HIPAA and AI Voice Agents: What Contact Centers Must Know

HIPAA and AI Voice Agents: What Contact Centers Must Know

ON THIS PAGE

Written by: Matt Beucler, CEO, Plura AI

Key Takeaways

  • AI voice agents align with HIPAA only when a BAA covers the primary vendor and every PHI-touching subprocessor, encryption is enforced in transit and at rest, access is locked down, audit logs are retained, and PHI is excluded from model training.
  • PHI can flow through seven layers in a typical stack: telephony, STT, LLM, TTS, storage, EHR or CRM integration, and analytics.2 Each layer needs its own contractual and technical safeguards.
  • A BAA with the primary vendor covers that vendor only. Buyers must confirm the full sub-BAA chain and review documentation before signing any contract.
  • “HIPAA-ready” and “HIPAA-compliant” are marketing terms. HHS does not certify vendors, and covered entities remain responsible for their own compliance programs.
  • Plura AI operates as an FCC-licensed carrier on 100% U.S. infrastructure with HIPAA-aligned encryption, access controls, and audit logging.1 See how Plura’s subprocessor chain and compliance dashboard work in practice.

Where PHI Flows In An AI Voice Agent Stack

Most vendor marketing focuses on whether the vendor signs a BAA. That question starts the compliance conversation and does not finish it. In a typical AI voice agent deployment, PHI can persist in seven distinct components: the telephony carrier’s recording store, the speech-to-text vendor’s request logs, the LLM provider’s prompt and completion logs, the text-to-speech vendor’s synthesis input, the application’s own logs and traces, analytics or QA tooling that reads transcripts, and backups or snapshots of all of the above. The total number of PHI-touching systems varies by deployment, with sources describing stacks of roughly five to eight services. Each component that touches PHI requires its own contractual and technical control. The table below summarizes each layer, whether it touches PHI, and the controls required to keep PHI protected.

  1. Telephony and Carrier Layer. Live call audio travels over a carrier network from the moment a call connects. The carrier acts as a subprocessor. Under 45 CFR § 160.103, a person who creates, receives, maintains, or transmits PHI on behalf of a covered entity for a regulated function or service qualifies as a business associate, except for mere conduits that only provide transmission services (including temporary storage incident to transmission) and do not access PHI on a routine basis. A BAA with the carrier and encryption in transit are the baseline controls to verify.
  2. Speech-to-Text (STT). STT converts live audio into a text transcript. PHI flows through this layer on every call that involves a patient’s name, date of birth, diagnosis, medication, or other individually identifiable health information. The STT subprocessor requires a BAA and documented no-retention terms if the vendor does not retain transcripts by default.
  3. Large Language Model (LLM). The LLM processes the transcript to generate a response. PHI flows through the LLM unless the transcript is redacted upstream. The LLM provider is a subprocessor. A BAA or zero-retention terms are required, and the BAA should explicitly address model training on PHI. OpenAI offers HIPAA-eligible API endpoints under a BAA4 for accounts provisioned with Modified Retention. Google Cloud’s HIPAA BAA covers Speech-to-Text, Text-to-Speech, and Conversational Agents4 for services explicitly listed in the BAA. Azure OpenAI is covered under Microsoft’s BAA through the Data Protection Addendum for eligible customers, though having a BAA does not by itself make a workload HIPAA-compliant.
  4. Text-to-Speech (TTS). TTS renders the AI’s response as audio. PHI can flow through TTS if the response includes patient-specific information. The TTS subprocessor requires a BAA and encryption in transit.
  5. Conversation Storage and Databases. Transcripts and recordings stored at rest represent a high-volume PHI exposure point in the stack. Encryption at rest, role-based access control, and audit logging are core technical controls. A BAA with the storage provider is also required.
  6. EHR and CRM Integration. When the AI voice agent writes structured PHI into an electronic health record (EHR) or customer relationship management (CRM) system, that integration layer also touches PHI. The integration middleware and the destination system both require BAAs and access controls. Plura’s integrations directory covers 50+ tools across CRM, calendar, and data categories.
  7. Analytics and Reporting. Whether analytics touch PHI depends on configuration. Aggregated, de-identified data may not require a BAA. Raw transcripts or recordings fed into a reporting layer do. The control required depends on whether PHI is present in the data set.

