Consultations
All articles Compliance

HIPAA and AI Phone Answering: What a Medical Practice Must Check

An AI service that records why a patient is calling is a business associate under HIPAA. The three questions to ask any vendor in writing, what minimum necessary means for an intake script, and why the clinical boundary is a compliance issue too.

By the Consultations team · July 2026 · 9 min read

The Intake Desk
Intake and scheduling, not advice
Run intake for

Pick a profession, watch the brief fill itself

The AI runs the discovery consultation, qualifies the lead, collects details and documents, and books the paid appointment, then hands you a prepped brief.

Intake brief

Name
Need
Budget / fit
Timeline
Docs
Verdict

↑ pick a profession to run the intake

Discovery consultation

live

Intake brief

Qualification

Scored against this firm's intake criteria, with the reasons on the brief.

Appointment

booked

at

Brief ready for

Brief ready

Live and interactive · qualified, briefed, and booked

Every lead qualified, briefed, and booked · intake and scheduling, not advice · you own your data

Run a sample intake · the AI qualifies, books, and hands you a prepped brief

An AI service that answers your practice's phone and records why a patient is calling is handling protected health information on your behalf, which makes it a business associate under HIPAA. That means you need a signed business associate agreement in place before real patient calls reach it, and no feature, certification badge, or reassurance from a salesperson substitutes for that document. HIPAA compliance is a property of the arrangement between your practice and the vendor, not a property of the software, and the obligation sits with you as the covered entity regardless of what the vendor promises.

Last updated July 2026. This is general information about a common vendor question, not legal advice. Your counsel or compliance officer should review any arrangement involving patient data.

Why an answering service is a business associate

HIPAA treats a vendor as a business associate when it creates, receives, maintains, or transmits protected health information on behalf of a covered entity. A phone service crosses that line almost immediately. The moment a caller says their name and that they are calling about an appointment for a specific condition, the service is holding information that identifies an individual and relates to their health or their care. It does not matter that the call was two minutes long or that nobody clinical was involved.

This is worth stating plainly because a lot of small practices reason their way past it. The service only takes messages, so surely it is like a phone company. It is not: the conduit exception is narrow and applies to entities that merely transmit data without accessing it, like a telecom carrier or a courier. A service that listens, understands, transcribes, and stores what a patient said is doing considerably more than transmitting. If the vendor keeps a recording or a transcript, that settles it.

The three questions to ask before any patient call reaches a vendor

Get answers in writing. A vendor who is comfortable with these questions will answer them in a paragraph; one who deflects has told you something useful.

Will you sign a business associate agreement, and at which plan tier? The second half of that question is the one people forget. Several vendors in adjacent categories restrict the BAA to their highest tier, which materially changes the real price of the product for a medical office. A $49 plan you cannot lawfully use is not a $49 plan. Ask before you compare pricing, not after.

Where does the data live, how long is it kept, and who can access it? You want to know whether call recordings and transcripts are stored, for how long, whether you can configure that retention, whether staff at the vendor can read them, and whether any of it is used to train models. Shorter retention is better for you. Data that was never kept cannot be breached, and a vendor who lets you set a retention window is a vendor who has thought about this.

Can we export and delete on request? Patients have rights over their information, and you have to be able to honor them. If a patient asks what you hold or asks for deletion, an answer that depends on a support ticket and a two-week wait is a problem. This question also tells you what leaving the vendor would look like later, which is useful for entirely non-compliance reasons.

What to confirm Good answer Warning sign
Business associate agreement Signed before go-live, available on your plan Available only on enterprise, or "we are HIPAA compliant" with no BAA
Recording and transcript retention Stated period, configurable by you Indefinite, or nobody can say
Vendor staff access Restricted, logged, need-based Unclear, or broad support access with no logging
Use of your data for model training Not used, stated in the agreement Permitted by the terms of service by default
Export and deletion Self-service, on request, documented Manual, slow, or conditional
Breach notification Timeline written into the BAA Not addressed

Minimum necessary: the part you control

Compliance is not only about the vendor. HIPAA's minimum necessary standard says you should limit protected health information to what is needed for the purpose, and in an automated intake that principle translates directly into how you write the question set. Every field you ask for is data you now hold, protect, and are responsible for. An intake script that collects a full history because it seemed thorough has created risk in exchange for nothing, since none of it gets used before the appointment.

