{"id":54165,"date":"2026-02-01T12:29:58","date_gmt":"2026-02-01T18:29:58","guid":{"rendered":"https:\/\/heartbeat.ai\/healthcare\/not-hipaa-no-patient-data\/"},"modified":"2026-08-29T07:04:43","modified_gmt":"2026-08-29T12:04:43","slug":"not-hipaa-no-patient-data","status":"publish","type":"post","link":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/","title":{"rendered":"HIPAA and recruiting contact data: what procurement should verify (no patient data)"},"content":{"rendered":"<p class=\"article-last-updated\"><strong>Last updated:<\/strong> August 29, 2026<\/p>\n<p><img decoding=\"async\" loading=\"false\" class=\"aligncenter\" src=\"http:\/\/hc.heartbeat.ai\/wp-content\/webp-express\/webp-images\/uploads\/2026\/02\/not-hipaa-no-patient-data-3aa05bdd.png.webp\" alt=\"54164\" \/><\/p>\n<p><strong>Ben Argeband, Founder &amp; CEO of Heartbeat.ai<\/strong> \u2014 Written for procurement review. This is general information; your counsel should confirm applicability to your organization.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\r\n<div class=\"ez-toc-title-container\">\r\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">What\u2019s on this page:<\/p>\r\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\r\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Who_this_is_for\" >Who this is for<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Quick_answer\" >Quick answer<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Answering_%E2%80%9Care_you_HIPAA_compliant%E2%80%9D_without_hand-waving\" >Answering &#8220;are you HIPAA compliant?&#8221; without hand-waving<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#%E2%80%9CAre_you_a_covered_entity_or_business_associate%E2%80%9D\" >&#8220;Are you a covered entity or business associate?&#8221;<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Step-by-step_review_method\" >Step-by-step review method<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Step_1_Classify_the_data_youre_actually_using_field_by_field\" >Step 1: Classify the data you&#8217;re actually using, field by field<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Step_2_Look_for_what_would_flip_this_into_a_HIPAA-scoped_workflow\" >Step 2: Look for what would flip this into a HIPAA-scoped workflow<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Step_3_Get_the_%E2%80%9Cno_patient_data%E2%80%9D_boundary_in_writing\" >Step 3: Get the &#8220;no patient data&#8221; boundary in writing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Step_4_Evaluate_outreach_compliance_controls_%E2%80%94_this_is_where_the_real_risk_lives\" >Step 4: Evaluate outreach compliance controls \u2014 this is where the real risk lives<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Step_5_Require_standard_metrics_not_vanity_numbers\" >Step 5: Require standard metrics, not vanity numbers<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Step_6_What_to_actually_request_from_the_vendor\" >Step 6: What to actually request from the vendor<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Diagnostic_table\" >Diagnostic table<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Weighted_checklist\" >Weighted checklist<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Outreach_templates\" >Outreach templates<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Email_template_first_touch\" >Email template (first touch)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Text_template_only_where_appropriate_for_your_program\" >Text template (only where appropriate for your program)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Voicemail_template\" >Voicemail template<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Stop-request_handling_flow\" >Stop-request handling flow<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Common_pitfalls\" >Common pitfalls<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#1_Treating_%E2%80%9CHIPAA%E2%80%9D_as_a_checkbox_instead_of_scoping_the_data\" >1) Treating &#8220;HIPAA&#8221; as a checkbox instead of scoping the data<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#2_Letting_users_paste_sensitive_information_into_free-text_fields\" >2) Letting users paste sensitive information into free-text fields<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#3_Weak_opt-out_handling\" >3) Weak opt-out handling<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#4_Measuring_the_wrong_things\" >4) Measuring the wrong things<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-24\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#How_to_improve_results\" >How to improve results<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-25\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#1_Fix_suppression_before_scaling_volume\" >1) Fix suppression before scaling volume<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-26\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#2_Standardize_measurement_and_review_cadence\" >2) Standardize measurement and review cadence<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-27\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#3_Practice_data_minimization\" >3) Practice data minimization<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-28\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#4_Use_language_patterns_that_reduce_complaints\" >4) Use language patterns that reduce complaints<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-29\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#5_Match_controls_to_how_recruiters_actually_work\" >5) Match controls to how recruiters actually work<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-30\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Legal_and_ethical_use\" >Legal and ethical use<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-31\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Evidence_and_trust_notes\" >Evidence and trust notes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-32\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#FAQs\" >FAQs<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-33\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Does_recruiting_outreach_involve_PHI\" >Does recruiting outreach involve PHI?