The true cost of a missed call at a dental practice
A missed call is a new patient who booked with the practice down the road. Here is how to actually put a number on what that costs you.
ReadNew: Casey now creates patient charts over the phone. See how
A plain-language guide to the compliance questions worth your time, the vendor claims that mean nothing, and the specific documents you should have on file before going live.
Let us clear this up first, because it shapes everything else. HHS does not certify anyone as HIPAA compliant. There is no audit, no badge, and no registry. Compliance is a continuous obligation, not a certificate you hang on the wall.
So when a vendor’s homepage says "HIPAA certified", you have learned something useful — just not what they intended. Look for specific, checkable claims instead.
Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and must sign a Business Associate Agreement. This is not optional and it is not negotiable. Without a signed BAA, using the service with patient data puts your practice in breach, regardless of how secure the vendor’s engineering actually is.
Read what the BAA says about subcontractors. Voice AI usually involves several downstream processors for speech recognition, language modelling, and telephony. Each one touching PHI needs to be covered.
First: is our data used to train models? For any shared or third-party model, the answer must be no. Get it in writing in the contract, not in a sales email.
Second: what is the retention policy, and can we change it? You should be able to set how long audio and transcripts live, including discarding audio at the end of the call and keeping only the structured outcome written to the chart.
Third: who internally can access our recordings? The answer should involve named roles, least-privilege access, and an audit log you can request.
TLS 1.3 in transit and AES-256 at rest is the baseline. If a vendor leads with encryption as their headline security feature, they are describing the floor as though it were the ceiling. The more interesting questions are about key management, access control, and data residency.
Ask where processing happens and where data rests, and ask separately whether any personnel outside the United States can access recordings or transcripts. These are different questions and a vendor can pass the first while failing the second.
Update your Notice of Privacy Practices to reflect automated call handling. Check your state’s call-recording consent rules, since roughly a dozen states require all-party consent. Add the vendor to your risk analysis and your incident response plan. Compliance is shared, and the parts that stay yours stay yours.
Signed BAA on file. Written confirmation that your data is not used for model training. Documented retention settings that you chose. A named security contact. Breach notification terms you have actually read. Recording consent language reviewed against your state law. Get those six things and you are in far better shape than most practices going live this year.
A missed call is a new patient who booked with the practice down the road. Here is how to actually put a number on what that costs you.
ReadEvery vendor in this category demos beautifully. These are the questions that separate a genuine front-desk replacement from a glorified phone tree with a nicer voice.
ReadLive in 10 business days
See Casey answer, book, and document a real call in a 20-minute demo — using your scheduling rules, not a canned script.