Compliance
AI intake calls are recorded, transcribed, and timestamped. All patient data is encrypted at rest and in transit, with audit logs showing who accessed the intake summary and when. HIPAA-compliant by design.
Intake summaries are never emailed. Staff access them via a secure, HIPAA-encrypted portal. Even if email is hacked, patient data is not compromised. Reduces breach risk.
A patient asks for their medical record. You can provide the intake call recording, transcript, and summary—proving exactly what was captured and when. Full traceability supports patient transparency and regulatory compliance.
If there's a compliance concern, the audit log shows precisely which staff member accessed the intake data, when, and from where. Quickly identify if data was accessed inappropriately or if a system vulnerability exists.
MedReception maintains a Business Associate Agreement (BAA) and provides audit logs on demand. Your compliance team can point to documented security controls during regulatory review or insurance audit.
End-to-end encryption for all calls
Audio, transcript, and structured data encrypted at rest and in transit
Timestamped access logs
Every view of an intake summary recorded with user ID, timestamp, and device info
HIPAA Business Associate Agreement
Signed BAA provided; security documentation and audit logs available on demand
Configurable data retention
Automatic purge policies and manual deletion available per your compliance requirements
Yes. When the AI begins the call, it informs the caller that the conversation is being recorded for quality and compliance purposes. This complies with one-party consent laws in most US states. Your practice should include AI call recording in your privacy notice and consent forms. MedReception provides language templates.
By default, recordings are retained for 1 year. You can configure a shorter or longer retention period based on your compliance requirements. After the retention period expires, recordings are automatically deleted. Manual deletion is available on request.
Staff can listen to recordings within the secure MedReception portal. Download options can be restricted to specific roles (chart manager, compliance officer). All access is logged. Your practice sets granular permission levels for who can access, listen to, or delete recordings.
You can request deletion from MedReception immediately. However, if the patient data has already been entered into your EMR chart, the chart record remains (per typical EMR retention policy). The intake call recording is separate and can be deleted independently of the chart.
No. Intake summaries are not sent via email or text. They are accessed via a secure, HIPAA-encrypted web portal. Staff log in with multi-factor authentication, and the summary is delivered over an encrypted connection. All access is logged for audit trail purposes.
Regulatory
HIPAA and compliance
Encryption, audit logs, Business Associate Agreements, and breach safeguards.
Workflow Hub
Patient intake
Intake workflows with built-in compliance and security controls.
Product
Meet Katie, the AI receptionist
How Katie handles HIPAA compliance and patient privacy during intake calls.
See how MedReception AI handles after-hours calls, scheduling, intake, and patient communication for medical practices like yours.
Want the numbers first? See plans and pricing