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-34\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#What_should_procurement_ask_a_recruiting_data_vendor_to_provide\" >What should procurement ask a recruiting data vendor to provide?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-35\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#What_would_make_a_recruiting_workflow_higher_risk_under_HIPAA\" >What would make a recruiting workflow higher risk under HIPAA?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-36\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#How_should_we_handle_%E2%80%9CSTOP%E2%80%9D_requests_from_clinicians\" >How should we handle &#8220;STOP&#8221; requests from clinicians?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-37\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#What_metrics_indicate_an_outreach_program_is_under_control\" >What metrics indicate an outreach program is under control?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-38\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Where_can_we_review_Heartbeatais_trust_approach\" >Where can we review Heartbeat.ai&#8217;s trust approach?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-39\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#Next_steps\" >Next steps<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-40\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#About_the_Author\" >About the Author<\/a><\/li><\/ul><\/nav><\/div>\r\n<h2><span class=\"ez-toc-section\" id=\"Who_this_is_for\"><\/span>Who this is for<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This page is written for procurement, compliance, and security reviewers who need a clean way to evaluate recruiting outreach data and tools \u2014 especially when the question on the table is: &#8220;Is this HIPAA?&#8221;<\/p>\n<p>For Heartbeat.ai&#8217;s recruiting use case, we handle no patient data. The practical review isn&#8217;t really about a HIPAA label at all \u2014 it&#8217;s about data scope, access controls, and outreach governance.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Quick_answer\"><\/span>Quick answer<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<dl>\n<dt>Core answer<\/dt>\n<dd>Recruiting contact data about providers is generally not patient PHI. HIPAA risk turns on whether patient-identifying health information is created, received, maintained, or transmitted \u2014 not on the fact that the contact happens to be a clinician.<\/dd>\n<dt>Key insight<\/dt>\n<dd>Procurement should verify data types, access controls, opt-out and suppression handling, and outreach compliance controls \u2014 then document the &#8220;no patient data&#8221; boundary in writing.<\/dd>\n<dt>Best for<\/dt>\n<dd>Procurement, compliance, and security reviewers approving recruiting outreach tools and data sources.<\/dd>\n<\/dl>\n<blockquote>\n<p><strong>Compliance &amp; safety<\/strong><\/p>\n<p>This method is for legitimate recruiting outreach only. Respect candidate privacy, opt-out requests, and local data laws. Heartbeat does not provide medical advice or legal counsel.<\/p>\n<\/blockquote>\n<h2><span class=\"ez-toc-section\" id=\"Answering_%E2%80%9Care_you_HIPAA_compliant%E2%80%9D_without_hand-waving\"><\/span>Answering &#8220;are you HIPAA compliant?&#8221; without hand-waving<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>When a reviewer asks that question, they&#8217;re usually trying to de-risk two separate things at once:<\/p>\n<ul>\n<li><strong>Data scope risk:<\/strong> Are you touching PHI (protected health information) or anything that could become PHI?<\/li>\n<li><strong>Operational risk:<\/strong> Even if it&#8217;s not PHI, are you running outreach in a way that creates regulatory, reputational, or deliverability problems?<\/li>\n<\/ul>\n<p>A procurement-ready way to handle this is to split it into four checks rather than one yes\/no answer:<\/p>\n<ol>\n<li><strong>What data is in scope?<\/strong> Provider recruiting contact data (business contact details, professional history) versus patient information.<\/li>\n<li><strong>What systems touch it?<\/strong> Where data is stored, who can access it, and how access is logged.<\/li>\n<li><strong>What is the intended use?<\/strong> Recruiting outreach to clinicians \u2014 not patient care, billing, or clinical operations.<\/li>\n<li><strong>What controls exist?<\/strong> Opt-out and suppression, consent signals where applicable, and auditability.<\/li>\n<\/ol>\n<h3><span class=\"ez-toc-section\" id=\"%E2%80%9CAre_you_a_covered_entity_or_business_associate%E2%80%9D\"><\/span>&#8220;Are you a covered entity or business associate?&#8221;<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>In a recruiting-only workflow built on provider contact data with no patient data involved, a vendor may not be acting as a HIPAA business associate at all, since no PHI is in the picture. That said, role and applicability are fact-specific. Procurement should have counsel confirm this based on the actual workflow and contract language rather than take a vendor&#8217;s self-description at face value.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Step-by-step_review_method\"><\/span>Step-by-step review method<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Step_1_Classify_the_data_youre_actually_using_field_by_field\"><\/span>Step 1: Classify the data you&#8217;re actually using, field by field<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Start by listing the exact fields your recruiting workflow touches. For clinician recruiting, that&#8217;s typically name, specialty, practice location, employer or affiliation, and professional contact channels.<\/p>\n<p>The useful distinction for reviewers:<\/p>\n<ul>\n<li><strong>Provider contact data:<\/strong> information used to reach a clinician about a job opportunity \u2014 work email, office phone, specialty. This is generally not patient PHI.