Buyer evaluation framework

HIPAA-Compliant AI Receptionist Solutions: A Buyer's Evaluation Framework

Every AI receptionist vendor claims to be HIPAA-compliant. Very few can produce the documentation, controls, and operational evidence that survive an OCR inquiry. This framework gives medical practice buyers the exact controls to verify, the red flags to listen for on sales calls, and the documents to request in writing before signing any contract that touches PHI.

Procurement Guide for Healthcare Buyers

Controls to Verify

5

Must-verify HIPAA controls every vendor must demonstrate

Red Flags

6

Vendor sales-call signals that disqualify on the spot

Documents to Request

8

Compliance artifacts a credible vendor delivers without friction

MedReception AI

Full

Attestation package ships with every onboarding by default

The core distinction

"HIPAA-Claimed" vs. "HIPAA-Proof" Vendors

Almost every voice AI startup will tell a prospect they are HIPAA-compliant. The question is whether they can prove it under scrutiny. The buyer's job is to separate marketing copy from operational reality, because the practice, not the vendor, holds the liability when PHI is mishandled.

HIPAA-Claimed (Marketing Language)

  • • "We are HIPAA-compliant" stated on a homepage, with no artifacts behind it
  • • BAA offered only after signing, or only on enterprise tier, or never
  • • Encryption mentioned generically without naming algorithms or key management
  • • No sub-processor list, or sub-processors that themselves do not sign BAAs
  • • No SOC 2 Type II or HITRUST evidence, only self-attestation
  • • Cannot describe their breach-notification workflow when asked directly

HIPAA-Proof (Operational Evidence)

  • • BAA shared during evaluation, signed before any PHI is exchanged
  • • Named encryption standards (AES-256 at rest, TLS 1.2+ in transit) with KMS-backed keys
  • • Maintained sub-processor list with BAAs in place for every PHI-touching vendor
  • • SOC 2 Type II report and HITRUST CSF certification available under NDA
  • • Documented breach-notification process within HIPAA's 60-day window
  • • Minimum-necessary data flows engineered into the product, not bolted on later

The 5 controls to verify

The Five Controls Every Buyer Must Verify Before Signing

These are the non-negotiable controls. If a vendor cannot demonstrate all five with documentation, they are not ready to handle PHI on behalf of a covered entity. Walk away politely and shortlist the next candidate.

1. BAA Scope and Signature

  • • Vendor provides a Business Associate Agreement covering every service that touches PHI
  • • BAA is signed before any patient data is captured, transmitted, or stored
  • • Sub-processors (LLM providers, telephony, transcription, storage) all sign downstream BAAs
  • • Scope explicitly includes call recordings, transcripts, and structured intake data

2. Encryption and Key Management

  • • AES-256 encryption at rest across databases, object storage, and backups
  • • TLS 1.2 or higher for all transit, including internal service-to-service hops
  • • Keys managed in a dedicated KMS with rotation policy, never embedded in code
  • • Customer-managed key options for practices with stricter procurement standards

3. End-to-End Audit Logging

  • • Every PHI access logged with user, action, resource, and timestamp
  • • Logs immutable, retained for at least six years per HIPAA requirements
  • • Practice can request a full audit trail for any patient on demand
  • • Admin actions, configuration changes, and API access all captured

4. Minimum-Necessary PHI in AI Prompts

  • • AI prompts pass only the minimum patient data needed for the current task
  • • PHI redacted or tokenized before being sent to general-purpose LLM endpoints
  • • No PHI used to fine-tune, train, or improve foundation models
  • • Prompt-engineering reviews documented as part of the change-management process

5. Breach Response Readiness

  • • Written breach-notification playbook with named owners and contact tree
  • • Detection tooling (SIEM, anomaly alerts) wired into 24/7 on-call rotation
  • • Tabletop exercises run at least annually with documented after-action reports
  • • Practice notified within 24 hours of any suspected incident, with the 60-day HIPAA clock fully tracked

Red flags on vendor sales calls

The Six Red Flags That Should End a Sales Call

These are the patterns we have seen across hundreds of vendor evaluations in healthcare. Any one of them is enough to disqualify a candidate. Two or more, and the vendor is not in the HIPAA conversation at all.

Red Flag 1: PHI Used to "Train Models"

If the vendor says patient calls or transcripts are used to "improve the model," that is a clear violation of the minimum-necessary rule and almost always a BAA violation. PHI in training data is exfiltration by another name.

Red Flag 2: "We Don't Sign BAAs"

Any version of this answer ends the call. Variants include "We pass through your BAA with the LLM provider" or "Our customers handle BAAs themselves." Neither satisfies HIPAA's business-associate definition.

Red Flag 3: Opaque Sub-Processor List

If the vendor cannot list every downstream service that touches PHI, or refuses to share that list under NDA, the practice cannot meet its own due-diligence obligations. This is table stakes.

