HomeResourceWhat Clinics Should Actually Check Before Letting AI Answer Patient Calls

What Clinics Should Actually Check Before Letting AI Answer Patient Calls

Almost every voice AI vendor now puts the word HIPAA somewhere on its homepage. Far fewer explain what that word is actually doing there.

Here is the part that trips up clinic buyers. There is no certification body that declares software HIPAA compliant. No agency issues a badge. Compliance is a property of how you and the vendor operate together, and it lives in a contract long before it lives in a feature list.

That changes the order of the evaluation. Confirm the contractual position first, then compare capability among whatever survives. Done the other way round, practices fall for a product they then have to abandon at procurement.

Key Takeaways

  • No AI platform is inherently HIPAA compliant. The vendor’s contract and controls decide it, not the marketing page.
  • A signed Business Associate Agreement is the baseline. What separates vendors is whether it is included by default or gated behind a tier.
  • Ask directly whether patient data is used to train models, because many general-purpose voice platforms cannot commit to that on standard terms.
  • Retention and deletion policies matter more than encryption slides, since call recordings are the most sensitive artefact in this product category.
  • Configure the clinical escalation script before go-live and test it yourself. It is the single most important setup decision.

How We Assessed These

Every claim below comes from the vendor’s own published material rather than third-party roundups, which in this category are frequently written by competing vendors.

The ranking weighs compliance posture first, then the practical things that decide whether a system survives contact with a real front desk: what it does with a call once it answers, where the booking lands, and whether pricing is published or hidden behind a quote.

One caveat. Terms in this market change quickly and most of these companies publish no pricing at all. Confirm anything that matters directly before you sign.

The Five Checks That Decide Compliance

Blue low-poly illustration of a headset-wearing head with two chat bubbles, representing ai chat support.

A signed BAA. Any vendor creating, receiving, maintaining or transmitting protected health information on your behalf needs one. Ask for the standard template before the demo, not after.

Encryption in transit and at rest. Ask specifically about call recordings and transcripts, which is where patient data actually accumulates in a voice product.

A retention and deletion policy you control. How long are recordings kept, can you shorten that, and is deletion real deletion or a flag on a database row.

No model training on your data. Get it in writing that patient data is not used to train or fine-tune models and is not passed to subprocessors for that purpose.

Access controls and audit logging. You need to know who at the vendor can reach call data, and you need a report you can hand an auditor.

Five Platforms Worth Shortlisting

1. Central AI

Best for: small and mid-size practices that want published pricing and a self-serve start rather than an enterprise sales cycle.

Central AI runs an AI-first model with human backup, and its AI receptionist answers calls 24/7, books appointments live against your calendar and escalates to a live receptionist when it cannot resolve something.

It publishes fully HIPAA compliant status with BAAs executed for all customers handling patient data, ISO 27001:2022 certification, SOC 2 reports under NDA, and an explicit statement that customer data is never used for model training. Plans start at a published rate and include a free trial.

Trade-off: built for small businesses across many industries rather than healthcare exclusively, with no named EHR write-back integrations.

2. Assort Health

Best for: specialty and multi-location groups where scheduling rules would break a generic agent.

Assort is healthcare-only and the strongest of this group on record integration. Its own materials name Epic, Oracle Health, athenahealth, ModMed, NextGen, eClinicalWorks, Allscripts and Veradigm, alongside telephony platforms including Genesys, Five9 and NiCE.

Coverage runs past scheduling into triage, refills, referrals, insurance eligibility and intake, across voice, text, email and web chat. The company states it is HIPAA compliant and SOC 2 Type II certified, and provides a security questionnaire, SOC 2 report and signed BAA on request.

Trade-off: no published pricing, and implementation is engineer-led rather than self-serve.

3. Sully.ai

Best for: practices deliberately going AI-first across more than the phone.

Sully treats reception as one module among several AI roles, including scribing and coding, running under a single platform and one record connection. Practices expecting to add capability later without switching vendors tend to land here.

It states it is HIPAA compliant and will sign a BAA before processing patient data, encrypts that data in transit and at rest, applies role-based access and audit logging, and commits that patient data is not used for model training unless explicitly permitted. SOC 2 Type II and ISO 27001 attestations are available through its trust portal.

Trade-off: no published pricing, and heavier than a clinic needing phone cover alone.

4. Arini

Best for: dental practices and dental service organisations specifically.

Arini is built only for dental, which is both the pitch and the limit. Integration is native and bidirectional with OpenDental, Dentrix, EagleSoft, Denticon and CareStack among others, so a booking taken on the call lands on the schedule rather than in someone’s task list.

