Compliance

HIPAA-compliant AI receptionist: 12-point BAA checklist

How to tell if an AI answering service is really HIPAA compliant: the BAA, encryption, PHI minimization, audit logs, model training and data retention.

Quick answer: A HIPAA-compliant AI receptionist signs a Business Associate Agreement on the plan you buy, encrypts calls and records with TLS 1.2+ and AES-256, collects only the PHI each task needs, logs every access, never trains shared models on your patients' data and flows the same terms to its sub-processors. "HIPAA ready" without a signed BAA is not compliance.

By Radiatus team · Published 01 Oct 2026 · Updated 04 Oct 2026 · 8 min read

Every AI receptionist vendor now says "HIPAA compliant" somewhere on its site. Some mean it. Some mean "HIPAA ready", which means nothing has been signed. At least one popular service states on its own medical page that it is not HIPAA compliant. Because an answering service hears names, dates of birth, symptoms and insurance IDs on almost every call, it is a business associate under the HIPAA Privacy Rule, and you, the covered entity, carry the liability if it is not handled correctly. Here is the checklist we use ourselves.

1. A signed Business Associate Agreement, on your plan

The BAA is the only thing that makes a vendor a lawful business associate. Ask two questions: will you sign one, and is it included on the plan I am buying? Several vendors sign BAAs only on enterprise tiers or for an extra fee. HIPAA has no small-practice exception, so a solo dentist needs the same agreement as a hospital group. If the vendor cannot send you the BAA before you sign up, stop there.

2. What the BAA must cover

  • Permitted uses of PHI (answering, booking, verifying, transcribing) and nothing else.
  • Safeguards: encryption in transit and at rest, access control, workforce training.
  • Breach notification within a stated number of days (60 is the regulatory maximum; good vendors commit to fewer).
  • Sub-processor flow-down: every telephony, transcription and AI model provider that touches PHI signs the same terms.
  • Return or destruction of PHI at termination, with a timeline.
  • Your right to audit or receive audit evidence.

3. Encryption, specifically

"Encrypted" should mean TLS 1.2 or higher for every call leg, API connection and web session, and AES-256 for recordings, transcripts and database storage. Ask where the keys are held and whether recordings are encrypted on the telephony provider's side as well as the vendor's.

4. PHI minimization

A good AI receptionist asks only what the task needs. A booking needs name, date of birth, phone, reason for visit and insurance ID. It does not need a full medical history, and it should not store a credit card. Ask the vendor to show you the exact fields written to the record.

5. No PHI used to train models

This is the question most practices forget. Many AI products improve their models on customer data by default. Under a BAA that is not a permitted use. The vendor's policy should state that transcripts and recordings from your practice are processed for your practice only and never used to train shared or public models, and that their model providers are bound by the same terms.

6. Access controls and audit logs

Role-based access (owner, office manager, front desk, provider, billing), per-location scope, optional two-factor authentication, and a log of every recording played, transcript opened or record changed, with who, when and from where. You will need that log for your own risk assessment and for any OCR inquiry.

7. Retention you control

State medical record laws differ, so you should be able to set retention for recordings and transcripts yourself, typically from 30 days to 7 years, and honor a patient's deletion request within a documented window.

8. Where the data lives

HIPAA does not require US hosting, but your BAA and your state may. Ask for the hosting regions and the sub-processor list. A vendor that cannot produce a sub-processor list has not mapped its own PHI flow.

9. Identity verification on the call

Before reading back an appointment, balance or coverage, the AI should confirm at least two identifiers (name plus date of birth, or phone on file plus DOB). It should refuse to disclose anything to a caller who fails verification and offer a transfer instead.

10. Voicemail and text discipline

Texts and voicemails are disclosures. The system should send confirmations only to the number on file, keep them minimal ("your appointment is confirmed for Tuesday 9:30") and, for behavioral health, never reveal the practice name on a voicemail without the client's consent.

11. Honest AI disclosure and a path to a human

Not a HIPAA rule but a trust one, and increasingly a state one: the assistant should introduce itself as a virtual assistant and transfer to a person whenever the caller asks.

12. Your own documentation

Add the vendor to your business associate inventory, file the signed BAA, note the risk assessment date and train staff on when to use the AI's transcripts. Compliance is a practice-side task too.

How Clinic Answering Service answers the checklist

Clinic Answering Service signs the BAA (version 2026-10) on every plan including Solo, binds every sub-processor that touches PHI to a BAA, encrypts with TLS 1.2+ and AES-256, asks only the fields a booking needs, never uses PHI for model training, logs every PHI access and keeps that log six years, reports breaches within 10 business days of discovery, keeps recordings while the workspace is active (or a fixed 30-day to 7-year period set on request; self-service controls are planned), hosts production PHI in an AWS US region (trial workspaces run in AWS Mumbai with sample data only) and always transfers on request. The security page lists the safeguards, and the BAA and sub-processor list are sent on request before you sign.

Questions to ask on the demo call

A vendor's website tells you what marketing wrote. A 20-minute demo call tells you what is true. Ask these five questions and note who answers quickly and who has to "check with the team":

  1. Can you email me the BAA today, for the plan I am buying? A HIPAA compliant answering service has a standard BAA ready. If it is only offered on an enterprise tier, price that tier.
  2. Which sub-processors touch PHI? Telephony, speech-to-text, the language model and hosting should each be named, with a BAA or equivalent terms in place.
  3. Show me the fields written to my EHR. Ask to see a test booking in the schedule and the note attached to it. Anything beyond name, date of birth, phone, reason and insurance needs a reason.
  4. What happens to recordings after 30 days? The answer should be "whatever you set", with an audit trail of deletions.
  5. How does a caller reach a human? Try it yourself: say "person" mid-call and time the transfer.

Clinic Answering Service includes the same BAA on Solo ($149 a month), Practice ($349) and Group ($699); see clinic answering service pricing. If you are still deciding between AI and a human service such as Ruby or Smith.ai, read medical answering service: AI vs human.

Questions people ask

Is "HIPAA ready" the same as HIPAA compliant?

No. "Ready" usually means the vendor believes it could meet the requirements if asked. Compliance for your practice begins only when a BAA is signed and the safeguards in it are actually in place.

Do I need a BAA if the AI only takes messages?

Yes. A message with a name and a reason for calling is PHI. Any vendor that stores, transmits or transcribes it on your behalf is a business associate.

Can a vendor outside the US be HIPAA compliant?

Yes, HIPAA governs how PHI is handled, not where the company is incorporated. What matters is the BAA, the safeguards and, if your policy requires it, US-region hosting of the data.

Related guides

Never send a patient to voicemail again.

Ask for a demo and a person replies within one US business day. BAA signed before the first patient call. No long-term contract.