Skip to main content

Use case

HIPAA compliant answering service: how to verify one

There is no such thing as a HIPAA certification. No body issues one, so “HIPAA compliant” on a vendor’s website is a self-assessment — and compliance is a property of your arrangement with them, not of their software. What makes it real is a signed Business Associate Agreement, plus controls you can actually evidence.

PHI handled in call

Inbound · Compliance

PHI handled in call

Minimum necessary capture

Inbound · Records

Minimum necessary capture

Encrypted call storage

Platform · Security

Encrypted call storage

Audit-ready transcripts

Platform · Audit

Audit-ready transcripts

PHI handled in call

Inbound · Compliance

PHI handled in call

Minimum necessary capture

Inbound · Records

Minimum necessary capture

Encrypted call storage

Platform · Security

Encrypted call storage

Audit-ready transcripts

Platform · Audit

Audit-ready transcripts

What it covers

Evaluating a HIPAA answering service vendor

Six things to check before patient data reaches any phone system, including the ones vendors rarely volunteer.

No certification exists

No body issues a HIPAA certification, so any vendor claim of compliance is a self-assessment rather than an audited result.

The BAA comes first

Your practice signs a Business Associate Agreement with each vendor touching PHI, and signs it before any patient data moves.

Encryption in place

Recordings, transcripts and PII are encrypted with AES-256 at rest and TLS 1.3 in transit by default.

Transcripts widen the surface

An AI service stores verbatim transcripts, audio and extracted fields, so the same PHI sits in several systems with separate retention.

Ask about the model layer

Finn does not train on customer data and uses zero-retention model APIs, so the provider does not hold audio after the call.

Audit log you can query

Every data access, API call and configuration change is written to an immutable, exportable log you can produce on request.

How it works

How a patient call moves through Finn

Before the call

The agreement is signed before any data moves

BAA per engagement

Finn executes a Business Associate Agreement for enterprise engagements that process PHI, requested through the trust centre.

Sign it first

A BAA agreed after the fact does not retroactively cover calls that already carried patient data through the system.

The agreement is signed before any data moves

The call arrives

The patient speaks and PHI is captured

PHI from the first words

A patient discloses protected health information the moment they give a name and a reason for calling.

Redaction as it lands

Card numbers, SSNs and account IDs can be auto-redacted from transcripts, with custom patterns for anything specific to your organisation.

The patient speaks and PHI is captured

After the call

What is kept and who can see it

Retention with a mechanism

A stated retention policy needs a deletion job behind it, otherwise it is a statement of intent rather than a control.

Who read this record

Access control is only worth what you can prove, so the answer to who opened a given record has to be producible.

What is kept and who can see it

Testimonial

Better than IVR

Experience a smarter, more intuitive AIsolution that outperforms traditional IVRsystems.

Delivers a customer experienceindistinguishable from a humanconversation

Deliver natural, engaging conversations thatfeel just like speaking with a real human.

Effortless Transitionto Human Agents

When needed, customers can smoothly connect tolive agents without frustration.

"Conversion rate up from 65% to 82%. Agent workload reduced by 40%. Lead response time under 2 minutes."

Ayush Pateria

Ayush Pateria

CEO & Cofounder, Snazzy

"Pillar Bridge scaled multilingual customer support — handling case details and payments in Hindi, Tamil, and Kannada with zero wait time and perfect empathy."

Rajesh Bangera

Rajesh Bangera

Founder, PBS

In detail

What actually matters here

What HIPAA requires of a phone system

A patient discloses protected health information the moment they give a name and a reason for calling. That pulls the answering service inside the regulation as a business associate, and four obligations follow.

A signed BAA is the first and the one people skip. Then encryption of the data in transit and at rest — the audio, the transcript, and anything written into your systems. Then access control with an audit trail, so you can say who read a given record. Then a retention policy with a mechanism behind it, because a stated policy with no deletion job is a statement of intent.

Two things HIPAA does not require, which vendors often imply it does: a SOC 2 report and any particular certification. Those are useful evidence of general security practice, and they are not the regulation.

