Is an AI Answering Service HIPAA Compliant? What Medical Practices Need to Know (2026)
HIPAA compliance for an AI answering service isn't automatic — it depends on a signed BAA, encryption, and audit logging. Here's what medical practices need to verify before signing, with real vendor pricing.
Short answer: No AI answering service is "HIPAA compliant" out of the box just because a vendor says so — compliance depends on whether they'll sign a Business Associate Agreement (BAA), encrypt patient data in transit and at rest, and keep an audit log of who accessed what. Some vendors (Ruby, Assort Health) build for this. Others (Smith.ai, by its own guidance) point practices without PHI-handling needs toward their standard plans, not PHI-heavy calls. The label on the website isn't the answer — the contract is.
What actually makes an AI answering service HIPAA compliant?
HIPAA doesn't certify software the way a fire marshal certifies a building — there's no seal to check for. What actually matters when evaluating a vendor:
- A signed Business Associate Agreement (BAA) — the vendor is legally on the hook for how it handles PHI, not just claiming good practices in a blog post
- Encryption in transit and at rest — call recordings, transcripts, and patient data can't sit in plain text anywhere in the pipeline
- Audit logging — a record of who or what system accessed a given patient's information and when
- Data retention and deletion controls — you can show a regulator exactly how long PHI is kept and how it's purged
- Where the AI model itself sits — if a vendor routes calls through a general-purpose model without a BAA covering that model provider, the chain breaks even if the vendor's own platform is compliant
A vendor can be a legitimate business and still not offer any of this. Ask for the BAA before you ask about features.
Which AI answering vendors actually support medical practices?
| Vendor | Built for healthcare/PHI? | Starting price (2026) |
|---|---|---|
| Assort Health | Yes — purpose-built AI voice agent for healthcare, cites HIPAA, HITRUST, and SOC 2; signs a BAA | ~$1,500/mo for smaller clinics, scaling to $10,000+/mo for larger networks; custom pricing |
| Ruby | Yes — HIPAA-compliant security included across its live-receptionist plans | $129-$999/mo depending on call/chat volume (Call Ruby and Chat Ruby tiers) |
| Weave | Yes — communications platform used widely across dental and medical practices, with call intelligence on higher tiers | ~$249/mo+ per location (Pro), commonly $400-$900/mo once add-ons and setup are counted |
| Smith.ai | Conditional — human-in-the-loop receptionist; the vendor's own guidance steers PHI-heavy call handling elsewhere | Plans generally start in the low hundreds per month; confirm current tiers directly |
(Pricing pulled from vendor sites and third-party pricing trackers as of 2026. Enterprise healthcare AI pricing is often custom-quoted — treat these as a budgeting starting point, not a locked quote.)
Why does a general-purpose AI receptionist tool fall short here?
Most AI answering tools built for home services or retail were never designed to touch PHI. They may encrypt data reasonably well and still lack the one piece medical practices need: a BAA naming them, in writing, as a business associate under HIPAA. Without that signed agreement, using the tool for patient scheduling, symptoms, or insurance details can expose the practice to liability regardless of how secure the software actually is — the exact gap Smith.ai flags in its own guidance.
:::cta Not sure whether your current phone setup actually meets the bar for patient calls? The free strategy brief maps what you're using today against what HIPAA actually requires. Get my free strategy brief → :::
What's the real "cost of the stack" for a compliant medical answering setup?
The headline monthly price is rarely the full bill. Practices piecing this together typically end up paying for:
- The core answering/receptionist platform (the number vendors quote)
- A signed BAA and any compliance review to confirm it covers your specific use case
- Integration work to connect the answering tool to your EHR or scheduling system
- Staff time reviewing transcripts or escalations the AI can't resolve on its own
- A separate no-show reminder or patient-intake tool, since most answering platforms don't cover all of it natively
For a small to mid-size practice handling routine call volume, a realistic all-in range lands around $300-$1,500/month once compliance and integration are counted — with purpose-built platforms like Assort Health running well above that for larger, multi-location groups.
Does a HIPAA-compliant answering service replace front-desk staff entirely?
No, and vendors that imply otherwise are overselling it. These tools handle routine volume — appointment requests, rescheduling, basic triage questions, after-hours coverage — and route anything ambiguous to a human. Front-desk staff still make the clinical judgment calls. The realistic win is fewer routine calls landing on staff, not zero staff.
Where does StoryDrips fit in?
We don't sell a standalone HIPAA-compliant phone line as a separate subscription. StoryDrips builds the AI answering layer into your practice's broader customer-service setup — connected to your scheduling calendar, with a compliance posture reviewed for your specific use case, instead of a bolted-on tool with its own login and its own bill. The same AI Operating Partner that answers a patient's call can also handle the no-show reminders that keep your schedule full and the answering-service cost question dental practices ask — see how it maps to your practice at our healthcare industry page.
None of these compare — StoryDrips is an AI Operating Partner that runs patient answering as one engine of many, coordinated in one chat instead of scattered across separate vendor logins.
FAQ
Is ChatGPT or a generic AI phone tool HIPAA compliant? No, not by default. General-purpose AI tools are not HIPAA compliant unless the specific vendor has signed a BAA covering that exact deployment. Assume "no" until you have that document in hand.
What is a BAA, and why does it matter here? A Business Associate Agreement is a legal contract that makes a vendor directly accountable under HIPAA for how it handles PHI on your behalf. Without one, a genuinely secure tool still leaves your practice exposed if something goes wrong.
Is Weave or Ruby a better fit than a healthcare-specific platform like Assort Health? Depends on scale. Weave and Ruby serve medical and dental practices broadly at lower price points. Purpose-built platforms like Assort Health go deeper on healthcare-specific workflows but start materially higher, aimed at larger clinics and networks.
How do I verify a vendor's HIPAA compliance claim before signing? Ask directly for a BAA, ask where call data and transcripts are stored and for how long, and ask which AI model or subprocessor handles the call if it's not fully in-house. A vendor that hesitates on any of these is a signal, not an answer.
Does this article count as legal or compliance advice? No. This is a starting point for vendor evaluation, not a compliance determination for your practice. Confirm HIPAA obligations with your compliance officer or healthcare counsel before signing any vendor agreement.