On compliance it states a signed BAA is included on every deployment rather than sold as an add-on, alongside AES-256 encryption, SOC 2 Type II infrastructure, call audit logs and role-based access controls as standard. Calls are handled in English and Spanish.

Trade-off: dental only, and no published pricing. If you run a medical clinic, this is not your shortlist.

5. Hello Patient

Best for: specialty practices that want the billing line covered as well as scheduling.

Hello Patient focuses on specialty patient access and states that appointments and updates are written back into the record rather than queued for staff. Its published coverage extends to inbound billing support and payment resolution, which is unusual in this category.

The company states it is HIPAA compliant, SOC 2 Type II certified, and signs a Business Associate Agreement with every customer.

Trade-off: no published pricing, and the specialty focus means a general practice should confirm the workflows match before committing.

Quick Comparison

Platform Best for BAA position Pricing published
Central AI Small and mid-size practices Executed for all customers handling patient data Yes
Assort Health Specialty and multi-location Provided on request No
Sully.ai AI-first operations Signed before patient data is processed No
Arini Dental groups and DSOs Included on every deployment No
Hello Patient Specialty plus billing Signed with every customer No

Every platform here will put a BAA in front of you, so the agreement alone will not separate them. What does separate them is where the booking lands, whether pricing is visible before a sales call, and how much implementation you are signing up for.

Where the Boundary Sits

A well-configured clinical agent handles scheduling, rescheduling and cancellation, demographic and insurance capture, refill request intake, directions and hours, and routine pre-visit instructions.

It does not triage. Anything that sounds like a symptom description, and specifically any mention of chest pain, breathing difficulty, severe bleeding or thoughts of self-harm, needs an unambiguous path that ends the booking flow and points the caller to emergency services.

Write that script before you go live, then call the number yourself and try to break it. Most buyers skip this and find the gap the hard way.

Test It Like Any Other Business Tool

The evaluation discipline here is not unique to healthcare. Pick three or four real scenarios, run every vendor through the identical script, and score them on the same sheet rather than on demo polish.

That is the approach worth taking with any AI you bring into the business, and this AI assistant comparison walks through the method for general-purpose assistants in detail.

For an agent answering patient calls, add three clinical scenarios to whatever else you test: a caller describing symptoms, a caller who wants a human immediately, and a caller speaking a language other than English.

One Email That Settles the Rest

If you take one thing from this, take this. Send every vendor on your shortlist the same message: please send your standard BAA, tell me which product surfaces it covers, and confirm in writing that patient data is not used to train models.

A vendor that works in healthcare will have that attached within a day. One that does not will offer you a call instead. Response time on that single email tells you more than any feature comparison, and it costs nothing to send to the whole list at once.

Frequently Asked Questions

Is any AI phone agent actually HIPAA compliant?

No software is inherently compliant. It becomes usable under HIPAA when the vendor signs a BAA, encrypts data in transit and at rest, gives you control over retention, commits in writing not to train on your data, and provides audit logs. Get all five before going live.

What should a clinic ask about pricing?

Ask whether the headline price includes the compliance tier. Where a BAA is gated behind an enterprise plan, you are buying that plan regardless of what the pricing page advertises, so the real cost is the compliant tier plus any overage.

Can these systems book directly into a practice management system?

Some can, write the appointment back during the call, and name the platforms they support. Others take the booking and hand it to staff to enter. Ask which you are buying, and ask to watch it happen on a live demo.

Should AI ever handle a clinical call?

No. Every serious vendor builds an escalation path that detects clinical language and routes to a callback queue or nurse line. Confirm the path exists, then test it with a real scenario before launch.

How long does deployment usually take?

It varies by model. Self-serve platforms with published pricing move fastest, while healthcare-native vendors with deep record integration typically run engineer-led rollouts. Ask for a written timeline rather than an estimate given on a call.

author avatar
Sonia Shaik
Soniya is an SEO specialist, writer, and content strategist who specializes in keyword research, content strategy, on-page SEO, and organic traffic growth. She is passionate about creating high-value, search-optimized content that improves visibility, builds authority, and helps brands grow sustainably online. She enjoys turning complex SEO concepts into clear, actionable insights that businesses and creators can actually use to grow. Through her work, Soniya focuses on helping brands strengthen their digital presence, rank higher in search engines, and build long-term organic growth strategies—while continuously exploring how content, storytelling, and strategy can drive meaningful online success.

Must Read

Recent Published Startup Stories