<\/li>\n<li><strong>PHI:<\/strong> individually identifiable health information about a patient, tied to care or payment, as defined under HIPAA. For baseline definitions, see the <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/index.html\" target=\"_blank\" rel=\"noopener\">HHS HIPAA Privacy Rule overview<\/a>.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Step_2_Look_for_what_would_flip_this_into_a_HIPAA-scoped_workflow\"><\/span>Step 2: Look for what would flip this into a HIPAA-scoped workflow<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Ask explicitly whether any of the following are created, received, maintained, or transmitted in the recruiting workflow:<\/p>\n<ul>\n<li>Patient identifiers or patient-specific clinical details buried in notes, attachments, or messages.<\/li>\n<li>Patient referral details stored in a system of record.<\/li>\n<li>Scheduling or operational data that includes patient identifiers.<\/li>\n<li>Any integration pulling patient-related fields from clinical systems into recruiting tools.<\/li>\n<\/ul>\n<p>If any of these show up, that&#8217;s a different review path \u2014 bring in counsel and security early rather than trying to force it through the standard recruiting review.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Step_3_Get_the_%E2%80%9Cno_patient_data%E2%80%9D_boundary_in_writing\"><\/span>Step 3: Get the &#8220;no patient data&#8221; boundary in writing<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Ask the vendor, or your own internal team, to state plainly:<\/p>\n<ul>\n<li>We process no patient data for recruiting outreach.<\/li>\n<li>We do not request or ingest patient charts, claims, diagnoses, or patient identifiers.<\/li>\n<li>We do not use recruiting outreach to infer patient conditions.<\/li>\n<\/ul>\n<p>Also confirm what happens if a user pastes patient information into a free-text note or message. Look for acceptable-use rules, monitoring, and a way to remove the content once it&#8217;s flagged.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Step_4_Evaluate_outreach_compliance_controls_%E2%80%94_this_is_where_the_real_risk_lives\"><\/span>Step 4: Evaluate outreach compliance controls \u2014 this is where the real risk lives<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Most of the actual risk in recruiting outreach isn&#8217;t HIPAA at all \u2014 it&#8217;s communications compliance and brand risk: calling and texting rules, email rules, and how quickly opt-outs get honored.<\/p>\n<p>Verify:<\/p>\n<ul>\n<li><strong>Suppression\/opt-out:<\/strong> a durable &#8220;do not contact&#8221; mechanism that applies across campaigns and users, not just one recruiter&#8217;s list.<\/li>\n<li><strong>Source transparency:<\/strong> where contact data came from and how often it&#8217;s refreshed.<\/li>\n<li><strong>Auditability:<\/strong> who contacted whom, when, and through what channel.<\/li>\n<li><strong>Respectful messaging patterns:<\/strong> clear identification, stated purpose, and a clean exit path.<\/li>\n<\/ul>\n<p>The trade-off worth naming: tighter controls can reduce raw outreach volume in the short term, but they usually improve deliverability and connect rates while cutting the escalations that slow hiring down.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Step_5_Require_standard_metrics_not_vanity_numbers\"><\/span>Step 5: Require standard metrics, not vanity numbers<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Even a trust review should require basic measurement, using consistent definitions:<\/p>\n<ul>\n<li><strong>Connect rate<\/strong> = connected calls \/ total dials<\/li>\n<li><strong>Answer rate<\/strong> = human answers \/ connected calls<\/li>\n<li><strong>Deliverability rate<\/strong> = delivered emails \/ sent emails<\/li>\n<li><strong>Bounce rate<\/strong> = bounced emails \/ sent emails<\/li>\n<li><strong>Reply rate<\/strong> = replies \/ delivered emails<\/li>\n<\/ul>\n<p>In practice, this means requiring a weekly export or dashboard that breaks these down by channel, campaign, and sender identity, plus a log of opt-outs and complaints.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Step_6_What_to_actually_request_from_the_vendor\"><\/span>Step 6: What to actually request from the vendor<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>If you want a review that holds up later, ask for artifacts you can file, not just verbal assurances:<\/p>\n<ul>\n<li><strong>Data inventory:<\/strong> field list and purpose for each field used in recruiting outreach.<\/li>\n<li><strong>System touchpoints:<\/strong> where data is stored or processed and who has access.<\/li>\n<li><strong>Retention &amp; deletion:<\/strong> retention schedule and deletion mechanism.<\/li>\n<li><strong>Suppression proof:<\/strong> a sample suppression export plus a documented test showing suppression actually propagates across users and campaigns.<\/li>\n<li><strong>Audit log sample:<\/strong> a redacted outreach event export (who, when, channel) and an opt-out log export.<\/li>\n<li><strong>Acceptable-use policy:<\/strong> including an explicit prohibition on uploading patient information.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"Diagnostic_table\"><\/span>Diagnostic table<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>Visual note:<\/strong> use this as a do\/don&#8217;t reference during procurement review.<\/p>\n<div class=\"table-scroll\" style=\"overflow:auto;-webkit-overflow-scrolling:touch;width:100%\">\n<table class=\"separated-content\">\n<thead>\n<tr>\n<th>Question procurement asks<\/th>\n<th>What &#8220;good&#8221; looks like<\/th>\n<th>Red flags<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Are you handling PHI under HIPAA?<\/td>\n<td>Vendor states recruiting workflow uses provider contact data and no patient data; scope is documented; escalation path if PHI is accidentally introduced.