All articles

What makes an AI bot genuinely HIPAA-compliant, in plain terms

Voice or chat, any bot handling patient calls is handling protected health information. Here is the short list of things that actually make it compliant, and the marketing phrases that mean nothing.

Voice or chat, it is all PHI

Whether a patient speaks to a voice agent or types to a chatbot, the moment their name, symptoms, or contact details are involved, you are handling protected health information. The friendly interface does not change the legal category. Every compliance question you would ask about a human handling that data applies to the bot, and to every downstream service the bot relies on.

“HIPAA certified” is not a thing

Start by discounting the badge. HHS does not certify anyone as HIPAA compliant; there is no audit body and no registry. A vendor claiming certification is either being sloppy or hoping you will not check. Compliance is an ongoing obligation demonstrated through specific, verifiable practices, not a logo.

The BAA is the foundation, including subcontractors

Any bot vendor that touches PHI is a business associate and must sign a Business Associate Agreement. Without it, using the tool with patient data puts you in breach no matter how good their engineering is. Then read the subcontractor clause, because AI bots lean on downstream providers for speech recognition, language models, and telephony, and each one touching PHI has to be covered by the chain of agreements.

The training question you must get in writing

This is the one people forget. Ask directly whether your patients’ data, audio, transcripts, or chat logs, is ever used to train shared or third-party models. For any model not dedicated to you, the answer must be no, and it must live in the contract, not in a reassuring sales email. Data used for training can resurface in ways you cannot control.

Retention, access, and residency

Compliant bots let you decide how long audio and transcripts are kept, ideally including discarding raw audio at the end of a call and retaining only the structured outcome written to the chart. Access should be least-privilege, limited to named roles, and logged. And ask separately where data is processed and stored, and whether anyone outside the United States can reach it; a vendor can pass one of those and fail the other.

Encryption is the floor, not the headline

TLS 1.3 in transit and AES-256 at rest is the baseline every serious vendor meets. If encryption is the centrepiece of a security pitch, they are describing the floor as if it were the ceiling. The more telling questions are about key management, access control, and exactly which subcontractors see what.

Your side of the compliance line

Some obligations stay yours no matter how compliant the bot is. Update your Notice of Privacy Practices to reflect automated call and chat handling, add the vendor to your risk analysis and incident response plan, and check your state’s recording-consent law, since roughly a dozen require all-party consent. Get the signed BAA, the written no on training, your chosen retention settings, a named security contact, and reviewed breach-notification terms, and you are ahead of most practices going live this year.

Put a number on it

See what your own missed calls are costing.

Keep reading

HIPAA and voice AI: what actually matters

A plain-language guide to the compliance questions worth your time, the vendor claims that mean nothing, and the specific documents you should have on file before going live.

Read

Live in 10 business days

Your next patient is calling right now.

See Casey answer, book, and document a real call in a 20-minute demo, using your scheduling rules, not a canned script.

Book a Demo ROI