The BAA flow-down problem runs through every layer above. A BAA with the primary AI voice agent vendor covers that vendor only. That obligation is described at 45 CFR § 164.504(e)(2)(ii)(D), which requires that when a business associate engages a subcontractor to perform any function involving PHI, that subcontractor must enter an equivalent agreement with the primary business associate.2 Missing sub-BA agreements are among the most common compliance gaps discovered during audits.

Component-By-Component PHI Exposure Table

Stack Component Touches PHI Required Control
Telephony / carrier Yes, live call audio BAA with carrier, encryption in transit
Speech-to-text (STT) Yes, audio to transcript BAA with STT subprocessor, no-retention terms
Large language model (LLM) Conditional, depends on redaction BAA or zero-retention terms, no training on PHI
Text-to-speech (TTS) Conditional, depends on response content BAA with TTS subprocessor, encryption in transit
Storage / database Yes, transcripts and recordings at rest BAA, encryption at rest, access control, audit logging
EHR / CRM integration Yes, structured PHI written to system of record BAA with integration layer, access control, audit logging
Analytics / reporting Conditional, depends on aggregation and redaction BAA if raw PHI present, redaction, access control

The table shows where controls are required, and one contractual gap runs through every layer: the BAA flow-down problem.

The BAA Flow-Down Problem

A BAA with the primary AI voice agent vendor is a contractual relationship between the covered entity and one company. It extends to subprocessors only if the primary vendor has separately executed BAAs with each one that touches PHI.

The flow-down requirement at 45 CFR § 164.504(e)(2)(ii)(D) places the obligation on the primary business associate to ensure its subcontractors are bound by equivalent agreements.2 The buyer’s job is to verify that the chain exists. Key questions to ask a vendor include:

  • Which subprocessors touch PHI in your stack?
  • Do you have executed BAAs with each of those subprocessors?
  • Can you provide documentation of the subprocessor BAA chain?
  • Does your BAA with us flow down to your subprocessors by its terms?

A vendor that cannot answer those questions with documentation has a gap in the chain. HHS model BAA language on permitted uses states that a business associate may use or disclose PHI only as necessary to perform the services described in the agreement, a restriction that must be mirrored in every sub-BA agreement downstream. Readers should consult qualified counsel and the HHS business associate guidance for the specific elements a compliant BAA must address.

See Plura’s BAA structure and subprocessor chain in a live walkthrough.

“HIPAA-Ready” Versus “HIPAA-Compliant” Claims

HHS does not certify vendors as HIPAA-compliant. As Google Cloud’s own HIPAA documentation states, no certification program approved by HHS exists through which a cloud service provider can demonstrate HIPAA and HITECH Act compliance. The same reality applies to AI voice agent vendors. “HIPAA-ready” and “HIPAA-compliant” function as marketing terms, not regulatory designations.

When a vendor claims HIPAA compliance, buyers gain clarity by asking specific follow-ups:

  • Which safeguards are implemented, and at which layer of the stack?
  • Which subprocessors hold BAAs?
  • Will the vendor sign a BAA that flows down to subprocessors?
  • Does the vendor hold a third-party attestation such as SOC 2 Type II?

Customers remain responsible for their own HIPAA obligations regardless of what a vendor signs. A BAA transfers certain contractual obligations to the vendor and does not transfer the covered entity’s compliance program. The HHS cloud computing guidance and the HHS business associate guidance are primary sources for understanding what a covered entity’s obligations are in a cloud or AI deployment.

The 2026 HIPAA Rule Change

HHS published a Notice of Proposed Rulemaking (NPRM) to overhaul the HIPAA Security Rule on January 6, 2025 (90 FR 800). The comment period closed in March 2025. As of July 2026, no final rule has been issued, with the federal regulatory agenda showing final action pushed to July 2027.5 The proposed changes would eliminate the addressable implementation specification category, mandate encryption of ePHI at rest and in transit, require multi-factor authentication, and mandate a written technology asset inventory and network map showing how ePHI moves through systems.