<\/td>\n<td>Vague &#8220;yes we&#8217;re HIPAA&#8221; marketing language without defining data scope; inability to describe what data is stored.<\/td>\n<\/tr>\n<tr>\n<td>Are you a covered entity or business associate in this use case?<\/td>\n<td>Vendor explains role based on workflow boundaries and contracts; procurement confirms with counsel; no PHI in recruiting-only scope.<\/td>\n<td>Overconfident blanket statements; refusal to describe data flows.<\/td>\n<\/tr>\n<tr>\n<td>What data fields are stored?<\/td>\n<td>Clear list of fields; purpose limitation (recruiting outreach); retention and deletion policy.<\/td>\n<td>&#8220;We store whatever users upload&#8221; with no controls; no retention policy.<\/td>\n<\/tr>\n<tr>\n<td>How do you handle opt-outs and stop requests?<\/td>\n<td>Central suppression list; immediate enforcement across users; documented workflow for &#8220;stop&#8221; requests.<\/td>\n<td>Opt-outs handled per-user only; delays; no audit trail.<\/td>\n<\/tr>\n<tr>\n<td>How do you reduce spam\/harassment risk?<\/td>\n<td>Respectful language patterns; frequency caps; identity disclosure; easy exit; escalation for complaints.<\/td>\n<td>Encouraging repeated contact after a clear &#8220;stop&#8221;; no frequency controls.<\/td>\n<\/tr>\n<tr>\n<td>How do you prove outreach quality?<\/td>\n<td>Metrics tracked with standard definitions (connect\/answer\/deliverability\/bounce\/reply) and reviewed regularly.<\/td>\n<td>No measurement; only vanity metrics like &#8220;emails sent.&#8221;<\/td>\n<\/tr>\n<tr>\n<td>What&#8217;s the differentiator for reaching clinicians?<\/td>\n<td>Operationally: better routing and prioritization (e.g., Heartbeat.ai has ranked mobile numbers by answer probability).<\/td>\n<td>Claims of guaranteed reach or implied harassment enablement.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2><span class=\"ez-toc-section\" id=\"Weighted_checklist\"><\/span>Weighted checklist<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Use this as a scoring sheet during vendor review. Total 100 points.<\/p>\n<ul>\n<li><strong>(25) Data scope clarity:<\/strong> written statement of provider contact data versus PHI; explicit no patient data boundary; documented handling if PHI is accidentally introduced.<\/li>\n<li><strong>(20) Opt-out &amp; suppression:<\/strong> central suppression list; applies across channels; immediate enforcement; exportable audit log.<\/li>\n<li><strong>(15) Outreach governance:<\/strong> frequency caps; role-based access; campaign approvals; complaint handling.<\/li>\n<li><strong>(15) Measurement &amp; reporting:<\/strong> connect rate, answer rate, deliverability rate, bounce rate, and reply rate tracked with denominators and trend lines.<\/li>\n<li><strong>(10) Source transparency:<\/strong> data provenance; refresh cadence; correction process.<\/li>\n<li><strong>(10) Security basics:<\/strong> access controls, logging, and incident response contacts.<\/li>\n<li><strong>(5) Documentation quality:<\/strong> clear acceptable-use policy and reviewer-ready answers.<\/li>\n<\/ul>\n<p>A useful rule of thumb: if a tool scores low on suppression and opt-out handling, it will create downstream risk regardless of whether HIPAA technically applies.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Outreach_templates\"><\/span>Outreach templates<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>Visual note:<\/strong> use these as examples of respectful language that reduce complaints and make &#8220;stop&#8221; handling unambiguous.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Email_template_first_touch\"><\/span>Email template (first touch)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>Subject:<\/strong> Quick question about your next role<\/p>\n<p><strong>Body:<\/strong> Hi Dr. [Last Name] \u2014 I recruit physicians in [Specialty\/Service Line]. Are you open to hearing about a [Role Type] opportunity in [Location\/Health System]? If not, reply &#8220;no&#8221; and I won&#8217;t follow up.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Text_template_only_where_appropriate_for_your_program\"><\/span>Text template (only where appropriate for your program)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Hi Dr. [Last Name] \u2014 this is [Name] recruiting for [Org]. Are you open to a quick call about a [Role] in [Location]? Reply STOP to opt out.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Voicemail_template\"><\/span>Voicemail template<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Hi Dr. [Last Name], this is [Name] with [Org]. I&#8217;m calling about a [Role] opportunity in [Location]. If you&#8217;re not interested, no problem \u2014 tell me and I&#8217;ll close the loop. My number is [Callback].<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Stop-request_handling_flow\"><\/span>Stop-request handling flow<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>Visual note:<\/strong> this is the minimum flow procurement should require from any recruiting outreach tool.<\/p>\n<ol>\n<li><strong>Candidate says &#8220;stop&#8221; (any channel):<\/strong> treat it as an opt-out request immediately.<\/li>\n<li><strong>Confirm once:<\/strong> &#8220;Understood \u2014 I&#8217;ll mark you as do-not-contact. If you ever want to reconnect, you can reply anytime.&#8221;<\/li>\n<li><strong>Suppress:<\/strong> add to a central suppression list (email and phone) tied to the identity, not just the campaign.<\/li>\n<li><strong>Propagate:<\/strong> make sure suppression applies across all users, teams, and future sequences.<\/li>\n<li><strong>Log:<\/strong> record timestamp, channel, and who processed it for audit.<\/li>\n<li><strong>Review:<\/strong> if the stop came with a complaint, check the prior touches for frequency and tone, and adjust templates and caps accordingly.