Security & Compliance

Is an AI receptionist HIPAA compliant?

No software is HIPAA compliant on its own, and no vendor can be HIPAA certified — that certification does not exist. An AI receptionist is HIPAA-aware when the vendor acts as a business associate under a signed BAA, encrypts PHI in transit and at rest, isolates each practice's data, and keeps audit logs. Compliance is shared with your practice.

Updated August 23, 2026 · 7 min read

A clinician preparing sterile dental instruments

Why the question does not have a yes-or-no answer

Every dentist evaluating an AI phone system asks some version of this question, and every honest answer starts the same way: HIPAA does not apply to products. It applies to covered entities — your practice — and to business associates, the vendors who handle protected health information on your behalf. A phone system is not compliant or non-compliant the way a battery is charged or dead. It is a component inside an arrangement that either meets the rule or does not.

So the useful version of the question is: can this vendor be operated as a compliant business associate, and will they contractually commit to it? That question has a real answer, and you can check it in an afternoon. This page is a practical walkthrough, not legal advice — the specifics of your practice, your state, and your existing agreements should go to your own counsel.

Does an AI receptionist actually touch PHI?

Yes, and it is worth being blunt about it, because some vendors get vague here. Protected health information is any health information tied to an identifiable person. When someone calls a dental office and says "this is Maria Lopez, I chipped a molar and I need to be seen", that call is PHI from the first sentence. So are:

Any vendor that answers your phone is handling PHI. That is not a reason to avoid AI — a human answering service handles exactly the same data and has been doing so for decades. It is a reason to run the same due diligence you would run on any other business associate. If you are still working out what an answering service does at all, start with what is a dental answering service and the dental answering service overview.

What does HIPAA actually require of a phone vendor?

The Security Rule is organized around administrative, physical, and technical safeguards. Translated into things you can verify about an AI receptionist, that comes down to a short list.

Ask the vendorWhy it mattersAnswer to look for
Will you sign a BAA, and when?Without it you cannot lawfully route PHI to them at allYes — signed before any live patient data
How is PHI encrypted?Calls, transcripts, and stored records are all exposure pointsEncrypted in transit and at rest
Is my practice's data isolated?Multi-tenant systems can leak across customers if not separatedPer-practice isolation, no shared patient records
Are there audit logs?You need to be able to answer who accessed what, and whenAudit logging on access to PHI
Which subprocessors touch PHI?Your BAA obligations flow down the chainA named list you can review
How long are recordings kept?Retention you cannot control is retention you cannot defendA stated policy you have some say over
What is your breach process?Your notification clock depends on theirsA written process with a defined timeline

If a vendor cannot answer six of these seven in writing, that is the finding. You do not need to be a security expert to run this checklist — you need the answers on paper.

Why is "HIPAA certified" a red flag?

There is no federal HIPAA certification. HHS does not certify vendors, and no private body has the authority to make a product officially compliant. When a marketing page says HIPAA certified, it usually means one of three things: someone on the team took a training course, the company ran a self-assessment, or a consultant issued a certificate with no regulatory standing.

None of those are worthless, but none of them are what you are buying. The words that carry actual weight are HIPAA-aware plus a signed BAA: one describes how the system is built, the other creates enforceable obligations. Be equally careful with the phrase fully compliant — a vendor cannot be fully compliant on your behalf, because half of the arrangement is inside your office.

What is a BAA, and when does it have to be signed?

A Business Associate Agreement is the contract that extends HIPAA obligations to a vendor handling PHI for you. It covers permitted uses of the data, required safeguards, subcontractor obligations, breach notification, and what happens to the data when the relationship ends.

The timing rule is the part practices get wrong. The BAA has to be in place before any live patient data reaches the vendor. Signing it later does not cover what already flowed. In practice, that means a scripted demo on test data is fine before signing, and a pilot week where the AI answers real patient calls is not. Dentovox signs a BAA before any live patient data is involved — the terms are on the BAA page, and the technical safeguards are described on security.

Who is responsible when something goes wrong?

Both parties, in different ways, and this is the single most important thing to understand before signing anything.

