Clinivocx

Compliance

Is AI HIPAA Compliant? The Nine Questions That Decide

When HIPAA applies to AI tools, why a BAA is non-negotiable, and the nine questions to ask any AI phone vendor.

Ade MercerFounder, ClinivocxUpdated 7 min read

The honest answer is a hedged yes. AI tools can absolutely be used in a HIPAA-compliant way, and many practices already do. But no model, no API, and no voice agent is HIPAA compliant on its own. Compliance is a property of the deployment: the agreements signed, the data handled, the controls in place, and your own policies around the tool. A vendor who says "our AI is HIPAA compliant" and stops there has told you nothing.

When HIPAA applies

HIPAA reaches your AI vendor through two definitions worth knowing in plain language.

  • Covered entities are health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with certain transactions. If you bill insurance electronically, that is you.
  • Business associates are the vendors who create, receive, maintain, or transmit protected health information on a covered entity's behalf. Your answering service, your transcription tool, and your AI phone agent are all business associates the moment they touch patient data.
  • Protected health information is individually identifiable health information: a patient's name attached to an appointment, a phone number attached to a reason for the visit, a recording of someone describing their symptoms. The rule of thumb that keeps practices out of trouble is that if it identifies a person and relates to their care or payment for care, treat it as PHI.

Note what this means for phone calls specifically. A caller saying their name and asking for a follow-up on last week's lab results has created PHI in the first ten seconds. There is no version of an AI answering a medical line where PHI is not involved.

Why a BAA is non-negotiable

A business associate agreement is the contract that makes a vendor legally accountable for the PHI they handle: what they may use it for, the safeguards they must maintain, their obligation to report breaches, and what happens to the data when the relationship ends.

No BAA, no PHI. If a vendor will not sign one, the conversation about their features is over.

This is the cleanest filter in vendor selection. It takes one email to apply, it cannot be talked around, and it removes most of the AI tools being pitched to medical practices in a single step.

Why consumer ChatGPT is not HIPAA compliant for PHI

This comes up constantly, so it is worth being blunt. OpenAI does not offer a business associate agreement on consumer ChatGPT plans. Without a BAA, pasting a patient's name, chart note, or call transcript into the chat box is a disclosure of PHI to a vendor with no HIPAA obligations to you. It does not matter how careful the prompt is or whether chat history is turned off.

Enterprise and API products from AI vendors are frequently governed by different terms, and some are available under a BAA. Do not assume; verify the current terms directly with the vendor, in writing, before anything clinical goes near the tool. The same test applies to every AI note-taker, scribe, and summarizer your staff might install on their own.

The nine questions to ask any AI vendor

  1. Will you sign a BAA? Ask for the actual document, not a reassurance. Read what it says about permitted uses.
  2. Exactly what PHI do you capture? Names, phone numbers, dates of birth, reasons for calling, insurance details: make them enumerate it rather than describe it in general terms.
  3. Do you record calls, and how long do you retain data? Ask for the retention period in days, whether you can shorten it, and whether deletion is real deletion.
  4. How is data encrypted? In transit and at rest, and who holds the keys.
  5. How is access controlled? Role-based access, multi-factor authentication for every account, and a process for removing access when staff leave.
  6. Do you keep audit logs, and can I see mine? You need to be able to answer who accessed what, and when.
  7. What is your SOC 2 status? SOC 2 is not required by HIPAA, but the answer tells you how mature the security program is. Accept a straight "not yet, and here is our timeline"; treat vagueness as a red flag.
  8. What is your breach notification process? Who tells you, how fast, and what the BAA commits them to.
  9. Who are your subprocessors? The model provider, the telephony carrier, the cloud host, the transcription layer. Every one of them touches your data, and each needs to be covered downstream.

Get the answers in writing and keep them with your vendor file. When a risk assessment comes around, that file is the difference between a documented decision and an improvised one.

How Clinivocx answers them

We hold ourselves to the same nine questions, and we would rather lose a deal than fudge one of them. Our full detail lives on the HIPAA page; the summary:

  • BAA: yes, signed before go-live, every customer, no exceptions.
  • PHI captured: what a phone call requires, with PHI masking applied so sensitive fields are not exposed where they are not needed.
  • Access control: multi-factor authentication is mandatory, not optional, on every account.
  • Audit logs: maintained, and reviewable.
  • Integrations: webhook-based and HMAC-signed. We do not integrate with your EHR, which is a deliberate scope decision and one fewer path for PHI to travel.
  • SOC 2: we are not SOC 2 certified today. We would rather tell you that here than have you find out in a security review.

If you are evaluating an AI medical receptionist, run those nine questions past every vendor on your list, including us, and compare the written answers rather than the sales language.

One closing note

This article is educational content, not legal advice. HIPAA obligations depend on your specific circumstances, and your compliance officer or healthcare counsel should review any vendor arrangement involving PHI before it goes live.

Frequently asked questions

Hear it answer your phones

A 30-minute demo with your real call scenarios. No commitment.