Dental Call Tracking: What You Can Record
What dental practices may legally record on tracked calls, how two-party consent states change the rules, why transcripts are PHI, and what may reach an ad platform.
A dental practice can record and transcribe patient calls, but only inside systems covered by a Business Associate Agreement, only with the consent the caller's state requires, and never in a form that reaches an ad platform, and Curve is the HIPAA-compliant tracking layer that keeps the attribution signal flowing outward while the recording stays behind. Two constraints stack here and practices usually only think about one. State wiretap law governs whether you may record at all. HIPAA governs what happens to the recording afterward. Curve includes a signed BAA on every plan.
Two separate legal questions, constantly confused
When a dental practice asks whether it can record calls, it is really asking two questions with different answers and different consequences.
The first is a wiretap question. Every state has a law about recording a conversation, and it has nothing to do with healthcare. Violating it is a criminal and civil matter under state law, and it applies identically to a pizza shop.
The second is a HIPAA question. A recording of a patient describing a broken molar and asking about sedation options is protected health information the moment it exists. Where it is stored, who processes it, and whether that vendor signed a BAA are all now in scope.
A practice can be fully compliant on the first question and badly exposed on the second. That is the common shape of the problem: the front desk plays a recording disclosure, everybody feels covered, and the recordings sit in a call tracking platform that never signed anything.
One-party and two-party consent, and why it matters more for dental
Most states are one-party consent jurisdictions. If one participant in the call consents, the recording is lawful, and the practice is a participant, so it may record.
A meaningful minority require all-party consent. California, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, and Washington are the states most commonly cited in this group, and the specifics vary. In those states every participant must consent before recording begins.
Dental practices hit this harder than most healthcare businesses for a structural reason: they advertise locally and receive calls from people who are physically nearby but not necessarily in the same state. A practice in a border metro area takes calls from two or three jurisdictions on a normal Tuesday. A group practice with locations across state lines has multiple rule sets running against one phone system.
And when the caller and the practice are in different states, both states' rules may be in play. The conservative and generally recommended approach is to apply all-party consent everywhere. Announce the recording, announce it before anything substantive is said, and let it stand as the practice's uniform policy. It is simpler than routing by area code and it does not break when someone calls from a mobile number with an out of state prefix.
What a usable disclosure looks like
Three properties matter more than the wording.
- It plays before the conversation starts, not after the caller has already described their symptoms to a receptionist.
- It is unambiguous. "This call may be monitored or recorded" is standard language and is generally treated as sufficient notice, with continuing the call treated as consent.
- It is logged. If you cannot demonstrate the disclosure played on a given call, you cannot demonstrate consent for that call.
Also worth stating plainly: a caller who objects should be able to continue without being recorded. A practice with no path to a non-recorded line has a policy that only works until the first person says no.
Transcripts are PHI, and they are worse than recordings
Practices tend to treat transcripts as a lighter version of a recording. They are the opposite.
An audio file is a blob. It is hard to search, hard to index, and hard to accidentally pipe into another system. A transcript is text. It is searchable, indexable, and trivially forwarded. It flows into CRMs, into automation platforms, into spreadsheets, into help desk tickets, into email.
A dental call transcript routinely contains the caller's name, phone number, the reason for calling, a description of pain or a visible problem, insurance details, and the appointment made. That is a compact PHI record with excellent metadata. When a call tracking platform's AI features summarize it, tag it, or score it for intent, that processing is another handling of PHI by another system.
The practical rule: wherever transcripts and call summaries land, that system needs to be BAA-covered and treated as a clinical system, not a marketing convenience.
The AI features question
Modern call tracking platforms offer automated transcription, sentiment scoring, keyword spotting, and lead qualification. These are genuinely useful for a dental front desk, and they are also the fastest way to move PHI into a subprocessor nobody evaluated.
Before enabling any of it, ask three things. Does the vendor sign a BAA that covers this specific feature and not just call storage? Which subprocessors perform the processing, and are they covered? Is the transcript retained by the AI provider for model training, and can that be turned off in writing?
A vendor that signs a BAA for call recording but routes transcription through an uncovered third party model provider has a gap, and it is your gap, not theirs.
What may actually reach an ad platform
This is where the marketing side of the question lives, and the answer is narrow.
What can go outward: that a call happened, that it lasted long enough to count as a qualified call, that it converted into a booked appointment, a hashed contact identifier, and the click ID that produced the call. That set is enough to optimize a campaign properly.
What cannot go outward: the recording, the transcript, any summary of the transcript, keyword tags derived from the call, the stated reason for calling, and any conversion name that encodes the procedure discussed. An event called "emergency_extraction_call" that reaches Meta with a hashed email attached has disclosed the caller's clinical situation as surely as sending the audio would have.
Neither Meta nor Google signs a BAA for its advertising products. There is no configuration inside those platforms that makes them a lawful recipient of call content. The control has to sit upstream, before the data leaves your infrastructure.
The keyword-triggered conversion trap
Call tracking platforms let you fire a conversion when a transcript contains certain words. Set up naively, this creates an event whose very existence encodes clinical content. If your platform fires "high_value_call" only when the transcript mentions implants, then every one of those events tells the ad platform something about the caller.