You cannot outsource your side of that to a software subscription. What a good vendor does is make your side easier to satisfy: clear logs, controllable retention, a real security page, and a BAA that does not need a month of redlining. What you should not accept is a vendor whose answer to responsibility questions is that their platform handles it.

What about call recordings, transcripts, and AI models?

Two questions come up constantly, and both deserve straight answers from any vendor you evaluate.

Recordings and transcripts. These are PHI. Ask how long they are stored, who inside the vendor can read them, whether access is logged, and whether you can shorten retention. Also make sure your outbound greeting discloses recording where required — recording-consent rules vary by state and are a separate body of law from HIPAA, so this one goes to your counsel too.

Model training. Ask directly whether your patient data is used to train models, and get the answer in the BAA rather than in an email. This is the newest question in vendor due diligence and the one most likely to be answered loosely.

The same logic applies to SMS. Text messages about appointments are PHI, and they also sit under the separate consent regime of the TCPA — quiet hours, STOP handling, records of consent. Dentovox messaging supports STOP opt-out and quiet-hour windows in English and Spanish, but which patients you may text, and on what basis, is a policy decision for you and your counsel.

How Dentovox approaches it

To state it plainly and without decoration: Dentovox is built HIPAA-aware, and a BAA is signed before any live patient data. PHI is encrypted in transit and at rest, each practice's data is isolated from every other practice's, and access to PHI is audit-logged. Bookings are written into Dentrix, Open Dental, or Eaglesoft through the NexHealth integration rather than into a parallel record you would then have to reconcile.

The AI receptionist answers in English or Spanish based on how the caller speaks — see bilingual and Spanish-speaking dental patients — and escalates emergencies to your on-call path. It is not an emergency service: a caller in a medical emergency is directed to 911. Plans start at $249/month for Starter and run $399 Core, $599 Growth, and $899 per location for Multi / DSO, with 15% off annual — details on pricing. What none of that does is make compliance automatic on your side. It makes your side checkable.

Frequently asked questions

Is an AI receptionist HIPAA compliant?

An AI receptionist can be operated in a HIPAA-aware way, but no product is HIPAA compliant on its own. HIPAA compliance is a property of how a covered entity and its business associate work together. For a dental practice, that means a signed Business Associate Agreement before any live patient data, encryption of PHI in transit and at rest, per-practice data isolation, audit logging, and internal policies on your side that match. Consult your counsel for your own situation.

Can a vendor be HIPAA certified?

No. There is no official HIPAA certification body and no government-issued HIPAA certificate. Any vendor advertising itself as HIPAA certified is describing something that does not exist, usually a self-assessment or a third-party training course. Ask instead for a Business Associate Agreement, a description of safeguards, and evidence of how they handle breach notification.

What is a BAA and when does it need to be signed?

A Business Associate Agreement is the contract that binds a vendor handling protected health information on your behalf to HIPAA safeguard, use, and breach-notification obligations. It has to be signed before any live patient data reaches the vendor. Signing it afterward does not retroactively cover what already flowed. Demos and pilots that use real patient calls count as live data.

Does an AI receptionist actually handle PHI?

Yes. The moment a caller gives a name and a reason for calling to a dental office, that combination is protected health information. Appointment times, insurance details, chart lookups, callback numbers, and call recordings are all PHI when tied to an identifiable patient, so the vendor answering the phone is handling PHI and must be treated as a business associate.

Who is responsible if an AI receptionist causes a HIPAA breach?

Responsibility is shared. The practice remains the covered entity and is accountable for vendor due diligence, having a BAA in place, and its own workforce practices. The vendor, as a business associate, is directly liable for its safeguards and for notifying the practice of a breach on the timeline set in the BAA. Your counsel should review both sides for your specific arrangement.

What should I ask an AI phone vendor before sending real patient calls?

Ask whether they will sign a BAA and how quickly, how PHI is encrypted in transit and at rest, whether each practice's data is isolated from other customers, whether audit logs exist and who can read them, how long recordings and transcripts are retained and whether you can control that, which subprocessors touch PHI, and what the breach-notification process and timeline look like.

This page is general information about vendor due diligence, not legal advice. HIPAA, state recording-consent law, and TCPA consent rules depend on your specific circumstances — consult your counsel before you change how patient calls or messages are handled.