privacycompliancetcpa

HIPAA and Home Service: Privacy Considerations for Contractor Call Data

HIPAA does not apply to HVAC companies. But call recording laws, TCPA regulations, and state-level AI disclosure rules do. Here is what contractors need to know about call data privacy when using an AI answering service.

By George M. Espinoza Acosta·February 28, 2026·7 min read

The headline is intentionally provocative: HIPAA — the Health Insurance Portability and Accountability Act — does not apply to HVAC companies, plumbers, or electricians. Home service contractors are not covered entities under HIPAA and do not handle protected health information. So why the title? Because every week, a contractor asks us about HIPAA when what they actually want to know is: 'Is it legal for you to record my customers' calls, and how do you protect that data?' Those are legitimate questions, and they deserve straight answers.

What Laws Actually Apply to Contractor Call Recordings

Call recording law in the United States is governed primarily at the state level. States are categorized as either 'one-party consent' or 'two-party consent' (also called 'all-party consent') jurisdictions. In one-party consent states, a call can be recorded with the consent of only one participant — typically the business. In two-party consent states, all parties on the call must be informed that the call is being recorded. Currently, two-party consent states include California, Florida, Illinois, Maryland, Massachusetts, Nevada, New Hampshire, Oregon, Pennsylvania, Washington, and a handful of others. If you operate in any of these states, callers must be notified at the start of the call.

How CallJolt Handles Recording Disclosure

CallJolt can be configured to play a brief disclosure at the start of every call — 'This call may be recorded for quality purposes' — which satisfies the notification requirement in all US states, including two-party consent states. This disclosure is standard practice and does not deter callers. It is the same message they hear when calling any major business. We recommend enabling this disclosure for all CallJolt accounts regardless of state, as it protects your business and sets a consistent standard.

TCPA Considerations for Post-Call SMS

The Telephone Consumer Protection Act (TCPA) governs automated text messages. When CallJolt sends an SMS confirmation to a caller after booking, that message is a transactional communication — a confirmation of an appointment the caller actively requested. TCPA generally permits transactional messages without prior written consent. However, if you use CallJolt to send marketing messages or promotional follow-ups, prior express written consent is required. CallJolt's default SMS behavior (booking confirmation and call summary) is transactional and compliant.

AI Disclosure Laws

Several states have enacted or are considering laws that require businesses to disclose when a caller is speaking to AI rather than a human. The regulatory landscape is evolving, and more states are likely to add disclosure requirements. CallJolt's virtual assistant identification — 'Hi, this is CallJolt, the virtual assistant for [Your Company]' — satisfies current disclosure requirements in all enacted state laws and positions your business ahead of requirements that may be coming.

11+
US states with two-party call recording consent laws
Disclosure required in these states
Growing
Number of states with AI disclosure requirements
Regulatory landscape evolving in 2025–2026
AES-256
Encryption standard for CallJolt call recordings and data at rest
Bank-grade encryption

How CallJolt Protects Customer Data

  • All call recordings are encrypted at rest using AES-256 and in transit using TLS 1.3
  • Call data is stored in US-based data centers
  • Access to call recordings is restricted to authenticated account users
  • Data retention policies are configurable — you can set automatic deletion after a specified period
  • CallJolt does not sell or share caller data with third parties
  • SOC 2 Type II compliance in progress

What You Should Tell Your Customers

You do not need to make a big announcement that you are using AI. Most businesses simply update their privacy policy to note that inbound calls are answered and processed by AI and that calls may be recorded. Your privacy policy should be accessible from your website. If a customer directly asks whether they spoke to a human or AI, be straightforward — the relationship is better served by honesty.

Not Legal Advice

This post is educational and not legal advice. If you have specific compliance questions related to your state or business type, consult a qualified attorney. CallJolt's compliance team is available to discuss how our platform handles disclosure and data handling in your specific jurisdiction.

Frequently Asked Questions

Do I need to tell customers their call is being recorded by AI?

In two-party consent states (including California, Florida, and Illinois), you must notify callers that the call may be recorded. CallJolt can be configured to play this disclosure automatically at the start of every call. We recommend enabling it in all states as a best practice.

Does HIPAA apply to home service contractors?

No. HIPAA applies to covered entities such as healthcare providers, health plans, and their business associates. Home service contractors — HVAC, plumbing, electrical, roofing — do not handle protected health information and are not subject to HIPAA.

Is the SMS confirmation CallJolt sends compliant with TCPA?

Yes. CallJolt's default post-call SMS messages are transactional communications confirming appointments the caller requested. Transactional messages do not require prior express written consent under TCPA. Marketing messages do — CallJolt does not send marketing SMS by default.

How long does CallJolt retain call recordings?

Retention is configurable. By default, CallJolt retains recordings for 90 days. You can adjust this setting in your account dashboard to as short as 30 days or as long as 1 year based on your business needs.

Can I download and delete call recordings?

Yes. All call recordings are accessible from your CallJolt dashboard and can be downloaded or deleted at any time by authenticated account administrators.

What Service Business Owners Are Saying

★★★★★

“I was missing 8-10 calls a week and didn't even know it. CallJolt fixed that in one afternoon. It's the best $149 I spend every month.”

Marcus T.·Owner · Marcus Heating & Air·HVAC
★★★★★

“My guys are on job sites all day. Having an AI that answers, takes the info, and texts me the summary is exactly what I needed. Highly recommend.”

Deb R.·Owner · Riverside Plumbing Co.

Ready to answer every call?

CallJolt sets up in 5 minutes and pays for itself within the first week. No contracts. No per-minute billing.