<\/li>\n<\/ol>\n<h2><span class=\"ez-toc-section\" id=\"Common_pitfalls\"><\/span>Common pitfalls<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"1_Treating_%E2%80%9CHIPAA%E2%80%9D_as_a_checkbox_instead_of_scoping_the_data\"><\/span>1) Treating &#8220;HIPAA&#8221; as a checkbox instead of scoping the data<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Reviews go sideways when teams argue over labels instead of listing data fields and system boundaries. Start with what data is stored, where, and why.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"2_Letting_users_paste_sensitive_information_into_free-text_fields\"><\/span>2) Letting users paste sensitive information into free-text fields<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Even with recruiting-only intent, free-text notes can accidentally capture sensitive details. Require acceptable-use rules, training, and a removal or escalation path.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"3_Weak_opt-out_handling\"><\/span>3) Weak opt-out handling<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>If a clinician says &#8220;stop&#8221; and gets contacted again, that&#8217;s a reputational incident, not a technicality. Central suppression and audit logs aren&#8217;t optional.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"4_Measuring_the_wrong_things\"><\/span>4) Measuring the wrong things<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>&#8220;Emails sent&#8221; is not a control metric. Require deliverability, bounce, and reply rates with denominators, and review trends by sender and campaign.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_to_improve_results\"><\/span>How to improve results<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Improvement here means fewer complaints, better reach, and faster recruiter throughput \u2014 without increasing risk.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"1_Fix_suppression_before_scaling_volume\"><\/span>1) Fix suppression before scaling volume<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Before expanding outreach, confirm suppression works across channels and users. Tie it to the person, not just the contact point, and keep it exportable for audits.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"2_Standardize_measurement_and_review_cadence\"><\/span>2) Standardize measurement and review cadence<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li>Track deliverability rate weekly by sender domain and campaign.<\/li>\n<li>Track bounce rate weekly and investigate spikes immediately.<\/li>\n<li>Track reply rate by template; retire templates that drive negative replies.<\/li>\n<li>Track connect rate and answer rate by time-of-day and number type.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"3_Practice_data_minimization\"><\/span>3) Practice data minimization<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li>Keep recruiting contact fields and outreach logs; avoid collecting unrelated sensitive details.<\/li>\n<li>Limit free-text fields or enforce acceptable-use rules so patient information never enters the system.<\/li>\n<li>Prefer centralized suppression over scattered notes that are hard to audit.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"4_Use_language_patterns_that_reduce_complaints\"><\/span>4) Use language patterns that reduce complaints<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Make the exit path explicit (&#8220;reply no,&#8221; &#8220;reply STOP&#8221;), identify yourself and the organization, and avoid repeated follow-ups after a clear decline.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"5_Match_controls_to_how_recruiters_actually_work\"><\/span>5) Match controls to how recruiters actually work<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Controls shouldn&#8217;t push recruiters into shadow tools. If the approved system makes opt-outs hard, people will route around it \u2014 so make the compliant path the easiest one.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Legal_and_ethical_use\"><\/span>Legal and ethical use<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Whether HIPAA applies depends on facts and roles \u2014 for example, covered entity or business associate status \u2014 and how data is handled. For HIPAA basics, see the <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/index.html\" target=\"_blank\" rel=\"noopener\">HHS HIPAA Privacy Rule overview<\/a> and confirm applicability with your counsel.<\/p>\n<p>Separately, recruiting outreach must follow applicable communications and privacy rules. Two references procurement teams commonly review:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.fcc.gov\/general\/telephone-consumer-protection-act-1991-tcpa\" target=\"_blank\" rel=\"noopener\">FCC overview of the Telephone Consumer Protection Act (TCPA)<\/a><\/li>\n<li><a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/can-spam-act-compliance-guide-business\" target=\"_blank\" rel=\"noopener\">FTC CAN-SPAM Act compliance guide<\/a><\/li>\n<\/ul>\n<p>Ethically: don&#8217;t pressure clinicians, don&#8217;t misrepresent identity, and honor opt-outs immediately. Build systems that prevent repeat contact after a stop request.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Evidence_and_trust_notes\"><\/span>Evidence and trust notes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Heartbeat.ai publishes how we think about trust, sourcing quality, and reviewable claims here: <a href=\"http:\/\/heartbeat.ai\/resources\/resources\/trust-methodology\/\">Trust methodology<\/a>. If you&#8217;re running a vendor assessment, start there and map it to your internal controls.