The HIPAA Buyer's Guide for AI Voice Vendors

Last updated: 27 August 2026

HIPAA compliance for an AI voice vendor means the vendor meets five verifiable requirements: a signed Business Associate Agreement before deployment, named encryption standards for data at rest and in transit, a published subprocessor list with BAAs at every layer, a written commitment that Protected Health Information is not used for model training, and audit logs exportable to the practice on demand. There is no government-issued HIPAA certificate. Any vendor presenting one is describing a different framework, usually SOC 2. Compliance is a posture you verify, not a badge you accept. This page provides a weighted scoring framework a practice can use on any AI voice vendor, including us. Ten criteria, 100 points total, with what a strong answer looks like and what a weak answer looks like for each. Print the scorecard at the bottom. Bring it to vendor calls. Score every vendor the same way. Last updated: 2026. ---

Why AI voice needs its own HIPAA framework

Standard healthcare IT procurement checklists were written for systems that store structured records. AI voice systems introduce three exposures those checklists do not cover.

Voice is biometric. A recorded voice identifies a person the way a fingerprint does. Standard de-identification techniques that work on text records do not reliably de-identify audio. This makes "we only use anonymized data" a claim that deserves scrutiny in voice specifically.

The processing chain is longer. A text-based EHR module might touch one cloud provider. An AI voice system routinely touches a telephony provider, a cloud host, a speech recognition service, and a language model provider. Each is a business associate. Each needs a BAA. Compliance leaks at whichever layer lacks one.

Model training is a live question. Traditional software vendors do not have an incentive to retain your data for product improvement in the same way AI vendors do. The question "do you train on our data" did not need asking five years ago. It does now.

The ten criteria, weighted

1. Business Associate Agreement (20 points)

The foundational requirement. HIPAA does not permit PHI to flow to a vendor without one.

Full marks: Vendor provides a standard BAA template on request, signs before the first live call, and the BAA covers all five required sections (permitted uses, safeguards, breach notification, subcontractor requirements, return or destruction on termination).

Partial: BAA available but only at higher pricing tiers, or the template is thin on subcontractor obligations.

Zero: No BAA, BAA "in development," or vendor argues one is not needed.

2. Encryption standards, named (10 points)

Full marks: Vendor names AES-256 at rest and TLS 1.3 in transit, and can describe key management and rotation practice.

Partial: Named standards but vague on key management.

Zero: "Everything is encrypted" with no standard named.

3. Subprocessor disclosure (15 points)

Full marks: Published subprocessor list, publicly accessible, naming each vendor and its role, with confirmation that each operates under a BAA. Willing to provide subprocessor BAA copies for the practice's compliance file.

Partial: List provided on request but not published, or some layers unconfirmed.

Zero: Declines to disclose subprocessors, or claims subprocessors do not handle PHI when they clearly do.

4. Model training commitment (15 points)

Full marks: Written commitment in the BAA that practice PHI is never used to train, fine-tune, or evaluate models, enforced at the infrastructure level.

Partial: Commitment in a policy document but not the BAA, or carve-outs for "anonymized" or "aggregated" data.

Zero: Reserves the right to train on customer data, or cannot answer clearly.

5. Audit logging and export (10 points)

Full marks: Every call, every EHR action, and every administrative access logged. Practice administrators can view logs in-product and export the full record on demand.

Partial: Logging exists but export requires a support ticket, or logs cover calls but not administrative access.

Zero: No customer-accessible audit logs.

6. Breach notification SLA (10 points)

Full marks: Specific commitment substantially shorter than HIPAA's 60-day maximum, stated in hours or days in the BAA, with a defined disclosure package.

Partial: "In accordance with HIPAA" (which defaults to 60 days).

Zero: No stated SLA.

7. Data retention and termination handling (5 points)

Full marks: Defined retention period, configurable within HIPAA bounds, with PHI returned or destroyed within a stated window on termination.

Partial: Retention defined but termination handling vague.

Zero: Indefinite retention, or no documented policy.

8. Minimum necessary access (5 points)

Full marks: Vendor can describe exactly which EHR fields the system reads and writes, and the scope is limited to what the task requires.