The fix is not to abandon keyword scoring. It is to let the scoring happen inside the BAA-covered system and forward only a neutral, generic conversion outward. Your reporting can distinguish call types. The ad platform receives a name that means nothing on its own.
How Curve handles call attribution without moving call content
Curve is HIPAA-compliant ad tracking, attribution, and analytics for healthcare, and call-heavy verticals like dental are a core use case. The architecture puts a server-side layer between your site and the ad platforms, which is what makes the split above enforceable rather than aspirational.
- Click ID capture at landing. The
gclid,fbclid, andmsclkidare captured when the visitor arrives and stored server-side, so a call that happens ten minutes later can still be tied back to the campaign that caused it. - Inbound webhook matching. Call tracking platforms post call outcomes back into Curve, matched by email, click ID, or bridge token. Incoming data cannot override protected core attribution and contact fields, so a misconfigured call platform cannot corrupt your attribution.
- Per-destination field mapping. Only explicitly mapped fields forward to a given destination. Default is that nothing goes. Transcript text, call notes, and keyword tags arriving on a webhook do not reach Meta or Google unless someone deliberately maps them, and they should not be mapped.
- Neutral event aliases. Your internal reporting can call it what it is. The ad platform sees a neutral name with no clinical content.
- SHA-256 identifier hashing. Caller phone and email are hashed per each platform's conversion API requirements before forwarding.
- PHI-pattern detection. Payloads containing PHI-shaped values get flagged as a monitoring signal. This is how you discover that a call platform integration started including a summary field after a vendor update.
- Offline conversion uploads. Calls that turn into attended appointments days later can be uploaded in bulk with click ID matching, so the campaign gets credit for the outcome rather than just the ring.
CallRail connects to Curve as an inbound webhook connector rather than as a forwarding destination, which is the correct direction of flow: call data comes in for attribution, and only neutral conversions go out. A signed BAA is included on every plan. For the wider picture, see HIPAA-compliant lead routing from ad click to CRM and the DSO marketing technology stack.
A retention policy you can defend
Recordings and transcripts accumulate silently, and most practices have years of them without an intentional decision.
Set a retention window and enforce it in the platform's settings rather than in a document. Ninety days covers dispute resolution and quality review for most practices. Longer windows need a stated reason, because every additional month is additional breach surface holding nothing but downside.
Restrict access by role. The marketing agency reviewing call quality does not need the audio; it needs call duration, source, and outcome. If your agency currently has a login that plays recordings, that agency is handling PHI and needs a BAA with you.
And write down where transcripts go. In most practices the surprising answer is "four places," and two of them were never evaluated.
Frequently asked questions
Do we need to announce recording in a one-party consent state?
Legally, usually not, since the practice is a party to the call. Practically, announce it anyway. You cannot reliably tell where a mobile caller is physically located, and a uniform disclosure removes the question entirely.
Is a call recording PHI even if no diagnosis is discussed?
Generally yes. A recording that identifies a caller and relates to their seeking care from a dental provider is health information. The topic does not have to be clinical for the fact of seeking treatment to be protected.
Can we send call duration to Google Ads?
Yes. Duration is a behavioral signal, not clinical content, and duration-qualified calls are a legitimate conversion type. Send it as a neutral conversion with a hashed identifier and the click ID.
Does our call tracking vendor need a BAA?
If it records, stores, or transcribes patient calls, yes. It is handling PHI on your behalf, which makes it a business associate regardless of how it markets itself.
What about calls that come from Google Business Profile rather than ads?
Track them, but report them as a separate local presence channel rather than folding them into paid performance. Mixing organic map calls into paid attribution inflates the paid numbers and hides what the ads actually produced.
Can we use AI call scoring to route leads?
Yes, inside BAA-covered systems. The scoring output can drive internal routing and internal reporting. What must not happen is the score, or a conversion event whose name reflects the score's clinical basis, traveling to an ad platform.
What is the minimum viable compliant setup?
A disclosure that plays before conversation, a BAA with the call platform, a defined retention window, transcripts confined to covered systems, and a server-side path that forwards only neutral conversions with hashed identifiers to ad platforms.
Where to start
Audit what you have before changing anything. List every system that currently holds call audio or transcripts, including the ones a previous agency set up. For each, confirm whether a BAA exists and what its retention setting is. That inventory usually produces at least one surprise.
Then fix the outbound side. Curve gives you the pipeline: click ID capture at landing, inbound webhooks that match call outcomes to campaigns, per-destination field mapping so nothing forwards unless mapped, neutral event aliases, SHA-256 hashed identifiers, PHI-pattern monitoring, offline uploads for calls that convert later, and a signed BAA on every plan.
Run the free compliance scanner against your practice site, review the dental marketing compliance checklist, or visit curvecompliance.com to work through your call attribution setup.
Reviewed August 2026. State recording laws, ad platform conversion APIs, and healthcare advertising policies change frequently. Verify current requirements with counsel before implementation.
Related articles
- GuideDental Practice Facebook Ads After Meta 2026 Restrictions: What DSOs and Solo Dentists Can Still Do
- GuideIs Hotjar HIPAA Compliant? Session Recording Risks That Could Cost Your Practice Millions
- GuideIs CallRail HIPAA Compliant? Call Tracking Rules for Medical Practices
- GuideGoogle Ads Call Tracking for Medical Practices: HIPAA-Compliant Phone Attribution
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit