Last updated: July 2026. In 2015, incidents involving a business associate accounted for 5% of all individuals affected by healthcare data breaches. By 2025 that share had reached 65% (The HIPAA Journal analysis of the HHS OCR breach portal, June 2026). Two out of every three patients whose records were exposed last year were exposed in a breach that involved a vendor. That is the backdrop for a question we get from almost every dental and medical practice we talk to: is a HIPAA compliant AI receptionist actually a thing you can buy, and how would you know?
This article is general information, not legal advice. HIPAA obligations depend on your practice, your state, and how your calls are actually handled. Review your setup with your own privacy counsel or compliance officer before relying on it.
Key takeaways
- No software is "HIPAA certified." HHS recognizes no certification for any product or vendor. Treat the badge as a marketing claim.
- An AI receptionist is almost always a business associate. HHS wrote that the conduit exception covers "only those entities providing mere courier services" (78 Fed. Reg. 5571). Anything that transcribes or stores a patient call sits well past that line.
- No BAA means no deployment. A signed business associate agreement under 45 CFR 164.504(e) is what turns a vendor from an exposure into a compliant part of your operation.
- Your vendor is directly liable too, and that does not reduce your own exposure. OCR can enforce 10 HIPAA provisions straight against a business associate.
- 2026 penalties run from $145 to $73,011 per violation, capped at $2,190,294 a year for uncorrected willful neglect (91 Fed. Reg. 3665).
- The Security Rule rewrite slipped to July 2027. Most articles still say spring 2026. Buy against the proposed baseline anyway.
Is an AI receptionist HIPAA compliant?
A HIPAA compliant AI receptionist is achievable, but compliance is a property of the arrangement you build rather than a feature you buy. Three conditions have to hold at once. The vendor has to qualify and act as a business associate. A signed business associate agreement has to be in place before the system handles a single patient call. And the safeguards behind it have to actually exist and be documented, which means encryption, access controls, audit logging, and breach notification.
Where the liability sits is what makes this framing matter. HIPAA obligations do not transfer to your vendor when you sign a contract. They extend to your vendor while remaining yours. A practice that routes patient calls through an AI phone system with no BAA in place is very likely making an impermissible disclosure of protected health information from the first call onward, however strong the encryption happens to be. The technology is rarely the compliance problem. The paperwork and the diligence are.
Is there such a thing as "HIPAA certified" AI software?
No. There is no government HIPAA certification for any product, vendor, or platform. In its guidance on Security Rule compliance, HHS states that it "does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations under the Security Rule." It adds that a third-party certification "does not preclude HHS from subsequently finding a security violation" (HHS OCR HIPAA FAQ). The department made the same point in the Security Rule preamble, noting that "HHS does not rate or endorse any such guidelines and/or models" (68 Fed. Reg. 8334, 8337).
This is worth knowing because "100% HIPAA certified" is among the most common claims in AI receptionist marketing, and it tells you quickly whether a vendor understands the rule it is selling against. A SOC 2 Type II report or a HITRUST assessment is genuinely useful evidence of controls. Neither is certification, and no auditor can grant it.
Is an AI receptionist a business associate, or just a phone line?
An AI receptionist that transcribes, stores, or logs patient calls is a business associate. This question decides whether you need a BAA at all, and vendors occasionally argue their way out of it by claiming they are merely a conduit for information, the way a phone carrier is. That argument rarely survives contact with the rule.
Under 45 CFR 160.103, a business associate is anyone who "creates, receives, maintains, or transmits" protected health information on behalf of a covered entity. HHS addressed the conduit question head-on in the 2013 Omnibus Final Rule:
"The conduit exception is a narrow one and is intended to exclude only those entities providing mere courier services, such as the U.S. Postal Service or United Parcel Service and their electronic equivalents, such as internet service providers (ISPs) providing mere data transmission services." A conduit, HHS explained, "transports information but does not access it other than on a random or infrequent basis." By contrast, "a data storage company that has access to protected health information qualifies as a business associate, even if the entity does not view the information or only does so on a random or infrequent basis."
HHS, HIPAA Omnibus Final Rule, 78 Fed. Reg. 5566, 5571 (January 25, 2013)
Now apply that to a voice AI. It listens to the caller, converts speech to text, works out what the call is about, writes a summary, pushes an appointment into your scheduling system, and keeps a record. That is persistent access to health information rather than transient transport, so the conduit exception does not reach it. Pure call forwarding with no access to content sits closer to the line, but almost nothing sold as an AI receptionist works that way. If a vendor claims otherwise, ask them to put that position in writing.
What has to be in the business associate agreement?
A compliant BAA must define the permitted uses and disclosures of PHI, require the vendor to apply appropriate safeguards and comply with the Security Rule, require it to report breaches and security incidents to you, bind its own subcontractors to the same terms, and provide for return or destruction of your data when the contract ends. Those terms come from 45 CFR 164.504(e), and they are a floor, not a ceiling.
The subcontractor clause matters more with AI
A voice agent usually sits on top of a stack: a telephony provider, a speech-to-text service, a language model, and a hosting environment. Every link that touches PHI needs to be covered by a chain of agreements. Ask your vendor to name its subprocessors and confirm each one is under a BAA. A vendor that cannot answer has not mapped its own data flows, which is precisely the work you are trusting it to have done.
Two provisions practices regret leaving vague
First, the breach notification timeline: how fast the vendor must tell you, and through which channel. Second, retention. Decide up front how long call recordings, transcripts, and summaries are kept, and get that number into the contract rather than accepting a default. Many platforms retain audio indefinitely because it is useful for tuning their systems. Indefinite retention of patient audio expands the blast radius of any future breach and creates records you may have to produce later, so shorter is usually better.
Who is on the hook if the AI vendor gets breached?
Both parties. Since the HITECH Act, business associates have been directly liable for a defined set of HIPAA obligations, and your own breach-notification clock keeps running regardless of what your vendor does. OCR published a fact sheet on May 24, 2019 listing the 10 provisions it can enforce straight against a vendor, among them Security Rule compliance, impermissible uses and disclosures, failure to notify the covered entity of a breach, failure to apply the minimum necessary standard, and failure to sign BAAs with its own subcontractors.
A settlement announced on March 5, 2026 shows how this plays out for exactly this audience. MMG Fusion, a Maryland software company serving oral healthcare providers, was infiltrated in December 2020 in an incident affecting roughly 15 million individuals. OCR only learned of it when someone filed a complaint in January 2023. The company settled for $10,000, an amount OCR attributed to its limited ability to pay, plus a three-year corrective action plan (HHS OCR; The HIPAA Journal). Among the cited failures: no thorough security risk analysis, an impermissible disclosure, and no notification to the provider clients whose patients were affected. Those practices spent two years unable to meet obligations they did not know had been triggered.
"When a breach occurs, business associates must notify affected covered entities without unreasonable delay and within 60 calendar days of discovery. This timeliness is crucial for a covered entity to meet its own breach notification obligations, such as timely notification to HHS and to individuals."
Paula M. Stannard, Director, HHS Office for Civil Rights, announcing the MMG Fusion settlement, March 5, 2026
Note the small settlement against a very large breach. A vendor's ability to pay a penalty is not the same as its ability to absorb your risk, and a thinly capitalized vendor can leave you carrying the consequences almost alone.
Do not skip your own risk analysis
Adding any vendor that handles PHI should trigger an update to your security risk analysis under 45 CFR 164.308(a)(1)(ii)(A). This is the single most frequently cited failure in OCR enforcement, and it was the lead finding against MMG Fusion. Document what the AI system touches, what could go wrong, and how you have mitigated it. That document is what an investigator asks for first.
What does HIPAA require of the call itself?
Appointment reminders are permitted without patient authorization, because HHS treats them as part of treatment, and leaving a message on an answering machine is allowed. What governs the content is the minimum necessary standard at 45 CFR 164.502(b): practice name and a callback number are appropriate, while the reason for the visit, test results, or clinical detail are not.
The requirement almost nobody configures for is 45 CFR 164.522(b). A covered provider "must permit individuals to request and must accommodate reasonable requests by individuals to receive communications of protected health information by alternative means or at alternative locations," and it "may not require an explanation from the individual as to the basis for the request." So when a patient asks you to call their mobile instead of their home, or to leave no detail on voicemail, you generally have to accommodate that request, and you cannot ask them why. The rule does let a provider require the request in writing and clarify how payment will be handled, but "no" is not on the menu for a reasonable ask.
An automated calling system needs somewhere to store that preference and needs to honor it on every subsequent call. Ask any vendor to show you where that setting lives. It is a quick, concrete test of whether a product was built for healthcare or simply pointed at it.
How do front-desk options compare under HIPAA?
