Menu
See the rankings

AI voice · compliance

HIPAA voice AI: why one BAA is never enough

A Business Associate Agreement (BAA) is the signed contract HIPAA requires before a supplier may touch patient data. A composed voice agent hands each call to four or five suppliers in a row, and US health-privacy rules expect a signature at every hop. We quote the regulation, walk one stack hop by hop, price the enforcement and show who across our 27-vendor directory actually signs.

By Voxrater · 9 min read · Published 2026-07-12

Every regulatory quote and vendor position in this piece comes from a dated primary capture listed in the sources. This is reporting on published rules and published vendor paperwork, not legal advice; confirm your own BAA chain with your compliance counsel before a single patient call goes through it.

One BAA covers one company. A composed voice agent passes each call through a platform, a transcriber, a language model, a voice engine and a phone carrier, and US health-privacy rules treat every hop that touches patient data as a business associate needing its own signed agreement. Missing one signature has cost a clinic $750,000.

That figure is a real HHS settlement, and we will get to it. Groundwork first, because the acronyms hide a lot here.

A voice agent is a PHI machine

Protected health information, PHI from here on, is any health detail tied to an identifiable person. Not just medical records: a name next to an appointment time qualifies, and so does a phone number next to a symptom. Now think about an ordinary Tuesday call. A caller says who they are, why they are ringing, what hurts and when it started, and the system turns that into a recording, a transcript, a caller record and a stack of logs. All of it is PHI. The call is not a channel that brushes against health data. The call is the health data.

Two consequences follow. First, HIPAA (the US health-privacy law) requires written assurances before a supplier handles that data: HHS guidance says they “must be in writing, whether in the form of a contract or other agreement” (45 CFR 164.502(e) and 164.504(e)). That written assurance is the Business Associate Agreement, a precondition, not a nicety. Second, “we cannot read your data” is not an exit: HHS’s cloud guidance says a service holding encrypted patient data without the decryption key is still a business associate. If the audio passes through you, you are in the chain.

One call, five companies

The argument fits in a sentence: most voice agents are assembled from separate suppliers, and the law follows the data through every one of them.

The regulation text is blunt about it. The definition of business associate in 45 CFR 160.103 includes “A subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate”. HHS’s cloud guidance spells out the consequence: a cloud service subcontracted to handle patient data “itself is a business associate”, and a HIPAA-compliant BAA must sit at that link too. A chain, not an umbrella.

So walk one typical composed stack, hop by hop. Five companies touch each call, and the paperwork at every hop is published policy, not theory:

HopWhat it does with the callA published position (dated)
PlatformRuns the agent; holds recordings and logsRetell: self-serve BAA, no fee (2026-07-11)
Speech-to-textReceives the caller’s audio, returns textDeepgram: BAA on request (2026-05-31)
Language modelReceives the transcript, decides the replyOpenAI: API BAA on request (re-verified 2026-07-12)
Text-to-speechTurns the reply into audioElevenLabs: Enterprise-plan feature (2026-07-11)
TelephonyCarries the callTwilio: BAA requires Security or Enterprise Edition (2026-07-12)

The scope lines under those signatures matter as much as the yes. Twilio’s BAA covers only its listed HIPAA-eligible products, on the right edition. Anthropic’s covers the first-party API and HIPAA-ready Enterprise plans, excludes consumer tiers and some API features, and requires 30-day retention on covered models. Google signs over a defined product list and tells you to switch off the rest when PHI is in play. A signature with a scope you have not read is a signature you do not have.

The platforms confirm the chain themselves. Vapi publishes a list of which speech-to-text, language-model and text-to-speech providers its HIPAA mode allows, a platform saying out loud that not every hop qualifies. And Trillet’s trust centre lists GCP, AWS, MongoDB Atlas and Twilio as subprocessors: four downstream companies behind one logo.

The enforcement receipts

HHS’s Office for Civil Rights has settled over exactly this paperwork, at both ends of the provider scale.

SettlementYearWhat happenedCost
Raleigh Orthopaedic Clinic2016Released X-ray films holding the PHI of about 17,300 patients to a vendor with no BAA executed$750,000
Center for Children’s Digestive Health2017Records with storage vendor FileFax from 2003; no signed BAA producible before 12 October 2015$31,000

Read those two together. Neither settlement involved a hack. In both cases the violation was the missing signature itself: PHI went to a vendor, no BAA existed, and OCR treated that absence as the offence. The OCR Director’s line on the Raleigh case has aged well: BAAs are “more than a mere check-the-box paperwork exercise”.

The arithmetic sharpens it. A year of Vapi’s $2,000-a-month HIPAA add-on is 2,000 × 12, so $24,000. Genuinely dear, and still less than the $31,000 a small children’s practice paid over one missing agreement. The compliant path costs less than the settlement.

