Gian McCoy

Is an AI receptionist HIPAA compliant? What practice owners need to verify

By Gian McCoy · Updated · 9 min read

An AI receptionist is not HIPAA compliant by itself. Compliance depends on how your practice sets it up and runs it. Every vendor that stores or transmits patient information must sign a business associate agreement, the receptionist should collect only what it needs, and recordings need controlled storage and access.[1] No vendor can sell you a HIPAA certification.[2]

Medical practitioner in scrub suit using a laptop for remote consultation and documentation.
Photo by https://kaboompics.com/ on Pexels

Why can’t a vendor just promise HIPAA compliance?

HIPAA applies to your practice (the covered entity) and to the vendors that handle patient information on your behalf (business associates). It does not apply to a piece of software in the abstract. A platform can have good security and still be used in a way that breaks the rules, for example by recording calls into an account nobody signed an agreement for.

HHS is direct about certifications: it "does not endorse or otherwise recognize private organizations’ ‘certifications’" for the Security Rule.[2] A "HIPAA certified" badge on a vendor website tells you about their marketing. It does not transfer any responsibility away from you.

Does an AI receptionist handle PHI?

Almost always, yes. A caller who gives their name, date of birth, and the reason they need an appointment has just shared protected health information. The AI platform turns that audio into text, may store a recording and a transcript, and may pass details to your scheduling system. Each of those steps involves a vendor creating, receiving, maintaining, or transmitting PHI.

Which vendors need a business associate agreement?

HHS allows a covered entity to share PHI with a business associate only with "satisfactory assurances" in a written contract, known as a business associate agreement (BAA).[1] For an AI receptionist, map every system the call touches and ask each vendor for a BAA.

Typical vendors behind an AI receptionist
VendorWhat it touchesBAA needed?
AI voice platformLive audio, transcripts, call summariesYes
Cloud storage for recordingsStored audio and transcriptsYes, even if the data is encrypted[3]
Scheduling or practice management integrationPatient names, appointment detailsYes
Text or email reminder serviceNames, appointment timesYes
Phone carrierCall routing only, no stored contentOften no (see the conduit exception below)
Your IT or managed service providerSystems that store PHIYes, if they can access PHI

What is the conduit exception?

Some vendors only carry data from one place to another, like the phone company or the postal service. HHS calls these conduits and says their access to PHI is "only transient in nature." The exception ends the moment a vendor stores the data. HHS says a cloud service that "maintains ePHI for the purpose of storing it will qualify as a business associate."[3] An AI platform that keeps transcripts is not a conduit.

What should the receptionist be allowed to collect?

HIPAA’s minimum necessary standard asks you to take "reasonable steps to limit the use or disclosure of, and requests for, protected health information to the minimum necessary."[4] For a receptionist, that turns into simple rules:

What California rules apply on top of HIPAA?

Practices in Orange County, Los Angeles, the Inland Empire, and San Diego answer to state law as well as HIPAA. Three rules matter most for an AI receptionist.

Call recording consent

California makes it a crime to record a confidential phone conversation without the consent of all parties (Penal Code 632), and requires all-party consent for calls involving cell phones (Penal Code 632.7).[6][7] If the receptionist records calls, the greeting should say so before the conversation starts.

AB 3030 and generative AI

Since January 1, 2025, California Health and Safety Code 1339.75 requires a health facility, clinic, physician’s office, or group practice that uses generative AI for patient communications "pertaining to patient clinical information" to include a disclaimer and instructions for reaching a human. For audio, the disclaimer comes at the start and the end of the interaction. The rule does not cover administrative matters such as appointment scheduling and billing, and it does not apply when a licensed provider reads and reviews the message first.[8]

The statute names physician offices and clinics. It does not name dental offices, so a dental practice should ask its attorney whether it applies. A receptionist that sticks to scheduling and logistics stays outside the rule either way.

The Confidentiality of Medical Information Act

California’s CMIA bars providers and their contractors from disclosing medical information without authorization, except in listed situations.[9] It runs alongside HIPAA, so vendor contracts should cover it too.