Partial: Broad API scope with no articulated limitation.

Zero: Full EHR read access with no explanation of why.

9. Infrastructure location and hosting posture (5 points)

Full marks: PHI hosted in named US regions on HIPAA-eligible infrastructure, not general-purpose consumer services.

Partial: US hosting confirmed but infrastructure tier unclear.

Zero: Hosting location undisclosed or outside intended jurisdiction without a documented basis.

10. Independent security validation (5 points)

Full marks: SOC 2 Type II report available under NDA, or equivalent third-party assessment.

Partial: SOC 2 in progress with a stated target date, or penetration testing documented.

Zero: No third-party validation and none planned.

Scoring bands

ScoreInterpretation
90 to 100Strong compliance posture. Proceed with standard diligence.
75 to 89Good. Identify the gaps and get written commitments on remediation timelines.
60 to 74Meaningful gaps. Do not deploy without closing the highest-weighted misses first.
Below 60Do not proceed. The gaps expose your practice, not just the vendor.

A vendor scoring below full marks on criterion 1 (BAA) should be disqualified regardless of total score. That criterion is not a preference. It is the legal floor.

How to run this evaluation in one vendor call

Thirty minutes, in this order.

Step 1: Send the ten questions in advance

Vendors who receive the list ahead of the call arrive prepared with documentation. Vendors who improvise reveal how much thought they have given the subject.

Step 2: Ask for the BAA template first

Request it before discussing product features. It reframes the conversation from sales to diligence, and the response time tells you something.

Step 3: Score live during the call

Do not reconstruct from memory afterward. Score each criterion as it is answered.

Step 4: Ask the two follow-up questions that matter most

"Can you send the subprocessor list and confirm each has a BAA with you?" and "Is the no-training commitment in the BAA itself or in a separate policy?" These two produce the most differentiation across vendors.

Step 5: File the scorecard

Keep completed scorecards in your compliance file. If OCR ever asks how you evaluated the vendor handling your patient calls, the scorecard is the answer.

The printable scorecard

#CriterionMaxScoreNotes
1Signed BAA before deployment20
2Encryption standards named10
3Subprocessor list published, each under BAA15
4No PHI used for model training (in BAA)15
5Audit logs exportable on demand10
6Breach notification SLA under 60 days10
7Retention and termination handling defined5
8Minimum necessary access scope5
9US hosting on HIPAA-eligible infrastructure5
10Third-party security validation5
Total100

Download as PDF: [FILL: PDF link once produced]

Related reading on this site: the athenahealth AI receptionist page for the live integration, how AI phone agents work for the mechanics, the published AI receptionist pricing, and the healthcare AI glossary for any term above. For the rules themselves rather than our summary, Health and Human Services publishes the HIPAA Rules, and the Bureau of Labor Statistics publishes the wage data for medical secretaries behind the staffing figures.

The HIPAA Buyer's Guide for AI Voice Vendors FAQ

The questions that come up most often on this subject.

Still have questions?

Can't find the answer you're looking for? Reach out to our team and we'll get back to you shortly.

Yes. A voice recording that identifies a patient and relates to their health, treatment, or payment is Protected Health Information under HIPAA. Voice is also biometric, which makes standard de-identification approaches unreliable for audio.

Yes. Any subprocessor that creates, receives, maintains, or transmits PHI on the vendor's behalf is itself a business associate and requires a BAA. That typically includes the telephony provider, cloud host, speech recognition service, and language model provider.

HIPAA's outer limit is 60 days from discovery. Serious vendors commit to substantially shorter windows, commonly 24 to 72 hours, written into the BAA. A vendor defaulting to the statutory maximum is optimizing for their own exposure rather than yours.

Send them the ten questions and request written remediation timelines on the gaps. Document the exchange in your compliance file. If they cannot close the highest-weighted gaps within a defined period, the safer path is to migrate.

Yes. HIPAA makes no distinction based on vendor size. A two-person company handling PHI carries the same business associate obligations as a large cloud provider. Evaluate the posture, not the headcount. ---

Now hear one take a real call.

Twenty minutes. Your EHR, a real call, and straight answers to anything on this page.

Book a demo