Buyer's FAQ
Are AI receptionists HIPAA compliant?
What HIPAA actually requires of an AI receptionist, why a Business Associate Agreement is the thing to check first, and where patient data goes.
An AI receptionist can be HIPAA compliant, but it is not automatic: the vendor must sign a Business Associate Agreement, encrypt protected health information in transit and at rest, restrict access by role, and log it. A general-purpose voice bot or consumer chatbot typically will not sign a BAA, which alone makes it unusable for patient calls.
Questions
HIPAA compliance & security, answered
Some are and some are not, and the word on the marketing page is not the test. HIPAA compliance for an AI receptionist means a signed Business Associate Agreement, encryption of protected health information in transit and at rest, role-based access, audit logging, and a minimum-necessary configuration. Echo meets those and signs a BAA before the first patient call. A consumer chatbot bolted onto a phone line generally will not sign one at all.
Ask before anything else, because it is the shortest disqualifying question in the category. A Business Associate Agreement is what makes a vendor legally accountable for the protected health information it handles on your behalf, and without one your practice carries the exposure alone. Echo executes a BAA with every customer before any patient contact is enabled, not after go-live.
With Echo, calls, transcripts, messages, form submissions, recordings, and AI summaries are encrypted in transit and at rest, stored in the United States, and reachable only by the roles you grant. Every access is logged, which is what an audit actually asks for — an assurance is not an access control. Ask any vendor where the audio lives and who at the company can play it back.
It should not be, and this is worth getting in writing. A vendor that improves its models on your conversations has made your patients part of its product. Echo does not use patient data to train models. When you evaluate alternatives, look for that stated explicitly rather than inferred from a general privacy policy.
It has to. Patients reach a practice by phone, text, and web form, and protected health information does not respect channel boundaries, so compliance that stops at the phone line is not compliance. Echo applies one control set across voice, text, email, and digital forms rather than treating the phone as the only regulated surface.
It should not, and a vendor that lets it is selling you a liability. Echo makes no clinical judgment. It answers non-clinical and policy questions — hours, location, visit types, coverage, scheduling — and routes anything involving symptoms, medication, or urgency to your staff, escalating on the conditions you define. That boundary is configured during onboarding rather than left to the model.
Your BAA should say, and you should read that clause before signing rather than at termination. Ask specifically how long data is retained after the agreement ends, in what format you can export transcripts and appointment history, and what the deletion process and confirmation look like. Any vendor unwilling to put that in writing has told you something useful.
No, and vendors sometimes blur them. SOC 2 is an audited report on a company's security controls; HIPAA is a legal obligation about protected health information, enforced through the BAA. A vendor can hold SOC 2 and still be unusable for patient calls if it will not sign a BAA. Treat SOC 2 as evidence of maturity and the BAA as the requirement.
Go deeper
Other questions buyers ask
Ready when you are
See the AI receptionist answer your calls.
A 30-minute demo answers the questions a page cannot: your systems, your rules, your call volume.
