Compliance & Security
What the BAA covers, how recordings are encrypted and auto-purged on your retention schedule, and exactly what each audit log entry captures.
Audit logs, encryption certificates, and BAA documentation available on demand. No surprises during HHS or state audits.
All calls and patient information encrypted. Access to your patient data is restricted by documented key management and access controls, with customer-managed key options for practices with stricter procurement standards.
Set retention rules once; calls and recordings auto-delete after 30, 60, 90 days, or per your practice's policy. No manual purging or accidental data lingering.
Access monitoring and audit logs capture which staff member accessed a call and when. Supports compliance verification, training, and incident response workflows.
HIPAA BAA included
Covered service provider; audit-ready documentation
Complete audit logs
Timestamp, caller, options, data, staff actions, and dispositions
Automatic data retention policies
Auto-delete calls and recordings per your compliance schedule
Yes. A HIPAA BAA is included with every account. It defines MedReception as a Business Associate and outlines our obligations to encrypt, audit, and protect PHI. You remain the Covered Entity and are ultimately liable for HIPAA compliance.
Yes. All calls are encrypted end-to-end using AES-256 or equivalent. Recordings are encrypted at rest. Only authorized staff in your practice can access call data; MedReception staff cannot.
Timestamp, caller phone number (masked for privacy), reason for call, menu options selected, patient data captured, which staff member accessed the call, when they accessed it, and the final disposition (appointment booked, escalated, etc.).
Yes. You define a retention period (30, 60, 90 days, or custom). Calls and recordings outside that window are automatically deleted. You can also manually request deletion of specific calls.
No. All patient data is retained within your practice's MedReception account and your EMR. We do not sell, share, or use patient data for any purpose other than fulfilling the call and appointment booking.
MedReception's encryption, data handling, and retention policies support HIPAA, CCPA, PIPEDA, and similar state/provincial regulations. We recommend consulting your compliance officer to confirm your specific obligations.
Technical
AI Receptionist EHR Integration Guide
How patient data is captured, structured, and synced to your EMR securely.
Industry
Best Voice AI Healthcare Solutions
Comparison of AI phone solutions for healthcare; compliance and security features across vendors.
Deployment
IVR Replacement AI Implementation Roadmap
Learn how to plan, deploy, and optimize an AI IVR system. Includes EMR integration, staff training, call flow…
Related
After-Hours and Weekend IVR Replacement for Medical Practices On-Call Coverage
Extend AI phone reception beyond business hours.
Pillar guide
AI Phone Tree Replacement for Medical Offices
Replace your phone tree with conversational AI that routes calls, answers questions, and schedules visits.
Related
Voice AI HIPAA Compliance: Encryption, Audit Logs, and Healthcare Regulations
Healthcare voice AI must be built for compliance from day one.
Related
AI Intake Compliance: HIPAA Recording, Audit Logs, and Regulatory Readiness
AI receptionists that collect patient intake must encrypt calls, log access, maintain audit trails, and comply with HIPAA.
See how MedReception AI handles after-hours calls, scheduling, intake, and patient communication for medical practices like yours.
Want the numbers first? See plans and pricing