A plain-language guide to the compliance questions worth your time, the vendor claims that mean nothing, and the specific documents you should have on file before going live.
There is no such thing as HIPAA certification
Let us clear this up first, because it shapes everything else. HHS does not certify anyone as HIPAA compliant. There is no audit, no badge, and no registry. Compliance is a continuous obligation, not a certificate you hang on the wall.
So when a vendor’s homepage says "HIPAA certified", you have learned something useful, just not what they intended. Look for specific, checkable claims instead.
The BAA is the actual foundation
Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and must sign a Business Associate Agreement. This is not optional and it is not negotiable. Without a signed BAA, using the service with patient data puts your practice in breach, regardless of how secure the vendor’s engineering actually is.
Read what the BAA says about subcontractors. Voice AI usually involves several downstream processors for speech recognition, language modelling, and telephony. Each one touching PHI needs to be covered.
Three questions that reveal the most
First: is our data used to train models? For any shared or third-party model, the answer must be no. Get it in writing in the contract, not in a sales email.
Second: what is the retention policy, and can we change it? You should be able to set how long audio and transcripts live, including discarding audio at the end of the call and keeping only the structured outcome written to the chart.
Third: who internally can access our recordings? The answer should involve named roles, least-privilege access, and an audit log you can request.
Encryption is table stakes, not a differentiator
TLS 1.3 in transit and AES-256 at rest is the baseline. If a vendor leads with encryption as their headline security feature, they are describing the floor as though it were the ceiling. The more interesting questions are about key management, access control, and data residency.
Data residency and offshore access
Ask where processing happens and where data rests, and ask separately whether any personnel outside the United States can access recordings or transcripts. These are different questions and a vendor can pass the first while failing the second.
Your own obligations do not disappear
Update your Notice of Privacy Practices to reflect automated call handling. Check your state’s call-recording consent rules, since roughly a dozen states require all-party consent. Add the vendor to your risk analysis and your incident response plan. Compliance is shared, and the parts that stay yours stay yours.
A short pre-launch checklist
Signed BAA on file. Written confirmation that your data is not used for model training. Documented retention settings that you chose. A named security contact. Breach notification terms you have actually read. Recording consent language reviewed against your state law. Get those six things and you are in far better shape than most practices going live this year.
Chiropractic clinics live and die by the rebooking cadence, yet the same staff answering the phone are the ones checking patients in for adjustments. Here is where the calls go missing.
When your next opening is weeks out, every cancellation is precious and every missed call is a cosmetic consult that booked with someone else. Here is how the front desk quietly leaks revenue.
Every vendor in this category demos beautifully. These are the questions that separate a genuine front-desk replacement from a glorified phone tree with a nicer voice.