Valian

July 3, 2026 · 7 min read

What makes an AI receptionist HIPAA-compliant?

Quick answer

A HIPAA-compliant AI receptionist has signed Business Associate Agreements (BAAs) with every vendor that touches patient data, encrypts information in transit and at rest, enforces role-based access with audit logging, follows minimum-necessary data handling, and never sends protected health information to tools not covered by a BAA. Compliance is about the whole data chain, not a single certificate.

A HIPAA-compliant AI receptionist is not a feature you toggle on — it is a property of the entire system that handles the call. For a phone or AI front desk, compliance comes down to a few concrete requirements: signed Business Associate Agreements (BAAs) with every vendor that can touch protected health information (PHI), encryption in transit and at rest, role-based access controls with audit logging, minimum-necessary data handling, and a hard rule that PHI never flows to a tool that is not under a BAA. If any link in that chain is missing, the whole thing is out of compliance — no matter how good the demo sounds. This article is general education, not legal advice; confirm your own obligations with counsel and your compliance officer.

What HIPAA actually protects on a front-desk call

The moment a caller says their name and mentions an appointment, a symptom, or an insurance ID, you are handling PHI. HIPAA covers that information whether it is spoken on a call, transcribed by AI, stored in a database, or texted back to the patient. A dental or medical practice is a "covered entity," and any technology vendor that processes PHI on the practice's behalf becomes a "business associate." That relationship has to be governed by a signed BAA — a contract in which the vendor agrees to protect PHI, restrict its use, report breaches, and pass the same obligations down to any subprocessor it relies on.

This is where AI front desks get complicated. A single call may pass through a telephony provider, a speech-to-text engine, a language model, an SMS gateway, and a database. Every one of those is a subprocessor touching PHI. Compliance means each of them is covered by a BAA — not just the company whose logo is on the website.

The five things a compliant AI front desk must do

  • Signed BAAs with every subprocessor that touches PHI — telephony, transcription, the AI model, SMS/email, and storage. A BAA with the front-desk vendor alone is not enough if its vendors are not covered.
  • Encryption in transit and at rest — calls, transcripts, messages, and stored records are encrypted so intercepted or stolen data is unreadable.
  • Role-based access controls and audit logging — only authorized staff can see PHI, each has their own login, and every access is logged so you can answer "who saw what, and when."
  • Minimum-necessary data handling — the system collects and shares only the information needed to do the job (book the visit, verify coverage), not everything it could capture.
  • No PHI to non-covered tools — patient data is never piped into analytics, generic chatbots, or third-party tools that are not under a BAA.

Guardrails matter as much as encryption

Technical safeguards keep data safe, but a front desk also needs behavioral guardrails. A good AI receptionist does not pretend to be a clinician. Valian's voice AI, Amy, never gives medical advice, diagnoses, or makes clinical decisions — the moment a caller needs a person or asks a clinical question, she warm-transfers to your team with a full briefing so staff pick up mid-conversation, not from scratch. That boundary is both a safety and a compliance posture: it keeps the AI inside the narrow, non-clinical lane a front desk is supposed to occupy, and it keeps sensitive judgment calls with licensed humans.

Questions to ask any AI receptionist vendor

You do not need to be a compliance expert to vet a vendor. You need to ask direct questions and expect specific answers. Vague reassurance is a red flag; a serious vendor can name its subprocessors and show you paperwork.

  • Will you sign a BAA with our practice? (If the answer is no, or "we do not need one," stop there.)
  • Which subprocessors touch PHI — telephony, transcription, the AI model, SMS/email, storage — and do you have a signed BAA with each?
  • Is data encrypted in transit and at rest, and where is it stored?
  • How do you control staff access, and can you produce an audit log of who accessed a patient record?
  • What is the minimum data you collect and retain, and can we set retention limits?
  • Do you ever use patient data to train shared AI models or send it to tools not under a BAA?
  • What is your breach-notification process and timeline?

Red flags to walk away from

  • A vendor that will not sign a BAA, or claims one is unnecessary because "we do not really see the data."
  • "HIPAA-compliant" claimed as a badge with no detail on encryption, access controls, or subprocessor BAAs.
  • No clear answer on which third parties process your calls and messages.
  • Patient conversations used to train general-purpose AI models by default.
  • Free or ultra-cheap consumer tools repurposed as a front desk — free tiers almost never come with a BAA.

How Valian approaches it

Valian is built to operate under HIPAA with BAAs in place across the vendors that handle PHI, with encryption in transit and at rest, role-based access and audit logging, and minimum-necessary data handling baked into how calls, texts, and records are processed. Amy stays strictly non-clinical and escalates to your team when a caller needs a human. Pricing stays simple and usage-based — $1.50 per call minute, $0.25 per SMS, $0.25 per email, $5.00 per real-time insurance verification, and $10 per month per number — so you are not locked into a seat you cannot audit. Compliance is an ongoing program, not a finish line, and additional attestations are on our roadmap; the right test is always whether the whole data chain is covered, and that is the standard we build to. If you want to see exactly how it handles a patient call, book a demo and ask us the questions above.

Stop sending patients to voicemail

Valian answers every call 24/7 and books straight into your PMS. Live in 24 hours, pay only for what Amy uses.

// VALIAN · MEDICAL REVENUE OPERATING SYSTEM

Valian