HIPAA

Adopting AI in a medical practice: the HIPAA questions to ask before you automate

Voice agents answering patient calls, AI intake, automated follow-ups — the productivity is real, and so is the PHI. The questions to settle with any AI vendor before the first patient interaction runs through it.

By ClearCompliance teamPublished 2026-09-21Last reviewed 2026-09-21For: Practice owners, office managers, and professional-services firms adopting AI

The automation wave has reached the front desk

AI has moved past the demo stage for practices: voice agents that answer and triage patient calls, intake bots that collect histories before the visit, automated recall and follow-up campaigns, and document workflows that read referrals and faxes. Specialist builders now assemble these systems for law firms and medical practices — Firm Intelligence is one example of the category: platforms, automations, and voice agents built for professional-services workflows.

Every one of those workflows touches protected health information the moment a patient says their name. That doesn't make automation a bad idea — it makes the vendor conversation a HIPAA conversation, and the practice is the party HIPAA holds responsible for having it.

First principle: your AI vendor is a business associate

A vendor whose system creates, receives, maintains, or transmits PHI on your behalf is a business associate. A voice agent that hears patient calls, an intake bot that stores answers, an automation that reads appointment data — all of it qualifies. Before go-live, not after, you need a signed business associate agreement with the vendor, and the vendor needs BAAs with its own chain: the model provider, the telephony platform, the transcription service, the hosting.

A builder that serves medical practices regularly will expect this question and answer it quickly. Treat hesitation on the BAA as a red flag, whatever the demo looked like.

The questions to settle before the first patient interaction

  1. Where do recordings and transcripts live, and for how long? Voice AI produces recordings, transcripts, and summaries — three copies of PHI per call. Get storage locations, retention periods, and deletion behavior in writing.
  2. Is our data used to train models? The answer for patient data should be no, contractually — not a dashboard toggle someone might flip.
  3. Who at the vendor can see our patients' information? Debugging, quality review, and prompt tuning all create human access paths. Ask how access is controlled and logged.
  4. Which subprocessors are in the chain? Model provider, telephony, transcription, hosting, analytics — each one that touches PHI needs BAA coverage, and you're entitled to the list.
  5. What happens when the AI gets it wrong? A misrouted message or a hallucinated callback is an operational incident; one that exposes PHI is potentially a reportable one. Agree on incident notification duties and timelines in the BAA.
  6. Can we get our data out? Export and deletion at offboarding should be defined before onboarding.

Update your own program — automation changes your risk analysis

HIPAA's Security Rule requires your risk analysis to reflect how ePHI actually flows, and adding an AI layer changes that picture: new systems in the inventory, new data flows, new vendors on the BAA list, and new staff procedures (what the front desk does when the voice agent escalates a call, who reviews AI-drafted messages before they send). A one-page addendum to your risk analysis and an updated vendor inventory cover most of it — the practices that get in trouble are the ones whose documentation still describes the pre-automation office.

The same logic applies beyond healthcare

Law firms and other professional-services firms adopting the same automations aren't usually covered entities, but their files are full of medical records and their clients expect HIPAA-grade handling. The vendor questions above translate almost verbatim — and a firm that serves healthcare clients as a business associate inherits the full obligation set.

Automation and compliance are not in tension. A practice with a documented program, signed BAAs, and an updated risk analysis can adopt AI faster than one improvising — because every vendor conversation starts from a checklist instead of a blank page.

Sources

HIPAA does not provide or recognize an official private certification. ClearCompliance provides readiness, implementation, and assessment services; clients remain responsible for their legal obligations. SOC 2 reports are issued by independent qualified CPA firms. ClearCompliance is not a law firm and does not provide legal advice. This article is educational and is not legal advice.

Apply this to your company.

Contact us and leave with a recommended scope, realistic timeline, and budget range.