AI Receptionists and HIPAA: What Healthcare Practices Need to Know
Medical offices need phone coverage more than almost any other business. But they also have the strictest data rules. AI receptionists can be HIPAA compliant, but not all of them are.
What HIPAA Requires
- Business Associate Agreement (BAA): any vendor that handles protected health information (PHI) must sign a BAA. If your AI provider won’t sign one, they’re not HIPAA compliant. Full stop
- Encryption: all PHI must be encrypted in transit and at rest. This means the AI’s voice processing, text storage, and any data transmission must use encryption
- Access controls: only authorized personnel can access call recordings and transcripts
- Audit trail: every access to PHI must be logged
What AI Can and Can’t Do
Safe for AI:
- Scheduling and rescheduling appointments
- Confirming appointment times
- Providing office hours, directions, accepted insurance lists
- Routing calls to the appropriate department
Needs careful handling:
- Prescription refill requests (involves PHI)
- Lab results or test inquiries (PHI)
- Discussing symptoms or medical history (PHI)
Compliance Guardrails
- Configure the AI to never repeat back medical information to the caller
- Route any call involving symptoms or medical history directly to a nurse or staff member
- Don’t store call recordings longer than necessary (define a retention policy)
- Verify caller identity before sharing any appointment details
- Ensure the LLM provider supports HIPAA (not all do — check their compliance page)
Key question to ask: “Will you sign a BAA?” If yes, review the terms. If no, walk away. No BAA = no HIPAA compliance, regardless of what their marketing says.