Why can’t a vendor just promise HIPAA compliance?
HIPAA applies to your practice (the covered entity) and to the vendors that handle patient information on your behalf (business associates). It does not apply to a piece of software in the abstract. A platform can have good security and still be used in a way that breaks the rules, for example by recording calls into an account nobody signed an agreement for.
HHS is direct about certifications: it "does not endorse or otherwise recognize private organizations’ ‘certifications’" for the Security Rule.[2] A "HIPAA certified" badge on a vendor website tells you about their marketing. It does not transfer any responsibility away from you.
Does an AI receptionist handle PHI?
Almost always, yes. A caller who gives their name, date of birth, and the reason they need an appointment has just shared protected health information. The AI platform turns that audio into text, may store a recording and a transcript, and may pass details to your scheduling system. Each of those steps involves a vendor creating, receiving, maintaining, or transmitting PHI.
Which vendors need a business associate agreement?
HHS allows a covered entity to share PHI with a business associate only with "satisfactory assurances" in a written contract, known as a business associate agreement (BAA).[1] For an AI receptionist, map every system the call touches and ask each vendor for a BAA.
| Vendor | What it touches | BAA needed? |
|---|---|---|
| AI voice platform | Live audio, transcripts, call summaries | Yes |
| Cloud storage for recordings | Stored audio and transcripts | Yes, even if the data is encrypted[3] |
| Scheduling or practice management integration | Patient names, appointment details | Yes |
| Text or email reminder service | Names, appointment times | Yes |
| Phone carrier | Call routing only, no stored content | Often no (see the conduit exception below) |
| Your IT or managed service provider | Systems that store PHI | Yes, if they can access PHI |
What is the conduit exception?
Some vendors only carry data from one place to another, like the phone company or the postal service. HHS calls these conduits and says their access to PHI is "only transient in nature." The exception ends the moment a vendor stores the data. HHS says a cloud service that "maintains ePHI for the purpose of storing it will qualify as a business associate."[3] An AI platform that keeps transcripts is not a conduit.
What should the receptionist be allowed to collect?
HIPAA’s minimum necessary standard asks you to take "reasonable steps to limit the use or disclosure of, and requests for, protected health information to the minimum necessary."[4] For a receptionist, that turns into simple rules:
- Collect what the front desk needs for the task: name, callback number, date of birth to find the chart, and a short reason for the visit.
- Do not ask for detailed symptoms or history unless your clinical team wants that before a callback.
- Do not read clinical information back to a caller whose identity has not been confirmed.
- Keep voicemail and callback messages short. HHS guidance allows messages at home but advises limiting the information left.[5]
What California rules apply on top of HIPAA?
Practices in Orange County, Los Angeles, the Inland Empire, and San Diego answer to state law as well as HIPAA. Three rules matter most for an AI receptionist.
Call recording consent
California makes it a crime to record a confidential phone conversation without the consent of all parties (Penal Code 632), and requires all-party consent for calls involving cell phones (Penal Code 632.7).[6][7] If the receptionist records calls, the greeting should say so before the conversation starts.
AB 3030 and generative AI
Since January 1, 2025, California Health and Safety Code 1339.75 requires a health facility, clinic, physician’s office, or group practice that uses generative AI for patient communications "pertaining to patient clinical information" to include a disclaimer and instructions for reaching a human. For audio, the disclaimer comes at the start and the end of the interaction. The rule does not cover administrative matters such as appointment scheduling and billing, and it does not apply when a licensed provider reads and reviews the message first.[8]
The statute names physician offices and clinics. It does not name dental offices, so a dental practice should ask its attorney whether it applies. A receptionist that sticks to scheduling and logistics stays outside the rule either way.
The Confidentiality of Medical Information Act
California’s CMIA bars providers and their contractors from disclosing medical information without authorization, except in listed situations.[9] It runs alongside HIPAA, so vendor contracts should cover it too.
A checklist to verify before you go live
Map the call path
List every system a call touches: phone carrier, AI platform, storage, scheduling integration, reminder service.
