If you are evaluating an AI receptionist for a covered entity or a business associate that touches protected health information, “we’re encrypted” is not a compliance program. HIPAA does not ban voice AI. It does require a practical control set around BAAs, PHI on calls, recordings, subprocessors, access, and auditability. This checklist is operational, not legal advice. Have counsel review your specific facts. Use this to ask vendors sharper questions and to avoid the common gap between a marketing security page and a production call path that stores PHI in three unmanaged places.

Velzyx builds operational AI for healthcare-adjacent and clinical-adjacent front offices, including dental and medical aesthetics. The controls below are the ones we expect operators to demand from any serious vendor, including us. For broader trust posture see security and trust.

1. Business Associate Agreement (BAA)

If the vendor creates, receives, maintains, or transmits PHI for a covered entity, you generally need a BAA before go-live—not after the pilot “proves value.” Ask: Will you sign a BAA? Which legal entity signs? Does the BAA cover voice, chat, SMS, recordings, transcripts, and backups? What happens to PHI at contract end (return/destruction timelines)? A pilot that processes real patient calls without a BAA is not a clever shortcut. It is a process failure.

2. PHI on live calls

AI receptionists routinely hear names, dates of birth, member IDs, symptoms, and appointment reasons. Treat the call path as a PHI channel. Minimum expectations:

  • Collect only what the workflow needs (minimum necessary).
  • Avoid prompting for Social Security numbers or full card data unless there is a justified, secured payment/intake flow.
  • Route clinical triage carefully; the agent should escalate rather than freestyle medical advice.
  • Document which fields are written into the PMS/EHR versus kept only in the voice platform.

Operators should map data flows on a whiteboard before the first production call: caller audio → speech-to-text → LLM/runtime → PMS write → SMS → logs. Every arrow is a decision.

3. Recordings and transcripts

Recordings are useful for quality and dispute resolution. They are also PHI stores. Ask where recordings live, who can play them, retention defaults, encryption at rest, and whether transcripts inherit the same controls. Prefer role-based access with least privilege, not a shared vendor login emailed to the whole front desk. If your state has two-party consent rules for call recording, configure disclosure language accordingly—HIPAA is not the only regime on the call.

4. Vendor subprocessors

Modern voice stacks often include telephony, STT, TTS, model providers, storage, and observability tools. Each subprocessor that can touch PHI needs to be inventoried. Ask for a current subprocessor list, whether those parties are under BAAs or equivalent contractual flow-downs where required, and how you are notified of changes. “We use best-in-class cloud AI” without a list is not an answer.

5. Access controls and authentication

Admin consoles that can pull transcripts, export CSVs, or change escalation rules must have SSO or strong MFA, unique users, and revoke-on-termination. Shared passwords are a finding waiting to happen. Separate production from sandbox. Limit which staff can download bulk recordings. Log admin actions.

6. Audit logs and incident response

You need to reconstruct who accessed what and when. Demand audit logs for playback, exports, configuration changes, and API writes into the PMS. Ask for the incident response outline: detection, customer notification timelines, forensic retention. Run a tabletop once: “A contractor exported last month’s transcripts—what do we do in the first two hours?”

7. Integration and write-back hygiene

Writing appointments and demographics into OpenDental, eClinicalWorks, or similar is valuable and risky. Use scoped credentials, not a full admin login pasted into a vendor portal. Prefer least-privilege service accounts. Confirm that failed writes do not dump PHI into unconstrained error emails. The same write-back discipline in the write-back thesis applies with a compliance overlay.

8. Patient rights and retention

Know how you will fulfill access/amendment requests that touch AI-stored transcripts. Align retention with your official record policy; do not keep forever “for training” unless counsel and your BAA allow it and patients were appropriately notified. Be explicit: is call data used to train foundation models? For most healthcare operators the acceptable answer is no, or only in tightly controlled, de-identified, contractually bounded cases.

Practical checklist summary

  • BAA executed before PHI flows.
  • Data-flow diagram for audio, text, PMS, SMS, backups.
  • Recording/transcript retention and access policy.
  • Subprocessor inventory with flow-down terms.
  • MFA/SSO, unique users, admin audit logs.
  • Incident response contacts and timelines on file.
  • Scoped integration credentials; no shared admin passwords.
  • Clear statement on model training use of customer data.
  • Escalation rules for clinical content documented and tested.
  • Counsel review of disclosure language and state recording consent.

Disclaimer: This article is for operational planning. It is not legal advice, a certification, or a guarantee of HIPAA compliance. Regulations and interpretations change; your counsel and compliance officer own the final call.

If a vendor cannot walk this checklist without hand-waving, treat that as a product signal. Compliance theater is another form of the demo problem we wrote about in why AI demos die in production. For dental-specific operations context, see AI receptionist for dental practices and Open Dental AI receptionist.

What “good enough for a pilot” still has to include

Pilots fail compliance the same way they fail operations: by deferring the boring controls. Even a two-week pilot on a subset of clinics should include a signed BAA if PHI will flow, a restricted retention window, named admin users, and a written rule that pilot recordings will not be used to train external foundation models. Do not invent a shadow IT path “just to see if patients like the voice.” Patient experience testing does not require unmanaged PHI sprawl.

Also separate marketing claims from attestations. SOC 2 helps; it is not a HIPAA authorization. Encryption helps; it does not replace access policy. A pretty trust center helps; it does not replace your data-flow diagram. Pair this checklist with the production mindset in the boring 80% of production AI and the security pages at /security and /trust.

Walk the checklist against your stack

We will map BAA coverage, PHI data flows, recording retention, and write-back credentials for your PMS—then tell you honestly what is ready and what is not.

Talk to engineering