Clinivocx

Trust and security

HIPAA-compliant AI phone answering

Nine questions every practice should ask an AI phone vendor, answered here in public.

Is an AI phone answering service HIPAA compliant? Yes, when specific conditions are met: the vendor signs a Business Associate Agreement, limits the PHI it collects, encrypts it in transit and at rest, restricts and logs access to it, and names its subprocessors. Below are Clinivocx's public answers to all nine.

Gboyega OfiFounder, ClinivocxUpdated

The checklist

Our answers, in the order you should ask them

Every claim here is one we can evidence. Where we cannot yet, you see a placeholder, not a promise.

01

Will you sign a Business Associate Agreement?

Yes. Clinivocx signs a BAA with every customer, and it is included in all three plans at no extra charge. It is signed before your line is forwarded, not after the first patient call.

This is the question that ends most vendor evaluations. Any AI phone tool that handles patient calls for you is a business associate under HIPAA, and one that declines to sign is telling you it is not built for healthcare.

02

What patient information does the AI actually capture?

Caller name, phone number, the reason for the call, and the details of any appointment booked or changed. That is the working set, and it is deliberately small.

Clinivocx has no EHR or EMR connection, so it cannot read charts, lab results, medication lists, or claims. Less PHI in the system means a smaller surface to secure and a shorter security review for you.

03

Do you record calls, and do you store transcripts?

Call recording is an opt-in toggle at the practice level and is off until you enable it. Some practices want the audio; others want none of it. That is your call, not ours.

Transcripts are produced for every call either way, because the transcript is what generates your summary, sentiment, and action items, and it is the record of what the AI told your patient.

04

How long is call data retained?

[PLACEHOLDER: exact retention period for recordings, transcripts, and call metadata; whether retention is configurable per practice; and whether a zero-retention option is offered. Do not launch this page without a real answer here.]

05

Is data encrypted in transit and at rest?

Yes. Patient data is encrypted in transit and encrypted at rest across the platform.

[PLACEHOLDER: confirm cipher and protocol specifics with engineering before naming AES-256 or specific TLS versions on this page. We would rather publish a general true statement than a specific one we cannot evidence.]

06

Who inside the vendor can see PHI?

Access is role-based, and roles that do not need patient identifiers see them masked. Multi-factor authentication is mandatory for every dashboard user, with no opt-out for administrators.

Sessions expire on HIPAA-grade timeouts and the screen locks on inactivity, so an unattended workstation at a busy front desk is not an open chart.

07

Are PHI access events logged, and can we get the logs?

Yes. Every access to protected health information is written to an audit log with the user, the record, the action, and the timestamp.

Those logs are exportable as CSV or JSON, which matters when your own compliance review, or an investigation, needs evidence rather than assurances.

08

Are you SOC 2 certified?

No. Clinivocx is not SOC 2 certified today. We will not blur that on a trust page, and you should be skeptical of any vendor that answers this one vaguely.

What we offer instead is specific: a signed BAA, the controls documented on this page in plain language, and direct answers to your security questionnaire. [PLACEHOLDER: certification roadmap statement from the founder.]

09

What is your breach process, and who are your subprocessors?

Three subprocessors touch the service: OpenAI for voice AI, Twilio for telephony, and AWS for hosting. They are listed below with their role, and no others are used for patient calls.

[PLACEHOLDER: confirm downstream BAA status with each subprocessor and publish the breach notification SLA, including the notification window to customers and the named contact who issues it.]

Minimal-PHI design

What the AI holds, and what it never sees

The smallest working set that still lets the phone get answered properly.

DataStatusWhy
Caller nameCapturedNeeded to identify the patient and the appointment
Phone numberCapturedNeeded to call back, confirm, and enforce do-not-contact
Reason for the callCapturedNeeded to route, book the right visit type, and trigger escalation
Appointment detailsCapturedProvider, date, time, visit type, and location of the booking
Clinical records and chart dataNot accessedClinivocx has no EHR or EMR connection and cannot read your charts
Insurance and payment card dataNot collectedThe AI does not take payments or capture card numbers

This is the practical reason Clinivocx goes live in days rather than quarters: there is no chart-system connection to review, harden, and certify. See the go-live sequence and escalation protocol on how it works.

Subprocessors

Who else touches a patient call

Three vendors, named. If that changes, this table changes.

SubprocessorRoleBAA status
OpenAIVoice AI and language understanding[PLACEHOLDER: confirm downstream BAA status and zero-retention configuration]
TwilioTelephony: inbound and outbound calls[PLACEHOLDER: confirm downstream BAA status]
AWSHosting, storage, and encryption at rest[PLACEHOLDER: confirm downstream BAA status]

A question we get weekly

Is ChatGPT HIPAA compliant?

No, and the reason is worth understanding before you evaluate any AI vendor.

Consumer ChatGPT does not offer a Business Associate Agreement. If no BAA exists, the vendor has accepted no HIPAA obligations, and typing a patient's name and symptoms into it is a disclosure of PHI to a party with no duty to protect it. That is true no matter how careful the individual staff member is being.

The distinction is not the model. It is everything around the model: a signed contract that makes the vendor accountable, a configuration that limits what is collected and how long it is kept, access controls and audit logs over the stored data, and a named list of subprocessors.

A consumer chatbot has none of those. A vendor operating under a BAA is required to have all of them, and can be held to it.

The longer version, with the regulation itself, is in our guide to whether AI is HIPAA compliant.

What it costs

The BAA is not an upsell

Every control on this page ships in every plan.

Some vendors gate the BAA, audit logs, or SSO behind an enterprise tier. Clinivocx does not: the signed BAA, mandatory MFA, PHI masking, role-based access, and exportable audit logs are included at $799, $1,999, and $4,999 per month alike. See pricing or compare approaches on AI receptionist vs answering service.

HIPAA questions

The eight we are asked most, answered without hedging.

This page is a plain-language security overview, not legal advice. Your practice remains the covered entity and is responsible for its own HIPAA obligations. Review our BAA and this page with your own compliance counsel before making a decision.

Bring your security questionnaire

We answer it on the call, including the questions we cannot answer yet.