The conduit trap

There is one legitimate exception, and it is narrower than the vendors citing it. Skip this section if nobody in your stack claims to be just the pipes.

HHS waives the BAA for an organisation “that acts merely as a conduit for protected health information”: the US Postal Service, certain private couriers and “their electronic equivalents”. Then it boxes the exception in hard. It “is limited to transmission-only services”, access must be “only transient in nature”, and on whether a cloud service can be a conduit the answer is “Generally, no.”

Now the live example. Telnyx, a carrier that turns up in composed voice stacks, claims the conduit exception in its help centre and does not sign BAAs, while HIPAA is asserted in its site footer. We record Telnyx as hipaa: false: whatever the merits of the conduit argument for pure call transport, a healthcare buyer cannot get a signature there. Our read: if a carrier does nothing but carry, the exception is at least arguable; the moment recordings, transcripts, voicemail or logs sit with the carrier, it is not. If you need the carrier hop covered, pick one that signs. Twilio does, with the conditions above.

Who actually signs, across our directory

We track formal compliance positions for all 27 directory vendors: 17 record a documented HIPAA claim, 10 do not, and at least 4 of the 10 assert HIPAA somewhere in their marketing with nothing signable behind it. Below, the positions most relevant to a composed stack, dated; the HIPAA roundup ranks how usable each path is.

VendorHopDocumented position (captured)
RetellPlatformBAA and DPA self-serve, click-to-sign, no fee (2026-07-11); pricing page still shows “Custom BAA” under Enterprise
VapiPlatformHIPAA add-on $2,000/mo (no logs, recordings or transcripts kept while on); zero data retention is a separate $1,000/mo add-on (2026-05-30)
BlandPlatformHIPAA self-attested with a BAA; SOC 2 Type II independently audited (2026-06-15)
SynthflowPlatformHIPAA badge on its enterprise pricing card, from $30,000/yr (2026-07-11)
LiveKitInfrastructureHIPAA BAA on Scale and Enterprise tiers (2026-05-31)
Pipecat CloudInfrastructureOne BAA can cover Pipecat Cloud, Daily WebRTC and transcription, enabled per account (2026-05-31)
DeepgramSpeech-to-textBAA on request (2026-05-31)
AssemblyAISpeech-to-textStandard BAA, arranged through sales (2026-05-31)
ElevenLabsText-to-speechEnterprise-plan feature, not on self-serve tiers (2026-07-11)
RimeText-to-speechBAA on Enterprise custom plans (2026-06-15; page since redesigned, re-verification due)
HumeText-to-speechBAA and DPA on request via [email protected] (2026-05-31)
OpenAI RealtimeLanguage modelHIPAA BAA available for the API on request (2026-05-31, re-verified 2026-07-12)
TelnyxCarrierDeclines BAAs, claims the conduit exception (2026-06-15)

Which paths shrink the multi-BAA problem? My lean, matching our roundup. Bland bundles the model, the speech, the voice and the line under one vendor, so one signature covers the lot. Retell made the paperwork painless this month: self-serve and click-to-sign, at no fee. One honest wrinkle: its pricing page still showed “Custom BAA” under Enterprise at the same capture; the click-through agreement is the one that binds. Pipecat Cloud shows the structural fix: one BAA covering several hops because one company owns them. And Vapi’s $2,000-a-month add-on plus its compliant-provider list is the dearest path in the table but the most explicit about the chain underneath.

”SOC 2” is not “HIPAA”, and nobody is “HIPAA certified”

Two badge patterns to read past. SOC 2 first. It is an independent audit of a company’s security controls, genuinely worth having, and it says nothing about whether the company will sign a BAA.

Second, “HIPAA certified” does not exist. Google’s own compliance page says it flat: “there is no certification recognized by the US HHS for HIPAA compliance”. Any vendor using that phrase is selling wording, not paperwork.

The pattern in the wild: Cognigy’s marketing page claims HIPAA while its own Trust Center lists SOC 2 Type II, three ISO standards, TISAX, BSI C5 and GDPR, with HIPAA absent. Cartesia’s enterprise tier advertises SOC 2 and HIPAA; we could not open a certificate for either. My AI Front Desk offers a “HIPAA-ready configuration”, and “ready” is doing heavy lifting: no BAA offer is documented anywhere on the site. Trillet’s homepage carries a SOC 2 Type II badge while its own trust centre shows SOC 2 as “In progress”. We record all four as hipaa: false, not as an accusation but because there is nothing a buyer could sign or verify. The only sentence that matters is “we will sign a BAA on plan X”. Everything else is decoration.

What to do this week

Five concrete moves, in order.