Because the proposal has not been finalized, it imposes no new legal obligations as of the date of this article. Organizations can treat the draft as a planning baseline and monitor HHS.gov for the current regulatory status. The HIPAA Security Rule obligations that OCR is actively enforcing, including the risk analysis and risk management requirements at 45 CFR 164.308(a)(1)(ii)(A) and (B), predate any proposed overhaul.

Regardless of how the rule change unfolds, the same vendor evaluation questions apply today.

Vendor Evaluation Checklist For AI Voice Agents

Use this checklist to audit any AI voice agent vendor’s compliance posture before signing a contract.

  1. Contractual questions. Does the vendor sign a BAA? Do the vendor’s STT, TTS, telephony, and database subprocessors also sign BAAs? Can the vendor show the full subprocessor BAA chain?
  2. Data handling questions. Where is PHI stored, and is it encrypted at rest? What is the data retention and deletion policy for recordings and transcripts? Is PHI used for model training?
  3. Access and logging questions. Are access controls role-based and least-privilege? Are audit logs retained and exportable?
  4. Infrastructure and incident questions. Does the vendor run on U.S. infrastructure? Does the vendor report breaches with the elements required under its BAA? Is there a documented termination and PHI return or destruction process?
  5. Assurance questions. Does the vendor hold SOC 2 Type II or an equivalent third-party attestation?

Walk through this checklist with the Plura team in a live session.

How Plura AI Supports HIPAA-Aligned Deployments

Plura AI operates as its own FCC-licensed audio bridging carrier, so voice traffic originates on Plura’s domestic infrastructure and does not route through a third-party CPaaS (Communications Platform as a Service). Every call carries STIR/SHAKEN authentication. PHI remains on U.S. infrastructure at every point in the stack.

Screenshot of Plura’s fully compliant AI communications platform showing business registration and phone number provisioning workflows for AI Voice, SMS, RCS, and Webchat communication automation.
Plura’s FCC-licensed AI communications platform simplifies compliant business registration and phone number provisioning for AI Voice, SMS, RCS, and Webchat workflows.

Plura holds SOC 2 Type II and ISO certifications, and its platform applies HIPAA-aligned encryption, access controls, and audit logging across voice, AI SMS, RCS, and AI webchat.1 These controls extend to outbound contact: every call is checked against federal and state DNC registries in real time before dial, TCPA consent records are timestamped and immutable, and quiet-hours rules enforce automatically through time-zone detection.2 The compliance dashboard then exports audit-ready reports in one click.

Plura Security & Compliance dashboard highlighting SOC 2, ISO, and GDPR standards with secure trust verification management.
Plura Security & Compliance supports SOC 2, ISO, and GDPR standards with trust registration, verification management, and secure AI communications.

For healthcare operators, Plura’s AI voice agent supports appointment confirmations, patient intake, and high-complexity eligibility surveys, with sensitive-data redaction at the field level. Plura supports up to a 40% improvement in no-shows3 for healthcare deployments. Plura’s CRM integration directory covers EHR-adjacent systems across 50+ tools.

Plura supports customer compliance. It does not absolve customers of their own HIPAA obligations, and using Plura does not make a customer compliant with HIPAA or any other standard. Customers remain responsible for their own compliance programs, risk analyses, and regulatory obligations. Readers can compare plans and rates to evaluate which configuration fits their deployment requirements.

For context on how Plura compares to Twilio-based API resellers on compliance architecture, see Plura AI vs. Vapi4 and Plura AI vs. Synthflow.

Frequently Asked Questions

Are Any AI Agents HIPAA Compliant?

No AI agent vendor is certified as HIPAA-compliant by HHS. AI agents can be deployed in HIPAA-aligned configurations when a BAA is in place with the primary vendor and all subprocessors that touch PHI, encryption is enforced in transit and at rest, access controls are configured, audit logs are retained, and PHI is not used for model training. The covered entity remains responsible for its own compliance program regardless of what the vendor signs.

Is A Voice Recording A HIPAA Violation?

