For Central European medical practices, GDPR governs every patient phone call, not HIPAA, which is a United States framework with no legal force in Europe. The practice is the data controller and remains legally responsible even when an external answering service handles the calls. Three actions reduce regulatory risk immediately: sign an Article 28 Data Processing Agreement (DPA) that restricts the processor to documented instructions only. Verify that the answering service uses SRTP/TLS call encryption and EU-hosted or HDS-equivalent infrastructure for any stored recordings; and add a short consent or notice script at the start of each call before any health details are discussed.
- Sign or update the DPA before sending any patient data to the answering service.
- Confirm SRTP for media and TLS for signaling are active on the vendor’s VoIP system.
- Restrict telephone scripts to scheduling intent only; clinical details stay for the consultation.
- Run a DPIA and vendor security checklist before go-live.
Pro Tip: Keep a signed copy of the DPA alongside your Record of Processing Activities. Supervisory authorities routinely request both together during inspections.
GDPR penalties for serious breaches can reach up to 4% of a company’s total annual global turnover, and healthcare data is treated as high-risk by supervisory authorities across Central Europe.
Key Takeaways
GDPR governs patient telephone calls in Central Europe; the medical practice is the data controller and cannot transfer that legal responsibility to an outsourced answering service.
| Point | Details | ||||
|---|---|---|---|---|---|
| Controller liability stays with the practice | Even with full outsourcing, the practice defines lawful basis, data categories, and supervisory-authority reporting. | ||||
Table of Contents
- Who is legally responsible for phone call data under GDPR?
- When does a phone call involve special-category health data?
- What technical measures must an outsourced phone service provide?
- What are the rules for recording patient calls?
- What must an Article 28 DPA include before signing?
- How should call handlers limit exposure of health data daily?
- What is the typical onboarding timeline and what drives cost?
- What should a practice do immediately after a telephone data breach?
- Why does a specialist medical answering service reduce compliance risk?
- What practices consistently get wrong about telephone compliance
- Clicfone offers a compliance-ready medical answering service
- Sources
- FAQ
Who is legally responsible for phone call data under GDPR?
The medical practice is the controller. The answering service is the processor. That distinction, established in EDPB guidance on controller/processor roles, determines who carries which obligations.
Controller responsibilities that cannot be delegated:
- Determining the lawful basis for processing patient call data.
- Defining which categories of data the answering service may collect.
- Reporting breaches to the supervisory authority within 72 hours.
- Maintaining the Record of Processing Activities.
Processor duties under Article 28:
- Act only on the controller’s documented instructions.
- Implement appropriate technical and organizational security measures.
- Assist the controller with data-subject access requests and erasure requests.
- Obtain prior written authorization before engaging any subprocessor.
- Provide audit evidence on request.
Pro Tip: Write granular, workflow-level instructions in the DPA: what the agent may ask, what fields may be recorded, and what must never be captured. Vague instructions create liability for the controller.
When does a phone call involve special-category health data?
A call crosses into Article 9 territory the moment the conversation includes a symptom, a diagnosis, a prescription, or the reason for a consultation. Scheduling a cardiology follow-up, for example, reveals a health condition by implication. That triggers the heightened protections of GDPR Article 9, not just Article 6.
Applicable lawful bases for medical telephone handling:
- Article 9(2)(h): processing necessary for the provision of health care, combined with Article 6(1)© or (e) for the general processing layer.
- Explicit consent under Article 9(2)(a): appropriate for optional services but not a reliable default for core appointment workflows, since withdrawal of consent would disrupt care.
- Legal obligation: where national health law mandates documentation of patient contacts.
The practical rule is minimization. The answering service should capture only the patient’s name, preferred callback number, appointment intent, and a generic call category. Clinical details belong in the consultation, not the call log.
Pro Tip: Declare a controller-side lawful basis tied to care delivery in the DPA rather than relying on broad consent for routine scheduling. Consent-based processing creates withdrawal risk that can disrupt appointment continuity.
What technical measures must an outsourced phone service provide?
Healthcare telephony security guidance specifies a clear set of controls that vendors must demonstrate. Supervisory authorities treat an insecure call as an improperly secured patient record.
Minimum required controls:
- VoIP encryption: SRTP for media streams, TLS for signaling. Unencrypted PSTN bridges require documented compensating controls.
- Hosting: Recordings or structured notes containing health data must reside on HDS-certified or equivalent EU infrastructure. ISO 27001 certification is the standard evidence auditors expect.
- Access controls: Per-user accounts, role-based permissions, multi-factor authentication (MFA) for access to call recordings and patient logs, and timely revocation when staff leave.
- Audit logs: Immutable, timestamped records of every access and export event, with regular access reviews.
- Operational controls: Signed staff confidentiality agreements, recurring privacy training, least-privilege policies, and a maintained subprocessors register.