<\/p>\n<p>External references commonly used in procurement reviews:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.fcc.gov\/general\/telephone-consumer-protection-act-1991-tcpa\" target=\"_blank\" rel=\"noopener\">FCC: TCPA overview<\/a><\/li>\n<li><a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/can-spam-act-compliance-guide-business\" target=\"_blank\" rel=\"noopener\">FTC: CAN-SPAM compliance guide<\/a><\/li>\n<\/ul>\n<p>Related internal resources worth including in the same review packet:<\/p>\n<ul>\n<li><a href=\"http:\/\/heartbeat.ai\/resources\/resources\/trust-methodology\/data-ethics-acceptable-use\/\">Data ethics and acceptable use policy<\/a><\/li>\n<li><a href=\"http:\/\/heartbeat.ai\/resources\/resources\/recruiting-compliance\/\">Recruiting compliance overview for outreach programs<\/a><\/li>\n<li><a href=\"http:\/\/heartbeat.ai\/resources\/resources\/company\/contact\/\">Contact Heartbeat.ai for security\/procurement review<\/a><\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"FAQs\"><\/span>FAQs<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Does_recruiting_outreach_involve_PHI\"><\/span>Does recruiting outreach involve PHI?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Often, no. Recruiting outreach typically uses provider contact data \u2014 professional identifiers and contact channels. PHI is individually identifiable health information about a patient, connected to care or payment. Confirm your exact data fields and workflow with counsel.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_should_procurement_ask_a_recruiting_data_vendor_to_provide\"><\/span>What should procurement ask a recruiting data vendor to provide?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Request a field-level data inventory, system touchpoints, retention\/deletion approach, suppression\/opt-out workflow with export, and audit logs for outreach and opt-outs.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_would_make_a_recruiting_workflow_higher_risk_under_HIPAA\"><\/span>What would make a recruiting workflow higher risk under HIPAA?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>If patient identifiers or patient-specific clinical details enter the workflow \u2014 for example in notes, attachments, or integrations pulling patient fields \u2014 treat it as a different review path and involve counsel and security early.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"How_should_we_handle_%E2%80%9CSTOP%E2%80%9D_requests_from_clinicians\"><\/span>How should we handle &#8220;STOP&#8221; requests from clinicians?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Process immediately, confirm once, add the person to a central suppression list across channels, propagate to all users and campaigns, and log the action for audit. Do not continue outreach after a clear stop.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_metrics_indicate_an_outreach_program_is_under_control\"><\/span>What metrics indicate an outreach program is under control?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>At minimum: deliverability rate (delivered\/sent), bounce rate (bounced\/sent), reply rate (replies\/delivered), connect rate (connected\/total dials), and answer rate (human answers\/connected calls), each reported with denominators and trends.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Where_can_we_review_Heartbeatais_trust_approach\"><\/span>Where can we review Heartbeat.ai&#8217;s trust approach?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Start with our <a href=\"http:\/\/heartbeat.ai\/resources\/resources\/trust-methodology\/\">trust methodology<\/a>, then review our <a href=\"http:\/\/heartbeat.ai\/resources\/resources\/trust-methodology\/data-ethics-acceptable-use\/\">acceptable use<\/a> policy and your internal outreach compliance requirements.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Next_steps\"><\/span>Next steps<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li>If you&#8217;re in procurement: use the diagnostic table and weighted checklist above as your review worksheet.<\/li>\n<li>Draft your approval memo using data inventory, system touchpoints, retention\/deletion policy, and suppression plus audit log exports.<\/li>\n<li>For policy alignment, read <a href=\"http:\/\/heartbeat.ai\/resources\/resources\/trust-methodology\/data-ethics-acceptable-use\/\">data ethics and acceptable use<\/a> and <a href=\"http:\/\/heartbeat.ai\/resources\/resources\/recruiting-compliance\/\">recruiting compliance<\/a>.<\/li>\n<li>To evaluate Heartbeat.ai in your workflow: <a href=\"https:\/\/heartbeat.ai\/signup\" target=\"_blank\" rel=\"noopener\">create an account to review the product<\/a> or route questions through <a href=\"http:\/\/heartbeat.ai\/resources\/resources\/company\/contact\/\">our contact page<\/a>.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"About_the_Author\"><\/span><b>About the Author<\/b><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><a href=\"http:\/\/heartbeat.ai\/resources\/author\/ben-argeband\"><span style=\"font-weight: 400;\">Ben Argeband<\/span><\/a><span style=\"font-weight: 400;\"> is the Founder and CEO of Swordfish.ai and Heartbeat.ai. With deep expertise in data and SaaS, he has built two successful platforms trusted by over 50,000 sales and recruitment professionals. Ben&#8217;s mission is to help teams find direct contact information for hard-to-reach professionals and decision-makers, providing the shortest route to their next win. Connect with Ben on <\/span><a href=\"https:\/\/www.linkedin.com\/in\/ben-m-argeband-2427a8a3\/\"><span style=\"font-weight: 400;\">LinkedIn<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><br \/>\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"Article\",\"about\":[{\"@type\":\"Thing\",\"name\":\"HIPAA\"},{\"@type\":\"Thing\",\"name\":\"PHI\"},{\"@type\":\"Thing\",\"name\":\"HHS\"}],\"author\":{\"@type\":\"Person\",\"jobTitle\":\"Founder & CEO of Heartbeat.ai\",\"name\":\"Ben Argeband\"},\"headline\":\"HIPAA and recruiting contact data\",\"isPartOf\":{\"@type\":\"WebSite\",\"name\":\"Heartbeat.ai\",\"url\":\"https:\/\/heartbeat.ai\"},\"mainEntityOfPage\":{\"@id\":\"https:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/\",\"@type\":\"WebPage\"},\"publisher\":{\"@type\":\"Organization\",\"name\":\"Heartbeat.ai\"}}<\/script><\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Often, no. Recruiting outreach typically uses provider contact data (professional identifiers and contact channels). PHI is individually identifiable health information about a patient, in connection with care or payment. Confirm your exact data fields and workflow with counsel.