
The short version
- An AI phone vendor that handles patient information for a covered entity is a business associate and needs a BAA.
- Limit what the agent collects and stores, and decide retention up front.
- Ask vendors specific questions about encryption, access logs, subcontractors and breach notification.
Clinics, dental offices, therapy practices and other healthcare providers are among the businesses that benefit most from AI phone agents. They handle a high volume of scheduling and routine calls, and front-desk staff are stretched. They're also covered by HIPAA, which shapes how any vendor touching patient information has to operate.
This article covers what to check before an AI agent answers patient calls. It's general information, not legal advice. Your compliance officer or counsel should review any specific arrangement.
Why HIPAA applies
HIPAA's Privacy and Security Rules apply to covered entities (most healthcare providers, health plans and clearinghouses) and to their business associates: outside companies that create, receive, maintain or transmit protected health information (PHI) on the covered entity's behalf.
When a patient calls to book an appointment, the call itself contains PHI: their name, phone number, that they're a patient of your practice, and often the reason for the visit. An AI phone vendor that processes those calls for you is generally acting as a business associate.
The business associate agreement
Before any PHI flows to the vendor, you need a business associate agreement (BAA). It's a contract that requires the vendor to protect PHI, use it only for permitted purposes, report breaches, and pass the same obligations down to any subcontractors that handle the data.
If a vendor won't sign a BAA, don't send them patient calls. "HIPAA compliant" on a marketing page means nothing without a signed agreement.
Questions to ask an AI phone vendor
About the agreement
- Will you sign our BAA, or provide yours for our review?
- Which subcontractors process our call data (cloud hosting, speech recognition, language models, telephony)? Do they have BAAs with you?
- How and how quickly will you notify us of a breach?
Subcontractors matter more with AI products than many buyers realize. A voice agent built from several third-party APIs may send audio and transcripts to multiple companies. Each is a link in the chain.
About data handling
- What do you store: audio, transcripts, summaries, extracted fields? Can we turn off storage of any of these?
- Where is data stored, and is it encrypted in transit and at rest?
- How long is it kept by default, and can we set our own retention period?
- Is our data used to train models? Can we opt out?
- How is data deleted when we end the contract?
About access
- Who at your company can access our call data, and why?
- Are accesses logged? Can we get those logs?
- Do you support role-based access and single sign-on for our staff?
About security practices
- Do you perform risk assessments and regular security testing?
- What certifications or independent audits can you share?
- How are staff trained on handling PHI?
Design the agent for minimum necessary
HIPAA's minimum necessary standard asks you to limit uses and disclosures of PHI to what's needed for the purpose. For a scheduling agent, that translates into practical design choices:
- Collect only what's needed to book. Name, date of birth for matching, phone number and appointment type. The agent usually doesn't need detailed symptoms to book a routine visit.
- Don't read sensitive details back unnecessarily. "You're booked with Dr. Patel on Thursday at 2:15" rather than "your follow-up for your test results."
- Store summaries instead of full audio where full recordings aren't needed.
- Set short retention periods for transcripts and recordings.
Verify identity before sharing anything
The agent should never confirm or discuss appointment details with someone who hasn't been verified. Common approaches:
- Match the caller's number to the patient record, plus one more identifier such as date of birth
- Ask for two identifiers before discussing any existing appointment
- Treat requests from third parties (family members, employers) as a handoff to staff, unless your records authorize them
Write these rules explicitly into the agent's instructions, and test them with callers who try to get information they shouldn't.
Reminder calls and messages
Appointment reminders are generally permitted under HIPAA as part of treatment and operations, but keep them minimal: date, time, location, and a way to reschedule. Avoid mentioning the reason for the visit in voicemails, which someone else might hear. Our article on appointment reminder calls has scripts you can adapt.
Phone and text reminders also fall under the TCPA. The FCC has an exemption for certain healthcare messages, but it has conditions. Check how it applies to your calls, as covered in TCPA and AI voices.
Handoffs for clinical questions
AI agents shouldn't give medical advice. Set clear rules:
- Symptoms, medication questions and test results go to clinical staff
- Anything that sounds urgent triggers instructions to call 911 or the on-call line
- The agent can take a message for the care team with the caller's consent
A checklist before launch
- Signed BAA with the vendor, and confirmation that subcontractors are covered
- Data storage, retention and training use agreed and configured
- Identity verification rules written and tested
- Minimum necessary data collection in the agent's design
- Clinical and emergency handoff rules written and tested
- Recording disclosure on every call where you record
- Staff access to transcripts limited by role
- Your own risk analysis updated to include the new system
Example: a front-desk agent for a dental practice
Here's how the principles above might come together for a three-dentist practice:
- The agent answers overflow and after-hours calls.
- New patients can book a new-patient exam. The agent collects name, date of birth, phone number, email, and whether they have dental insurance, nothing more.
- Existing patients are verified by matching the calling number to the record plus date of birth before any appointment details are discussed.
- The agent can book, confirm, move and cancel appointments.
- Questions about treatment, pain, medications or bills are passed to staff as a callback, with only a short description.
- If a caller describes facial swelling, uncontrolled bleeding or trouble breathing, the agent tells them to go to the emergency room or call 911.
- Transcripts are kept for 90 days for QA and then deleted. Summaries are written to the practice management system.
- The vendor has signed a BAA, and its subcontractors that touch call data are covered.
This setup lets the agent handle a large share of routine calls while keeping PHI exposure narrow and predictable.

Patient-facing transparency
Patients should know what's happening on the call. In practice that means:
- The agent introduces itself as an automated assistant
- Recording and transcription are announced if they happen
- The practice's notice of privacy practices reflects how phone calls are handled
- Patients can ask to speak with staff instead
Transparency reduces complaints and supports the trust patients place in the practice.
Incident planning
Even with good safeguards, plan for something going wrong:
- Misdirected information. What happens if the agent shares details with someone who passed verification but wasn't the patient? Who investigates, and how is it reported?
- Vendor breach. The BAA should spell out notification. Know who at your practice receives that notice and what they do next.
- Agent error. If the agent books wrong or gives incorrect information, how is the patient contacted and the record corrected?
Write these down in your incident response plan alongside your other HIPAA procedures.
Training staff
Front-desk and clinical staff should understand:
- What the agent does and doesn't handle
- How to read the summaries and transcripts it produces
- How to correct records the agent created
- How to report a problem with the agent
- That they shouldn't paste PHI into other AI tools that aren't covered by a BAA
The last point matters. Staff sometimes use general-purpose AI chat tools to draft messages or summarize notes. If those tools aren't covered, that use can create a HIPAA problem entirely separate from your phone agent.
Frequently asked questions
Can an AI agent be "HIPAA certified"?
There's no official HIPAA certification. Compliance depends on the vendor's safeguards, the BAA and how you configure and use the system.
Does using an AI agent increase HIPAA risk?
Any new system that handles PHI adds risk that must be managed. A well-configured agent with a BAA, minimal data collection and short retention can be lower risk than voicemails piling up on an old phone system.
Can patients opt out of talking to the AI?
It's good practice to let them reach a person, for example by asking or pressing zero.


