Skip to content
Workflows Resources Case Studies Pricing About
Guides

HIPAA Compliant AI Receptionist: What to Verify First

What HIPAA actually requires of an AI receptionist, when your vendor must sign a BAA, and the questions to ask before patient data reaches your phone line.

By Ahmad TawfikPublished 10 min read

There is no such thing as a "HIPAA-certified" AI receptionist. HHS does not certify software or vendors, so the label on a vendor's homepage tells you nothing. What actually determines your exposure is whether the tool creates, receives, maintains or transmits protected health information (PHI) on your behalf, whether the vendor will sign a business associate agreement, and how the system is configured, secured and logged. Everything else is marketing.

This article describes what the rules say, using HHS's own published guidance, and lists what you should verify with your counsel before patient calls run through any phone agent. It is not legal advice, and no article can replace a lawyer who knows your state, your practice and your contract.

Key takeaways

  • HIPAA regulates covered entities and their business associates; HHS explicitly lists a third-party AI chatbot that handles patient PHI, such as appointment scheduling, as an example of a business associate.
  • A business associate agreement (BAA) is the contract that permits PHI to flow to a vendor. HHS publishes sample provisions that outline what the agreement must contain.
  • "HIPAA certified" is not a real credential; there is no certification body, so treat the claim as unverified.
  • Recordings and transcripts of calls containing PHI are PHI, and recording consent is a separate state-law question you must confirm with counsel.
  • State and federal layers sit on top of HIPAA: Washington's My Health My Data Act covers consumer health data outside HIPAA, and the FTC's Health Breach Notification Rule applies to many health apps and tools that HIPAA does not reach.
  • A well-configured agent keeps PHI out of prompts where possible, escalates anything clinical to a human, and logs every action.

What HIPAA actually covers

HIPAA's Privacy, Security and Breach Notification Rules apply to covered entities: health plans, clearinghouses, and providers who transmit health information electronically in connection with covered transactions. A dental practice, med spa, chiropractic clinic or physical therapy office that bills insurance is a covered entity. So is a solo practitioner.

The rules also apply directly to business associates: people or companies that perform functions involving PHI on a covered entity's behalf, or provide services that involve disclosing PHI to them. HHS's guidance page gives examples, and one of them is directly relevant here: a "third-party vendor Artificial Intelligence (AI) chatbot on a provider's patient portal that provides services involving the patient's PHI such as symptom assessment, medical reminders, and appointment scheduling."

Read that example slowly, because it describes what most AI receptionists do. If your agent answers calls, schedules appointments, and captures symptom or insurance details, then the vendor is very likely a business associate, and a BAA is expected before PHI flows.

When does a phone call create PHI

Not every call involves PHI, and being precise about this is what separates a real compliance review from vendor slogans.

  • Scheduling with patient context. A caller schedules a cleaning and confirms their details. Under HHS's example, this falls inside PHI territory. Assume a BAA is needed.
  • Symptoms, medications, conditions. Anything a caller discloses about their health is PHI when the practice can link it to the individual.
  • Insurance and billing details. Also PHI.
  • General questions with no health facts. A caller asking for your address, hours or directions, with nothing health-related, is generally not a PHI exchange. But a series of such calls from the same number can still be sensitive information about the person's relationship with your practice, so do not design as if context does not exist.
  • Recordings and transcripts. If the agent records calls and transcripts contain any of the above, those artifacts are PHI and inherit every storage, access and deletion obligation you have.

The practical conclusion: for most healthcare practices, an AI receptionist that books appointments will touch PHI, so plan for the BAA path rather than hoping to avoid it.

The BAA: what it is and what to check

A BAA is a written contract in which you obtain satisfactory assurances that the business associate will appropriately safeguard PHI. HHS publishes sample provisions that walk through the required elements, including permitted and required uses and disclosures, the vendor's commitments, and what happens when obligations are breached. Your counsel should review the actual agreement, but the following items are the ones clients most often miss.

