Intake Coaching

Law Firm Intake and HIPAA: What Your Phone Staff Must Know Before Taking the First Call

August 1, 2026 / 10 min read

Sixty-two percent of personal injury law firms collect protected health information on intake calls without a single written HIPAA policy in place. That number comes from eNZeTi’s own analysis of intake operations at firms across the country. The intake call is where HIPAA exposure is highest, and it is almost universally unaddressed.

HIPAA does not only apply to hospitals. If your firm handles personal injury, workers’ compensation, medical malpractice, or any practice area where the caller’s medical history matters to case qualification, your intake process touches protected health information (PHI). And the person on the phone — whether that is your receptionist, a paralegal pulling double duty, or a dedicated intake coordinator — is the compliance risk.

This article breaks down exactly what HIPAA requires during intake, what your phone staff needs to know, and what eNZeTi’s real-time coaching layer does to keep your team on the right side of the line.

What Counts as Protected Health Information on an Intake Call

HIPAA’s definition of PHI is broader than most attorneys realize. Protected health information is any information that identifies an individual and relates to their health condition, healthcare treatment, or payment for healthcare. On an intake call, that can include:

On a standard personal injury intake call, your team collects all of this within the first five minutes. “How did the accident happen?” “Were you treated at the hospital?” “Are you still receiving physical therapy?” Every one of those answers is PHI the moment it is linked to a name and a phone number.

The question is not whether your intake staff collects PHI. They do. The question is whether they are handling it in a way that satisfies HIPAA’s safeguards requirements.

When HIPAA Applies to Law Firms

HIPAA directly regulates “covered entities” — health plans, healthcare clearinghouses, and healthcare providers. Law firms are generally not covered entities. But the compliance picture is more complicated than that binary suggests.

Business Associate Agreements (BAAs). If your firm receives PHI from a covered entity — such as a hospital sending medical records, or a health insurer providing claim information — and uses that information in providing services, you may be functioning as a business associate. Business associates must sign a BAA and comply with HIPAA’s Security Rule.

State law analogs. Even where federal HIPAA does not directly apply, most states have enacted their own medical privacy statutes that parallel HIPAA’s requirements. California’s CMIA, Texas Health and Safety Code Chapter 181, and New York’s SHIELD Act all impose obligations on entities that handle medical information. Calling it “not our HIPAA problem” does not insulate you from state-level liability.

Ethical obligations. Bar rules in every state impose an independent duty of confidentiality on attorneys that extends to all information relating to the representation — including health information disclosed during intake calls, before any engagement has been signed.

The practical position for any law firm is this: assume HIPAA standards apply to every intake call where medical information is discussed. You will never be wrong, and you will never be exposed.

The Four Intake Scenarios Where HIPAA Exposure Is Highest

Not all intake calls carry equal risk. The following four scenarios represent where most law firm HIPAA issues originate.

1. Unencrypted Call Notes

Whoever picks up the phone takes notes during intake. Whether that is a paper form, a shared Google Doc, a spreadsheet, or a CRM, those notes contain PHI. If they are stored on a personal device, emailed unencrypted, or accessible to unauthorized staff, that is a potential breach. The HHS Office for Civil Rights has investigated law firm business associates for exactly this kind of record-keeping failure.

2. Third-Party Verification Calls

Your front desk calls the hospital to verify a treatment date. Your intake coordinator calls an insurance adjuster to confirm coverage. These outbound calls involve disclosing a client’s PHI to a third party. If that disclosure happens without appropriate authorization — or without confirming you are speaking to the right recipient — it is a potential HIPAA violation, even if you initiated the call.

3. Leaving Detailed Voicemails

The HHS guidance on this is explicit: you may leave a voicemail for a patient or client, but you should limit the information disclosed to the minimum necessary. “This is Sarah from Miller Law calling about your accident case” is acceptable. “This is Sarah from Miller Law calling about the hip fracture you sustained in the fall at Walmart on November 14th” is not. The person who picks up that voicemail might not be your caller.

4. Intake Forms With No Security Controls

Online intake forms that ask for medical history, injury description, or treating physicians are collecting PHI. If those forms are not encrypted in transit, not stored on a secure server, and not protected by access controls, they represent a technical safeguard failure under HIPAA’s Security Rule — and an analogous failure under most state health information privacy laws.

What Your Phone Staff Needs to Know: The Six Rules

HIPAA training does not need to be a half-day seminar. Your intake team needs six working rules. They need to know them cold, because they will face all six situations in the first week on the job.

Rule 1: Minimum Necessary

Collect only the PHI you actually need to evaluate the case. For a personal injury intake, you need the nature of the injury, the treatment status, and whether liability is contested. You do not need the caller’s full prescription history or their psychiatric diagnoses unless those are directly relevant to the claim. Ask for what you need. Do not fish for more.

Rule 2: Verify Before You Disclose

If someone calls claiming to be the caller’s doctor, insurance company, or family member requesting information about the case, your team should not confirm anything without a written authorization. “I can’t share case information without a signed release from our client. Can I take your contact information and have someone follow up?” That is the complete answer. Train your team on it.

