third parties, minimum necessary failures, and untimely access. The OCR Right of Access Initiative, announced in 2019, has produced settlements across hospital, physician group, and post-acute settings. The cost compounds when the covered entity cannot show evidence of a working monitoring program, and a 2% QA sample is hard to characterize as one.
The 21st Century Cures Act information blocking rule, codified at 45 CFR Part 171, applies to healthcare providers, certified health IT developers, and health information networks and exchanges. It prohibits practices likely to interfere with access, exchange, or use of electronic health information, subject to defined exceptions. Patient phone calls are a primary surface: telling a patient their record is not available electronically when it is, requiring an in-person visit for an electronic record request, charging a fee that exceeds what is permitted, or routing a request into a process designed to discourage it. The provider disincentives rule finalized by HHS in 2024 made the language of these calls a financial risk.
Accreditors look at the same surface from a different angle. The Joint Commission, CHAP, ACHC, and state survey agencies cite communication, patient rights, and complaint handling under the relevant Conditions of Participation, including 42 CFR Part 482 for hospitals, Part 484 for home health, and Part 418 for hospice. State law overlays raise the floor: California's CMIA, Texas HB 300, New York SHIELD, Washington's My Health My Data Act. Sensitive categories with their own consent regimes, including 42 CFR Part 2 for SUD records, are scoped separately. Every flagged signal ties to a specific conversation, timestamp, and transcript line, so a privacy committee, audit committee, surveyor, and outside counsel work from the same record.
Compass replaces sampling QA with a structured understanding of every patient conversation. It ingests from your existing recording infrastructure, builds transcripts with speaker separation, and runs each conversation through Contextual Entity Resolution, which connects callers, patients, providers, and disclosures across calls so a complaint or investigation starts with the history already assembled. The output is layered: Conditions (factual observations), Signals (scored behavioral patterns), Outcome Lift (impact on outcomes, adjusted for call difficulty), and Guidance (what to do next).
Conversation Compliance. Disclosure tracking for identity verification, minimum necessary, authorization scope, right of access tagging, and information blocking language. Every flagged call carries an audit trail with timestamped transcript and signal-level evidence.
Conversation Insights. 100% coverage across scheduling, registration, billing, nurse triage, patient relations, intake, and post-discharge follow-up. Theme detection surfaces complaint patterns and access friction before they become an OCR data request or a survey citation.
Conversation Coaching. Evidence-backed coaching moments per rep, tied to actual conversations and signals. The agent gets the specific call, the specific moment, and the comparison to what the conversation looks like when it goes well.
Conversation Quality. Conditions, Signals, Outcome Lift, and Guidance for every call. The scorecard does not have to disappear. Many teams run it in parallel and let it become a subset of the signal library over time.

Q: Do you sign a BAA? A: Yes, before anything else. Compass operates as a business associate and signs a BAA covering recording, transcription, storage, and analytics scope. We do not ask you to send recorded patient calls before the BAA is executed. Standard paperwork (BAA, NDA, DPA) is available on request.
Q: How is PHI handled in transcripts and storage? A: Compass applies controls aligned with the HIPAA Security Rule for encryption in transit and at rest, role-based access, audit logging, and key management. Subprocessor list and data flow diagrams are available during your vendor review. SOC 2 is in progress; current security documentation is available on request.
Q: Is patient data used to train your models? A: No customer PHI is used to train models that serve other customers. Model governance documentation, including training data scope, evaluation methodology, and how flagged disclosures are adjudicated before they enter an audit trail, is available on request.
Q: Subprocessors and breach notification? A: The subprocessor list is available during vendor review and covers transcription, language, and analytics components in scope. Breach and incident notification SLAs are written into the BAA, scoped to fit inside the HIPAA 60-day window from discovery.
Q: Sensitive categories like behavioral health or SUD? A: 42 CFR Part 2 applies a stricter consent standard than HIPAA for SUD records. Compass identifies calls touching those categories so they can be routed through the right policy, and Part 2 covered programs are scoped explicitly. State overlays including CMIA, Texas HB 300, and Washington My Health My Data are configured for the states you operate in.
Q: What about call recording consent and workforce monitoring in two-party-consent states? A: California, Florida, Illinois, Pennsylvania, Washington, and other two-party-consent states shape how disclosures and workforce monitoring notices are written. Compass does not change the recording itself, so your existing notice carries through. We work with your employment counsel on whether workforce monitoring language needs to be updated to cover automated analysis of recorded calls.
Q: Will this work with our existing recording and telephony platform? A: Compass ingests from the call recording, telephony, and CCaaS platforms common in healthcare. Setup is primarily normalizing metadata so site, queue, rep, and call type map correctly.
Q: Non-English calls and interpreter lines? A: Compass supports multi-language transcription and analysis, including bilingual calls and three-way calls with a contracted interpreter. Identity verification and disclosure tracking are scored against the rep's portion of the exchange when the interpreter is a third party.
Q: How is this different from Gong, NICE, Verint, or CallMiner? A: Gong is built for revenue teams and does not address the patterns OCR investigates. NICE, Verint, and CallMiner provide recording, search, and rules-based scoring. Compass is built around 100% understanding rather than 100% scoring, with output structured for HIPAA, Cures Act, accreditation, and state law together.
A 30-minute working session is the fastest way to see whether Compass fits your program. We can walk shared examples, or run a sandbox built from non-PHI scenarios. If you want to look at your own calls, the BAA goes first. Bring your privacy lead and your QA lead; security can join the same hour.