Telephony
Carries the caller's voice, phone number, routing data, and call metadata.
What to ask: Ask whether the agreement covers voice traffic, metadata, and any recordings on the selected account.
The answer is more complicated than a checkmark on a product page. This guide explains the entire chain of contracts, data handling, and operating choices behind a responsible deployment.
By James Marques Robinson · Founder, Legacy Business Partners · Last reviewed: September 2026
The short answer
No software is HIPAA certified. HIPAA compliance is a process, not a product. A platform can be SOC 2 certified and still be legally unable to touch protected health information if it has not signed a Business Associate Agreement. The right question is not whether a vendor says it is HIPAA compliant. It is whether every vendor in the chain has signed a BAA on the plan you are actually using.
The chain
A voice agent is not one vendor. Telephony, speech-to-text, the language model, text-to-speech, the orchestration platform, and the CRM each independently touch protected health information. Each layer needs a signed Business Associate Agreement for the account in use; one missing link breaks the chain.
Carries the caller's voice, phone number, routing data, and call metadata.
What to ask: Ask whether the agreement covers voice traffic, metadata, and any recordings on the selected account.
Converts spoken patient details into text that may contain protected health information.
What to ask: Ask whether processing, temporary files, logs, and diagnostic data are all included in the agreement.
Receives call context and generates the agent's next response.
What to ask: Ask whether prompts and outputs are retained, reviewed, or used for training, and what the agreement covers.
Turns generated responses into audio and may process patient details within those responses.
What to ask: Ask whether generated audio, request logs, and temporary processing are covered and retained.
Coordinates the conversation, tools, transfers, transcripts, and data passed between services.
What to ask: Ask for the complete subprocessor list and confirm that the agreement extends through every connected service.
Stores contact details, appointment requests, notes, transcripts, and completed actions.
What to ask: Ask where records live, who can access them, how long they remain, and how deletion is verified.
The gating problem
The same company may sign an agreement for one account and decline it for another. Self-serve and consumer API tiers typically do not include a Business Associate Agreement, even when they use similar underlying technology.
This is a contractual and billing-tier distinction, not merely a technical setting. “HIPAA eligible” means a service may support a qualifying configuration; “HIPAA compliant” describes the complete, correctly contracted and operated environment.
Two ways to deploy
The agent takes a name, callback number, and appointment request. The workflow excludes clinical intake and would keep recordings and transcripts from being retained, deliberately reducing the protected-information surface.
A caller will sometimes volunteer clinical information without being asked. That becomes protected health information the moment it is recorded or stored. Minimized scope only holds if recording and transcript retention are genuinely off, not simply unasked for.
This model would include clinical intake, retained recordings, and records written into the practice's systems. It would require every layer to be on a BAA-eligible tier, with enterprise vendor agreements, a longer deployment, and higher cost.
The scope, contract chain, access model, and retention policy would be documented before patient information entered the workflow.
Vendor due diligence
These questions apply whether you evaluate a broad AI receptionist service or a workflow designed specifically for healthcare organizations.
Proof
Operational metrics from the deployed agent's own inbound dashboard. No projections, no estimates.
Read the Vitality Home Healthcare case study“Our missed-call rate has dropped to zero, which has directly boosted our revenue. More importantly, our administrative burden is cut in half, allowing our team to focus entirely on what matters most: delivering high-quality, hands-on patient care. If you are an agency owner looking to scale your business, eliminate staff burnout, and improve client satisfaction, this is the single best investment you can make.”
FAQ
An AI receptionist is not compliant merely because a product page says so. A compliant deployment would require appropriate safeguards, documented operating procedures, and signed Business Associate Agreements with every service that handles protected health information.
A Business Associate Agreement is a contract that defines how a service provider may handle protected health information for a covered entity or another business associate. Each service in the call path that creates, receives, maintains, or transmits that information may need to be covered, including relevant subprocessors.
Not necessarily. A virtual receptionist may be a person, a managed answering service, or software, while an AI receptionist uses automated speech and language systems; either model requires its own review of people, technology, contracts, and data handling.
It can be designed to handle patient information when the deployment has the required agreements, safeguards, access controls, and documented workflows. The information collected should be limited to what the approved workflow genuinely needs.
The same analysis applies to a dental practice when calls involve protected health information. The practice would need to verify the full vendor chain, sign the necessary agreements, configure retention and access controls, and train staff on the approved workflow.
That depends on configuration and contract terms. Before launch, a practice should know whether recordings are created, where every copy is stored, who can access them, how long they remain, and how deletion is confirmed.
It can. A name, callback number, appointment request, or volunteered clinical detail may become protected health information when connected to care, so a booking-only workflow does not automatically remove HIPAA obligations.
HIPAA eligible usually means a service can support a qualifying configuration or agreement. Compliance describes the complete deployment and its ongoing operation, including contracts, settings, access, training, policies, and actual use.
For the operational impact beyond compliance scope, read the research on unanswered business calls.
Start a scoping conversation about which of the two deployment models would fit your practice.