Compliance & Security
HIPAA compliance is not a marketing badge; it's infrastructure. Learn what questions to ask, what documentation to request, and how to verify a voice AI vendor's security.
Your practice remains liable for HIPAA violations even if a vendor caused them. Requesting compliance documentation upfront protects you from inheriting a vendor's security debt. Get it in writing.
A Business Associate Agreement is a legal document that specifies how the vendor handles PHI (Protected Health Information), what happens in a breach, and how data is destroyed. Many vendors skip this or use weak templates. Negotiate; don't just sign.
Encryption is common infrastructure language, but implementation varies widely. Ask the vendor: What encryption standard (TLS 1.2+)? Where are keys stored? Who has access? Weak answers indicate weak security.
Ask the vendor for their breach notification protocol and response time. In a pilot, request a security incident simulation to confirm they can notify you, preserve evidence, and support remediation.
HIPAA BAA included
Signed Business Associate Agreement specific to your practice and use case
Staff access logged
Audit trail records every user login, data access, and admin change with timestamp and role
Type I is a point-in-time audit; Type II is ongoing monitoring over at least 6 months. For healthcare, Type II is more meaningful because it shows sustained compliance, not just a snapshot. Ask the vendor for Type II if available.
The BAA holds the vendor responsible for notification and remediation, but your practice is still liable under HIPAA. The BAA protects you contractually and establishes consequences for the vendor, but it doesn't eliminate your obligation. Verify the vendor carries cyber liability insurance that covers healthcare breaches.
Yes. Most voice AI systems should not retain raw recordings longer than is operationally necessary (typically 24–72 hours for quality assurance). Specify in your contract that recordings are deleted after review and that staff can request permanent deletion on demand.
That's a red flag. Established healthcare vendors have these reports; they're standard in the industry. If a vendor can't produce recent security documentation, their platform is either immature or cutting corners on compliance. Move on.
HIPAA applies to all PHI, whether in motion, at rest, or in memory. Every step of data handling — the call, transcription, storage, staff access, and deletion — must be covered by your security infrastructure. The vendor is responsible for their part; you're responsible for integration with your practice's controls.
Governance
HIPAA and compliance
Full guide to voice AI compliance and what HIPAA means for front-desk automation.
Workflow
Patient intake
How patient data captured on the call is handled and returned as a structured summary for staff review and filing.
Product
Meet Katie, the AI receptionist
MedReception's compliance-first architecture and audit practices.
See how MedReception AI handles after-hours calls, scheduling, intake, and patient communication for medical practices like yours.