AI Receptionists for Medical Practices: What HIPAA Actually Requires
An AI receptionist that answers patient calls or stores transcripts is a HIPAA business associate of the medical practice. Every company in the chain that touches patient information needs a signed business associate agreement (BAA). No vendor can be “HIPAA certified,” because HHS does not certify anyone.
This guide explains what HIPAA requires for AI receptionists in medical and dental practices, for agencies selling them and for practices buying them. It is general information, not legal advice.
Is an AI receptionist a HIPAA business associate?
Yes. Under 45 CFR 160.103, a business associate is anyone who “creates, receives, maintains, or transmits” protected health information (PHI) on behalf of a covered entity. An AI receptionist hears patient names, dates of birth and reasons for visits, and it usually stores transcripts. That makes the vendor a business associate.
Encryption does not change this. HHS says a cloud provider that stores encrypted health data is still a business associate, even when it cannot decrypt the data.
What patient information flows through an AI receptionist call?
A typical AI receptionist call at a medical practice carries protected health information (PHI) from the first sentence: who the patient is, when they are coming in, and why. Common examples:
- The patient’s name, date of birth and phone number
- Appointment dates, times and provider names
- The reason for the visit or the symptoms described
- Insurance details
Call recordings, transcripts and call logs that contain these details are PHI once the practice or its vendor holds them. HHS does not name call recordings in its guidance; this follows from how the regulation defines PHI.
What must a HIPAA business associate agreement include?
A HIPAA BAA for an AI receptionist must meet 45 CFR 164.504(e): it limits how the vendor uses PHI, requires safeguards and breach reporting, binds subcontractors, and requires PHI to be returned or destroyed at the end. In full, it has to cover:
- The permitted uses and disclosures of PHI, and a promise not to go beyond them
- Security Rule safeguards for electronic PHI
- Reporting of unauthorized disclosures and breaches
- Subcontractors agreeing to the same restrictions
- Support for patient rights: access, amendment and an accounting of disclosures
- Making books and records available to HHS
- Returning or destroying PHI when the contract ends
- The practice’s right to terminate if the vendor materially breaches the agreement
Who signs a BAA when an agency resells an AI receptionist?
When an agency resells a white-label AI receptionist, each link in the chain signs a BAA with the next one. HIPAA lets a business associate share PHI with a subcontractor only under a BAA with the same protections (45 CFR 164.502(e)(1)(ii)).
| Party | Signs a BAA with |
|---|---|
| Medical practice (covered entity) | The agency it contracts with |
| Agency (business associate) | The white-label platform |
| White-label platform (subcontractor) | The voice AI provider and any other vendor that touches PHI |
| Voice AI provider, such as Retell AI | Its own subprocessors |
The practice does not need a BAA with every downstream vendor. Each business associate is responsible for its own subcontractors. The common gap is a practice signing directly with the voice provider while a middleman agency or platform also handles PHI with no BAA of its own.
Retell AI, the voice platform Call Supplai is built on, requires a signed BAA before any PHI flows through it and lets customers self-sign it.
Is there such a thing as a “HIPAA certified” AI receptionist?
No. HHS says it does not endorse or recognize private HIPAA certifications, and a certification does not relieve anyone of their legal obligations. SOC 2 and HITRUST are real third-party audits and useful evidence of good security, but they are not HIPAA certification. Treat “HIPAA certified” in a sales pitch as a red flag.
Which HIPAA Security Rule safeguards apply to AI receptionists?
The HIPAA Security Rule applies to any electronic PHI an AI receptionist handles. The safeguards that matter most:
- Risk analysis. The practice and each business associate must assess risks to electronic PHI and manage them (45 CFR 164.308(a)(1)).
- Access controls. Unique user logins for staff who can see transcripts and recordings.
- Audit controls. Logs of who accessed call data and when.
- Transmission security. Protection for PHI moving between systems.
- Minimum necessary. The agent should collect only what the task needs. A scheduling agent rarely needs a full medical history.
- Retention. Keep recordings and transcripts only as long as needed. Retell AI offers configurable retention and PII redaction.
Under the current rule, encryption is “addressable” rather than strictly mandatory, but in practice every serious vendor encrypts data in transit and at rest.
Has the 2025 HIPAA Security Rule update taken effect?
No. HHS proposed a major Security Rule update on January 6, 2025, which would make encryption and multi-factor authentication mandatory. As of September 2026 it has not been finalized, and reports indicate final action has been pushed to 2027. The current rule remains in force, but building to the proposed standard now is sensible.
Do automated appointment reminder calls need patient consent?
Automated reminder calls from an AI voice agent fall under the TCPA as well as HIPAA. The FCC ruled in 2024 that AI-generated voices count as “artificial or prerecorded voice” under the TCPA.
- Cell phones: healthcare messages such as appointment reminders need the patient’s prior express consent, not the written consent required for marketing. Giving the practice a phone number for care usually establishes it.
- Landlines: healthcare calls are exempt, but since July 2023 the exemption is limited to one call per day and three per week, with an opt-out.
- Marketing calls do not qualify for the healthcare rules at all.
State laws can add requirements, so check the rules where your client practices.
HIPAA checklist for agencies selling AI receptionists to medical practices
- Sign a BAA with each medical client before any patient calls go live.
- Confirm your white-label platform and voice provider have BAAs in place down the chain.
- Configure the agent to collect only the information the task needs.
- Set recording and transcript retention to the shortest period the practice can work with.
- Give practice staff individual logins; never share accounts.
- Document which reminder calls go out, to whom, and how patients opt out.
- Never describe your service as “HIPAA certified.”
For platform costs and BAA terms side by side, see Retell AI vs Vapi vs Synthflow. New to selling in this space? Start with how to start an AI voice agency.
To see how Call Supplai agencies deploy white-label AI receptionists for medical front desks, book a demo.
Frequently asked questions
Is Retell AI HIPAA compliant?
Retell AI supports HIPAA workloads: it requires a signed BAA before any PHI flows through it, lets customers self-sign the BAA, and is SOC 2 Type 1 and Type 2 audited. Each practice remains responsible for its own HIPAA obligations.
Are AI receptionist call recordings and transcripts PHI?
Yes, when they contain identifiable health information such as a patient's name with an appointment or reason for visit, and are held by a covered entity or its business associate.
Can an AI receptionist be HIPAA certified?
No. HHS does not certify or endorse any HIPAA certification. SOC 2 and HITRUST are useful third-party audits, but a vendor claiming to be HIPAA certified is a red flag.