Automation

AI Voice Agent HIPAA Rules: Can One Legally Take Patient Calls?

📅 September 17, 2026 · ✍️ Ali Khan · 🕐 17 min read ·
AI Voice Agent HIPAA Rules: Can One Legally Take Patient Calls?
Key Takeaways Can an AI Voice Agent Legally Take Patient Calls? Step #1: Check Whether the AI Voice Agent HIPAA Rules Apply to You Step #2: Decide Whether Your Vendor Is a CONDUIT or a Business Associate Step #3: Get a BAA That Actually Covers AI Step #4: Map Where PHI Appears in a Single Call Step #5: Lock Down Retention, Training and Logs Step #6: Handle Identity Verification and Disclosure Step #7: Understand Who Is Liable When It Goes Wrong What Should an AI Voice Agent Never Do? Frequently Asked Questions Next Steps

The demo went beautifully.

The agent answered on the second ring, took the caller’s details, found a slot, booked it and wrote a summary before anyone had hung up.

Then somebody from compliance asked where the recording goes, and who else can hear it.

Nobody in the room knew. The technology stopped being the hard part about eighteen months ago. The AI voice agent HIPAA rules did not.

We build AI voice and chat systems for businesses, and every healthcare client opens with the same question.

Can this thing legally answer the phone?

The short answer is yes. The useful answer is that almost every AI voice agent HIPAA rules discussion gets the vendor relationship wrong, and that is the part that creates liability.

This guide walks the seven AI voice agent HIPAA rules steps in order, using the wording from the Department of Health and Human Services rather than a summary of a summary.

Not legal advice: this is an operational guide written by people who build these systems, not lawyers. It quotes HHS guidance directly so you can check every claim yourself. Have counsel review your specific setup before it takes a real call.

Key Takeaways

  • An AI voice agent is almost never a conduit. HHS limits that exception to transmission-only services with transient access, and AI agents transcribe and store.
  • That makes the vendor a business associate, which means a BAA is mandatory and the vendor is directly liable to HHS, not just to you.
  • Encryption does not exempt anyone. HHS is explicit that a provider holding encrypted PHI without the key is still a business associate.
  • A traditional landline sits outside the Security Rule because the information is not electronic. Your AI agent is not a landline.
  • The riskiest artefact is not the recording. It is the transcript, the embeddings and the model logs nobody wrote a retention policy for.
Medical reception handling an inbound patient call
HIPAA never mentions AI. It regulates who touches the information afterwards.

Can an AI Voice Agent Legally Take Patient Calls?

Yes.

The AI voice agent HIPAA rules do not ban automation, do not mention artificial intelligence, and do not require a human to answer a telephone.

What it regulates is protected health information: who touches it, under what agreement, with what safeguards.

So the question is never whether the agent may answer. It is what happens to the information after it does.

And that is decided by one thing above all others.

Whether your vendor is a conduit or a business associate.

Get that classification right and the rest of the AI voice agent HIPAA rules are a checklist. Get it wrong and you have signed nothing, safeguarded nothing, and assumed all of it.

Step #1: Check Whether the AI Voice Agent HIPAA Rules Apply to You

Not every business handling health-adjacent information is covered by the AI voice agent HIPAA rules.

HIPAA applies to covered entities, which are health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with certain transactions.

It also applies to their business associates, and to those business associates’ subcontractors.

Three quick tests settle it for most businesses.

  • Are you a provider, plan or clearinghouse? Dental practices, clinics, therapists, labs and pharmacies generally are.
  • Do you handle PHI on behalf of one? Then you are a business associate, and your own vendors become subcontractors.
  • Neither? A gym, a supplement store, a wellness app selling direct to consumers is often outside HIPAA, though other privacy law still applies.

That third group causes the most confusion, because people assume anything health-related is HIPAA-regulated.

It usually is not. But do not celebrate too early: state privacy law, the FTC and consumer protection rules do not care that HIPAA let you off. If you are outside the AI voice agent HIPAA rules, an ordinary automated first line is a much simpler build.

Step #2: Decide Whether Your Vendor Is a CONDUIT or a Business Associate

This is the whole article in one step, and the point on which the AI voice agent HIPAA rules turn.

Vendors love the word conduit, because a conduit needs no agreement and carries no liability. The telephone company is the classic example.

HHS defines the exception narrowly.

The conduit exception is limited to transmission-only services for PHI (whether in electronic or paper form), including any temporary storage of PHI incident to such transmission. Any access to PHI by a conduit is only transient in nature.US Department of Health and Human Services, Guidance on HIPAA and Cloud Computing

Read that against what an AI voice agent actually does.

