The moment a caller says "this is Maria Alvarez, I chipped a molar and I need to be seen today," your AI receptionist is holding protected health information. Name, phone number, and a reason for the visit is PHI under HIPAA — it does not require a chart number or an insurance ID to qualify.
That makes the vendor a business associate of your practice, not a neutral software supplier. You, as the covered entity, are the one exposed if they mishandle it. A BAA is the contract that pushes defined obligations onto them and gives you recourse.
The subprocessor problem nobody mentions
Almost no AI receptionist runs its own speech recognition, language model and telephony. Behind the product sits a stack of third parties. If your vendor signs a BAA but its speech provider does not, the chain is broken and your PHI is sitting somewhere uncovered.
Ask directly: which subprocessors touch call audio or transcripts, and is each one covered by a BAA? A vendor that has done the work will answer in one sentence. A vendor that has not will change the subject to encryption.
