Back to all writing

Is AI phone software HIPAA compliant?

It depends entirely on the vendor, there is no certificate anyone can show you, and here is how to tell the difference in one conversation.

Agni Patel, August 27, 2026, 8 min read

The question is asked as though it has one answer for the whole category. It does not. Some products in this market are built to hold protected health information properly and some are general purpose voice tools with a healthcare page bolted on.

AI phone software is HIPAA compliant only when the specific vendor encrypts patient data in transit and at rest, restricts and logs access to it, holds every supplier that touches it to the same obligations, keeps it out of general purpose model training, and commits to all of that in a signed written agreement with the practice. Compliance is a property of the vendor and the deployment, not of the technology.

This post is vendor neutral on purpose. I sell in this category, so treat the checklist as something to use on me as well as on everybody else.

Why does voice data count as PHI?

Because a call about a patient appointment identifies a person and relates to their care, which is the whole test.

Under 45 CFR 160.103, protected health information is individually identifiable health information transmitted or maintained in any form by a covered entity or by a vendor acting on its behalf. A recording in which a patient gives their name and date of birth and asks to move an appointment with their cardiologist meets that definition without any interpretation required.

Three things follow from that, and each one gets missed regularly.

  • The audio is PHI, not just the transcript. Some vendors will tell you only the text counts. That is wrong, and someone who believes it has not thought about where the recordings are stored
  • Metadata can be PHI too. A call log showing a phone number, a timestamp and the fact that the call was routed to an oncology line is identifiable health information in most readings
  • Every system the audio passes through is inside the compliance boundary. If the call is transcribed by one supplier and interpreted by another, both of them are holding PHI

If a vendor tells you call audio is not protected health information, or that only the transcript is, end the evaluation there. It is not a debatable position and it tells you what the rest of the architecture looks like.

What does HIPAA compliance actually require from a vendor?

The Security Rule at 45 CFR 164 is organized into administrative, physical and technical safeguards. Translated into questions a practice owner can ask on a call, it comes to six things.

RequirementWhat a strong answer sounds like
Encryption in transitA named standard such as TLS 1.3 on every hop, including between the vendor and its own suppliers
Encryption at restA named standard such as AES 256, covering recordings, transcripts, logs and backups, with managed key rotation
Access controlRole based, least privilege, with named roles inside the vendor who can see PHI and a stated reason each one needs to
Audit loggingEvery call, every EHR action and every administrative access recorded, exportable by the practice on demand
Supplier coverageEvery supplier that can touch PHI held to the same obligations in writing, with the list available to a practice under confidentiality
Model trainingA flat no. Patient data is never used to train general purpose models, enforced at the infrastructure level rather than by policy alone

On top of those six sits the written agreement between you and the vendor that puts the obligations on paper and makes them enforceable. A vendor who will not sign one before the first live call is not offering you compliance, whatever the web page says.

Breach notification belongs in that agreement too. The legal floor is notification without unreasonable delay and no later than sixty days after discovery. Sixty days is a floor, not a target, and a serious vendor will commit to something much shorter in writing.

What does HIPAA compliance not mean?

Four misunderstandings that come up in almost every evaluation, and all four are used commercially.

It does not mean certified. There is no HIPAA certificate and no agency that issues one. The Office for Civil Rights enforces the rules, it does not accredit vendors. Any badge you see is either self declared or issued by a private auditor against their own criteria, which is a different claim entirely and one worth reading carefully.

It does not mean SOC 2. A SOC 2 report is a genuine, independently audited signal about security controls, and it is not the same thing as HIPAA compliance. A vendor can hold one without meeting HIPAA obligations, and can meet HIPAA obligations without holding one. Ask about both, separately.

It does not mean the whole stack is covered. This is the gap that catches practices out. A vendor can run a genuinely well built compliant platform and still route audio through a supplier operating outside those obligations, which puts a hole straight through the middle of it. Coverage is only as good as its weakest link.

It does not mean your own obligations go away. You remain the covered entity. Your risk analysis, your workforce training, your access policies and your incident response are still yours, and a vendor cannot take them on for you.

How do you verify a vendor claim?

Five moves, in order, and none of them require a lawyer for the first pass.

  1. Ask the six requirement questions above and get the answers in writing rather than on a call. Written answers are noticeably more careful than spoken ones
  2. Ask for the list of suppliers that can touch PHI, under confidentiality. Most vendors will not publish it publicly and that is reasonable. Refusing to give it to a customer under an agreement is not
  3. Ask what happens to your data when you leave. Returned or destroyed, on what timeline, with what confirmation. A vendor who has not thought about the exit has not thought about the relationship
  4. Ask for the retention period on call recordings and whether it is configurable per practice. Indefinite retention is a red flag and usually means something downstream depends on the data
  5. Ask them to describe their last security incident and what changed afterwards. The answer none is either true or evasive, and how they handle the question tells you which

Then read the agreement itself. You are checking that permitted uses are specific rather than broad, that safeguards are named rather than described as reasonable, that suppliers are covered explicitly, that breach notification has a stated timeline, that data is returned or destroyed at the end, and that you can terminate for a material breach. That is a ten minute read on a standard document.

Run this checklist on MedPhone

Questions people ask

Is AI phone software HIPAA compliant?

Only if the specific vendor makes it so. Compliance is a property of the vendor, the architecture and the signed agreement rather than of the technology category. Two products that look identical in a demo can sit on opposite sides of this.

Is there a HIPAA certification a vendor can show me?

No. No government body certifies HIPAA compliance. Any badge is self declared or issued by a private auditor against their own criteria. That is why the questions you ask matter more than the logos on the footer.

Are call recordings really PHI?

Yes. A recording that identifies a patient and relates to their treatment or payment for treatment is protected health information under 45 CFR 160.103. So is the transcript, and in most readings so is call metadata that identifies the patient and the service line.

Does SOC 2 mean a vendor is HIPAA compliant?

No, though it is a useful independent signal about security controls. The two frameworks overlap and neither substitutes for the other. Ask about both separately rather than accepting one as evidence of the other.

What if the vendor is compliant but their suppliers are not?

Then the deployment is not compliant. PHI leaves the protected boundary the moment it reaches an uncovered supplier. This is the most common real world gap in the category and it is invisible unless you ask for the supplier list.

Do we still have HIPAA obligations if the vendor handles the calls?

Yes. You remain the covered entity. Risk analysis, workforce training, access policies and incident response stay with the practice. A vendor reduces your exposure on the phone system, it does not transfer your obligations.

Do we have to tell patients they are speaking to an AI?

HIPAA does not address it, but state law increasingly does and several states are moving towards requiring disclosure for AI voice in healthcare settings. Check with your state medical board, and in the meantime disclose anyway. Patients react far worse to discovering it later.

Written by

Agni Patel is the founder and CEO of MedPhone, a HIPAA compliant AI phone agent for medical practices.

Want this run on your practice?

Bring twenty minutes and your call reports. We will use your call volume and your payer mix rather than the benchmarks in this post.

Book a 20 minute demo