It records the call. It transcribes the call. It extracts intent, writes a summary, stores a conversation history and often keeps embeddings for retrieval.

None of that is transient. It is the same persistence that makes any automation platform a processor rather than a pipe.

HHS closes the door explicitly on the encryption argument too.

A CSP that maintains ePHI for the purpose of storing it will qualify as a business associate, and not a conduit, even if the CSP does not actually view the information, because the entity has more persistent access to the ePHI.US Department of Health and Human Services, Guidance on HIPAA and Cloud Computing

So the vendor cannot escape the AI voice agent HIPAA rules by holding your data encrypted, and cannot escape by promising never to look.

Where the agreements go

Two boundaries, two agreements

The chain a single patient call actually travels, and the point at which each party stops being a conduit.

BAA hereBAA hereYour practiceCovered entityAI voice vendorBusiness associateModel providerSubcontractorpatient callstranscribes,stores, summarisesruns inference,retains promptsEvery dashed line is PHI leaving your controlA conduit only carries the call. Anything that keeps the content sits on the far side of a boundary.
Most practices sign one agreement and never learn the third box exists.

Classification per HHS guidance on cloud computing. Your architecture may add more boxes, never fewer.

There is one genuine exception worth knowing, and it is narrower than people hope.

HHS states that a covered entity may run an audio-only telehealth session using a smartphone without a BAA with the telecoms provider, where that provider does not create, receive or maintain any PHI from the session and is only connecting the call.

Then the next sentence, which is the one that matters to you.

However, a covered entity must enter into a BAA with a vendor that is more than a mere conduit for PHI.HHS, Guidance on Audio-Only Telehealth
Key point: the carrier moving the audio may be a conduit. The AI layer sitting on top of that call, transcribing and storing it, is not. Two different vendors, two different classifications, and only one of them needs a BAA. Most teams sign nothing because they are thinking about the phone line.
Reviewing a business associate agreement before signing with a vendor
Ask for the subcontractor list before you ask for the agreement.

Step #3: Get a BAA That Actually Covers AI

A standard BAA template was written before anyone was fine-tuning models on call transcripts, which is where the AI voice agent HIPAA rules get thin.

Sign it unchanged and you have covered storage while leaving the interesting parts undefined.

Worth knowing what you are actually getting: HHS states that once a BAA is in place the vendor is both contractually liable for meeting its terms and directly liable for compliance with the applicable HIPAA Rules.

That is real leverage. Use it on these clauses, the same way you would scope any process automation contract.

The clauses that matter

What to add to a standard BAA before signing

ClauseWhat to requireWhy it matters for AI
Model trainingNo training on your PHI, in writingDefault terms often permit it for service improvement
SubcontractorsNamed list plus notice before changesThe model provider is usually a subcontractor you never met
RetentionStated periods per artefactAudio, transcript, embeddings and logs have different lifespans
Deletion on exitCertified deletion including backupsVector stores are routinely missed
Breach notice windowDays, not “without unreasonable delay”Your own clock starts when they tell you
Location of processingNamed regionsInference can route anywhere by default
Audit rightsEvidence you can actually requestA logo on a trust page is not evidence

Row one is the one vendors push back on hardest, which tells you how much it is worth.

Pro tip: ask for the subcontractor list before you ask for the BAA. If the vendor cannot name which model provider processes the audio, they cannot honestly sign a clause about it, and you have learned something important in one email.

Step #4: Map Where PHI Appears in a Single Call

Most teams apply the AI voice agent HIPAA rules to the whole call, discover the safeguards are unworkable, and quietly stop enforcing them.

The better approach is to map the call second by second.

The PHI surface

Seventy per cent of this call is protected health information

Mapping where PHI appears second by second shows which questions are creating the exposure.

GreetingReason for callingName and date of birthSymptom detailHoldAppointment optionsConfirmationClosing and directions0 min1 min2 min3 minOne three and a half minute call, segment by segmentRed segments carry protected health information. Grey ones carry none.146 seconds of 210 contain PHI, which is 70% of the call
Drop the symptom question and the PHI surface falls from 70% to 51% of the call.

Illustrative call structure. Run the same exercise on ten of your own transcripts before designing the flow.

Two things fall out of this immediately.

The PHI surface is larger than most teams assume. In the call above it is 70% of the duration, because appointment details and confirmations count too, not just symptoms.

The PHI arrives in a predictable window. Usually the moment the caller states why they are calling, and again when an appointment is confirmed.

Which means you can shrink it by design rather than blanket-encrypting everything and hoping.

Three design choices follow naturally.