BAA and who signs it

The covered entity — your practice — signs with each business associate that touches PHI. That includes the answering service, and it includes anyone the answering service passes the data to, which is the chain most evaluations stop short of following. An AI agent has a model provider behind it, and their retention behaviour is part of your exposure whether or not it appears in your contract.

Finn executes BAAs for enterprise engagements that process PHI, per engagement rather than as a blanket clause on every plan, requested through the trust centre. Sign it before any patient data moves. A BAA agreed afterwards does not retroactively cover what already happened.

Worth being clear about where the line sits: the vendor is responsible for the platform’s controls, and you remain responsible for what you use it to do — which calls you make, on what basis, to whom. That division is set out in the consent and legal guidance, and no vendor can take that half from you.

PHI in transcripts and recordings

This is where AI answering services differ materially from human ones, and where the evaluation should concentrate. A human service produces a message: a short, curated note somebody typed. An AI service produces a verbatim transcript of everything the patient said, plus the audio, plus whatever structured data was extracted — several copies of the same PHI in different systems, each with its own retention behaviour.

More data is not automatically worse; a transcript is genuinely more useful and more auditable than a paraphrase. But it is more surface area, and it should be treated that way. Finn encrypts recordings, transcripts and PII with AES-256 at rest and TLS 1.3 in transit by default, and can auto-redact card numbers, SSNs and account IDs from transcripts with custom patterns for anything specific to your organisation — so some categories never persist in readable form at all.

The model layer is the part most reviews miss. Finn does not train on customer data and uses zero-retention model APIs, meaning the audio is not held by the model provider after the call. Ask every vendor that question specifically, because “we don’t train on your data” and “our subprocessors don’t retain it” are two different claims and only one is usually made.

Retention and access control

Access control is only worth what you can prove. Finn writes every data access to an immutable, exportable audit log alongside API calls and configuration changes, which is the artefact that matters in an investigation — the question is never “do you have access controls” but “show me who opened this record”.

On certifications, plainly: Finn holds ISO/IEC 27001:2022 and ISO/IEC 20000-1:2018. Finn is not SOC 2 attested today — an audit is under way with A-LIGN and the report is expected in August 2026. That is stated here for the same reason this page exists: a guide telling you to interrogate vendor claims has no business being vague about its own.

Checklist

Six questions to put to any vendor, Finn included. The answers are more revealing than the compliance page.

  1. Will you sign a BAA, and at which plan?

    If the answer involves an upgrade, that is a price, not a compliance posture. Get the tier in writing.

  2. What exactly is encrypted, and where are the keys?

    'Encrypted' with no object is not an answer. Ask about audio, transcripts, backups and logs separately.

  3. How long do recordings and transcripts live, and what deletes them?

    A retention policy with no deletion mechanism is a statement of intent.

  4. Do your model providers retain or train on the audio?

    Your vendor's subprocessors are your exposure. Ask about the model layer specifically, not just the platform.

  5. Can you produce an access log for a specific record?

    The test is whether they can show you who read a given transcript, not whether logging exists in principle.

  6. Which certifications do you hold today, and which are in progress?

    'In progress' is fine and common. 'Compliant' used to imply an audit nobody has completed is not.

FAQ

Common questions

Do you sign a BAA?
Yes, for enterprise engagements that process protected health information. Finn executes the Business Associate Agreement per engagement rather than as a blanket term attached to every plan, and it is requested through the trust centre. Get it signed before any patient data moves — a BAA agreed after the fact does not retroactively cover what already happened.
Are recordings encrypted?
AES-256 at rest and TLS 1.3 in transit, covering recordings, transcripts and PII by default rather than as an option you enable. Worth asking any vendor the follow-up question rather than stopping at 'yes, encrypted': what is encrypted, at which points, and who holds the keys. Encryption in transit alone is a common and materially weaker answer.
Who can access transcripts?
Access is controlled per workspace, and every data access is written to an immutable, exportable audit log alongside API calls and config changes — which is the part that matters for an investigation, because a control you cannot evidence is not a control. Finn can also auto-redact card numbers, SSNs and account IDs from transcripts, with custom patterns for anything specific to your organisation, so some categories of sensitive data never persist in readable form.

Put the six questions to us

Every certificate, agreement and sub-processor is listed on the trust centre, current status included — nothing is behind a form.