Compliance

HIPAA and AI receptionists: what practice owners need to know

The short answer
  • An AI receptionist that hears names, symptoms, or appointment details is handling PHI, which makes the vendor your business associate under HIPAA.
  • HIPAA requires a signed business associate agreement (BAA) before any vendor touches patient information. No BAA, no deal.
  • "HIPAA certified" is a red flag — HHS does not certify vendors. Look for a BAA, encryption, audit logs, and PHI minimization instead.
  • Your practice stays the covered entity. Vetting the vendor, filing the BAA, and training your staff remain your responsibility.

What does HIPAA actually require when a vendor answers your phones?

When a patient calls and says "this is Maria Lopez, I need to reschedule my root canal," that sentence is protected health information, or PHI. It connects an identifiable person to their care. Under HIPAA, your practice is the covered entity — the party legally responsible for protecting that information, no matter who answers the phone.

Any company that creates, receives, stores, or transmits PHI on your behalf is a business associate. That includes billing services, transcription companies, human answering services, and AI receptionists. Under the rules described in HHS's HIPAA guidance for professionals, a covered entity must have a written business associate agreement, or BAA, in place before a vendor handles PHI. The BAA is the contract that binds the vendor to HIPAA's safeguards and spells out what happens if something goes wrong.

Those safeguards fall into three categories under the Security Rule: administrative (policies, staff training, controlling who has access), physical (protecting the servers and offices where data lives), and technical (encryption, access controls, and activity logging). You do not need to become a security expert. You do need to confirm your vendor can describe, in writing, how they meet each category.

Why is "HIPAA certified" a red flag?

There is no such thing as a HIPAA certification. HHS does not certify, accredit, or endorse any product or vendor, and no third party can issue a certificate that makes software compliant on its own. Compliance is an ongoing set of obligations — it depends on how a tool is built, configured, and used, not on a badge.

So when a vendor's homepage says "HIPAA certified," one of two things is true. Either they do not understand the rules they claim to follow, or they understand them and are hoping you do not. Neither is a good sign in a company you are about to trust with patient calls.

What a careful vendor can honestly claim: we sign BAAs, we encrypt data in transit and at rest, we follow the Security Rule safeguards, and we have had independent security audits. Those statements are specific and checkable. "Certified" is neither.

What should you ask an AI receptionist vendor?

You do not need technical vocabulary for this conversation. You need direct questions and written answers. Ask every AI receptionist vendor the following, and be wary of any answer that starts with "don't worry."

  • Do you store call audio and transcripts? Most systems keep both for a period. Ask how long, and whether you can set the retention period yourself.
  • Where is patient data stored? You want a named cloud provider and region, plus a list of any subcontractors who touch the data — they need BAAs too.
  • Is everything encrypted in transit and at rest? The answer should be an unqualified yes.
  • Will you sign a BAA, and at which pricing tier? A BAA that only comes with the most expensive plan tells you compliance is an upsell, not a default.
  • Is patient data used to train your AI models? The answer you want is no — in the contract, not just in conversation.
  • Do you keep audit logs? If there is ever a question about who accessed a record and when, logs are how you answer it.
  • What happens when a caller asks a clinical question? The right design transfers those calls to your staff. An AI that improvises medical guidance is a liability, not a receptionist.

If the vendor books directly into your scheduling system, ask how that connection is secured as well — our guide to how AI phone agents book into your PMS or EHR explains what to look for. For the broader buying conversation, see our 12 questions to ask before buying an AI receptionist.

What is PHI minimization, and why does it matter?

PHI minimization is a design principle with a simple premise: the safest patient data is data that was never collected in the first place. HIPAA's own "minimum necessary" standard points the same direction — use and share only what a task actually requires.

Booking an appointment requires very little: a name, a date of birth, a callback number, and the type of visit. It does not require a medical history, a list of medications, or a description of symptoms. A well-designed AI receptionist collects the short list and politely declines the rest — when a caller starts describing chest pain or asking whether two drugs interact, it transfers the call to your staff instead of recording an answer.

This is the approach we took with Pulse. It books appointments, handles intake, and runs reminders, and it hands anything clinical to a human. We describe its engineering as HIPAA-aware rather than "HIPAA certified," because the second phrase does not mean anything — and a compliance page that opens with an empty claim is not a page you should trust.

What stays your responsibility as the practice?

A signed BAA shares responsibility; it does not transfer it. Your practice remains the covered entity, which means you are still accountable for how patient information is protected — including the parts a vendor handles for you.

In practice, that means a few standing duties:

  • Vet vendors before they touch PHI, and keep the signed BAA where you can produce it.
  • Include the AI receptionist in your regular security risk analysis, the same as your practice management software.
  • Train your front desk on what the AI handles and what it hands off, so nobody assumes the system covers more than it does.
  • Know your breach notification duties. If a vendor reports an incident, the clock for notifying patients — and in larger breaches, HHS — starts with you.

None of this is unique to AI. You carry the same responsibilities with a human answering service or a billing company. The technology changes; the accountability does not.

A plain-English checklist before you sign

Before you sign with any AI receptionist vendor, walk through this list. Every item should be a yes you can point to on paper.

  1. A signed BAA is in hand before the first patient call, and filed where you can find it.
  2. You have written answers on what audio and transcripts are stored, where, and for how long.
  3. Encryption in transit and at rest is confirmed in writing.
  4. The contract states patient data is not used to train the vendor's AI models.
  5. Audit logs exist, and you know how to request them.
  6. You have placed a test call and heard the system hand a clinical question to a human.
  7. The vendor has never claimed to be "HIPAA certified" — or gave you a straight answer when you asked what they meant by it.
  8. The AI receptionist is on the agenda for your next security risk analysis.

A vendor who welcomes this list is a vendor you can probably work with. One who waves it off has told you what their compliance program looks like — before you ever signed a thing.

Common questions

Is any AI receptionist HIPAA certified?

No. HHS does not certify products or vendors, and no HIPAA certification exists. A vendor can sign a business associate agreement, encrypt data, and follow the Security Rule safeguards — those are the claims worth checking. "Certified" is a marketing phrase, not a legal status.

Does an AI receptionist need a business associate agreement?

Yes, if it handles protected health information — and answering patient calls almost always does. HIPAA requires a signed BAA before the vendor touches PHI. If a vendor will not sign one, or only offers one on premium plans, keep looking.

Are AI call recordings considered PHI?

Usually, yes. A recording that links an identifiable caller to their health or care — a name plus an appointment reason, for example — is protected health information. Ask vendors whether audio and transcripts are stored, where, for how long, and whether you can shorten retention.

Who is responsible if an AI vendor has a data breach?

Both parties carry obligations, but your practice remains the covered entity. The vendor must report the incident to you, and you are responsible for notifying affected patients — and, for larger breaches, HHS. That is why vendor vetting and a signed BAA matter before go-live.

Sources