\"},\"name\":\"Does recruiting outreach involve PHI?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Request a field-level data inventory, system touchpoints, retention\/deletion approach, suppression\/opt-out workflow (with export), and audit logs for outreach and opt-outs.\"},\"name\":\"What should procurement ask a recruiting data vendor to provide?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"If patient identifiers or patient-specific clinical details enter the workflow (for example, in notes, attachments, or integrations pulling patient fields), treat it as a different review path and involve counsel and security early.\"},\"name\":\"What would make a recruiting workflow higher risk under HIPAA?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Process immediately, confirm once, add the person to a central suppression list across channels, propagate to all users\/campaigns, and log the action for audit. Do not continue outreach after a clear stop.\"},\"name\":\"How should we handle \\\"STOP\\\" requests from clinicians?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"At minimum: Deliverability Rate (delivered\/sent), Bounce Rate (bounced\/sent), Reply Rate (replies\/delivered), Connect Rate (connected\/total dials), and Answer Rate (human answers\/connected calls), each reported with denominators and trends.\"},\"name\":\"What metrics indicate an outreach program is under control?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Start with our trust methodology, then review our acceptable use and your internal outreach compliance requirements.\"},\"name\":\"Where can we review Heartbeat.ai's trust approach?\"}]}<\/script><\/p>","protected":false},"excerpt":{"rendered":"<p>Procurement-ready guidance on HIPAA and recruiting contact data: scope the no-patient-data boundary and verify opt-out, audit, and outreach controls.<\/p>","protected":false},"author":5,"featured_media":54164,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_custom_permalink":"trust-methodology\/not-hipaa-no-patient-data","footnotes":""},"categories":[1],"tags":[],"class_list":["post-54165","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\r\n<title>HIPAA and recruiting contact data: procurement clarification | Heartbeat.ai<\/title>\r\n<meta name=\"description\" content=\"Procurement-focused guidance on HIPAA and recruiting contact data: provider contact info vs PHI, no patient data boundary, opt-out handling, audit logs, and outreach compliance controls.\" \/>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_US\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"HIPAA and recruiting contact data: procurement clarification | Heartbeat.ai\" \/>\r\n<meta property=\"og:description\" content=\"Procurement-focused guidance on HIPAA and recruiting contact data: provider contact info vs PHI, no patient data boundary, opt-out handling, audit logs, and outreach compliance controls.\" \/>\r\n<meta property=\"og:url\" content=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/\" \/>\r\n<meta property=\"og:site_name\" content=\"Heartbeat.ai\" \/>\r\n<meta property=\"article:published_time\" content=\"2026-02-01T18:29:58+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2026-08-29T12:04:43+00:00\" \/>\r\n<meta property=\"og:image\" content=\"https:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/not-hipaa-no-patient-data-3aa05bdd.png\" \/>\r\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\r\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\r\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\r\n<meta name=\"author\" content=\"Ben Argeband\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Argeband\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/#article\",\"isPartOf\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/\"},\"author\":{\"name\":\"Ben Argeband\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#\\\/schema\\\/person\\\/7b323ddce9b211907423482e2f9db173\"},\"headline\":\"HIPAA and recruiting contact data: what procurement should verify (no patient data)\",\"datePublished\":\"2026-02-01T18:29:58+00:00\",\"dateModified\":\"2026-08-29T12:04:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/\"},\"wordCount\":2504,\"commentCount\":0,\"publisher\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#organization\"},\"image\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/not-hipaa-no-patient-data-3aa05bdd.png\",\"articleSection\":[\"News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/\",\"url\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/\",\"name\":\"HIPAA and recruiting contact data: procurement clarification | Heartbeat.ai\",\"isPartOf\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/#primaryimage\"},\"image\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/not-hipaa-no-patient-data-3aa05bdd.png\",\"datePublished\":\"2026-02-01T18:29:58+00:00\",\"dateModified\":\"2026-08-29T12:04:43+00:00\",\"description\":\"Procurement-focused guidance on HIPAA and recruiting contact data: provider contact info vs PHI, no patient data boundary, opt-out handling, audit logs, and outreach compliance controls.