
HIPAA and State Rules for AI Dental Receptionists
A plain-language walkthrough of the BAA, plus the state statutes that add requirements on top of HIPAA in California, Texas, Washington, Illinois and New York.
Table of Contents
Practice owners evaluating an AI receptionist usually ask the compliance question late, which is unfortunate, because it is one of the few questions with a clear right answer.
The BAA is the threshold requirement
Any vendor that handles protected health information on your behalf is a business associate under HIPAA and must sign a Business Associate Agreement. A vendor that will not sign one cannot lawfully process your patient calls, and no other feature discussion matters until that is resolved.
The BAA should be signed before any patient data flows, not after a trial period. Ask for the document early; a vendor with a standard BAA ready to send is a vendor that has done this before.
What the technical safeguards should look like
Encryption in transit and at rest is the baseline. Beyond that, look for role-based access restricted on a least-privilege basis, configurable retention for recordings and transcripts, an audit trail of who accessed what, and a clear answer about subprocessors — which third parties touch the audio and under what agreement.
Also ask whether the system creates biometric identifiers. Voice AI does not need to generate a voiceprint to function, and one that does inherits a set of state-law obligations that one that does not simply avoids.
State law adds requirements in several markets
HIPAA is a floor, not a ceiling. A handful of states impose meaningful additional obligations.
California layers the Confidentiality of Medical Information Act and CCPA on top of HIPAA, with specific rules on disclosure and consumer rights including deletion.
Texas extends HIPAA-style duties to a broader class of entities under the Texas Medical Records Privacy Act and adds workforce training requirements.
Washington's My Health My Data Act is the broadest consumer health privacy statute in the country and reaches data that HIPAA does not, with a private right of action attached.
Illinois BIPA governs biometric identifiers, including voiceprints, and carries statutory damages. A system that does not generate voiceprints avoids the exposure entirely.
New York's SHIELD Act requires reasonable administrative, technical and physical safeguards for private information.
Massachusetts 201 CMR 17.00 requires a written information security programme and specific encryption standards.
Practical steps for a practice owner
Sign the BAA before go-live. Set a retention period deliberately rather than accepting a default — many practices choose ninety days for audio and longer for text transcripts. Decide who at the practice can access recordings and restrict it. Document the decision, because documentation is what an audit examines.
If your practice is in one of the states above, ask the vendor specifically how they handle that statute. A vague answer is itself informative.
Disclosure to patients
HIPAA does not require you to tell callers they are speaking to an automated system. Several state consumer-protection frameworks are moving in that direction, and patient trust argues for it regardless.
The practical approach most practices land on is disclosure on request as a minimum, with many choosing brief upfront disclosure. In our experience it has no measurable effect on booking rates, and it removes an entire category of complaint.
What to write down
Keep four documents: the signed BAA, a one-page description of what data the system collects and how long it is retained, the access list, and the clinical escalation protocol. Those four cover the overwhelming majority of what a compliance review will ask for, and assembling them takes about an hour.
Compliance for an AI receptionist is not exotic. It is the same discipline you already apply to your practice management system and your imaging vendor, applied to one more processor of patient information.
Abdul Ghani Bin Ahmed
Co-Founder, Wavez Automation
Co-founder focused on dental front-office automation and integrations.
Ghani co-founded Wavez Automation with a focus on the operational side of independent dental practices — front-desk workflows, appointment book behavior, insurance intake, and how AI voice agents actually plug into Dentrix, Open Dental, Eaglesoft, Curve, and Dolphin without breaking the schedule.
View author profile →Related Articles
Ready to Transform Your Practice?
See how Wavez AI receptionist can help you capture more appointments, reduce missed calls, and grow your revenue—starting in just 48 hours.