Ask what the appointment actually requires. For most scheduling calls that is the patient's name, contact details, insurance or referral information, whether they are an existing patient, and the reason for the visit in their own words. That last one should be recorded verbatim rather than interpreted, which is both safer and more useful to the clinician. Resist the temptation to add fields because the form has room.

The clinical boundary is a compliance issue too

The other half of doing this safely has nothing to do with data handling. An AI agent answering a medical practice's phone must not assess symptoms, judge urgency, advise on medication, or suggest what a patient should do. Recording that a caller said they have chest pain is administrative. Deciding what that means, or that it can wait until Thursday, is clinical judgment, and software should never be making it.

Configure the boundary as escalation triggers rather than as an instruction to use judgment. Write down what counts as urgent for your practice, who is notified, through which channel, and what the caller hears in the meantime, which for most practices means your standard emergency instruction. Then test it: call your own line and describe something that should trigger escalation, and confirm the handoff behaves as your policy says. A vendor willing to blur this line to win your business is offering you a liability, not a time saving.

Questions practices ask about this

Can an AI receptionist be HIPAA compliant? Yes, when the arrangement is right: a signed business associate agreement, clear data storage and retention terms, restricted access, an export and deletion path, and an intake script limited to what the appointment needs. Compliance describes the arrangement between your practice and the vendor, not a property the software has on its own.

Is a signed BAA really required for a service that only takes messages? Yes, if the service accesses, transcribes, or stores what the patient said. The conduit exception is narrow and covers entities that transmit data without accessing it. An answering service listens and records, which puts it well inside business associate territory.

Who is liable if the vendor has a breach? Both parties carry obligations, and as the covered entity your practice carries the primary duty to patients, which is the practical reason to insist on the agreement and on a written breach notification timeline. Regulators have made clear over the years that a covered entity cannot outsource responsibility along with the work.

Does HIPAA prevent using AI for patient scheduling at all? No. Scheduling, rescheduling, insurance and referral capture, and routine practice questions are administrative work that vendors have handled for decades under business associate agreements. What HIPAA governs is how that information is protected, not whether software may be involved.

What about state privacy laws? Several states impose obligations beyond HIPAA, and some have specific rules about recording calls with two-party consent. If you record, confirm what your state requires and what the caller is told at the start of the call. Your compliance advisor should confirm this for your jurisdiction rather than a vendor.

A short pre-launch checklist

Sign the BAA before the first real patient call. Confirm the retention period and set it as short as your practice can work with. Restrict who at your practice can read transcripts, and confirm who at the vendor can. Write the intake question set to the minimum the appointment needs. Define escalation triggers and test them from an outside line. Document all of it in one page, because the value of that page becomes obvious the first time anybody asks how the arrangement works.

Practices that carry several vendor relationships like this usually find the tracking is the part that slips, and it is worth keeping the agreements, retention terms, and review dates somewhere that maps each obligation to a control you can actually check rather than in an email thread from eighteen months ago. The agreement is only useful if you can find it and know when it was last reviewed.

For what an AI agent should and should not handle in a clinic, along with published July 2026 costs for after hours coverage, see the AI receptionist for medical offices page. If you are earlier in the decision, the AI receptionist versus virtual receptionist comparison covers who is actually on the call in each model, and the patient intake software page covers collecting the details a visit needs before the patient arrives.

See how Consultations runs intake for your field on the use cases page.

Run this on your practice

Consultations runs the discovery consultation, qualifies the lead, collects the details and documents, books the paid appointment, and hands you a prepped brief.

Explore features

Run the intake and book the appointment.

Let the AI run the discovery conversation, qualify the lead, collect the details and documents, book the paid appointment, and hand you a prepped brief. Intake only, never advice.

See pricing

One AI conversation · qualifies and books · intake only, never advice