Whether a voice recording is permissible depends on the context, the BAA in place, and the safeguards applied to the recording at rest and in transit. A recording that captures PHI typically requires a BAA with the storage provider, encryption, and access controls. Covered entities should evaluate specific recording configurations with qualified counsel against the applicable provisions of 45 CFR Part 164.

Is Texting HIPAA Compliant?

Text messaging can be used in HIPAA-aligned deployments when the messaging platform has a BAA in place, encryption is applied, and access controls are configured. Whether PHI is present in the message content determines the level of control required. Platforms that run on 10DLC-registered numbers with TCPA consent management and real-time DNC scrubbing address the messaging compliance layer, while the BAA and encryption requirements apply independently.

Is Google Voice HIPAA Compliant?

Google offers a BAA for certain Google Workspace services. Whether a specific Google Voice configuration falls within the scope of that BAA depends on the service tier, the specific features in use, and how the deployment is configured. Covered entities should review Google Cloud’s HIPAA documentation and consult qualified counsel before processing PHI over any Google Voice deployment. Having a BAA with Google does not by itself make a deployment HIPAA-compliant.

Does Your AI Vendor Need A BAA For Subprocessors?

The flow-down requirement at 45 CFR § 164.504(e)(2)(ii)(D) places the obligation on the primary business associate to ensure its subcontractors that touch PHI are bound by equivalent agreements. A BAA with the primary AI voice agent vendor does not automatically cover that vendor’s STT, TTS, telephony, LLM, or storage subprocessors. Buyers should request documentation of the full subprocessor BAA chain before signing any AI voice agent contract.

What Is The Difference Between HIPAA-Ready And HIPAA-Compliant?

Neither term is a regulatory designation. HHS does not certify vendors as HIPAA-compliant, and no certification program exists through which a cloud or AI vendor can demonstrate HIPAA compliance to HHS. “HIPAA-ready” and “HIPAA-compliant” function as marketing terms. The operative questions are whether the vendor signs a BAA, which subprocessors are covered, what technical safeguards are implemented, and whether the vendor holds a third-party attestation such as SOC 2 Type II.

What Is The New HIPAA Rule In 2026?

HHS published a proposed overhaul of the HIPAA Security Rule in January 2025 (90 FR 800). As of September 2026, no final rule has been issued.5 The federal regulatory agenda shows final action is not expected until July 2027. The proposal is not law and imposes no new obligations in its current form. Organizations should monitor HHS.gov for updates and consult qualified counsel on how the proposal may affect their compliance planning.

How Does Plura AI Support HIPAA-Aligned Deployments?

Plura operates as an FCC-licensed carrier on 100% U.S. infrastructure, with HIPAA-aligned encryption, access controls, and audit logging built into the platform. It holds SOC 2 Type II and ISO certifications. Every outbound contact is checked against DNC registries in real time, TCPA consent records are immutable, and the compliance dashboard exports audit-ready reports on demand. Plura supports customer compliance and does not guarantee compliance or replace customers’ own HIPAA obligations.

Conclusion: What To Verify Before You Sign

A BAA with the primary AI voice agent vendor is the starting point of the compliance question. PHI flows through telephony, STT, LLM, TTS, storage, EHR integration, and analytics, and every component that touches PHI requires its own contractual and technical control. As noted earlier, the BAA flow-down requirement places the obligation on the primary vendor to have executed BAAs with its subprocessors, while the buyer’s job is to verify that chain exists before signing.

The vendor evaluation checklist above gives compliance officers and technology leaders a structured framework to run against any vendor. The PHI exposure table maps where controls are required at each hop. Neither replaces a qualified legal review of the specific BAA terms and subprocessor chain for a given deployment.

Explore Plura’s carrier-grade infrastructure and compliance controls in a tailored demo. Then compare plans and rates side by side, or run your numbers through Plura’s ROI calculator to check projected cost savings in real time.


1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.

2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.

3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.

4 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.

5 This article contains forward-looking statements regarding industry trends, technology adoption, and future capabilities. These statements reflect current expectations and are subject to change. Plura AI undertakes no obligation to update forward-looking statements except as required.

This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.

This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.

Read Next

See how Plura AI transforms AI voice agents