All articles

HIPAA and voice AI: what actually matters

A plain-language guide to the compliance questions worth your time, the vendor claims that mean nothing, and the specific documents you should have on file before going live.

There is no such thing as HIPAA certification

Let us clear this up first, because it shapes everything else. HHS does not certify anyone as HIPAA compliant. There is no audit, no badge, and no registry. Compliance is a continuous obligation, not a certificate you hang on the wall.

So when a vendor’s homepage says "HIPAA certified", you have learned something useful — just not what they intended. Look for specific, checkable claims instead.

The BAA is the actual foundation

Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and must sign a Business Associate Agreement. This is not optional and it is not negotiable. Without a signed BAA, using the service with patient data puts your practice in breach, regardless of how secure the vendor’s engineering actually is.

Read what the BAA says about subcontractors. Voice AI usually involves several downstream processors for speech recognition, language modelling, and telephony. Each one touching PHI needs to be covered.

Three questions that reveal the most

First: is our data used to train models? For any shared or third-party model, the answer must be no. Get it in writing in the contract, not in a sales email.

Second: what is the retention policy, and can we change it? You should be able to set how long audio and transcripts live, including discarding audio at the end of the call and keeping only the structured outcome written to the chart.

Third: who internally can access our recordings? The answer should involve named roles, least-privilege access, and an audit log you can request.

Encryption is table stakes, not a differentiator

TLS 1.3 in transit and AES-256 at rest is the baseline. If a vendor leads with encryption as their headline security feature, they are describing the floor as though it were the ceiling. The more interesting questions are about key management, access control, and data residency.

Data residency and offshore access

Ask where processing happens and where data rests, and ask separately whether any personnel outside the United States can access recordings or transcripts. These are different questions and a vendor can pass the first while failing the second.

Your own obligations do not disappear

Update your Notice of Privacy Practices to reflect automated call handling. Check your state’s call-recording consent rules, since roughly a dozen states require all-party consent. Add the vendor to your risk analysis and your incident response plan. Compliance is shared, and the parts that stay yours stay yours.

A short pre-launch checklist

Signed BAA on file. Written confirmation that your data is not used for model training. Documented retention settings that you chose. A named security contact. Breach notification terms you have actually read. Recording consent language reviewed against your state law. Get those six things and you are in far better shape than most practices going live this year.

Put a number on it

See what your own missed calls are costing.

Keep reading

Live in 10 business days

Your next patient is calling right now.

See Casey answer, book, and document a real call in a 20-minute demo — using your scheduling rules, not a canned script.

Book a Demo ROI