Cordiva

    HIPAA-Compliant AI Receptionist: The BAA Is the Floor, Not the Ceiling

    Yes — an AI receptionist or virtual receptionist can be HIPAA compliant, but only if the vendor signs a Business Associate Agreement (BAA) and implements HIPAA's safeguards, including encryption of call recordings and transcripts. Spoken patient information is PHI, so a vendor answering calls for a covered med spa is a business associate. The BAA is the floor, not the ceiling.

    Is an AI answering service HIPAA compliant? The short answer

    It can be — under two conditions. First, HIPAA doesn't stop at the filing cabinet: the Privacy Rule protects PHI "in any form or media, whether electronic, paper, or oral" (HHS, Summary of the HIPAA Privacy Rule). A caller saying "I'm phoning about my filler follow-up" is sharing protected health information. Second, HIPAA explicitly permits handing that information to a vendor: under 45 CFR 164.502(e)(1)(i), a covered entity may disclose PHI to a business associate — and let it create, receive, maintain, and transmit PHI on the practice's behalf — if it obtains satisfactory assurance that the vendor will safeguard it. That assurance must be documented in a written BAA meeting 45 CFR 164.504(e).

    Two things AI phone vendors tend to gloss over:

    • Recorded calls are electronic PHI. The moment a call is recorded, transcribed, or processed by software, that voice data falls under the HIPAA Security Rule's administrative, physical, and technical safeguards — including encryption and access controls — not just the Privacy Rule.
    • The BAA permits the disclosure. It does not make the system secure. A vendor can sign a BAA and still run a leaky stack. That's why the BAA is the floor, not the ceiling — the rest of this guide covers what sits on top of it.

    One scoping note before we go deeper: not every med spa is a HIPAA covered entity. Under 45 CFR 160.103, status turns on whether your practice conducts standard electronic transactions (like billing insurance electronically), not on the treatments you offer — and it can flip with a single billing decision, which is why we'd recommend treating HIPAA as your operating baseline even where it doesn't strictly apply (state privacy laws may, regardless). For the full breakdown, including the cash-pay question, see Does HIPAA apply to med spas?. If you're unsure of your status, confirm it with a healthcare attorney — this guide is general information, not legal advice.

    What makes your answering service a business associate

    If your med spa is a covered entity, the vendor answering your phones is a business associate. Under 45 CFR 160.103, a business associate is anyone who creates, receives, maintains, or transmits PHI on a covered entity's behalf — the definition expressly includes practice management functions and administrative services that involve PHI disclosure. An AI receptionist taking calls that contain patient names, appointment reasons, or treatment details is doing exactly that.

    Watch for the "conduit" dodge. Some vendors claim they don't need a BAA because they "just pass calls through." The conduit exception is narrow: HHS reserves it for entities that act merely as a conduit for PHI — the US Postal Service, certain private couriers, and their electronic equivalents. A service that answers, records, transcribes, or stores health information is not a conduit. If a phone vendor invokes it, that's a red flag, not a technicality.

    Subcontractors are business associates too. Under the same definition, any subcontractor that creates, receives, maintains, or transmits PHI on behalf of the business associate is itself a business associate. Your AI receptionist vendor sits on top of a stack — telephony, speech-to-text, an AI model, storage. Every layer that touches PHI needs its own subcontractor BAA. Ask about the whole chain, not just the contract with you.

    What a real BAA must include

    A BAA is not just any contract with "HIPAA" in the header — 45 CFR 164.504(e)(2) prescribes its minimum contents. Before you sign, check that the agreement:

    • Establishes the permitted and required uses and disclosures of PHI by the vendor
    • Prohibits use or disclosure beyond the contract or what the law requires
    • Requires appropriate safeguards and Security Rule compliance for electronic PHI
    • Requires the vendor to report any unauthorized use or disclosure it becomes aware of, including breaches of unsecured PHI as required by § 164.410
    • Flows the same restrictions down to subcontractors that handle PHI on the vendor's behalf
    • Supports patient rights — making PHI available for access (§ 164.524), amendment (§ 164.526), and accounting of disclosures (§ 164.528)
    • Opens the vendor's internal practices, books, and records to the HHS Secretary for compliance review
    • Returns or destroys all PHI at termination, if feasible
    • Authorizes you to terminate the contract if the vendor violates a material term

    Per 45 CFR 164.502(e)(2), these assurances must be documented in a written contract. HHS publishes sample BAA provisions; have your counsel adapt them to the specific vendor relationship rather than signing whatever template lands in your inbox.

    What's at stake if you get it wrong

    Penalty exposure applies to covered entities and business associates alike — your vendor's compliance failure can become your problem, and vice versa.

    Civil penalties are tiered by culpability (45 CFR 160.404) and adjusted annually for inflation under 45 CFR 102.3. As adjusted effective January 28, 2026, they range from $145 minimum per violation at Tier 1 (did not know and could not reasonably have known) up to $2,190,294 at Tier 4 (willful neglect, not corrected), with a regulatory calendar-year cap of $2,190,294 for identical violations in each tier (45 CFR 102.3, current as of July 2026). In practice, under HHS's April 2019 Notification of Enforcement Discretion (84 FR 18151), OCR applies lower annual caps per tier — from $25,000 (no knowledge) up to $1,500,000 (uncorrected willful neglect), as adjusted for inflation.

