Compliance & Security

HIPAA-Compliant AI IVR Replacement with Full Call Encryption and Audit Trail

What the BAA covers, how recordings are encrypted and auto-purged on your retention schedule, and exactly what each audit log entry captures.

How it pays back

Regulatory Inspections Ready

Audit logs, encryption certificates, and BAA documentation available on demand. No surprises during HHS or state audits.

Patient Data Never Exposed in Motion

All calls and patient information encrypted. Access to your patient data is restricted by documented key management and access controls, with customer-managed key options for practices with stricter procurement standards.

Compliance Policies Automated

Set retention rules once; calls and recordings auto-delete after 30, 60, 90 days, or per your practice's policy. No manual purging or accidental data lingering.

Staff Accountability Built In

Access monitoring and audit logs capture which staff member accessed a call and when. Supports compliance verification, training, and incident response workflows.

HIPAA BAA included

Covered service provider; audit-ready documentation

Complete audit logs

Timestamp, caller, options, data, staff actions, and dispositions

Automatic data retention policies

Auto-delete calls and recordings per your compliance schedule

Frequently asked questions

Does MedReception need a HIPAA BAA?

Yes. A HIPAA BAA is included with every account. It defines MedReception as a Business Associate and outlines our obligations to encrypt, audit, and protect PHI. You remain the Covered Entity and are ultimately liable for HIPAA compliance.

Are calls and recordings encrypted?

Yes. All calls are encrypted end-to-end using AES-256 or equivalent. Recordings are encrypted at rest. Only authorized staff in your practice can access call data; MedReception staff cannot.

What information is logged for audit purposes?

Timestamp, caller phone number (masked for privacy), reason for call, menu options selected, patient data captured, which staff member accessed the call, when they accessed it, and the final disposition (appointment booked, escalated, etc.).

Can we set automatic deletion policies for calls and recordings?

Yes. You define a retention period (30, 60, 90 days, or custom). Calls and recordings outside that window are automatically deleted. You can also manually request deletion of specific calls.

Does the AI share patient data with third parties?

No. All patient data is retained within your practice's MedReception account and your EMR. We do not sell, share, or use patient data for any purpose other than fulfilling the call and appointment booking.

Are we compliant with state privacy laws (CCPA, etc.)?

MedReception's encryption, data handling, and retention policies support HIPAA, CCPA, PIPEDA, and similar state/provincial regulations. We recommend consulting your compliance officer to confirm your specific obligations.

Related reading

Bring this to your practice

See how MedReception AI handles after-hours calls, scheduling, intake, and patient communication for medical practices like yours.

Want the numbers first? See plans and pricing

HIPAA-Compliant IVR Replacement: Encryption & Audit Logs | Medreception AI