Standard cloud providers without health-specific certification are not sufficient for stored recordings that contain health data. HDS certification, or a country-equivalent, is the threshold.
What are the rules for recording patient calls?
Recordings that include health data trigger Article 9 protections and require a documented lawful basis before the record button is pressed. CNOM and CNIL guidance treats recorded telephone exchanges with the same seriousness as patient records.
Practical requirements:
- Provide a clear notice at the start of every call: the caller must know the call may be recorded and for what purpose.
- If relying on consent, capture and log that consent separately before recording begins.
- Where consent is impractical (emergency triage, for example), document the alternative lawful basis explicitly in the DPA.
- Define a short, proportionate retention window. Enforce automatic deletion and include export and deletion-proof clauses in the DPA.
- Encrypt recordings at rest, restrict access to named roles, and log every access event.
Pro Tip: Use a separate, minimal metadata record for scheduling (date, time, appointment type) and keep clinical notes entirely out of call transcripts. This reduces the data volume subject to HDS hosting requirements and simplifies deletion compliance.
What must an Article 28 DPA include before signing?
The CNIL guide on processor obligations specifies the mandatory clauses. A DPA missing any of these items is non-compliant on its face.
Mandatory DPA clauses:
- Documented instructions clause limiting the processor to specified actions only.
- Description of security measures (encryption standard, hosting certification, access controls).
- Subprocessors list with prior-authorization requirement for any additions.
- Assistance obligations for data-subject rights and supervisory-authority cooperation.
- Breach notification timeline (processor notifies controller without undue delay, enabling the 72-hour supervisory window).
- Deletion or return of all data on contract termination, with written proof.
- Audit access rights for the controller or a mandated third-party auditor.
- Cross-border transfer rules: if any subprocessor operates outside the EU/EEA, standard contractual clauses or equivalent safeguards must be documented.
Due-diligence steps before signing:
- Request HDS or ISO 27001 certificate (current, not expired).
- Ask for a DPIA summary or equivalent risk assessment.
- Inspect a sample of access logs to verify logging is active.
- Validate staff confidentiality agreements and training records.
- Confirm subprocessors register is complete and geographically scoped.
Require a defined incident-response SLA and clear reversibility terms (data export format and deletion proof) as non-negotiable negotiation points.
How should call handlers limit exposure of health data daily?
Operational discipline is where compliance either holds or breaks down. CNOM/CNIL practical guidance recommends 12-character minimum passwords, automatic screen locking, and encrypted storage for any device used in patient communication.
Daily operational rules for telephone agents:
- Verify caller identity using name and date of birth only; never ask for diagnosis or treatment details.
- For third-party callers (family members, pharmacies), confirm the patient has authorized disclosure before sharing any information.
- Capture only: full name, preferred contact number, appointment intent, and generic call category.
- No speakerphone in shared or open-plan environments. Dedicated workstations with privacy screens for patient calls.
- Mandatory session lock after every call. No patient data on personal devices.
- Monthly refresher training and an internal incident-report channel for unusual requests.
Pro Tip: Run quarterly role-play audits simulating a caller requesting clinical details or a third party claiming authorization. Staff responses to edge cases reveal gaps that written policies miss. See patient phone reception best practices for structured audit templates.
What is the typical onboarding timeline and what drives cost?
Vendor qualification and technical integration typically take six to ten weeks when structured properly.
Phased timeline:
- Vendor selection and DPA negotiation: 2–4 weeks.
- Security evidence review (HDS/ISO certificates, access logs, DPIA): 1–3 weeks.
- Integration with appointment platform (Doctolib, LibreRDV, Maiia, or CalenDoc) and testing: 1–3 weeks.
- Staff training and limited-PHI trial: 1–2 weeks.
Main cost drivers:
- Level of health data stored: HDS hosting adds cost; API-only appointment confirmations without clinical notes reduce it.
- Custom integrations with appointment software beyond standard connectors.
- SLA requirements for incident response and audit cooperation.
- Staff training hours and confidentiality-agreement administration.
- Liability and incident-insurance clauses in the contract.
Quick wins to reduce both time and cost: limit stored PHI from day one, prefer API-only confirmation workflows, reuse a standard DPA template aligned with CNIL recommendations, and stage go-live by function rather than activating all workflows simultaneously.
What should a practice do immediately after a telephone data breach?
Speed and documentation both matter. GDPR requires supervisory authority notification within 72 hours of becoming aware of a breach that poses a risk to individuals’ rights and freedoms.
Immediate response steps:
- Isolate affected systems, preserve logs, and revoke access for compromised accounts.
- Scope the data exposed: was it health data? How many patients? What is the likelihood of harm?
- Document findings in writing for the DPA and supervisory authority notification.