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/#primaryimage\",\"url\":\"http:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/not-hipaa-no-patient-data-3aa05bdd.png\",\"contentUrl\":\"http:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/not-hipaa-no-patient-data-3aa05bdd.png\",\"width\":1024,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/not-hipaa-no-patient-data\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HIPAA and recruiting contact data: what procurement should verify (no patient data)\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#website\",\"url\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/\",\"name\":\"Heartbeat.ai\",\"description\":\"\",\"publisher\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#organization\",\"name\":\"Heartbeat.ai\",\"url\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/Heartbeat.ai-logo.png\",\"contentUrl\":\"https:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/Heartbeat.ai-logo.png\",\"width\":704,\"height\":126,\"caption\":\"Heartbeat.ai\"},\"image\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#\\\/schema\\\/person\\\/7b323ddce9b211907423482e2f9db173\",\"name\":\"Ben Argeband\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g\",\"caption\":\"Ben Argeband\"},\"url\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/author\\\/ben-argeband\\\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HIPAA and recruiting contact data: procurement clarification | Heartbeat.ai","description":"Procurement-focused guidance on HIPAA and recruiting contact data: provider contact info vs PHI, no patient data boundary, opt-out handling, audit logs, and outreach compliance controls.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/","og_locale":"en_US","og_type":"article","og_title":"HIPAA and recruiting contact data: procurement clarification | Heartbeat.ai","og_description":"Procurement-focused guidance on HIPAA and recruiting contact data: provider contact info vs PHI, no patient data boundary, opt-out handling, audit logs, and outreach compliance controls.","og_url":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/","og_site_name":"Heartbeat.ai","article_published_time":"2026-02-01T18:29:58+00:00","article_modified_time":"2026-08-29T12:04:43+00:00","og_image":[{"width":1024,"height":1024,"url":"https:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/not-hipaa-no-patient-data-3aa05bdd.png","type":"image\/png"}],"author":"Ben Argeband","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ben Argeband","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#article","isPartOf":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/"},"author":{"name":"Ben Argeband","@id":"http:\/\/heartbeat.ai\/resources\/#\/schema\/person\/7b323ddce9b211907423482e2f9db173"},"headline":"HIPAA and recruiting contact data: what procurement should verify (no patient data)","datePublished":"2026-02-01T18:29:58+00:00","dateModified":"2026-08-29T12:04:43+00:00","mainEntityOfPage":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/"},"wordCount":2504,"commentCount":0,"publisher":{"@id":"http:\/\/heartbeat.ai\/resources\/#organization"},"image":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#primaryimage"},"thumbnailUrl":"http:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/not-hipaa-no-patient-data-3aa05bdd.png","articleSection":["News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#respond"]}]},{"@type":"WebPage","@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/","url":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/","name":"HIPAA and recruiting contact data: procurement clarification | Heartbeat.ai","isPartOf":{"@id":"http:\/\/heartbeat.ai\/resources\/#website"},"primaryImageOfPage":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#primaryimage"},"image":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#primaryimage"},"thumbnailUrl":"http:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/not-hipaa-no-patient-data-3aa05bdd.png","datePublished":"2026-02-01T18:29:58+00:00","dateModified":"2026-08-29T12:04:43+00:00","description":"Procurement-focused guidance on HIPAA and recruiting contact data: provider contact info vs PHI, no patient data boundary, opt-out handling, audit logs, and outreach compliance controls.","breadcrumb":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#primaryimage","url":"http:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/not-hipaa-no-patient-data-3aa05bdd.png","contentUrl":"http:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/not-hipaa-no-patient-data-3aa05bdd.png","width":1024,"height":1024},{"@type":"BreadcrumbList","@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/not-hipaa-no-patient-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/heartbeat.ai\/resources\/"},{"@type":"ListItem","position":2,"name":"HIPAA and recruiting contact data: what procurement should verify (no patient data)"}]},{"@type":"WebSite","@id":"http:\/\/heartbeat.ai\/resources\/#website","url":"http:\/\/heartbeat.ai\/resources\/","name":"Heartbeat.ai","description":"","publisher":{"@id":"http:\/\/heartbeat.ai\/resources\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/heartbeat.ai\/resources\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"http:\/\/heartbeat.ai\/resources\/#organization","name":"Heartbeat.ai","url":"http:\/\/heartbeat.ai\/resources\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/heartbeat.ai\/resources\/#\/schema\/logo\/image\/","url":"https:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2021\/04\/Heartbeat.ai-logo.png","contentUrl":"https:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2021\/04\/Heartbeat.ai-logo.png","width":704,"height":126,"caption":"Heartbeat.ai"},"image":{"@id":"http:\/\/heartbeat.ai\/resources\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"http:\/\/heartbeat.ai\/resources\/#\/schema\/person\/7b323ddce9b211907423482e2f9db173","name":"Ben Argeband","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g","caption":"Ben Argeband"},"url":"http:\/\/heartbeat.ai\/resources\/author\/ben-argeband\/"}]}},"_links":{"self":[{"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/posts\/54165","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/comments?post=54165"}],"version-history":[{"count":2,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/posts\/54165\/revisions"}],"predecessor-version":[{"id":65687,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/posts\/54165\/revisions\/65687"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/media\/54164"}],"wp:attachment":[{"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/media?parent=54165"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/categories?post=54165"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/tags?post=54165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}