  1. Map the hops. Write down every company that touches a call: platform, speech-to-text, model, voice, carrier, plus any QA or analytics tool that reads transcripts. If you cannot name them all, ask the platform for its subprocessor list.
  2. Collect signatures, not badges. For every supplier you contract directly, a signed BAA. For the hops your platform subcontracts, its written confirmation that its own agreement chain covers them. A verbal “we’re compliant” is worth nothing under the subcontractor rule.
  3. Read the scope lines. Eligible products, plan editions, excluded features, retention terms: match what your agent actually uses against what each agreement covers, line by line.
  4. Price the compliant tier, not the headline rate. Vapi is $2,000 a month on top of usage. ElevenLabs and Rime want Enterprise conversations. Synthflow starts at $30,000 a year. Put the compliance line into your cost-per-minute maths before you commit.
  5. Re-check on a schedule. These positions move: Retell’s BAA went self-serve between our May and July captures, and Rime redesigned its pricing page after ours. Put a quarterly reminder on the file.

The honest limits

We report published positions with capture dates; we have not audited any vendor or signed these agreements ourselves. The captures run from 30 May to 12 July 2026 and vendors move: Rime’s BAA basis is a page since redesigned, and Retell’s docs and pricing page currently disagree, so treat every row as dated evidence, not permanent fact. Also, no OCR guidance specific to AI existed as of 12 July 2026; the cloud guidance quoted above is the closest on-point primary for hosted models. We are a benchmark site, not a law firm; the sources below are what you hand to your compliance counsel.

Next step: check your shortlist against the HIPAA roundup and each vendor profile’s sourced compliance detail. If your agent also takes calls in Europe, the AI-disclosure duty arriving on 2 August 2026 is separate law again; we walked it in our EU AI Act piece.

Common questions

What is a BAA in voice AI?
A Business Associate Agreement is the written contract HIPAA requires before a supplier may handle protected health information on your behalf. For a voice agent that means the platform and every supplier underneath it that touches the call data: each needs its own signed agreement before patient calls flow.
Does my platform's BAA cover the AI model and the phone carrier underneath it?
Only if the platform holds its own agreements with those subcontractors. HHS treats a subcontractor that handles patient data as a business associate in its own right, needing its own BAA. Ask your platform for its subprocessor list and for written confirmation that its agreement chain covers every hop your calls take.See which platforms make this easy
Is SOC 2 the same as HIPAA compliance?
No. SOC 2 is an independent audit of a company's security controls, worth checking, and separate from HIPAA. It does not commit the company to signing a BAA, and no HIPAA certification recognised by HHS exists at all, so treat 'HIPAA certified' in marketing as a red flag and ask for the BAA instead.
Can a phone carrier avoid a BAA under the conduit exception?
Only if it truly does nothing but carry the call. HHS limits the conduit exception to transmission-only services where any access to patient data is transient, the electronic equivalent of a courier. If the carrier stores recordings, transcripts, voicemail or logs, the exception is gone and a BAA is required.

Sources

Every figure above is dated and links to its primary source.