  • Definition of the data. Does the agreement cover everything the agent touches, including call recordings, transcripts, summaries, and data written into your CRM?
  • Subcontractors. The vendor likely uses model providers, telephony platforms and cloud infrastructure. HIPAA requires downstream subcontractors that handle PHI to be bound by the same terms. Ask who they are and confirm flow-down language exists.
  • Permitted uses. The vendor should not use your patient data for model training, analytics or product improvement unless you explicitly permit it. Get that in writing.
  • Safeguards. Encryption in transit and at rest, access controls, and audit logging are the minimum conversation. Ask for specifics, not adjectives.
  • Breach notification. The agreement must specify how and when the vendor tells you about a security incident. Your counsel will care about the timeline and the definition of an incident.
  • Return or destruction. What happens to the data and recordings at termination? HIPAA expects return or destruction where feasible, and you should know which one your contract promises.
  • Assistance with your own duties. If a patient asks to amend or access records, the vendor must help you respond.

Configuration choices that reduce risk

Most exposure comes from how the agent is wired, not from the model underneath it.

  1. Collect the minimum necessary. The agent should capture what booking requires, not a medical history. Every question in the intake flow should have a reason, and the reason should be written down.
  2. Keep clinical judgment out. The agent should never give medical advice, dosage guidance or triage opinions beyond your approved script. Anything clinical escalates to a human, and that rule should be visible in the call flows you approve.
  3. Escalate early and often. Urgent clinical calls, distressed callers and anything a human should hear should leave the AI's hands quickly. Our AI agent governance guide covers escalation paths and audit trails in depth.
  4. Segment the data. Where the platform allows, keep PHI out of general summarization and marketing flows. A booking confirmation that says "see you Tuesday at 2" is safer than one that restates symptoms.
  5. Control staff access. Who on your team can replay recordings or read transcripts? Least privilege, reviewed quarterly, is the standard.
  6. Log everything. Every action the agent takes, every escalation, every write to your practice management system. Audit logs are how you prove what happened later.
  7. Test with PHI-like data. Run scenario calls with fake patients and realistic details before go-live, and verify what got stored, where, and for how long.
  8. Review the retention clock. Recordings and transcripts should expire on a documented schedule unless you have a reason to keep them.

The layers beyond HIPAA

Three more authorities show up in serious reviews.

  • Washington's My Health My Data Act is the first state law to protect consumer health data outside HIPAA's ambit. It applies to data collected by apps, platforms and businesses that are not covered entities, requires consent before collection or sharing, honors deletion requests, and carries a private right of action through the state Consumer Protection Act. If your practice is in Washington, or you market to Washington residents, counsel needs to see your call flows and privacy policy.
  • The FTC's Health Breach Notification Rule requires vendors of personal health records and related entities to notify consumers after breaches involving unsecured health information. It reaches many health tools and apps that HIPAA does not cover, and it is enforced by the FTC, not HHS.
  • Section 1557 of the ACA, as interpreted in HHS's 2024 final rule, applies nondiscrimination principles to the use of patient care decision support tools, including AI, and requires covered programs to take steps to identify and mitigate discrimination in their use. If any AI in your stack influences patient care decisions, this is part of the compliance picture.

What to verify with counsel before go-live

  • Whether your practice's specific AI setup creates or transmits PHI, and therefore triggers the BAA requirement.
  • Whether the vendor's BAA is adequate, including subcontractor flow-down, breach timelines and data-use restrictions.
  • Whether recording or transcribing calls requires a consent notice in your state, and what that notice must say.
  • Whether state consumer health data laws apply to you beyond HIPAA.
  • Whether your patient communication policies (appointment reminders, texts, voicemails) match your privacy notice and your patients' reasonable expectations.