Only two of the five common options require a BAA: a human answering service and an AI receptionist. The other three keep patient information inside your own control, which moves the compliance burden rather than removing it. The comparison below is about HIPAA posture specifically, not cost or call quality.
| Option | Business associate? | BAA required? | Where PHI ends up | Main compliance risk |
| Voicemail on your own system | No, if the system is yours | No | Your phone system and staff devices | Messages audible in shared spaces; no audit trail; unreturned calls |
| Telephone carrier | No, if transmission only | No, if transmission only | In transit; voicemail storage changes the answer | Exception is lost once the carrier stores or processes call content |
| Human answering service | Yes | Yes | Vendor call center, agent notes, message logs | Agent training and turnover; message handling; subcontracted overflow centers |
| In-house front desk | No, staff are workforce members | No | Your systems | Workforce training, sanctions policy, and access controls are all on you |
| AI receptionist | Yes, in nearly all configurations | Yes | Transcripts, recordings, summaries, CRM and scheduling records | Unsigned BAA; unmapped subprocessors; retention defaults nobody reviewed |
Keeping everything in-house puts the burden on your own training and access controls. Bringing in a vendor moves part of it into a contract. An AI receptionist is only riskier than a human answering service if you skip the diligence, and it is considerably more auditable if you do not, since every interaction is logged rather than depending on what an agent remembered to write down.
What are the penalties if you get this wrong?
Between $145 and $73,011 per violation in 2026, with an annual cap of $2,190,294 for willful neglect you never corrected. Penalties are tiered by culpability and adjusted for inflation each year; the current amounts took effect January 28, 2026 (91 Fed. Reg. 3665).
| Tier | Culpability | Per violation | Annual cap OCR says it applies |
| 1 | Did not know | $145–$73,011 | $36,505 |
| 2 | Reasonable cause | $1,461–$73,011 | $146,053 |
| 3 | Willful neglect, corrected | $14,602–$73,011 | $365,052 |
| 4 | Willful neglect, not corrected | $73,011–$2,190,294 | $2,190,294 |
The statutory annual cap is $2,190,294 for every tier. The lower figures in the last column come from an April 2019 Notice of Enforcement Discretion (84 Fed. Reg. 18151), in which OCR said it would apply reduced caps to the first three tiers pending future rulemaking, adjusted here for 2026 inflation (The HIPAA Journal, January 2026). That posture is not statute and OCR could revert, so plan against the higher number.
The fine is rarely the largest cost anyway. A healthcare data breach averaged $7.42 million in IBM's 2025 Cost of a Data Breach Report, down from $9.77 million the year before, and healthcare breaches took roughly 279 days to identify and contain (reported by The HIPAA Journal). That is about nine months of exposure before an incident is closed.
Is HIPAA about to change for AI phone systems?
Yes, eventually, and the timeline just moved. On January 6, 2025, OCR proposed the first serious overhaul of the HIPAA Security Rule in more than two decades (90 Fed. Reg. 898). The proposal would erase the distinction between "required" and "addressable" safeguards, making nearly all of them mandatory. It would also require encryption of electronic PHI at rest and in transit, multi-factor authentication, a technology asset inventory and network map, regular vulnerability scanning and penetration testing, and stronger verification that business associates have actually implemented what they promised.
As of July 2026 it is not final. OCR is still working through more than 4,700 public comments, over 100 hospital systems and provider associations have asked HHS to withdraw the proposal, and the Unified Agenda has moved the rulemaking to long-term actions with anticipated final action in July 2027 (Holland & Knight, July 6, 2026). Plenty of pages still promise spring 2026. They are out of date.
The practical read for a practice buying now: pick a vendor that already meets the proposed baseline. Encryption everywhere, MFA, a documented asset inventory, and annual evidence of safeguards are all things a serious vendor can demonstrate today. Buy to the proposed standard and you will not be renegotiating in 2027.
What should you ask an AI receptionist vendor before signing?
Ten questions, in the order that matters. Any vendor selling into healthcare should answer all of them in writing, without hesitation.
- Will you sign a business associate agreement, and can we see your standard BAA before we commit?
- Who are your subprocessors for telephony, transcription, language modelling, and hosting, and is each one under a BAA?
- Is PHI encrypted in transit and at rest, and to what standard?
- Are call recordings and transcripts retained, for how long, and can we set that retention ourselves?
- Is our data ever used to train models, whether yours or a third party's?
- Who on your team can access our call data, and is that access logged and auditable?
- How quickly will you notify us of a breach or security incident, and through what channel?
