What actually makes an AI receptionist HIPAA compliant
Every AI receptionist that wants healthcare customers says "HIPAA compliant" somewhere on its site. Most of them hope you will not ask a second question.
Here is the second question, and the third, and the rest of them.
HIPAA is a posture, not a badge
There is no such thing as a HIPAA certificate. No government body certifies software as compliant, which means a vendor advertising HIPAA certification is telling you mostly that they hope you will not check. What exists instead is a set of obligations: administrative, physical, and technical safeguards for protected health information (PHI), and a chain of accountability that follows the data wherever it goes.
For an AI receptionist, that chain starts the moment a patient says their name on a call. The recording, the transcript, the phone number, the appointment reason: all of it can be PHI. Whoever stores or processes it needs to be inside the compliance boundary with you.
The BAA is the whole ballgame
A Business Associate Agreement is the legal instrument that puts a vendor inside that boundary. If a vendor touches PHI on your behalf and will not sign a BAA, you cannot use them for patient calls. It is genuinely that simple.
So the first practical test of any "HIPAA compliant" claim is: how do I get the BAA? In this category the usual answer is a sales call, a security questionnaire, and a setup fee. That is not wrong, but it tells you compliance was bolted on for enterprise deals. A product actually built for small practices treats the BAA like part of signup. hireJudi presents its BAA in the same e-signature flow your patients use, you sign it during setup, and the countersigned PDF lands in your account. Minutes, not weeks. The healthcare page walks through the whole flow.
The controls that should back the claim
A signed BAA without technical controls is a promise without a lock on the door. The specific things to look for:
- Encryption of sensitive fields at rest. Not just "encrypted disks": field-level protection for the data that identifies a patient.
- Enforced multi-factor authentication. Optional MFA is a suggestion. HIPAA mode should require it for every user who can see PHI.
- Immutable audit logs. When someone views or edits a record, that fact should be recorded somewhere nobody can quietly edit.
- PII redaction on AI processing. The AI layer should see the minimum it needs, and identifying details should be scrubbed where possible.
- Role-based access. The person at reception and the provider do not need identical access.
- Retention controls. You decide how long recordings and transcripts live.
Ask a vendor to name their controls specifically. Vague answers ("bank-level security") are their own kind of answer. Ours are listed plainly on the security page.
The trap nobody mentions: automations
Here is where careful practices get caught. Your receptionist may be compliant, and your EHR may be compliant, and the automation glue between them may be neither.
General-purpose automation tools are useful for business data but are not an approved PHI path in hireJudi. Zapier is non-PHI only. A PHI-enabled customer may use Keragon only after confirming that the customer has its own current Keragon BAA; hireJudi does not hold that BAA. Custom API access follows the disclosed customer-responsibility model. Every integration on our site is labeled with how it connects, because a compliance boundary you cannot see is a boundary you will eventually cross by accident.
A five-question vendor test
- Will you sign a BAA, and what does it take to get one signed?
- Which fields are encrypted at rest, specifically?
- Is MFA enforced or optional?
- Can I read an audit log of who accessed a patient record?
- When your product connects to my other tools, does PHI ride a BAA-covered pipe?
Any AI receptionist worth trusting with patient calls can answer all five in plain language. If the answers arrive quickly and specifically, you have found a product that treats compliance as architecture. If they arrive as a meeting invitation, you have found a sales process.
Judi answers all five on one page, and you can hear her handle a call before you ever create an account.