  • Do not ask for what you do not need. Minimum necessary is a HIPAA principle and also excellent conversation design.
  • Redact at capture, not later. Strip identifiers from transcripts as they are written rather than cleaning them up on a schedule.
  • Route clinical detail to a human. An agent that books appointments does not need symptoms, and asking invites information you then have to protect.

That last one is the highest-value line in the whole build, and it is a scripting decision rather than a technical one. Conversation design does more for compliance here than infrastructure, which is also true of handing support to anyone else.

Storage systems retaining call transcripts, embeddings and application logs
One call, seven artefacts. Most teams have a policy for one of them.

Step #5: Lock Down Retention, Training and Logs

When people picture the AI voice agent HIPAA rules, they picture the recording.

It is rarely the one that causes the problem.

A single AI-handled call can produce seven separate artefacts, and most organisations have a retention policy for one of them.

  1. Call audio. The obvious one, usually covered.
  2. Transcript. Text is easier to search, copy and leak than audio, and it is almost always retained longer.
  3. Structured extraction. The name, date of birth and reason for calling, pulled into fields.
  4. Vector embeddings. Numerical representations used for retrieval, stored in a database that rarely appears on anyone’s data map.
  5. Model provider logs. Prompts and completions retained by whoever runs the model, for a period set in their terms.
  6. Application and error logs. Where PHI ends up accidentally, in a stack trace nobody reads until they do.
  7. Backups. Every one of the above, again, on a different schedule.

Items four, five and six are where audits find things.

The one to fix today: check whether PHI is reaching your application logs. It gets there through debug output, error traces and analytics events, it is often stored outside your BAA’d systems entirely, and it is the single most common finding we see when reviewing an AI voice build.

Set a retention period per artefact, write it down, and test that deletion actually happens. This is the least glamorous of the AI voice agent HIPAA rules and the easiest to fail.

Testing matters because deletion in a vector store frequently means removing the pointer while the vector survives. Build the check into a scheduled job, exactly as you would with any scheduled scenario.

Step #6: Handle Identity Verification and Disclosure

An AI agent will happily tell anyone anything, in a pleasant voice, at three in the morning. This is the part of the AI voice agent HIPAA rules that bites hardest.

HHS guidance is clear that where the individual is not known to the covered entity, the entity must verify their identity either orally or in writing, and that the Rules do not mandate a specific method.

That flexibility is useful, but the AI voice agent HIPAA rules put the design decision on you.

Two rules keep this simple.

Verify before disclosing, never before collecting. Taking a callback request needs no verification. Confirming what a patient is booked in for does.

Fail closed. If verification does not pass, the agent takes a message and a human calls back. It does not guess, and it does not offer a hint.

The same guidance also notes that civil rights laws generally require communication with an individual with a disability to be as effective as communication with others, which is worth designing for rather than retrofitting.

Practically: offer a human path at any point, support callers who cannot complete a voice flow, and do not make verification the only route to help. The cost of that human path is calculable, as we set out in cost per support ticket.

Step #7: Understand Who Is Liable When It Goes Wrong

Everyone in the chain, which is better news than it sounds. The AI voice agent HIPAA rules spread liability rather than concentrating it.

Who answers for it

Everyone in the chain, including you

How responsibility stacks when an AI voice agent mishandles protected health information.

Covered entityChose the vendor. Patient called you.Business associateDirectly liable to HHS, not only to you.SubcontractorSame obligations, one step further away.Liability nests. It does not transfer.Signing a BAA gives you a directly liable counterparty. It does not move your own obligations anywhere.

Per HHS guidance, business associates and their subcontractors are directly liable for applicable HIPAA Rules.

Under HHS guidance a business associate is directly liable for compliance with applicable HIPAA Rules, not merely answerable to you under contract.

Subcontractors sit in the same position relative to the business associate that hired them.

So the model provider processing your audio is inside the regime, whether or not they have ever heard of your practice.

What the AI voice agent HIPAA rules do not do is move responsibility off you.

You still chose the vendor, you still designed the flow, and you are still the one the patient telephoned. Vendor selection carries the same weight here as it does in choosing a CRM, only with regulators attached.

Note: breach notification obligations also flow through the chain. HHS notes that where breached ePHI is encrypted consistent with the standard at 45 CFR 164.402(2), the incident falls within the breach safe harbour. Encryption does not exempt anyone from being a business associate, but it can change what has to be reported.

What Should an AI Voice Agent Never Do?

Four things, regardless of how good the model gets, and none of them are negotiable under the AI voice agent HIPAA rules.

Hard limits

Where the agent stops and a person starts

NeverInsteadReason
Give clinical adviceRoute to a clinicianOutside scope, and a different kind of liability entirely
Disclose results or recordsVerified human callbackDisclosure risk is highest exactly where automation is most tempting
Improvise when unsureTake a messageA confident wrong answer is worse than no answer
Handle emergenciesDetect and escalate immediatelyEvery flow needs an unmissable emergency path, tested

Test row four monthly by actually saying the words into the phone. It is the one nobody checks.