None of this is exotic. It is the same due diligence you would do for a cloud EHR vendor, applied to the newest vendor on your phone line. If you want to see how we approach the phone side of healthcare intake, the AI receptionist service and the dental industry page describe setups that keep clinical matters with your team, and the appointment reminder workflow shows a low-risk automation to start with. Practices in aesthetics and wellness can start with the med spa page. For the messaging side of compliance, the SMS compliance guide addresses consent and registration questions that often arrive at the same time.

Next step

Start with a data-flow question, not a vendor question: list every piece of patient information your current phone process touches, and where it lives. The free six-step AI automation plan on our homepage templates that audit, including the compliance checkpoints to walk through with counsel: start your AI automation plan. When you are ready to review a specific vendor or build, book a call and we will go through the questions together.

FAQ

Is any AI receptionist "HIPAA certified"?

No. HHS does not certify products or vendors, so "HIPAA certified" is a marketing phrase, not a credential. What matters is whether your specific setup creates or handles protected health information, whether the vendor will sign a business associate agreement, and how their system is actually configured and secured.

Does my AI receptionist need a business associate agreement?

If the vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA expects a BAA. HHS's own guidance lists a third-party AI chatbot that provides services involving patient PHI, such as appointment scheduling, as an example of a business associate. If scheduling or symptom details flow through the tool, assume you need one and have counsel confirm.

What happens if an AI receptionist records calls with patient information?

Recordings and transcripts of calls containing PHI are themselves PHI, so they fall under your HIPAA obligations and your state's recording consent rules. Ask where the recordings are stored, how long they are kept, who can access them, and how deletion works. Have counsel confirm your consent notice requirements before you enable recording.

Does HIPAA apply to every business that answers a patient's call?

No. HIPAA applies to covered entities (most providers and plans) and their business associates. A dental office scheduling a patient's cleaning is squarely in scope. A business that just answers general questions without health information may fall outside HIPAA, but state consumer health laws like Washington's My Health My Data Act can still apply.

What should I ask an AI receptionist vendor about PHI?

Whether they will sign a BAA, where data is stored and processed, how it is encrypted, who can access it, how long it is retained, how deletion works, how breaches are reported to you, and whether subcontractors are bound by the same terms. Get answers in writing and have your counsel review the agreement before go-live.

Frequently asked questions

Is any AI receptionist "HIPAA certified"?
No. HHS does not certify products or vendors, so "HIPAA certified" is a marketing phrase, not a credential. What matters is whether your specific setup creates or handles protected health information, whether the vendor will sign a business associate agreement, and how their system is actually configured and secured.
Does my AI receptionist need a business associate agreement?
If the vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA expects a BAA. HHS's own guidance lists a third-party AI chatbot that provides services involving patient PHI, such as appointment scheduling, as an example of a business associate. If scheduling or symptom details flow through the tool, assume you need one and have counsel confirm.
What happens if an AI receptionist records calls with patient information?
Recordings and transcripts of calls containing PHI are themselves PHI, so they fall under your HIPAA obligations and your state's recording consent rules. Ask where the recordings are stored, how long they are kept, who can access them, and how deletion works. Have counsel confirm your consent notice requirements before you enable recording.
Does HIPAA apply to every business that answers a patient's call?
No. HIPAA applies to covered entities (most providers and plans) and their business associates. A dental office scheduling a patient's cleaning is squarely in scope. A business that just answers general questions without health information may fall outside HIPAA, but state consumer health laws like Washington's My Health My Data Act can still apply.
What should I ask an AI receptionist vendor about PHI?
Whether they will sign a BAAs, where data is stored and processed, how it is encrypted, who can access it, how long it is retained, how deletion works, how breaches are reported to you, and whether subcontractors are bound by the same terms. Get answers in writing and have your counsel review the agreement before go-live.
Keep reading

Related articles

Comparisons10 min read

AI Receptionist Pricing, Explained Honestly

How AI receptionist pricing really works - flat plans, per-minute, per-call and per-resolution models, what drives cost, and the fees quotes tend to hide.

Get Your AI Automation Plan