Is an AI answering service HIPAA compliant? What practices need to check
No answering service is HIPAA compliant on its own. What HIPAA requires of a phone vendor, 7 questions to ask an AI receptionist, and the gaps that fail audits.
Disclosure first: we build Genius Care, an AI receptionist for medical practices, and this guide includes our own answers to the checklist below. We wrote it because "HIPAA compliant" is the most common phrase on answering-service websites and the least meaningful one. HIPAA compliance is a property of your practice's whole program. A vendor can make it easier or harder, and the questions below tell you which.
The short answer to the title: no answering service, human or AI, is HIPAA compliant by itself. When a vendor handles calls that contain protected health information (PHI), it is a business associate under 45 CFR 164.502(e), and the practice stays responsible for the arrangement. What you can check is whether the vendor meets the obligations a business associate has to meet, and whether it will put them in writing.
What HIPAA actually requires of a phone vendor
A caller who says "I need to reschedule my colonoscopy" has handed the vendor PHI: an identity, a procedure, a date. From that moment the Privacy Rule and the Security Rule both apply to the vendor as a business associate. In practice that means five things.
A signed Business Associate Agreement. The BAA is the contract that binds the vendor to the Privacy and Security Rules, defines permitted uses of PHI, and assigns breach notification duties. Without it, every PHI-bearing call is an impermissible disclosure by the practice, regardless of how secure the vendor's stack is.
PHI handling limited to the job. The minimum necessary standard applies. A receptionist, human or software, needs enough information to book, cancel, or route a call. It does not need to keep a transcript of the whole conversation indefinitely, and it should not copy PHI into systems the BAA does not cover.
Access controls. Only named people and systems with a reason should be able to read PHI, and it should be possible to say who those are. For a staffed service, that means the operators and their supervisors. For an AI service, it means the engineers with production access and every subprocessor the audio or text touches.
Audit logs. The Security Rule requires a record of activity in systems that contain PHI. Ask what is logged, how long it is kept, and who can read it. Be suspicious of both extremes: no log at all, and a vendor that claims to replay every decision the system ever made.
Retention and disposal. HIPAA requires covered entities to keep required documentation, including BAAs, for six years. It does not require a vendor to keep call recordings or transcripts at all. Shorter retention of call content is usually the safer posture, because data you no longer hold cannot be breached.
The 7 questions to ask any AI receptionist vendor
Send these in writing before you sign, and keep the answers with the BAA. Genius Care's answers are included so you can see what a complete response looks like, and so you can hold us to them.
1. Which plan includes a signed BAA, and is it signed before go-live? A vendor that offers a BAA "on request" or only on an enterprise tier is telling you which customers it expects to handle PHI. Genius Care: the BAA is included on the Practice ($1,499/mo) and Enterprise tiers and is signed before any real-PHI workload runs. Starter and Pro do not include one; they are for evaluation and for practices that keep PHI out of the call flow.
2. Where does the call audio go, and is it stored? Voice AI needs speech recognition and speech synthesis, and both usually run on third-party infrastructure. Ask which providers, whether audio is retained, and whether those providers are covered by the vendor's own BAAs. Genius Care: speech recognition and synthesis run in the voice pipeline for the duration of the call. The audio is not the record; the appointment summary and the scheduling write are.
3. Is conversational PHI persisted anywhere other than my system of record? This is the question that separates a receptionist from a data warehouse. Genius Care: the agent does not persist conversational PHI outside the system of record it books into. The voice path records bounded latency and token metrics plus PHI-safe operational failure events (a stalled turn, a deferred write), not call content.
4. Is the call content used to train or improve any model? Some AI vendors improve their models on customer conversations by default. For PHI that is a use the BAA has to permit explicitly, and most practices will not want to. Get the answer in the contract, not on a sales call.
5. What is encrypted, and how? Expect a specific answer: protocol in transit, algorithm at rest. Genius Care: TLS 1.3 on the wire, AES-256 for stored data.
6. What does the audit log contain, and what does it not? Genius Care: PHI access is logged for review. Those logs are bounded on purpose. They are metrics and failure events, not a replay of every model decision, and we say so rather than call them a complete audit trail.
7. Which certifications do you hold today, as opposed to plan to hold? Genius Care: not currently SOC 2 audited. We do not describe the product as "HIPAA compliant" and the roadmap toward formal certifications is tracked publicly on the Genius Care page. A vendor that will not answer this question plainly is not a vendor you want holding your patients' phone calls.
Two more that are not HIPAA questions but belong on the same list: does the AI identify itself as AI at the start of the call, and how does it hand a clinical, billing, or upset caller to a person? Genius Care's opening identifies the receptionist as AI, and clinical, billing, unsupported, and degraded flows route to a human transfer path. Full detail on all of this is in our security, PHI handling, and BAA documentation.
Common gaps that fail a review
These are the patterns we see when a practice audits an answering service it already has.
Transcripts in third-party LLM logs. An AI receptionist built on a general-purpose language model API may be sending every turn of the conversation to that API, where the provider's default retention applies. If the vendor cannot name the provider, state the retention period, and produce the BAA or equivalent covering it, the transcript is outside your control.
PHI in SMS confirmations. "Your appointment with Dr. Patel, Oncology, is confirmed for Thursday at 2pm" is PHI on a carrier network and on a lock screen. Confirmation texts should carry the minimum: a time, a location, a callback number. Ask the vendor what its templates say and whether you can change them.
Recordings without consent. Call recording consent is governed by state law, not HIPAA, and roughly a dozen states require all parties to consent. A service that records by default for "quality" may be creating both a consent problem and a PHI store you did not ask for. Decide whether you want recordings at all; if not, turn them off and get the setting in writing.
Staff outside the BAA. Human answering services subcontract overflow and overnight shifts more often than their marketing suggests. Every person who hears a PHI call needs to be inside the BAA chain. For an AI service, the equivalent is every subprocessor, and the vendor should be able to list them.
No breach notification clause with a clock on it. The Breach Notification Rule gives the business associate up to 60 days to notify the covered entity, and most practices want much less. Put a shorter number in the BAA.
How to use this
Pick the service on triage and booking, because a receptionist that cannot finish the call is not worth securing. Then send the seven questions, keep the answers, and sign the BAA before the first PHI-bearing call. If you are comparing options, what an answering service costs in 2026 covers the pricing units, and the virtual medical receptionist, after-hours answering service, and AI receptionist for dentists pages cover the three ways practices usually deploy one.
