Is an AI receptionist HIPAA compliant?
- The short answer
- No product is HIPAA compliant, because HIPAA compliance is not a certification any vendor can hold. It is contractual: it depends on a signed business associate agreement with every layer that touches protected health information, which for a phone assistant means the telephony carrier, the speech-to-text engine, the language model and the text-to-speech engine. A vendor badge saying HIPAA compliant tells you nothing about that chain. GreetKeeper does not make a HIPAA claim.
The longer answer
Start with what HIPAA actually is. It is a law with a compliance regime, not a standard anyone certifies against. There is no auditor who issues a HIPAA certificate, so a logo is a marketing decision rather than a finding.
A covered entity, which for this purpose is your practice, stays responsible for PHI. When you pass PHI to a vendor, the mechanism that makes that lawful is a business associate agreement.
The part that catches people out is that the agreement has to run all the way down. Your vendor's subcontractors touch the same audio you do.
The questions to ask any vendor before a call touches PHI
Will you sign a BAA with us, and can we see it before we buy? A vendor who will sign will say so plainly and will not need a sales call to answer.
Name every subprocessor that touches call audio or transcripts. Carrier, speech recognition, language model, voice synthesis, storage, analytics. Ask for the list in writing.
Do you hold a BAA with each of those, and will you show us? This is the question that separates a real posture from a badge. If any layer in the chain has no agreement, the exposure lands on the practice.
What is stored, where, for how long, and who can read it? Then: can recording be switched off entirely, and can transcripts be deleted on request?
Scoping a dermatology practice's phone line
Say you manage a dermatology practice and you want the phone answered without turning transcripts into clinical records. The work is in the brief. You tell the assistant to collect four things: name, callback number, new or existing patient, and a preferred time. For the reason, it offers categories such as skin check, follow-up, cosmetic consult or billing question.
A caller starts describing a mole that has changed shape. The assistant doesn't ask follow-up questions about it. It says the clinician will go through the details at the visit, offers the next skin-check slot, and books it. If she says it's bleeding, your rule sends her to the nurse line.
Her description is still in the transcript, because she said it. Scoping reduces what the phone system gathers, but it can't stop a caller from volunteering more, which is why the storage questions still need answers.
Find out whether HIPAA reaches you at all
Not every health-adjacent business is a covered entity. HIPAA applies to health plans, clearinghouses, and providers who send health information electronically in connection with standard transactions such as billing an insurer. A cash-only massage studio, a personal trainer or a wellness coach may sit outside it. State privacy law can still apply, so take the question to whoever advises you rather than settling it from a web page.
If you are covered, your own risk assessment is the document that matters. Add the phone system to it like any other vendor: what information reaches it, where that's stored, who can read it and how it gets deleted. Write down the answers you receive and the date you received them.
Two settings deserve a decision rather than a default. Should call audio be kept, or only transcripts? And how long should either live before deletion? Shorter retention means less to worry about in a breach, at the cost of less history to look back on.
Since GreetKeeper makes no HIPAA claim, a practice that needs a signed agreement covering every layer should raise that in the first conversation with us.
How GreetKeeper handles it
GreetKeeper makes no HIPAA claim and holds no certification of any kind. We would rather tell you that on this page than let you find out during a risk assessment.
Healthcare setups on GreetKeeper scope themselves to inquiry and scheduling data: who called, what they wanted, when they are coming in. Treatment detail belongs in your practice-management system, not in a phone transcript.
Ask us what the system stores and we will answer specifically. Take that answer to whoever advises you on compliance rather than to a comparison table.
PHI and vendor questions
Is a caller's name and phone number PHI?
In the hands of a healthcare provider, identifying information tied to seeking treatment generally is. That is why scoping matters: the less clinical detail the phone system holds, the smaller the question.
Does a SOC 2 report cover HIPAA?
No. SOC 2 is an audit of controls against trust services criteria. It can be useful evidence, but it is not a BAA and it does not make PHI handling lawful on its own.
What if a caller volunteers medical detail anyway?
They will, which is exactly why the storage and retention answers matter more than the badge. Ask what happens to that audio and that transcript, and how you delete both.
Hear it take one of your calls
Two minutes, your own scenario, no card.