A checklist to verify before you go live

  1. Map the call path

    List every system a call touches: phone carrier, AI platform, storage, scheduling integration, reminder service.

  2. Collect the BAAs

    Get a signed business associate agreement from every vendor on the list that stores or processes PHI.[1]

  3. Write the collection rules

    Decide what the receptionist asks for, what it never asks for, and what it never repeats back.

  4. Set storage and access

    Choose where recordings and transcripts live, how long they are kept, and who can open them. Turn on access logs.

  5. Handle California disclosures

    Add the recording notice to the greeting. If any clinical content is AI-generated, add the AB 3030 disclaimer and a path to a human.[8]

  6. Test before launch

    Call through every route, including after-hours and transfers, and read the transcripts to check what was captured.

  7. Review after every change

    A new vendor, a new workflow, or a staff change means another pass through this list.

What does a HIPAA mistake actually cost?

The HHS Office for Civil Rights enforces HIPAA against small practices too, including over something as ordinary as a reply to an online review. In 2022 it settled with New Vision Dental in California for $23,000 after the practice disclosed patient information while responding to reviews.[10] The same logic applies to an AI system that says too much to the wrong caller. A short list of rules, written before launch, prevents most of it.

This guide explains how the rules apply to phone automation. It is not legal advice. Your privacy officer or attorney should sign off on your final setup.

Frequently asked questions

Is any AI receptionist HIPAA certified?

No. HHS does not recognize private HIPAA certifications.[2] Look instead for a vendor that will sign a business associate agreement and explain how it stores, protects, and deletes call data.

Does my phone company need a BAA?

Usually not, if it only carries the call. HHS treats pure transmission services as conduits. Any vendor that stores recordings or transcripts is a business associate and needs a BAA.[3]

Can an AI receptionist send appointment reminders under HIPAA?

Yes. HHS says appointment reminders are part of treatment and can be sent without patient authorization.[11] Keep the content to the appointment details.

Do I have to tell callers they are talking to AI in California?

For generative AI communications about clinical information, yes: AB 3030 requires a disclaimer and instructions for reaching a human. Scheduling and billing calls are exempt.[8] Many practices disclose AI on every call anyway, which keeps things simple.

Who is responsible if the AI receptionist discloses PHI?

Your practice remains the covered entity, and a vendor with a BAA carries its own obligations. That is why the vendor map, the agreements, and the collection rules matter more than any badge on a website.

Related services

Keep reading

Gian McCoy · Hanshiro Inc.

Gian works with independent medical, dental, and specialty practices across Orange County, Los Angeles, the Inland Empire, and San Diego. He is a former PTCB Certified Pharmacy Technician who handled patient data under HIPAA, spent 20+ years in enterprise IT and marketing technology (IBM Global Services; contract work at Kaiser Permanente and City of Hope), and holds an MBA in Brand Management from Thunderbird. More about Gian

Sources

  1. 1.U.S. Department of Health and Human Services (HHS). Business Associates.
  2. 2.HHS HIPAA FAQ. Are we required to certify our organization’s compliance with the standards of the Security Rule?.
  3. 3.U.S. Department of Health and Human Services (HHS). Guidance on HIPAA & Cloud Computing.
  4. 4.U.S. Department of Health and Human Services (HHS). Minimum Necessary Requirement.
  5. 5.HHS HIPAA FAQ. May health care providers leave messages for patients at their homes?.
  6. 6.Justia (California Code). California Penal Code § 632.
  7. 7.Justia (California Code). California Penal Code § 632.7.
  8. 8.LegiScan (California Legislature bill text). AB 3030 (2023-2024), chaptered text: Chapter 848, Statutes of 2024, adding Health and Safety Code § 1339.75 (2024-09-28).
  9. 9.Justia (California Code). California Civil Code § 56.10 (Confidentiality of Medical Information Act).
  10. 10.HHS Office for Civil Rights. New Vision Dental resolution agreement (2022-12-14).
  11. 11.HHS HIPAA FAQ. Are appointment reminders allowed under the HIPAA Privacy Rule without authorizations?.