  1. 45 CFR 160.103, fetched live from eCFR on 2026-07-12: the definition of business associate, including at (3)(iii) 'A subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate.' checked 2026-07-12
  2. HHS guidance on business associates (verified 2026-07-12 via Wayback snapshot 20260620003552; page 'Content last reviewed May 24, 2019'): the satisfactory assurances 'must be in writing, whether in the form of a contract or other agreement' (45 CFR 164.502(e), 164.504(e)), and the conduit exception for an organisation 'that acts merely as a conduit for protected health information', with the US Postal Service, certain private couriers and 'their electronic equivalents' as the examples. checked 2026-07-12
  3. HHS cloud computing guidance (verified 2026-07-12 via Wayback snapshot 20260628172858; page 'Content last reviewed December 23, 2022'): the conduit exception 'is limited to transmission-only services'; any access by a conduit 'is only transient in nature'; on whether a cloud service can be a conduit, 'Generally, no'; a no-view service holding encrypted ePHI without the key is still a business associate; and a subcontracted CSP 'itself is a business associate' that must be under a HIPAA-compliant BAA. checked 2026-07-12
  4. HHS enforcement bulletin (verified 2026-07-12 via Wayback snapshot 20260511182325): Raleigh Orthopaedic Clinic paid $750,000 in 2016 after releasing X-ray films holding the PHI of about 17,300 patients to a vendor without executing a BAA; OCR's Director called BAAs 'more than a mere check-the-box paperwork exercise'. checked 2026-07-12
  5. HHS resolution agreement page (verified 2026-07-12 via Wayback snapshot 20260511121044): Center for Children's Digestive Health paid $31,000 (announced 20 April 2017) after disclosing PHI to storage vendor FileFax since 2003, with no signed BAA producible for the period before 12 October 2015. checked 2026-07-12
  6. Google Cloud HIPAA compliance page (live capture; page last updated 2026-07-08): 'there is no certification recognized by the US HHS for HIPAA compliance'; Google signs a BAA over a defined covered-products list and instructs customers to disable products the BAA does not cover when working with PHI. checked 2026-07-12
  7. Twilio HIPAA page (live capture): PHI workflows 'must execute a Business Associate Addendum (BAA)', which requires Security Edition or Enterprise Edition and covers only Twilio's listed HIPAA Eligible Products and Services. checked 2026-07-12
  8. OpenAI enterprise privacy page (verified 2026-07-12 via Wayback snapshot 20260709163502): 'We are able to sign Business Associate Agreements (BAA)' for the API, on request; SOC 2 Type 2 for the API platform. checked 2026-07-12
  9. Anthropic BAA article (live capture): the BAA covers the first-party API and HIPAA-ready Enterprise plans only; Free, Pro, Max and Team plans plus some API and beta features are excluded; covered models require 30-day data retention; third-party data flows out of a feature are not covered. checked 2026-07-12
  10. Retell compliance docs: the BAA and DPA 'are available for self-signing at click-agreements.retellai.com' and 'There is no additional fee to sign these agreements'; SOC 2 Type 1 and 2. Retell's pricing page still showed 'Custom BAA' under Enterprise at the same capture. checked 2026-07-11
  11. Vapi pricing page: the HIPAA add-on is $2,000/mo (no logs, recordings or transcripts kept while it is on); the separate Zero Data Retention add-on is $1,000/mo. checked 2026-05-30
  12. Vapi HIPAA docs: the published list of STT, LLM and TTS providers compatible with Vapi's HIPAA mode, a platform-level statement that not every provider in a composed stack qualifies. checked 2026-05-30
  13. Bland trust page: SOC 2 Type II via an independent auditor, HIPAA self-attested with a BAA, GDPR self-attested with a DPA. checked 2026-06-15
  14. LiveKit security page: HIPAA BAA on the Scale and Enterprise tiers; SOC 2 Type II audited. checked 2026-05-31
  15. Pipecat Cloud HIPAA docs: Daily can sign a single BAA covering Pipecat Cloud, Daily WebRTC and transcription, enabled per account. checked 2026-05-31
  16. Synthflow pricing page: a single enterprise card from $30,000 annually, carrying SOC 2, GDPR, HIPAA and ISO 27001 compliance badges. checked 2026-07-11
  17. Deepgram trust page: SOC 2 Type 1 and 2, HIPAA BAA on request, GDPR, PCI. checked 2026-05-31
  18. AssemblyAI docs FAQ: 'we offer a standard Business Associate Addendum (BAA)', arranged through sales; SOC 2 Type 1 and 2. checked 2026-05-31
  19. ElevenLabs pricing page: HIPAA, SOC 2 and GDPR listed as Enterprise-plan features, not available on the self-serve tiers. checked 2026-07-11
  20. Rime pricing page: Enterprise custom plans with a BAA (HIPAA) and SOC 2 reports, plus on-prem and VPC options. A 2026-07-11 recapture shows a redesigned page; this BAA basis is the 15 June capture, queued for re-verification. checked 2026-06-15
  21. Hume developer privacy page (reconfirmed 2026-06-15): HIPAA compliant with a BAA and DPA available on request via [email protected]; the SOC 2 Type II and GDPR mentions are footer strings with no openable certificate, so we leave those unticked. checked 2026-05-31
  22. Telnyx help centre: Telnyx positions its services under the HIPAA conduit exception and does not sign BAAs, while HIPAA is asserted in the site footer; we record Telnyx as hipaa false. checked 2026-06-15
  23. Cognigy platform marketing page: a sentence claiming HIPAA compliance that Cognigy's own Trust Center does not list. checked 2026-07-11
  24. Cognigy Trust Center: SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, TISAX, BSI C5 and GDPR listed; HIPAA absent, so we record Cognigy as hipaa false. checked 2026-05-31
  25. Cartesia pricing page: the enterprise tier advertises SOC 2 and HIPAA; we found no openable certificate for either and record both false pending primary evidence. checked 2026-07-11
  26. My AI Front Desk product page: verbatim 'HIPAA-ready configuration' wording alongside SOC 2 controls language; no BAA offer documented anywhere on the site, so we record hipaa false. checked 2026-05-31
  27. Trillet trust centre (Sprinto): HIPAA marked compliant while SOC 2 shows 'In progress', contradicting the homepage SOC 2 Type II badge; the subprocessor list includes GCP, AWS, MongoDB Atlas and Twilio. checked 2026-07-12

Get the next piece

New analysis and dated test results land in the newsletter first. No spam.

Newsletter launching soon.