Red Flag 4: No SOC 2 or HITRUST

Self-attestation is not evidence. Without a SOC 2 Type II report or HITRUST CSF certification, there is no independent validation that the vendor operates the controls they claim to operate.

Red Flag 5: No Dedicated Environment Option

Shared multi-tenant is acceptable for most practices when designed correctly, but a credible vendor offers a dedicated single-tenant tier for buyers who require it. "Everyone is on the same database" is a procurement non-starter for larger groups.

Red Flag 6: Vague Breach Response

"We will let you know if anything happens" is not a breach plan. A credible vendor names owners, timelines, channels, and the exact 60-day clock language from the HIPAA Breach Notification Rule.

Compliance documents to request

The Eight Documents Every Buyer Should Request in Writing

A credible vendor delivers these without friction, usually under NDA. Slow responses, partial answers, or "we are working on that" replies tell you everything you need to know about the maturity of their compliance program.

1. Business Associate Agreement (BAA)

The signed legal instrument that binds the vendor to HIPAA obligations. Scope must cover every service that touches PHI.

2. Sub-Processor List

Maintained list of every downstream vendor (LLM, telephony, storage, transcription) and the BAA status with each.

3. SOC 2 Type II Report

Independent audit covering security, availability, confidentiality. Current report dated within the last 12 months.

4. HITRUST CSF Certification

Healthcare-specific control framework. Increasingly required by hospital systems and large multi-specialty groups.

5. Penetration Test Summary

Third-party pen test from the last 12 months with executive summary, severity counts, and remediation status.

6. Breach Notification Process

Written playbook including detection, escalation, customer notification timeline, and post-incident review process.

7. Data Flow Diagram

Diagram showing how PHI moves through the system, where it is stored, who has access, and where redaction occurs.

8. Security and Privacy Policies

Information security policy, privacy policy, incident response policy, and access control policy, with version history.

Deployment configurations

Common Deployment Configs and Their HIPAA Implications

Two vendors with identical feature sets can have very different risk profiles depending on how they deploy. These are the three architectural choices that matter most when evaluating a vendor's HIPAA posture.

Shared Multi-Tenant vs. Dedicated Single-Tenant

  • • Multi-tenant: lower cost, faster setup, requires strong logical isolation and per-tenant encryption keys
  • • Single-tenant: dedicated database, dedicated keys, easier audit story, higher cost
  • • Buyer question: which model is the default, and is the other available at what tier
  • • Hospital procurement teams often require dedicated for any new vendor

US-Only Hosting vs. Cross-Border Data Flow

  • • US-only hosting simplifies compliance for US covered entities
  • • Cross-border flows (offshore call review, foreign sub-processors) require explicit BAA coverage
  • • Canadian practices need PIPEDA and provincial parallel review (Ontario PHIPA, Alberta HIA)
  • • Confirm data residency in writing, with the storage region named in the BAA or DPA

Training-Data Opt-Out and PHI Boundaries

  • • Vendor must contractually guarantee that PHI is never used to train, fine-tune, or improve foundation models
  • • Confirm the LLM provider has zero-retention or no-training enterprise mode enabled at the API layer
  • • Request the configuration screenshot or API documentation that proves this setting is on
  • • Annual re-confirmation as part of vendor management, since LLM provider defaults can change

OCR readiness workflow

A Three-Step Audit and Inspection Workflow for OCR Readiness

1

Quarterly Vendor File Review

Pull the BAA, current SOC 2, current HITRUST status, sub-processor list, and the latest pen test summary into a single vendor file. Confirm dates and versions are current.

Refreshed every 90 days
2

Annual Access and Audit Log Pull

Request a sample audit log export from the vendor. Reconcile against your own roster of users, integrations, and administrative actions. Document the review for your HIPAA security officer file.

Documented for OCR
3

Tabletop Breach Drill

Run a simulated breach scenario annually with the vendor. Confirm the contact tree, escalation timing, and 60-day notification process work in practice, not just on paper. Capture an after-action report.

Annual after-action report

Vendor attestation package

What MedReception AI Delivers on Day One

Every MedReception AI onboarding ships with a complete attestation package: signed BAA, current sub-processor list, SOC 2 Type II report under NDA, HITRUST status, pen test summary, breach playbook, and a written data flow diagram. The procurement work is done before the practice goes live.

See the Compliance Hub

See the controls in production

Walk Through the Buyer Framework on a Live Demo

We will run the five-control checklist against a real MedReception AI deployment, share the attestation package under NDA, and answer procurement questions in real time. Bring your compliance officer.

Book a Compliance-Focused Demo

Related HIPAA resources

Continue the Compliance Research

The pages below cover the marketing-positioning hub, the deeper HIPAA primer, the proof-vs-claims breakdown, and the security and compliance overviews that round out a complete vendor evaluation.

HIPAA-Compliant AI Receptionist Solutions: Buyer's Evaluation Framework | MedReception AI | Medreception AI