Configuration Guide

The CTM HIPAA compliance checklist for treatment centers

CallTrackingMetrics can be run HIPAA-compliant. Most treatment center accounts are not, because compliance is eleven settings, a BAA, and a discipline about where PHI travels. Here is the full configuration, as an official CTM Partner sets it up.

Written by Jim Malcom, Founder, Crucial Consultants · Updated September 2026

Short answer: To run CallTrackingMetrics HIPAA-compliant at a treatment center you need an eligible plan, a signed Business Associate Agreement, HIPAA-eligible tracking numbers, individual logins with 15-minute idle logout and two-factor authentication, login-gated and encrypted call recordings, secure transcriptions with automatic redaction, and a hard rule that PHI never leaves CTM through notifications, text messages, exports, or non-compliant integrations. Seven requirements, four recommendations, one BAA.

Why this matters in admissions

Every admissions call is PHI.

A caller telling your coordinator their name, their insurance, and that they relapsed last night is protected health information the moment it is recorded, transcribed, or logged. Call tracking captures all three. That places CTM squarely inside your HIPAA obligations, and CTM is explicit that its use in healthcare is administrative use of PHI requiring a Business Associate Agreement.

The good news: CTM built the controls. Encryption in transit and at rest, access logging by user and IP, dedicated servers for PHI-handling components, secure notifications, and redaction are all available. The bad news: none of it is on by default, and the failure pattern we see on audits is not a missing feature, it is a marketing agency that bought numbers, turned on recording, and never opened the security tab.

Requirements

The seven non-negotiables.

SettingWhat to configureWhy it matters
Eligible planGrowth, Connect, Advanced, Marketing Pro, Sales Engage, or EnterpriseHIPAA features are not available on entry plans; verify before buying numbers
Business Associate AgreementRequest the BAA from CTM before patient calls flow through the accountCall tracking is administrative use of PHI; no BAA, no compliance
HIPAA-eligible numbersBuy only numbers without the "not eligible" asteriskIneligible numbers route through infrastructure outside the covered scope
Individual loginsOne unique CTM login per user, no shared floor loginsAccess logging is meaningless if five coordinators share one account
Security settings15-minute idle logout, two-factor authentication, login required for recordingsThe three switches most accounts have never opened
Encrypted recordingsEnable encrypted call recordings and encrypted recording storageUnencrypted recordings of admissions calls are a breach waiting for a subpoena
Secure transcriptionsEnable secure transcriptions so SSNs and personal numbers are detected and redactedTranscripts get copied into CRMs and emails; redact at the source

Recommendations

The four that separate compliant from defensible.

PracticeWhat to configureWhy it matters
Automatic redactionSchedule redaction daily or every 30/60/90 daysStore the minimum PHI for the minimum time
PHI stays inside CTMStrip PHI fields from triggers, notifications, SMS bodies, and call-log exportsThe #1 leak: a missed-call alert email with the caller’s name and story in it
Caller IDTurn off Caller ID and Enhanced Caller ID unless you need name and locationCollect only what admissions actually uses
Third-party integrationsConfirm every connected CRM, ad platform, or tool is used in a HIPAA-compliant mannerA compliant CTM feeding a non-compliant integration is still a breach

Where it breaks

The three leaks we find on almost every audit

1. The missed-call alert

The most useful CTM feature in admissions, the instant text or email when a call is missed, is also the most common leak. Default notification templates include caller name, number, and sometimes transcript snippets. That is PHI in an unsecured SMS. Fix: notify on the event, not the content. "Missed call on the Google Ads line, callback due" is compliant; the caller’s story is not.

2. The Friday export

Leadership wants the call log in a spreadsheet. The export includes caller ID, transcription, and notes, then lives in an inbox forever. Fix: build the reports inside CTM or inside the CRM under the BAA, and strip PHI columns from any export that must leave.

3. The agency login

One shared "agency" login used by an outside marketing vendor, three coordinators, and a former employee. Access logs cannot attribute anything, and the former employee still has the password. Fix: individual logins, role-scoped access, two-factor authentication, and an offboarding step in the HR checklist.

How we configure it

Compliance and conversion are the same build

Our CTM configuration standard runs the HIPAA checklist in the same pass as routing, attribution, and AI voice coverage: eligible plan and BAA first, HIPAA-eligible numbers per channel, security settings and encryption before the first recording, redaction scheduled, notification templates rebuilt without PHI, and every CRM integration reviewed for what it carries downstream. The result is an account that recovers missed admissions and survives an audit, because the two were never separate jobs.

Source: CallTrackingMetrics HIPAA compliance documentation and HIPAA checklist (2024). This guide is configuration guidance from an official CTM Partner, not legal advice; confirm your obligations with qualified counsel.

FAQ

Questions, answered.

Is CallTrackingMetrics HIPAA compliant?

CallTrackingMetrics offers HIPAA-eligible configuration on its Growth, Connect, Advanced, Marketing Pro, Sales Engage, and Enterprise plans, with a Business Associate Agreement available on request. Compliance is a configuration outcome, not a default: the account must be set up with HIPAA-eligible numbers, encrypted recordings, redaction, and user security controls.

Do treatment centers need a BAA with CallTrackingMetrics?

Yes. Call tracking that captures caller identity and treatment context is administrative use of PHI, so a Business Associate Agreement between the treatment center and CTM must be in place. Request it from CTM before routing patient calls through the account.

What is the most common HIPAA mistake in CTM setups?

Moving PHI out of CTM through notifications, SMS bodies, and call-log exports. A missed-call text or email alert that includes the caller's name, number, and what they said has just placed PHI in an unsecured channel. Strip PHI fields from every notification and export.

Can a treatment center record admissions calls under HIPAA?

Yes, with encrypted call recordings and encrypted storage enabled, login required to access recordings, and automatic redaction configured so sensitive details such as Social Security numbers are removed from recordings and transcripts.

Who configures CTM for HIPAA at a treatment center?

Crucial Consultants, an official CallTrackingMetrics Partner, configures CTM for behavioral health providers, including HIPAA settings, routing, attribution, CRM integration, and AI voice coverage.

Get your CTM account configured right, once.

HIPAA settings, routing, attribution, and AI coverage, built by an official CallTrackingMetrics Partner.

Book a Consultation →