The honesty page
HIPAA and AI receptionists: what’s real, what’s marketing.
Start with the sentence most vendors won’t put on a page: there is no official HIPAA certification—for anyone. Not for us, not for our competitors, not for your EHR. What exists instead is a set of obligations you can verify. This page explains them in plain English, and gives you the questions that expose overclaiming vendors—including how to test us.
Why “HIPAA certified” badges aren’t real
The U.S. Department of Health and Human Services does not certify products or companies as HIPAA compliant. There is no government-issued badge, seal, or accreditation—and HHS has said so publicly for years. Private companies sell “HIPAA certification” trainings and audits, and some of those reviews are genuinely useful diligence, but none of them carry legal force, and none make a vendor “certified” in the way the badge implies.
So when a voice-AI vendor puts HIPAA CERTIFIED in its hero section, you’ve learned something useful—just not what they intended: they either don’t understand the regulation or hope you don’t. Compliance isn’t a badge; it’s an ongoing set of obligations that lives in contracts, configurations, and habits.
This page is educational, not legal advice. HIPAA decisions for your practice belong with your compliance officer or healthcare counsel—bring them in before signing any voice-AI contract, ours included.
What HIPAA actually requires of a phone-answering vendor
When a vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity, it generally acts as a business associate. That status is what triggers the real obligations:
- A written business associate agreement (BAA) between the practice and the vendor, before PHI flows—defining permitted uses, safeguards, and breach duties.
- Minimum necessary handling: collect and expose only the PHI the task needs. An intake call needs a name and a callback number, not a medication history.
- Safeguards—administrative, technical, and physical: access controls, encryption in transit and at rest, audit trails, workforce rules.
- Retention and deletion policies someone can actually state: what’s stored, where, for how long, and how it’s destroyed.
- Breach notification duties that flow through the BAA chain to the practice.
The part specific to AI receptionists: the subprocessor chain
A voice agent is never one company. Telephony carries the call, a speech provider transcribes it, a language model generates responses, infrastructure stores transcripts. Each link that touches call content matters: your vendor should be able to name its subprocessors and explain the agreements and safeguards at every hop. If they can’t draw you that chain, they haven’t scoped it.
“Our AI never touches PHI” is usually wishful thinking
Even a strictly administrative workflow gets PHI volunteered at it. Callers say “I need to reschedule because my biopsy came back,” or ask whether a treatment is safe with the medication they just named. The workflow didn’t ask; the PHI arrived anyway.
Honest scoping assumes this will happen and answers it by design: minimize what’s asked, decline what shouldn’t be discussed, flag what arrived unprompted, and control what’s retained. Vendors who promise zero PHI exposure are describing their intake form, not their phone line.
How ClinicGreet approaches it
No badges. Before launch, we scope PHI handling with your practice in writing: what the agent may ask, what it must decline, which subprocessors touch call data, what’s retained and for how long, and your BAA requirements—settled before the agent takes its first call. Clinical questions—suitability, medication, dosing, outcomes—are never answered; they’re captured, labeled provider-only, and routed to your team. Emergencies are directed to 911 immediately.
Our public demo line shows the posture in miniature: the greeting announces a transcribed line, no audio recording is saved, transcripts are deleted within one day, and review happens only in aggregate. The demo is a fictional med spa—production configurations are scoped per clinic, and pilots don’t launch until the privacy scoping is done.
Take this to every vendor
Eight questions that expose overclaiming
Ask us these too—a vendor who resents the list is answering the last one for you.
- Will you sign a BAA? If PHI will flow and the answer is anything but a clear process, stop here.
- Which subprocessors touch call audio or transcripts? Telephony, transcription, language model, storage—named, with the agreements at each hop.
- Is audio recorded? Where does it live? “We don’t save audio” and “we record everything indefinitely” are very different products.
- What’s the transcript retention policy? A number and a deletion mechanism—not “industry standard practices.”
- Who at your company can read call data, and why? Access control is a who-and-why answer, not a “bank-grade encryption” slogan.
- How do you minimize PHI by design? What the agent refuses to ask, refuses to answer, and flags when volunteered.
- What happens on clinical questions and emergencies? The only right answer: route to providers; direct emergencies to 911. Every time.
- Are you “HIPAA certified”? Trick question. If they say yes, you’ve learned how they handle the truth under sales pressure.
Straight answers
HIPAA questions, answered honestly
Is any AI receptionist HIPAA certified?
No. HHS does not issue a HIPAA certification for vendors or products—for anyone. A “HIPAA certified” badge is marketing shorthand at best. The real questions are whether the vendor will sign a BAA, how PHI is scoped and retained, and which subprocessors touch call data.
Is an AI receptionist a business associate?
Generally, a vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity acts as a business associate and needs a written BAA. An AI receptionist answering a clinic’s phone typically fits, because callers volunteer health details even on administrative calls. Confirm specifics with your compliance counsel.
Does ClinicGreet claim HIPAA certification?
No, because no such certification exists. Instead, PHI handling, vendors, data retention, BAA requirements, and integrations are scoped with your clinic before launch—in writing, before the agent takes its first call.
Can an AI receptionist avoid PHI entirely?
You can minimize PHI—limit what’s asked, stored, and retained—but you shouldn’t assume zero exposure, because callers volunteer health information even when the workflow never asks. Sound scoping assumes PHI will appear and plans its handling.
What should I ask a vendor about HIPAA?
The eight questions above—BAA, subprocessors, audio storage, retention, access, minimization, clinical/emergency handling, and whether they claim a certification that doesn’t exist.
Honesty is the product
Scope it properly, or don’t ship it.
Hear the posture on a live line, then bring your compliance questions to the scoping call—we’d rather earn the pilot than the badge.
Call the live demoCompliance questions welcome: [email protected] — or start a pilot request.