Rule 3: Secure Your Notes

Paper intake forms should be kept in a locked file until they are scanned and destroyed. Electronic notes should be in a password-protected system accessible only to authorized staff. No intake notes go in personal email. No intake notes go in a shared Dropbox without access controls. This is not an IT problem — it is a workflow problem, and it starts with whoever answers the phone.

Rule 4: Voicemail Discipline

When leaving a callback voicemail, use a standard template: name, firm name, phone number, request to call back. Nothing more. Do not disclose why you are calling or what the call relates to. If the caller previously told you it is safe to leave detailed messages, document that authorization in the file before acting on it.

Rule 5: No Casual Conversations

The front desk should not be discussing caller cases in the hallway, in the break room, or at the front desk where other clients can overhear. This sounds obvious. It is one of the most common deficiencies identified in HIPAA audits of professional services firms. Your intake staff needs a designated, private space for intake calls — not a cubicle in an open floor plan next to the waiting area.

Rule 6: Breach Reporting Protocol

If your intake team suspects a disclosure was unauthorized — a call went to the wrong number, notes were sent to the wrong email, a voicemail was left for someone other than the client — they need to know exactly who to tell and how fast. HIPAA requires notification within 60 days of discovery of a breach. Most law firms do not have a defined breach reporting chain. Your intake team should know the answer to “who do I call if I think I just made a mistake?”

How Real-Time Coaching Protects Your Intake Calls

Knowing the rules and following them under pressure are different skills. An intake coordinator who knows the minimum-necessary rule in the abstract may still provide a complete medical history summary when a persistent insurance adjuster asks probing questions on the phone. The gap between training and real-world compliance is where law firm liability actually lives.

eNZeTi’s real-time AI coaching layer listens to intake calls as they happen and flags compliance-relevant moments for the intake coordinator in real time. When a caller’s statements edge into territory the coordinator should not be probing, eNZeTi surfaces a cue. When the coordinator starts down a disclosure path that violates minimum-necessary standards, the system redirects. When a third-party verification scenario appears, the coordinator gets the appropriate script.

This is categorically different from post-call analytics. Post-call review catches mistakes after they have already been made — and in the case of a PHI disclosure, after the breach has already occurred. Real-time coaching prevents the mistake from happening in the first place. For a practice area where a single breach report can trigger an OCR investigation and a regulatory fine averaging $50,000 per violation category, the distinction matters.

The firms that use eNZeTi’s coaching layer do not just convert more cases. They document a compliance infrastructure — real-time oversight of every intake call — that demonstrates reasonable safeguards. That documentation has value in regulatory response and in malpractice defense.

The Written Policy Your Firm Needs Now

Every law firm that handles PHI during intake should have a written intake privacy policy. It does not need to be complex. It needs to answer five questions:

  1. What PHI do we collect on intake calls, and why? Define the categories of information collected and the case evaluation purpose they serve.
  2. Who has access to intake PHI? Define authorized staff and access controls.
  3. How is intake PHI stored and transmitted? Define the technical safeguards (encryption, access controls, retention limits).
  4. What training is required for intake staff? Define the training content, frequency, and documentation standard.
  5. What is our breach response protocol? Define who is notified, what investigation steps are taken, and what client notification obligations exist.

If your firm cannot answer those five questions in writing right now, that absence is itself the risk. OCR investigations start with documentation requests. A firm with no written policy is already behind before the first interview.

The Intake Call as a Compliance System, Not Just a Sales Process

The tendency in law firm business development is to treat the intake call as a conversion problem. How do we sign more cases? How do we reduce objections? How do we move faster from first call to engagement?

Those are legitimate questions, and intake conversion matters. But an intake call is also a compliance event. The moment your team picks up that phone and a caller starts describing their injury, their treatment, and their insurance situation, you are operating inside a regulatory environment — whether or not your team knows it.

The firms that will be penalized in the next five years are not the ones that made a single egregious error. They are the ones that had no policy, no training, no protocol, and no oversight — and whose cumulative exposure eventually produced a reportable breach or a malpractice claim. The intake call is not just where you sign cases. It is where you either build a compliant intake infrastructure or quietly accumulate risk.

The good news is that the solution is not complicated. Written policy. Staff training. Secure record-keeping. Real-time coaching oversight. Those four elements address the overwhelming majority of law firm intake HIPAA exposure. None of them require a compliance department or a full-time HIPAA officer.

They require a decision to take the intake call as seriously as the deposition or the filing deadline.

What to Do Next

  1. Audit your intake call notes today. Where do they go after the call ends? Who has access? Are they encrypted? If you cannot answer those questions in under 60 seconds, you have an exposure.
  2. Write the five-question policy this week. One page. Internal document. Give it to whoever answers the phone and have them sign acknowledgment.
  3. Add a voicemail script to your intake SOP. One sentence of approved language for callbacks. Zero improvisation.
  4. Assign a breach reporting contact. One person. One protocol. So that if your front desk makes a mistake, they know exactly what to do in the next 10 minutes.
  5. Consider what real-time oversight looks like for your intake operation. See how eNZeTi works in a real law firm — Book a Free Call Analysis at enzeti.com.

Coach every call without listening to every call.

eNZeTi scores every sales call and coaches your reps in real time, so your manager knows exactly what to fix without sitting through hours of recordings.

Get Your Free Call Review →