There is no such thing as a HIPAA-compliant AI receptionist
HIPAA compliance is not a badge a product earns. It is a chain of contracts, and an AI receptionist has at least four links in that chain. Ask any vendor which ones they hold.
The short version
- HIPAA compliance is contractual rather than a certification, and it requires a business associate agreement with every layer that touches patient information.
- For a voice product that means the telephony carrier, the speech-to-text service, the language model and the voice synthesis, at minimum.
- GreetKeeper has no such agreements in place and makes no HIPAA claim. We would rather lose a sale than make one.
- A vendor claiming HIPAA compliance should be able to name the layers they have signed with. That answer is the useful part of the conversation.
Why a product cannot be certified for this
There is no government body that certifies software as HIPAA compliant. Nobody issues the badge, because the framework does not work that way. What exists is a set of obligations on covered entities and on their business associates, and those obligations flow through signed agreements.
So when a vendor page says HIPAA compliant, the honest translation is that they believe their practices meet the standard and they have agreements in place. That may well be true. The way to find out is to ask which agreements, with whom, and whether they will sign one with you.
The reason this matters more for voice than for most software is the number of parties. A call touches a carrier, a transcription service, a language model and a text-to-speech service before anyone has stored anything. Each of those is a separate company processing what a patient said out loud.
What we do instead of claiming it
We say plainly that GreetKeeper carries no certifications and makes no HIPAA claim, on the compliance page, on every industry page and in every roundup. It is the first thing a practice needs to know and burying it would be the whole problem.
We also scope the clinical pages deliberately. An assistant answering for a dental or medical practice is described as handling inquiries and scheduling, with clinical detail staying in the practice's own system. That scoping is a design decision rather than a disclaimer: the less a call needs to contain, the smaller the question becomes.
That is not a substitute for compliance and we are not presenting it as one. A practice that needs a business associate agreement should not buy from us today, and we would rather write that sentence than have the conversation after a sale.
The questions to ask every vendor, including us
Which subprocessors touch the audio and the transcript, by name? A vendor who cannot answer that quickly has not thought about it hard enough for a clinical deployment.
Will you sign a business associate agreement, and with which of your own suppliers do you hold one? The second half of that question is where most confident claims get quieter.
What is stored, for how long, and can it be turned off? For a practice, an assistant that keeps no audio and a short transcript is a materially different risk from one that keeps everything for a year.
And then ask your own counsel. We publish our position because the alternative in this category is a marketing claim nobody checks, not because our reading should substitute for advice you pay for.
Hear it handle one of your own calls
Your scenario, your greeting, a couple of minutes.