Shtello ConnectA SHTELLO CO SERVICE

Is an AI Receptionist HIPAA Compliant? A Ten Point Checklist

A HIPAA compliant AI receptionist is about vendor practice, not a feature. Here is a 10-point checklist for dental and medical offices, plus questions to send.

By Shtello Connect TeamSeptember 12, 20269 min readHIPAA and AI receptionists👁 66
Is an AI Receptionist HIPAA Compliant? A Ten Point Checklist
Portrait beautiful young woman big city woman big city
Listen to this article
Read by Jane AI, a Shtello Connect AI voice

An AI receptionist can be used in a HIPAA compliant way, but no software is HIPAA compliant on its own. Compliance comes from how the vendor handles protected health information: a signed Business Associate Agreement, encryption, access controls, retention limits and a breach process. Use the 10-point checklist below before letting any AI answer a dental or medical phone line.

Key takeaways

  • HIPAA compliance is a set of vendor practices and a contract, not a feature you can toggle on.
  • Almost every receptionist call contains PHI: a name plus a phone number plus a reason for calling is enough.
  • The single most important item is a signed Business Associate Agreement (BAA). No BAA, no deal.
  • Recording retention, SMS handling and staff access are where most offices get surprised.
  • This article is general information, not legal advice. Confirm your setup with a compliance professional.

Why is "HIPAA compliant AI" the wrong question?

HIPAA regulates covered entities (your practice) and their business associates (vendors that handle PHI for you). It does not certify products. There is no HIPAA seal, and a vendor who says "we are HIPAA certified" is using marketing language. What actually matters is whether the vendor will sign a BAA, whether its systems and staff meet the Security Rule safeguards, and whether your office uses the tool in a way that follows the Privacy Rule.

So the useful question is not "is this AI HIPAA compliant" but "can I use this AI receptionist and stay compliant, and what does the vendor commit to in writing?" The checklist below is built around that question.

What PHI does a receptionist call typically contain?

Owners sometimes assume the front desk line is low risk because nobody discusses diagnoses. In practice, a normal call includes several identifiers that HIPAA counts as PHI when tied to a health service:

  • Name and phone number (caller ID captures the number even if the caller never says it).
  • Reason for the visit: "I need a crown," "my child has an ear infection," "I want to book Botox."
  • Date of birth, which most offices ask to match a record.
  • Insurance carrier and member ID when the caller asks whether you take their plan.
  • Appointment details: provider, procedure, date and time.
  • Medication and symptom questions left in after-hours messages.

An AI receptionist records the audio, transcribes it, and stores the transcript and any text messages. That means the vendor holds PHI on your behalf, which is exactly the definition of a business associate.

What is on the 10-point HIPAA checklist for an AI receptionist?

  1. A signed Business Associate Agreement. The vendor must sign a BAA before the first call. Read it for the breach notification window, the subprocessor clause and what happens to your data at termination. If the vendor's answer is "we don't need one because the AI is automated," walk away.
  2. Encryption in transit and at rest. Calls, transcripts, recordings and text messages should be encrypted while moving between systems (TLS or equivalent) and while stored. Ask where the data lives and whether backups are encrypted too.
  3. Recording retention controls. You should be able to set how long recordings and transcripts are kept and delete them on request. Indefinite retention by default is a red flag. Many offices settle on 90 days to a year, but set that with your compliance advisor.
  4. PHI minimization. The AI should collect only what it needs to book or route the call. It does not need a Social Security number to schedule a cleaning. Ask what fields the AI is scripted to request and confirm you can remove any.
  5. No PHI in SMS without patient opt-in. Appointment reminders by text are common and permitted when the patient has agreed to receive them and the content is limited. "Your appointment is Tuesday at 2 p.m." is fine; "Your root canal with Dr. Lee is Tuesday" is more than needed. Confirm the AI asks for texting consent and keeps message content minimal.
  6. Role-based staff access. Not everyone in the office needs to hear every recording. The dashboard should support separate logins with different permissions, and access should be removed the day someone leaves.
  7. Audit logs. The system should record who listened to, exported or deleted a recording or transcript, and when. You need this to investigate a complaint or a suspected breach.
  8. A written breach process. Ask what the vendor does in the first 24 hours after a suspected incident, how fast they notify you, and who you call. HIPAA sets outer limits; the BAA should set tighter ones.
  9. A subprocessor list. AI receptionists rely on other companies for telephony, speech recognition, language models and hosting. Each of those touches PHI. The vendor should list them and confirm each is covered by a BAA or equivalent agreement.
  10. Patient disclosure wording. Callers should be told they are speaking with an automated assistant and, where required, that the call is recorded. Some states require two-party consent for recording. Ask to see the exact greeting and confirm you can change it.

How does the checklist look side by side?