Row three deserves a note, because it is the failure mode unique to this technology.

A phone tree that does not understand you says so. A language model fills the gap with something plausible.

Design the agent to be visibly stupid at the edges. It should say it does not know and pass the call, cheerfully and often. That restraint is what separates a useful automated workflow from a liability.

Further reading: the same boundary applies outside healthcare, where the question is what automation should hand to a person and when. We cover the general version in AI business automation.

Frequently Asked Questions

Is an AI voice agent HIPAA compliant?

No product is compliant on its own, because compliance describes how you use it. An AI voice agent can be used compliantly when the vendor signs a BAA, safeguards are in place and retention is controlled across every artefact the call produces.

Does an AI voice vendor need a BAA?

Almost always yes. HHS requires a BAA with any vendor that is more than a mere conduit, and an agent that transcribes, stores or processes call content has persistent access rather than transient access.

What is the conduit exception?

It covers transmission-only services where access to PHI is transient, such as a telephone carrier connecting a call. HHS states it is limited to transmission plus temporary storage incident to that transmission, which excludes anything that retains content.

Does encryption remove the need for a BAA?

No. HHS is explicit that a provider maintaining encrypted ePHI is still a business associate even without the decryption key, because it has persistent access to the information regardless of whether it can read it.

Does HIPAA apply to a normal phone line?

The Privacy Rule does, but HHS states the Security Rule does not apply to audio-only telehealth over a traditional landline because the information transmitted is not electronic. That exemption does not extend to internet-based or AI-mediated calls.

Can the vendor train models on our call data?

Only if your agreement permits it, and it usually should not. Default commercial terms often allow use for service improvement, so require an explicit no-training clause covering both the vendor and any model provider acting as a subcontractor.

Are transcripts riskier than recordings?

Generally yes, because text is searchable, copyable and easy to move between systems. Transcripts also tend to be retained longer than audio and are more likely to be replicated into logs, analytics and vector databases.

What about the model provider behind the vendor?

They are typically a subcontractor, and HHS treats a subcontractor creating or maintaining ePHI on a business associate’s behalf as a business associate in its own right. Ask for the subcontractor list in writing before signing anything.

How do we verify a caller’s identity?

HHS requires verification where the individual is not known to you but does not mandate a method, so choose something proportionate and design it to fail closed. If verification does not pass, take a message rather than disclosing anything.

Do we need consent to record calls?

That is governed by state recording law rather than HIPAA, and several states require all-party consent. Announce recording at the start of every call, which is both the safe default and simpler than maintaining rules per state.

What happens if the vendor has a breach?

They must notify you, and your own notification obligations follow. HHS notes that ePHI encrypted to the standard in 45 CFR 164.402(2) falls within the breach safe harbour, which is why encryption at rest still matters even though it does not change vendor classification.

Can we use a general-purpose assistant instead?

Only if that provider will sign a BAA covering the specific service and configuration you are using. Consumer tiers of most assistants explicitly exclude PHI, and using one anyway is the most common way small practices create an unreported problem.

Next Steps

Start here, in this order, and the AI voice agent HIPAA rules stop being abstract.

First, email your vendor and ask two questions: will you sign a BAA, and who are your subcontractors. The answers arrive within a day and tell you most of what you need.

Second, list the seven artefacts from Step #5 against your own system and write a retention period beside each. The gaps will be obvious, and our automation audit tool gives you a structure for the rest of the build.

Third, grep your application logs for a patient name. If you find one, fix that before anything else on this page.

Then read the HHS cloud computing guidance and the audio-only telehealth guidance in full. Between them they answer most questions this article raises.

If you want the build reviewed against these seven steps before it takes a real call, send us the call flow and we will mark it up.

Ali Khan, founder of Mezvic

Founder of Mezvic

I'm Ali Khan, the founder of Mezvic. I work with eCommerce brands on the parts of growth nobody posts about: marketplace accounts that have to stay compliant, catalogues that drift the moment you add a channel, and the automation that keeps both running without another hire. I write about what these platforms actually do rather than what their help pages say, usually because I have just spent a week fixing it for somebody.

Ready to Apply This?

Let Mezvic Build the System Behind Your Growth

Whether it's ranking higher on Google, automating your lead follow-up, or scaling your eCommerce revenue, we combine all three disciplines into one integrated system. Book a free 30-minute call and we'll show you exactly where your biggest opportunities are.

Free 30-minute audit No lock-in contracts 150+ businesses grown globally