Ona Health Logo

HIPAA-Compliant AI Receptionist: What Compliance Requires

What HIPAA requires of an AI receptionist handling patient calls - encryption, minimum necessary, access controls, audit trails - and how Ona meets each.

Ona Health team

9 min read

Share

A HIPAA-compliant AI receptionist must protect every patient call the way any handler of protected health information (PHI) does: encryption in transit and at rest, minimum-necessary access, role-based controls, and immutable audit trails, all under a signed business associate agreement. Ona runs its AI receptionist inside a HIPAA-grade platform, with each call logged straight to the chart.

Quick answer:

  • HIPAA (the Health Insurance Portability and Accountability Act) does not certify individual products. It sets requirements - encryption, minimum necessary, access controls, and audit trails - that any system touching PHI must meet.
  • An AI receptionist handles PHI the moment it answers a call, so it needs the same safeguards as your chart, plus a signed business associate agreement (BAA) with the vendor.
  • Ona builds its AI receptionist into a HIPAA-grade platform: calls are encrypted, PHI stays in your tenant, and every call is logged with a transcript tied to the patient record.

Why a phone call is a HIPAA event

When a patient calls to book, reschedule, or ask about results, they share protected health information - their name, the reason for the visit, sometimes symptoms or medication details. Under the Health Insurance Portability and Accountability Act (HIPAA), that information is protected the moment it is spoken, whether a human or an artificial intelligence agent answers.

Swapping a receptionist for software does not lower the bar. If anything, it raises the number of places PHI can travel: a call recording, a transcript, a booking record, a chart note. Each of those is subject to the HIPAA Security Rule. The U.S. Department of Health and Human Services (HHS) states that the Security Rule applies to electronic PHI "created, received, used, or maintained" by a covered entity or its business associate. An AI receptionist does all four.

What HIPAA actually requires when PHI moves over the phone

HIPAA does not hand out a "HIPAA-certified" badge. No product is certified compliant by the government; compliance is a posture a practice and its vendors maintain against a defined set of safeguards. For a phone line answered by AI, four requirements do most of the work, plus one contract that ties them together.

Encryption in transit and at rest

The Security Rule's technical safeguards call for protecting electronic PHI as it moves across networks and while it sits in storage. For an AI receptionist, that means encrypting the call audio, the transcript, and any structured data it writes - not only the live connection while the caller is on the line.

Minimum necessary

The HIPAA Privacy Rule requires covered entities and their business associates to limit uses, disclosures, and requests of PHI to the minimum necessary for the task. An agent booking an appointment needs the caller's identity and reason for visit; it does not need to expose an entire medical history to the whole front desk. Role-scoping keeps each person - and the agent - to only what the job requires.

Access controls and authentication

HHS lists access control - including unique user identification, automatic logoff, and encryption - and authentication among the Security Rule's technical safeguards, so that only authorized people reach electronic PHI. For an AI receptionist, that means the PHI it captures lands in a system where access is role-based, not in an open shared inbox or a general-purpose call tool.

Audit trails

The Security Rule requires audit controls: mechanisms that record and examine activity in systems that hold electronic PHI. Every call the agent takes should leave a durable, tamper-evident log of who called, what was captured, and where it went.

The contract behind all of it: the BAA

If a vendor's software handles PHI on your behalf, HHS requires a business associate agreement (BAA) - a written contract that binds the vendor to the same safeguards and to breach reporting. A third-party AI receptionist is a textbook business associate. No BAA means no compliant deployment, regardless of how good the technology is.

How Ona runs its AI receptionist inside a HIPAA-grade platform

The difference between a bolt-on phone bot and a compliant AI receptionist is usually where the data lands. A standalone voice tool captures PHI in one system, then hands it to your EHR (electronic health record) through an integration - two vendors, two logs, two BAAs, and a seam where data can leak.

Ona takes a different path. It is an AI-native, all-in-one practice management platform - combining CRM (customer relationship management), EHR, and RCM (revenue cycle management) in one place - and the AI receptionist is a native feature, not a plug-in. Per ona.health, calls are encrypted in transit and at rest, PHI stays in your tenant, and every call is logged with a full transcript tied to the patient record. Because the agent lives inside the chart, the transcript, recording, and structured intake it writes are already governed by the platform's role-based access controls and immutable audit trails - the same controls Ona applies across its messaging and video.

Ona states it is fully HIPAA compliant: patient data encrypted in transit and at rest, messaging and video end-to-end encrypted, immutable audit trails, role-based access controls, and consent logging with timestamp and IP. A BAA is signed at onboarding. And when a call turns sensitive - mental-health distress, a medication overdose, a safety concern - Ona's design routes it to a human rather than letting the agent handle it, which is both a safety measure and a minimum-necessary posture. Ona also states it never trains AI models on customer recordings.

For how the receptionist and the chart connect, see Ona's guide to a HIPAA EHR with an AI receptionist.

