Healthcare practices face a specific tension. They need to answer every patient call, and they need to protect sensitive health information while doing it. A general-purpose AI chatbot bolted onto a phone line does not clear that bar.
BAA coverage is non-negotiable
Any vendor that creates, receives, maintains, or transmits protected health information on your behalf is a business associate and must sign a Business Associate Agreement. That includes an AI answering service, because a caller describing symptoms to book an appointment has just disclosed PHI.
Without a signed BAA you are exposed even if the vendor never stores a patient record, and even if nothing goes wrong. The agreement itself is part of the requirement.
The checklist to run before go-live
- Signed BAA in place before the first live call, not after the pilot
- Call audio and transcripts encrypted in transit and at rest
- Written retention policy, so you know how long recordings are kept and who can delete them
- Explicit confirmation that your call data is not used to train shared or public models
- Role-based access control, so only named staff can open a transcript
- Audit trails covering call handling, transfers, and who viewed what
- A documented breach notification process with defined timelines
- Subcontractor disclosure, because your vendor's vendors handle your data too
The question most practices forget to ask
Ask where the underlying voice and language models run, and whether any part of the call leaves the covered environment. Many AI products are thin layers over third-party model providers. That is fine, provided those providers are themselves covered by the chain of agreements and are not retaining your data for training. Get the answer in writing.
Minimum necessary applies to AI too
The minimum necessary standard does not pause because a machine is on the line. Your agent should collect only what it needs to book the appointment and route the call. Design the script so it does not invite callers to volunteer a full clinical history, and make sure the summary written to your dashboard is scoped accordingly.
Why done-for-you usually beats DIY here
Building a compliant AI phone system in-house means legal review, vendor vetting, encryption and retention configuration, access control, and an ongoing owner for all of it. That is months of work before a single call is answered, and the obligation does not end at launch.
A managed service that signs the BAA, handles the configuration, and maintains it as models and vendors change lets you keep your attention on patient care. If you run a dental practice specifically, the operational side is covered in AI receptionist for dental offices.