Skip to main content

Blog · Guide

HIPAA Compliant AI Receptionist: What to Verify Before You Buy

Any AI receptionist that handles a call for a medical, dental, or behavioral health practice touches PHI. That means HIPAA applies, and you need a signed BAA plus real technical controls. Here's the honest 2026 buyer's guide, including the specific questions to ask before you sign.

By Samana Rob · Published July 19, 2026 · Contains affiliate links

Medical office phone with HIPAA compliance shield lock icon overlay in clinical setting

Why HIPAA applies the moment the phone rings

The moment a patient calls your practice and shares their name plus any health-related context ("I need to reschedule my colonoscopy"), that is Protected Health Information (PHI). Any vendor that touches that data, the AI receptionist, the transcription service, the call recording storage, the voice model API, becomes a Business Associate under HIPAA and must sign a BAA. This is stated plainly in HHS guidance on Business Associate Agreements.

No BAA = no HIPAA coverage = your practice is on the hook for the vendor's mistakes.

The BAA question: what to actually verify

  1. Does the vendor sign a BAA with your practice? Not "we're HIPAA-friendly", an actual executed BAA on their standard template.
  2. Does the vendor have BAAs with every subprocessor? The AI pipeline usually includes a voice model (OpenAI, Anthropic, ElevenLabs), a transcription service (Deepgram, Whisper), and cloud infrastructure (AWS, GCP, Azure). Each needs a BAA.
  3. Can you get the subprocessor list? Real vendors publish or share on request. Vague answers = red flag.
  4. What is the incident notification timeline? HIPAA requires vendor notice within 60 days of breach discovery. Best-in-class is 24-72 hours.
  5. Is there a SOC 2 Type II report? Not required by HIPAA but a strong secondary signal.

Technical safeguards checklist

ControlMinimum acceptableWhy it matters
Encryption in transitTLS 1.3Prevents call interception
Encryption at restAES-256Protects stored recordings/transcripts
Access controlsRole-based, MFA requiredLimits internal PHI access
Audit logsImmutable, 6-year retentionRequired for HIPAA audits
Data minimizationPHI redacted from analyticsReduces breach surface
Retention policyConfigurable, documentedMatch your practice's policy
Data residencyUS-basedSome states/payers require it
Right to deleteOn patient request within 30 daysHIPAA + state law compliance

The hidden risk: model API BAAs

This is where most consumer-grade AI phone tools fail HIPAA. They wire a call transcript into the standard OpenAI or ElevenLabs API without a BAA in place. That API call is a HIPAA violation even if everything else is perfect. OpenAI, Anthropic, Google, and Amazon all offer BAA-covered API endpoints, but the vendor has to actively opt in and pay for the covered tier.

Ask: "Are you using the BAA-covered endpoints from every model and transcription provider in your stack?" If they cannot answer specifically, move on.

Consent and disclosure

  • Play a consent notice at call start: "This call may be recorded and handled by an AI assistant."
  • Update your Notice of Privacy Practices (NPP) to reflect AI phone handling.
  • Provide a way to reach a human ("say 'human' or press 0 anytime").
  • Document consent in your compliance binder.

Behavioral health and psychiatry considerations

Behavioral health calls have stricter requirements under 42 CFR Part 2 (substance use records) and often state-level mental health privacy law. If your practice handles those, verify the vendor supports 42 CFR Part 2 opt-in workflows and does not train models on PHI (a common oversight).

State-level stack: CMIA, CCPA, HITECH

  • California CMIA: broader than HIPAA on some patient rights and vendor liability.
  • CCPA/CPRA: additional patient rights to know, delete, and correct.
  • Texas HB 300: employee training requirements for anyone handling PHI.
  • HITECH: federal, expands breach notification and vendor liability.

Vendor evaluation checklist (print this)

  1. [ ] Signed BAA on their standard template
  2. [ ] Subprocessor list including AI model providers
  3. [ ] BAA-covered API endpoints for all subprocessors
  4. [ ] TLS 1.3 in transit, AES-256 at rest
  5. [ ] Role-based access + MFA
  6. [ ] Configurable retention policy
  7. [ ] 6-year immutable audit logs
  8. [ ] US data residency confirmed
  9. [ ] Model training opt-out on PHI
  10. [ ] Incident notification SLA
  11. [ ] SOC 2 Type II report available
  12. [ ] State law addendums as needed (CMIA, HITECH)

Related reading

Ready to stop losing calls?

Try the AI receptionist that answers every call for one flat fee

No per minute charges. No missed leads. atAnswer covers your phones and website chat 24/7, and you can hear it for yourself on a live demo call.

Start Your Free Demo Call

$720/mo flat rate · Cancel anytime · Setup in minutes

Frequently Asked Questions

Does 'HIPAA compliant' mean anything by itself?

No. HIPAA compliance is a program, not a certification. Any vendor claim needs to be backed by a signed BAA, documented safeguards, and a subprocessor list. Ask for all three.

What is a BAA?

Business Associate Agreement. A contract required under HIPAA (45 CFR 164.504(e)) between a covered entity (your practice) and any vendor that handles PHI. Without it, using the vendor is a HIPAA violation.

What about the AI voice model itself?

This is the biggest hidden risk. If the vendor pipes calls through a public OpenAI or ElevenLabs API without a BAA, that's a violation. Ask specifically: 'Do you have BAAs with every model provider in your pipeline?'

Is call recording OK under HIPAA?

Yes, with proper consent notice ('this call may be recorded for quality') and secure storage. Recording is not required, some practices choose transcript-only.

How long can transcripts be stored?

Whatever your policy requires. Best practice: 6 years to match HIPAA retention, encrypted at rest, with role-based access and access logs. Configurable per practice.

What about state laws (HITECH, CMIA in California)?

State laws stack on top of HIPAA. California's CMIA is stricter. Ask the vendor which state addendums they support.

Does atAnswer meet this bar?

Yes. atAnswer signs BAAs, uses TLS 1.3 in transit, AES-256 at rest, maintains a subprocessor list, and offers configurable retention. Verify current specifics on their site.

24/7 call coverage · One flat monthly rate

Get a BAA-Backed AI Receptionist

Hear atAnswer take a HIPAA-appropriate patient call.

Affiliate link · Pricing, offers, and features can change at any time.

Try a Live Demo Call$720/mo flat · Unlimited 24/7 calls