No software is HIPAA compliant on its own, and no vendor can be HIPAA certified — that certification does not exist. An AI receptionist is HIPAA-aware when the vendor acts as a business associate under a signed BAA, encrypts PHI in transit and at rest, isolates each practice's data, and keeps audit logs. Compliance is shared with your practice.
Updated August 23, 2026 · 7 min read

Every dentist evaluating an AI phone system asks some version of this question, and every honest answer starts the same way: HIPAA does not apply to products. It applies to covered entities — your practice — and to business associates, the vendors who handle protected health information on your behalf. A phone system is not compliant or non-compliant the way a battery is charged or dead. It is a component inside an arrangement that either meets the rule or does not.
So the useful version of the question is: can this vendor be operated as a compliant business associate, and will they contractually commit to it? That question has a real answer, and you can check it in an afternoon. This page is a practical walkthrough, not legal advice — the specifics of your practice, your state, and your existing agreements should go to your own counsel.
Yes, and it is worth being blunt about it, because some vendors get vague here. Protected health information is any health information tied to an identifiable person. When someone calls a dental office and says "this is Maria Lopez, I chipped a molar and I need to be seen", that call is PHI from the first sentence. So are:
Any vendor that answers your phone is handling PHI. That is not a reason to avoid AI — a human answering service handles exactly the same data and has been doing so for decades. It is a reason to run the same due diligence you would run on any other business associate. If you are still working out what an answering service does at all, start with what is a dental answering service and the dental answering service overview.
The Security Rule is organized around administrative, physical, and technical safeguards. Translated into things you can verify about an AI receptionist, that comes down to a short list.
| Ask the vendor | Why it matters | Answer to look for |
|---|---|---|
| Will you sign a BAA, and when? | Without it you cannot lawfully route PHI to them at all | Yes — signed before any live patient data |
| How is PHI encrypted? | Calls, transcripts, and stored records are all exposure points | Encrypted in transit and at rest |
| Is my practice's data isolated? | Multi-tenant systems can leak across customers if not separated | Per-practice isolation, no shared patient records |
| Are there audit logs? | You need to be able to answer who accessed what, and when | Audit logging on access to PHI |
| Which subprocessors touch PHI? | Your BAA obligations flow down the chain | A named list you can review |
| How long are recordings kept? | Retention you cannot control is retention you cannot defend | A stated policy you have some say over |
| What is your breach process? | Your notification clock depends on theirs | A written process with a defined timeline |
If a vendor cannot answer six of these seven in writing, that is the finding. You do not need to be a security expert to run this checklist — you need the answers on paper.
There is no federal HIPAA certification. HHS does not certify vendors, and no private body has the authority to make a product officially compliant. When a marketing page says HIPAA certified, it usually means one of three things: someone on the team took a training course, the company ran a self-assessment, or a consultant issued a certificate with no regulatory standing.
None of those are worthless, but none of them are what you are buying. The words that carry actual weight are HIPAA-aware plus a signed BAA: one describes how the system is built, the other creates enforceable obligations. Be equally careful with the phrase fully compliant — a vendor cannot be fully compliant on your behalf, because half of the arrangement is inside your office.
A Business Associate Agreement is the contract that extends HIPAA obligations to a vendor handling PHI for you. It covers permitted uses of the data, required safeguards, subcontractor obligations, breach notification, and what happens to the data when the relationship ends.
The timing rule is the part practices get wrong. The BAA has to be in place before any live patient data reaches the vendor. Signing it later does not cover what already flowed. In practice, that means a scripted demo on test data is fine before signing, and a pilot week where the AI answers real patient calls is not. Dentovox signs a BAA before any live patient data is involved — the terms are on the BAA page, and the technical safeguards are described on security.
Both parties, in different ways, and this is the single most important thing to understand before signing anything.
You cannot outsource your side of that to a software subscription. What a good vendor does is make your side easier to satisfy: clear logs, controllable retention, a real security page, and a BAA that does not need a month of redlining. What you should not accept is a vendor whose answer to responsibility questions is that their platform handles it.
Two questions come up constantly, and both deserve straight answers from any vendor you evaluate.
Recordings and transcripts. These are PHI. Ask how long they are stored, who inside the vendor can read them, whether access is logged, and whether you can shorten retention. Also make sure your outbound greeting discloses recording where required — recording-consent rules vary by state and are a separate body of law from HIPAA, so this one goes to your counsel too.
Model training. Ask directly whether your patient data is used to train models, and get the answer in the BAA rather than in an email. This is the newest question in vendor due diligence and the one most likely to be answered loosely.
The same logic applies to SMS. Text messages about appointments are PHI, and they also sit under the separate consent regime of the TCPA — quiet hours, STOP handling, records of consent. Dentovox messaging supports STOP opt-out and quiet-hour windows in English and Spanish, but which patients you may text, and on what basis, is a policy decision for you and your counsel.
To state it plainly and without decoration: Dentovox is built HIPAA-aware, and a BAA is signed before any live patient data. PHI is encrypted in transit and at rest, each practice's data is isolated from every other practice's, and access to PHI is audit-logged. Bookings are written into Dentrix, Open Dental, or Eaglesoft through the NexHealth integration rather than into a parallel record you would then have to reconcile.
The AI receptionist answers in English or Spanish based on how the caller speaks — see bilingual and Spanish-speaking dental patients — and escalates emergencies to your on-call path. It is not an emergency service: a caller in a medical emergency is directed to 911. Plans start at $249/month for Starter and run $399 Core, $599 Growth, and $899 per location for Multi / DSO, with 15% off annual — details on pricing. What none of that does is make compliance automatic on your side. It makes your side checkable.
An AI receptionist can be operated in a HIPAA-aware way, but no product is HIPAA compliant on its own. HIPAA compliance is a property of how a covered entity and its business associate work together. For a dental practice, that means a signed Business Associate Agreement before any live patient data, encryption of PHI in transit and at rest, per-practice data isolation, audit logging, and internal policies on your side that match. Consult your counsel for your own situation.
No. There is no official HIPAA certification body and no government-issued HIPAA certificate. Any vendor advertising itself as HIPAA certified is describing something that does not exist, usually a self-assessment or a third-party training course. Ask instead for a Business Associate Agreement, a description of safeguards, and evidence of how they handle breach notification.
A Business Associate Agreement is the contract that binds a vendor handling protected health information on your behalf to HIPAA safeguard, use, and breach-notification obligations. It has to be signed before any live patient data reaches the vendor. Signing it afterward does not retroactively cover what already flowed. Demos and pilots that use real patient calls count as live data.
Yes. The moment a caller gives a name and a reason for calling to a dental office, that combination is protected health information. Appointment times, insurance details, chart lookups, callback numbers, and call recordings are all PHI when tied to an identifiable patient, so the vendor answering the phone is handling PHI and must be treated as a business associate.
Responsibility is shared. The practice remains the covered entity and is accountable for vendor due diligence, having a BAA in place, and its own workforce practices. The vendor, as a business associate, is directly liable for its safeguards and for notifying the practice of a breach on the timeline set in the BAA. Your counsel should review both sides for your specific arrangement.
Ask whether they will sign a BAA and how quickly, how PHI is encrypted in transit and at rest, whether each practice's data is isolated from other customers, whether audit logs exist and who can read them, how long recordings and transcripts are retained and whether you can control that, which subprocessors touch PHI, and what the breach-notification process and timeline look like.
This page is general information about vendor due diligence, not legal advice. HIPAA, state recording-consent law, and TCPA consent rules depend on your specific circumstances — consult your counsel before you change how patient calls or messages are handled.