- Can the system record and honor a patient's request for confidential communications under 45 CFR 164.522(b)?
- Do you have a current SOC 2 Type II report or equivalent independent assessment we can review?
- What happens to our data if we cancel?
Question five has changed most in the last two years, and it separates general-purpose voice AI platforms from healthcare-ready ones. "No" belongs in the contract, not just in the sales call.
When should a human still take the call?
Distress calls, anything needing clinical triage, complaints about care received, requests to discuss test results, and bereavements should reach a person quickly. AI handles structure well. It does not hear fear in a caller's voice the way your longest-serving front desk staffer does, and pretending otherwise does patients a disservice.
The sensible design puts AI in front as the layer that guarantees the call is answered and understood, then either books it or hands it to the right person with context attached. In our deployments, escalation rules are consistently the most-edited part of the configuration during the first two weeks, because owners only discover their real triage logic once they watch how calls actually arrive. We now expect that, and it is a large part of why the testing window exists at all.
How AIEmply approaches HIPAA
AIEmply is HIPAA-ready for healthcare clients, with enterprise-grade encryption, and your data is never shared with third parties. We are GDPR and CCPA compliant as well, and AIEmply is a product of Veltro Systems LLC. Consistent with everything above, two caveats we would rather state plainly. No vendor is "HIPAA certified," ourselves included, because HHS certifies no one. And HIPAA-ready becomes HIPAA-covered only once a signed business associate agreement is in place, so ask us for our BAA during your setup consultation before any patient calls get routed. Apply the ten questions above to us as rigorously as to anyone else.
Operationally, the relevant number for a compliance conversation is the audit trail: the AI answers 100% of calls against roughly 60% handled manually and picks up in under 3 seconds, and every interaction is logged, which is the kind of record the Security Rule expects you to be able to produce. Practices are typically ready to test in 1–2 weeks.
The bottom line
HIPAA is not an obstacle to a HIPAA compliant AI receptionist. It is an obstacle to a careless one. The rule does not care whether a human or a model answered the phone. It cares whether the entity handling patient information is under a business associate agreement, applies real safeguards, limits what it discloses to the minimum necessary, and tells you promptly when something goes wrong.
So run the diligence instead of trusting the badge. Get the BAA signed before go-live, map the subprocessors, set your own retention, confirm your data will not train anyone's model, and buy against the proposed Security Rule baseline. Do that and the vendor side of the question is handled. Your own risk analysis, workforce training, and policies remain a separate exercise, and a real one. Then you are back to the question that moves revenue: whether the phone gets answered when a new patient calls at 7pm on a Friday.
If you want the clinical-workflow detail rather than the compliance detail, our AI receptionist for dental clinics page covers new-patient intake, emergency triage, and hygiene scheduling, and how AI captures every new-patient call works through the numbers. AI disclosure and call-recording law is a separate question from HIPAA, covered in our guide to AI receptionist disclosure rules. New to the category? Start with how an AI receptionist works.
100% Answer Rate • Ready in 1–2 Weeks • Performance Guarantee
Want to see how this would run in your practice, BAA included? Book a 15-minute consultation and we will walk through your call flow, your compliance requirements, and what a configured AI Employee would handle. Plans and included minutes are on our pricing page, starting at $149 per month. Billing starts only after your AI Employee is live. If the first month delivers no measurable result, the next month is free. No credit card required.
Frequently asked questions
Does HIPAA apply if we are a cash-only practice?
Possibly not. A provider is a covered entity only if it transmits health information electronically in connection with a HIPAA standard transaction, such as an electronic claim or eligibility check (45 CFR 160.103). A genuinely cash-only practice that files nothing electronically may fall outside HIPAA, though state medical privacy laws still apply and are sometimes stricter. Most practices bill insurance electronically and are covered.
Do we need a BAA with our phone carrier?
Generally no, as long as the carrier only transmits calls. HHS treats pure transmission services as conduits. The answer changes if the carrier stores voicemail, records calls, or processes call content, because storage defeats the conduit exception. Check what your provider actually retains rather than assuming, since voicemail-to-email and call recording features are commonly enabled by default.
How long can an AI receptionist keep call recordings?
HIPAA sets no fixed retention period for recordings, so the limit is whatever your BAA and your own policy specify. Many platforms default to indefinite retention because the audio is useful for tuning their models. Set an explicit period, get it into the contract, and make sure deletion actually happens. Longer retention means a larger blast radius if the vendor is ever breached.
What if our AI vendor uses OpenAI or another model provider?
