Compliance

    HIPAA & BAA Checklist: 9 Things to Verify Before You Sign

    Every vendor says "HIPAA compliant." Very few will put the specifics in a Business Associate Agreement. Here is how to tell the difference in one phone call.

    Wavez Team10 min read
    Illustration of two people holding a compliance shield and a signed agreement

    Why an AI receptionist is always a business associate

    The moment a caller says "this is Maria Alvarez, I chipped a molar and I need to be seen today," your AI receptionist is holding protected health information. Name, phone number, and a reason for the visit is PHI under HIPAA — it does not require a chart number or an insurance ID to qualify.

    That makes the vendor a business associate of your practice, not a neutral software supplier. You, as the covered entity, are the one exposed if they mishandle it. A BAA is the contract that pushes defined obligations onto them and gives you recourse.

    The subprocessor problem nobody mentions

    Almost no AI receptionist runs its own speech recognition, language model and telephony. Behind the product sits a stack of third parties. If your vendor signs a BAA but its speech provider does not, the chain is broken and your PHI is sitting somewhere uncovered.

    Ask directly: which subprocessors touch call audio or transcripts, and is each one covered by a BAA? A vendor that has done the work will answer in one sentence. A vendor that has not will change the subject to encryption.

    What a real BAA actually covers

    • Permitted uses. Exactly what the vendor may do with PHI — and an explicit ban on using your call data to train general-purpose models.
    • Safeguards. Encryption in transit (TLS) and at rest (AES-256), role-based access, and audit logging of who opened what.
    • Subcontractors. A commitment that every downstream processor is bound by equivalent terms.
    • Breach notification. A concrete window — 72 hours or less is reasonable — and a named contact, not "without unreasonable delay."
    • Return or destruction. What happens to recordings and transcripts when you cancel, and how long default retention runs.
    • Individual rights. How the vendor supports a patient request for access to, or amendment of, their information.

    Retention is the clause practices skip and regret. If a vendor keeps every call recording indefinitely by default, your breach surface grows every month you stay a customer. Ask for a configurable retention window and set it to the shortest period your state record rules allow.

    Nine questions to ask before you sign

    1. Will you sign our BAA, or do we sign yours — and can I see it before the demo call ends?
    2. Which subprocessors handle call audio, transcripts, or patient identifiers?
    3. Is call audio encrypted at rest, and with what?
    4. Is our call data ever used to train shared or general-purpose models?
    5. What is the default retention period, and can we shorten it?
    6. Who on your team can listen to our recordings, and is that access logged?
    7. What is your breach-notification window in writing?
    8. Where is the data physically stored — US regions only?
    9. What happens to our data 30 days after we cancel?

    If a vendor cannot answer seven of those nine on the first call, they have not built for healthcare — they have built for whoever answered the ad. See our HIPAA overview for how Wavez answers each of them.

    Want our BAA and security summary before you talk to sales? We send both up front, not after a discovery call.

    Review our HIPAA posture

    Frequently asked questions

    Wavez operates under a signed Business Associate Agreement covering its voice and data subprocessors, with HIPAA-aligned data handling: encryption in transit and at rest, minimum-necessary patient data capture, role-based access with audit logging, and configurable retention for call audio and transcripts.