  • Signed BAA, What good looks like: Signed before go-live, covers subprocessors; Red flag: "Not needed for automated systems"
  • Encryption, What good looks like: In transit and at rest, backups included; Red flag: Vague "bank-level security" with no detail
  • Retention, What good looks like: Configurable, deletable on request; Red flag: Kept indefinitely by default
  • PHI minimization, What good looks like: Only booking and routing fields collected; Red flag: Asks for SSN or full history on the phone
  • SMS handling, What good looks like: Opt-in captured, minimal content; Red flag: Texts procedure names without consent
  • Staff access, What good looks like: Individual logins, role permissions; Red flag: One shared password for the office
  • Audit logs, What good looks like: Every play, export and delete recorded; Red flag: No log, or logs only for admins
  • Breach process, What good looks like: Written, with hours-based notification; Red flag: "We've never had one" as the answer
  • Subprocessors, What good looks like: Named list, each under agreement; Red flag: Will not say which AI or telecom providers are used
  • Disclosure wording, What good looks like: Editable greeting, recording notice by state; Red flag: No disclosure, or cannot be changed

What questions should you send a vendor?

Copy these into an email. A serious vendor answers all of them in a day or two; a vague reply is itself an answer.

  1. Will you sign a BAA before we go live? Can you send your standard BAA now?
  2. Which subprocessors (telephony, speech-to-text, language model, hosting) handle our call data, and are they under a BAA with you?
  3. Where are recordings and transcripts stored, and are they encrypted at rest and in transit?
  4. Can we set retention to a specific number of days and delete individual recordings?
  5. Does the AI ask for texting consent, and can we control what appears in SMS?
  6. Does your dashboard support separate user accounts with different permission levels?
  7. Is there an audit log of who accessed each recording?
  8. What is your incident response process and notification timeline?
  9. Is our call data used to train your models, and can we opt out?
  10. Can we edit the greeting to add an automated-assistant and recording disclosure?

Send them to Shtello Connect too. We would rather you ask them of every vendor you evaluate than take anyone's word for it. The short version is on our is an AI receptionist HIPAA compliant page.

What does your own office need to do?

The vendor side is half the job. HIPAA also expects the practice to use the tool properly:

  • Update your risk analysis. Adding an AI receptionist is a change to how PHI flows. Note it in your security risk assessment.
  • Train staff. Anyone with dashboard access should know what they may share, and that transcripts are PHI.
  • Apply minimum necessary. Give the AI a script that collects what booking requires and no more. If it is scheduling in Dentrix or Open Dental, see does an AI receptionist work with Dentrix for what data the integration needs.
  • Update your Notice of Privacy Practices if your compliance advisor recommends mentioning automated call handling.
  • Route clinical questions to a person. The AI should book, confirm and take messages, not give medical guidance. Urgent symptoms should transfer to a clinician or an on-call line.

Practices in specialties such as med spas and physical therapy have the same obligations, even when the service feels more retail than clinical. Our pages for dental offices and medical clinics cover the specifics.

Frequently asked questions

Is any AI receptionist automatically HIPAA compliant?

No. HIPAA does not certify software. A vendor can support compliance by signing a BAA and meeting the Security Rule safeguards, but the practice remains responsible for how the tool is used.

Do I need a BAA if the AI only books appointments?

Almost certainly yes. Booking involves a name, contact details and a reason for the visit, which together are PHI. Any vendor storing that on your behalf is a business associate.

Can the AI text patients appointment reminders?

Yes, when the patient has opted in and the message content is limited to what is needed. Avoid procedure names and clinical detail in texts unless your compliance advisor has approved the wording.

Are call recordings a HIPAA problem?

Recordings are PHI and must be protected like any other record: encrypted, access-controlled, logged and retained only as long as you decide. Check state recording-consent laws as well.

Does using an AI language model mean my data goes to a big tech company?

Often part of the processing does, which is why the subprocessor list matters. Ask whether those providers are under agreement, whether data is used for training, and whether you can opt out.

Should I talk to a lawyer before switching?

Talk to a HIPAA compliance professional or healthcare attorney before go-live. This article is general information to help you ask better questions, not legal advice.

If you want to hear how a compliant front desk call sounds, from the automated-assistant disclosure to the texting opt-in, you can listen to the live demo at Shtello Connect. Plans start at $199/mo on a 12-month plan, plus $0.80 a minute and a one-time $499 setup, and you should ask for the BAA and subprocessor list before you sign anything, from us or anyone else.

Found this helpful? Give it a like.
Your phone, finally answered

Never miss another call, text, or message

Shtello Connect answers 24/7, books the job, and follows up automatically, so you stop losing business to voicemail.

Get your AI front desk live →▶ Hear a live demo
Answers in under 2 rings · Live in days · Cancel anytime after 3 months

Comments

Loading comments...

← Back to all articles