Collect the BAAs
Get a signed business associate agreement from every vendor on the list that stores or processes PHI.[1]
Write the collection rules
Decide what the receptionist asks for, what it never asks for, and what it never repeats back.
Set storage and access
Choose where recordings and transcripts live, how long they are kept, and who can open them. Turn on access logs.
Handle California disclosures
Add the recording notice to the greeting. If any clinical content is AI-generated, add the AB 3030 disclaimer and a path to a human.[8]
Test before launch
Call through every route, including after-hours and transfers, and read the transcripts to check what was captured.
Review after every change
A new vendor, a new workflow, or a staff change means another pass through this list.
What does a HIPAA mistake actually cost?
The HHS Office for Civil Rights enforces HIPAA against small practices too, including over something as ordinary as a reply to an online review. In 2022 it settled with New Vision Dental in California for $23,000 after the practice disclosed patient information while responding to reviews.[10] The same logic applies to an AI system that says too much to the wrong caller. A short list of rules, written before launch, prevents most of it.
This guide explains how the rules apply to phone automation. It is not legal advice. Your privacy officer or attorney should sign off on your final setup.
Frequently asked questions
Is any AI receptionist HIPAA certified?
No. HHS does not recognize private HIPAA certifications.[2] Look instead for a vendor that will sign a business associate agreement and explain how it stores, protects, and deletes call data.
Does my phone company need a BAA?
Usually not, if it only carries the call. HHS treats pure transmission services as conduits. Any vendor that stores recordings or transcripts is a business associate and needs a BAA.[3]
Can an AI receptionist send appointment reminders under HIPAA?
Yes. HHS says appointment reminders are part of treatment and can be sent without patient authorization.[11] Keep the content to the appointment details.
Do I have to tell callers they are talking to AI in California?
For generative AI communications about clinical information, yes: AB 3030 requires a disclaimer and instructions for reaching a human. Scheduling and billing calls are exempt.[8] Many practices disclose AI on every call anyway, which keeps things simple.
Who is responsible if the AI receptionist discloses PHI?
Your practice remains the covered entity, and a vendor with a BAA carries its own obligations. That is why the vendor map, the agreements, and the collection rules matter more than any badge on a website.
Related services
Keep reading
AI receptionist vs answering service vs front desk →
AI receptionist vs answering service vs in-house front desk: a fair comparison of hours, booking, hard calls, HIPAA, and cost for small practices.
AI tools worth it for a small practice →
Which AI tools for a medical practice or dental office are worth it in 2026, sorted by job, with what each needs, its risk level, and how to vet any tool.
Gian McCoy · Hanshiro Inc.
Gian works with independent medical, dental, and specialty practices across Orange County, Los Angeles, the Inland Empire, and San Diego. He is a former PTCB Certified Pharmacy Technician who handled patient data under HIPAA, spent 20+ years in enterprise IT and marketing technology (IBM Global Services; contract work at Kaiser Permanente and City of Hope), and holds an MBA in Brand Management from Thunderbird. More about Gian
Sources
- 1.U.S. Department of Health and Human Services (HHS). Business Associates.
- 2.HHS HIPAA FAQ. Are we required to certify our organization’s compliance with the standards of the Security Rule?.
- 3.U.S. Department of Health and Human Services (HHS). Guidance on HIPAA & Cloud Computing.
- 4.U.S. Department of Health and Human Services (HHS). Minimum Necessary Requirement.
- 5.HHS HIPAA FAQ. May health care providers leave messages for patients at their homes?.
- 6.Justia (California Code). California Penal Code § 632.
- 7.Justia (California Code). California Penal Code § 632.7.
- 8.LegiScan (California Legislature bill text). AB 3030 (2023-2024), chaptered text: Chapter 848, Statutes of 2024, adding Health and Safety Code § 1339.75 (2024-09-28).
- 9.Justia (California Code). California Civil Code § 56.10 (Confidentiality of Medical Information Act).
- 10.HHS Office for Civil Rights. New Vision Dental resolution agreement (2022-12-14).
- 11.HHS HIPAA FAQ. Are appointment reminders allowed under the HIPAA Privacy Rule without authorizations?.