- Notify the supervisory authority within 72 hours if there is a risk to rights and freedoms; notify affected patients if the risk is high.
- Request vendor incident reports, forensic logs, remediation steps, and written proof of containment or deletion.
Pro Tip: Pre-agree an incident-response SLA and a named vendor escalation contact in the DPA. Without it, the 72-hour notification window can expire before the processor has even confirmed the scope of the breach.
Why does a specialist medical answering service reduce compliance risk?
A generalist call center trained on retail or utility workflows will not apply medical minimization scripts, will not know when a caller’s question crosses into Article 9 territory, and will not have tested integrations with Doctolib, LibreRDV, Maiia, or CalenDoc. The compliance gap is structural, not a matter of effort.
Clicfone has operated in medical and paramedical telephone answering since 2010, with more than half of its clients maintaining the relationship for over ten years. That continuity reflects tested integrations with the major appointment platforms and staff trained specifically on health-data minimization and confidentiality protocols.
How Clicfone maps to the compliance checklist:
- DPA aligned with Article 28, including a subprocessors register and audit-access clause.
- Per-user access controls and MFA for call recordings and patient logs.
- Encrypted VoIP (SRTP/TLS) and EU-hosted infrastructure.
- Staff confidentiality agreements and recurring privacy training.
- Demonstrated integrations with Doctolib, LibreRDV, Maiia, and CalenDoc via API-only appointment confirmation workflows.
- Onboarding support for DPIA preparation and supervisory-authority cooperation.
For practices that need secure paramedical phone handling, a specialist vendor with documented evidence is the lower-risk path compared to adapting a generalist provider.
What practices consistently get wrong about telephone compliance
The most common oversight is treating a vendor’s self-declared “GDPR compliance” as sufficient evidence. It is not. Compliance is a documented state, not a marketing claim. Practices that accept a vendor’s assurance without requesting HDS certificates, ISO 27001 documentation, access-log samples, and staff training records are carrying liability they believe they have transferred.

A second persistent gap is storing unnecessary clinical detail in call notes. When an answering service records the reason for a consultation in free text, that note may require HDS hosting, a longer retention justification, and a more complex deletion process. Limiting call capture to scheduling metadata eliminates most of that exposure.
The third blind spot is subprocessor clauses. A DPA that authorizes the processor to engage subprocessors “at its discretion” effectively removes the controller’s visibility into where patient data travels. Every subprocessor should be named, geographically scoped, and subject to the same security standards as the primary processor. Compliance is not a one-time checkbox; it requires DPA reviews, processor audits, and an updated processing registry on a recurring cycle.
Clicfone offers a compliance-ready medical answering service
Medical practices that outsource telephone answering need a partner with documented security controls, not a general-purpose call center that has added a GDPR clause to its standard contract. Clicfone’s medical tele-secretariat service is built specifically for healthcare, with Article 28-aligned DPA templates, SRTP/TLS encryption, EU hosting, and tested integrations with Doctolib, LibreRDV, Maiia, and CalenDoc ready from day one.

Practices can request a DPA sample, schedule a security review of their current telephone workflow, or start a limited-PHI trial to validate the integration with their existing appointment platform. Contact Clicfone to begin a compliance audit tailored to the practice’s patient volume and specialty. For practices in Paris and the surrounding region, the medical telephone secretariat for physicians page outlines service options and onboarding steps directly.
Sources
The following authoritative references support the legal and technical claims in this article and are the primary sources practices should consult when preparing DPAs, DPIAs, and vendor audit evidence.
- Legifrance
- Gdpr-info
- CNIL guide: obligations of processors and recommended DPA clauses
- Digitis — How to secure health telephony and comply with GDPR
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
FAQ
Does GDPR apply to patient phone calls in Central Europe?
Yes. Every telephone exchange in which health data is discussed constitutes data processing under GDPR, and the medical practice is the data controller responsible for its lawful handling.
What encryption is required for outsourced medical phone calls?
SRTP must protect media streams and TLS must protect signaling on any VoIP system used to handle patient calls. Unencrypted PSTN bridges require documented compensating controls to satisfy supervisory authorities.
What must an Article 28 DPA include for a telephone answering service?
The DPA must cover documented instructions, security measures, a named subprocessors register, assistance with data-subject rights, breach notification timelines, deletion or return of data on termination, and audit-access rights for the controller.
How long does a practice have to notify authorities after a breach?
The practice must notify the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals’ rights and freedoms, and must notify affected patients when the risk is high.
Can Clicfone provide a compliant DPA and integration with Doctolib or Maiia?
Clicfone provides Article 28-aligned DPA templates and tested integrations with Doctolib, LibreRDV, Maiia, and CalenDoc, with SRTP/TLS encryption and EU-hosted infrastructure included in its medical tele-secretariat service.