HIPAA requirement vs how Ona addresses it

HIPAA requirement for phone / PHI How Ona addresses it (per ona.health)
Encrypt PHI in transit and at rest Calls are encrypted in transit and at rest; PHI stays in your tenant.
Minimum necessary use and disclosure Role-based access controls and role-scoped records keep each person, and the agent, to what the task requires.
Access controls and authentication Access is role-based across the workspace; captured PHI lands inside the platform, not an open tool.
Audit controls / audit trails Every call is logged with a full transcript tied to the patient record; the platform keeps immutable audit trails.
Business associate agreement (BAA) A BAA is signed at onboarding and is in place with every Ona workspace.
Safe handling of sensitive PHI Sensitive flows (mental-health distress, overdose, safety concerns) bypass the agent and ring a human; human-only calls are warm-transferred.

What to ask any AI receptionist vendor

Whether you evaluate Ona or another tool, the compliance questions are the same. Treat them as a checklist before you route a single patient call:

  • Will you sign a BAA, and what does it cover?
  • Is the call audio encrypted in transit and at rest, or only the live connection?
  • Where does the captured PHI live - inside your system, or handed off to a third party?
  • Is access role-based, and can you show the audit log for one specific call?
  • How does the agent handle sensitive or emergency calls?
  • Do you train AI models on our calls? (Ona states it never trains models on customer recordings.)

A vendor that answers these cleanly is one you can deploy without guessing. For a broader view of the category, Ona's roundup of the best AI receptionists for medical clinics walks through what to weigh.

FAQ

Is an AI receptionist HIPAA compliant?

It can be, but no product is HIPAA certified by the government. Compliance is something the practice and its vendor maintain against the HIPAA safeguards: encryption of the data, minimum-necessary and role-based access, audit trails, and a signed business associate agreement (BAA). An AI receptionist that answers patient calls handles protected health information, so it has to meet the same standards as your chart.

Does a HIPAA-compliant AI receptionist need a business associate agreement?

Yes. If a third-party vendor's software handles protected health information on your behalf, the U.S. Department of Health and Human Services requires a business associate agreement (BAA) that binds the vendor to the same safeguards and to breach reporting. An AI receptionist is a textbook business associate. Ona states a BAA is signed at onboarding and is in place with every Ona workspace.

What does the minimum necessary standard mean for phone calls?

The HIPAA Privacy Rule requires covered entities and their business associates to limit uses, disclosures, and requests of protected health information to the minimum necessary for the task. For a phone line, an agent booking an appointment needs the caller's identity and reason for visit, not an entire medical history exposed to everyone. Role-scoping keeps each person, and the agent, to what the job requires.

Does Ona's AI receptionist store call recordings in the patient chart?

Yes. According to ona.health, the AI receptionist writes the transcript, recording, and structured intake into the patient record, and every call is logged with a full transcript tied to that record. Because the agent lives inside the chart, that data is governed by Ona's role-based access controls and immutable audit trails. Ona also states it never trains AI models on customer recordings.

Can the AI receptionist handle sensitive or emergency calls safely?

Ona's AI receptionist escalates. Per ona.health, sensitive flows such as mental-health distress, medication overdose, or safety concerns bypass the agent entirely and ring a human, and anything your rules flag as human-only is warm-transferred to staff. Routing sensitive calls to a person is both a safety measure and a minimum-necessary posture.

What HIPAA-compliant EHR includes an AI receptionist?

Ona is an AI-native, all-in-one practice management platform - CRM, EHR, and RCM in one place - that includes an AI receptionist as a native feature tied to the chart. Ona states it is fully HIPAA compliant, with data encrypted in transit and at rest and immutable audit trails. The AI receptionist add-on is $499 per month and includes 1,500 minutes, on top of Ona's per-seat pricing.

Next step

If a compliant AI receptionist is on your shortlist, the fastest way to judge it is to see the call, the transcript, and the chart in one place. Book a 15-min walkthrough - no obligation and ask the questions in the checklist above. You can also start a 14-day free trial with full access to every feature and no credit card required.

Written by

Ona Health team

Related reading

Keep exploring.

12 min read

Best AI-Native EHR for Practices That Cannot Hire More Staff (2026)

Run a lean or solo practice without hiring more staff: an AI receptionist answers calls, an ambient scribe writes notes, and billing runs from the chart.

Ona Health team
10 min read

How to Reduce No-Shows: Reminder and Scheduling Software

Reduce patient no-shows with easy online self-scheduling, self-reschedule, in-app and email reminders, and an AI receptionist that confirms every call.

Ona Health team
12 min read

Best EHR with a Built-In Patient App and Portal (2026)

See which EHR has the best built-in patient app and portal. How Ona handles booking, intake, consents, records, messaging, and payments from one login.

Ona Health team

See Ona in action.

One platform for scheduling, charting, billing and insurance. Try everything free for 14 days — no credit card required.