    Criminal penalties exist too, prosecuted by the Department of Justice: knowingly obtaining or disclosing individually identifiable health information in violation of the Privacy Rule carries up to $50,000 and one year of imprisonment — rising to $100,000 and five years for false pretenses, and $250,000 and ten years where the conduct involves intent to sell or use the information for commercial advantage, personal gain, or malicious harm (HHS, Summary of the HIPAA Privacy Rule).

    You don't need to memorize the tiers. You need a vendor whose paperwork and stack keep you out of them.

    HIPAA-compliant answering service checklist: 8 things to verify before you sign

    Use this when evaluating any AI receptionist, virtual receptionist, or answering service for your med spa — any "HIPAA compliant virtual receptionist" claim should survive all eight:

    1. A written BAA, on every plan. Not "available on enterprise," not "HIPAA-conscious workflows," not "eligible deployments can be covered." Hedged compliance language usually means the answer is no. If the BAA isn't offered before you pay, walk.
    2. BAA contents that match 45 CFR 164.504(e). Check for breach reporting, subcontractor flow-down, patient-rights support, and return-or-destroy at termination — the full list above.
    3. Security Rule safeguards for voice data. Recordings and transcripts are electronic PHI. Ask how they're encrypted, who can access them, and how access is logged.
    4. Subcontractor BAAs across the whole stack. Telephony, transcription, AI model, storage — every layer touching PHI needs its own agreement. Ask the vendor to name the chain.
    5. Breach notification commitments in writing. Who tells whom, and how fast, when something goes wrong.
    6. A data retention and deletion policy. How long call data lives, and what happens to it when you leave.
    7. A clear answer on AI training. Ask directly: is our patients' call data used to train models? Get the answer in writing.
    8. Published proof of testing. Anyone can claim their AI behaves. Ask how they verify it — and whether they'll show you the methodology, not just a badge.

    A vendor that clears all eight isn't rare because the bar is high. In our experience evaluating this market, it's rare because many phone AI products were built for plumbers and pizza shops first — with "healthcare" added to the pricing page later.

    How Cordiva handles HIPAA

    Cordiva is a bilingual AI receptionist built specifically for med spas — and HIPAA was a day-one design constraint, not a retrofit.

    • BAA in every plan — including the Starter plan ($299/month), not gated behind an enterprise tier. You can request our BAA template before signing anything. See pricing.
    • Every layer that touches PHI is under BAA. Voice provider, AI model, and data storage operate under agreements down the subcontractor chain, and integrations are PHI-minimized by design — patient data never reaches a layer that isn't covered. Our full compliance statement is at /hipaa.
    • Tested, and we show our work. We publish exactly how we test our agents — so "the AI behaves" is something you can verify, not something you take on faith.
    • Coverage where the calls actually happen. 45% of appointments scheduled via Zocdoc are booked after hours, per Zocdoc's own platform data — which is precisely when a front desk can't answer and a compliant AI receptionist earns its keep.
    • Bilingual by design. English and Spanish, native quality, with language detection mid-call — see our bilingual medical answering service. It matters: 35% of Hispanic adults prefer a Spanish-speaking provider for routine care, rising to 81% among Spanish-dominant Hispanics (Pew Research Center, 2022).
    • Live in 7 business days from the moment we have your services, pricing, booking access, and signed BAA.

    Ready to hear it handle a real call?

    On the discovery call we'll map your call flows, hand you the BAA template up front, and you can listen to the agent live before you sign anything.

    A necessary disclaimer

    This guide is general information about HIPAA as it applies to answering services, virtual receptionists, and AI receptionists — it is not legal advice, and reading it does not create an attorney-client relationship. Regulations and penalty amounts change: HHS adjusts civil penalty figures annually for inflation at 45 CFR 102.3, and the figures above reflect the adjustment effective January 28, 2026 (current as of July 2026). Confirm your practice's covered-entity status and review any BAA with a qualified healthcare attorney before signing.

    Frequently asked questions

    A BAA is a written contract required by HIPAA (45 CFR 164.504(e)) between a covered health care provider and any vendor that handles protected health information on its behalf. It must define permitted uses of PHI, require safeguards, mandate breach reporting, flow obligations down to subcontractors, and require the vendor to return or destroy PHI at termination.

    Yes. HIPAA expressly permits a covered practice to let a business associate create, receive, maintain, and transmit PHI on its behalf (45 CFR 164.502(e)(1)(i)) — provided a written BAA is in place. Once calls are recorded or transcribed, that data is electronic PHI, so the vendor must also meet the HIPAA Security Rule's technical, physical, and administrative safeguards.

    Almost never. HHS reserves the conduit exception for entities that merely transport PHI — the US Postal Service, certain private couriers, and their electronic equivalents. A service that answers, records, transcribes, or stores patient calls is creating, receiving, and transmitting PHI on your behalf, which makes it a business associate that needs a BAA. Treat a phone vendor invoking the conduit exception as a red flag.

    No — the BAA is the floor, not the ceiling. It permits the vendor to handle PHI and sets contractual obligations, but it doesn't by itself make the vendor's system secure. The vendor must also implement the Security Rule's safeguards for stored voice data and hold subcontractor BAAs with every downstream provider that touches PHI.

    Yes. The Privacy Rule protects PHI in any form or media — electronic, paper, or oral (HHS) — so patient information spoken on a call is PHI. Once a call is recorded, transcribed, or processed by software, the stored voice data becomes electronic PHI subject to the HIPAA Security Rule's safeguards as well.

    Ready to transform your business?

    Fill out this form and our virtual assistant will call you immediately to show you how Cordiva can help you automate your calls and grow your business.