Then that provider is a subcontractor handling PHI, and it needs to be under a business associate agreement too. HIPAA requires business associates to bind their own subcontractors to equivalent terms (45 CFR 164.504(e)). Ask your vendor to name every subprocessor in its stack and confirm the chain of agreements. A vendor that cannot produce that list has not mapped its own data flows.
Is a SOC 2 report enough on its own?
No. A SOC 2 Type II report is credible evidence that a vendor's controls were tested by an independent auditor, and it is worth reviewing. It is not HIPAA compliance and it does not replace a BAA. HIPAA requires a specific contractual relationship and specific safeguards; SOC 2 evaluates a different control framework. Treat it as supporting evidence alongside the agreement, never instead of it.
Do we need patient consent to use an AI receptionist?
HIPAA does not require separate patient authorization for a business associate to handle calls for treatment, payment, or healthcare operations, so a BAA covers the privacy side. Separate rules may still apply: several states require disclosure that a caller is speaking to AI, and call recording consent laws vary by state. Those are distinct from HIPAA and worth checking independently.
What happens if our AI receptionist vendor has a data breach?
Both parties can face enforcement. Business associates are directly liable for 10 HIPAA provisions, including Security Rule compliance and failure to notify you of a breach, per OCR's May 2019 fact sheet. Your own obligations to notify patients and HHS still apply and still run on a clock, which is why the notification timeline in your BAA is one of its most important terms.
Do dental practices need a HIPAA compliant AI receptionist?
Nearly always, because most dental practices bill insurance electronically and are therefore covered entities, and because appointment details, insurance information, and treatment discussions are all protected health information. Any system answering those calls needs a BAA. The March 2026 OCR settlement with MMG Fusion, a software vendor serving dental providers whose breach affected roughly 15 million individuals, shows the exposure is not theoretical.
Sources
- HHS Office for Civil Rights, "Are we required to 'certify' our organization's compliance with the standards of the Security Rule?" HIPAA FAQ, retrieved July 2026. hhs.gov
- HHS, Health Insurance Reform: Security Standards, Final Rule, 68 Fed. Reg. 8334 (February 20, 2003), retrieved July 2026. govinfo.gov
- HHS, Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules (Omnibus Final Rule), 78 Fed. Reg. 5566 at 5571, January 25, 2013, retrieved July 2026. govinfo.gov
- 45 CFR 160.103, definitions of business associate and covered entity, retrieved July 2026. Cornell Legal Information Institute
- 45 CFR 164.308(a)(1)(ii)(A), security risk analysis, retrieved July 2026. Cornell Legal Information Institute
- 45 CFR 164.504(e), business associate contracts, retrieved July 2026. Cornell Legal Information Institute
- 45 CFR 164.502(b), minimum necessary standard, retrieved July 2026. Cornell Legal Information Institute
- 45 CFR 164.522(b), confidential communications requirements, retrieved July 2026. Cornell Legal Information Institute
- HHS Office for Civil Rights, "Direct Liability of Business Associates," fact sheet, May 24, 2019, retrieved July 2026. hhs.gov
- HHS Office for Civil Rights, "OCR Settles HIPAA Investigation with MMG Fusion," March 5, 2026, retrieved July 2026. hhs.gov
- HHS, Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties, 84 Fed. Reg. 18151, April 30, 2019, retrieved July 2026. govinfo.gov
- HHS, Annual Civil Monetary Penalties Inflation Adjustment, 91 Fed. Reg. 3665, January 28, 2026, retrieved July 2026. govinfo.gov
- HHS, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, Proposed Rule, 90 Fed. Reg. 898, January 6, 2025, retrieved July 2026. govinfo.gov
- Holland & Knight, "HIPAA Security Rule Amendments Now Projected for July 2027," July 6, 2026, retrieved July 2026. hklaw.com
- The HIPAA Journal, "MMG Fusion Settles HIPAA Investigation," March 5, 2026, retrieved July 2026. hipaajournal.com
- The HIPAA Journal, "Business Associates Face Increased Regulatory Scrutiny as Vendor Breaches Soar," June 15, 2026, retrieved July 2026. hipaajournal.com
- The HIPAA Journal, "HIPAA Violation Fines," updated January 28, 2026, retrieved July 2026. hipaajournal.com
- The HIPAA Journal, "Average Cost of a Healthcare Data Breach," reporting IBM Cost of a Data Breach Report 2025, retrieved July 2026. hipaajournal.com