By Sagar Shankaran, Founder of CallSphere
OCR has named parental access to children's records an enforcement priority. COPPA 2.0 is sharpening minor data rules. The AI agent serving pediatric practices has to satisfy both layers — without breaking adolescent confidentiality.
Key takeaways
Pediatrics is the workflow where every privacy regime intersects: HIPAA, COPPA, FERPA, state mature-minor laws, and adolescent confidentiality. The AI agent must know who is on the phone, what they can access, and what state they are in.
flowchart LR
Voice[Voice call] --> Redact[PII / PHI redaction]
Redact --> LLM[LLM with BAA]
LLM --> Resp[Response]
Resp --> Sanitize[Remove non-needed PHI]
Sanitize --> Caller[Caller]
Resp --> AuditDB[(Audit DB)]A parent calls about a child's appointment, immunization record, or refill. Or an adolescent calls about a confidential service — STI screening, mental health, reproductive health, SUD treatment. The AI agent identifies the caller, validates their relationship to the patient, applies the practice's policy on parental access by age and service type, and routes accordingly. For COPPA-covered digital interactions (under-13 children using portal features), the agent captures verifiable parental consent.
Done well, the workflow respects both parental access rights and adolescent confidentiality. Done badly, it discloses an STI test to a parent who legally should not have access — or denies a parent legally entitled access.
45 CFR 164.502(g) recognizes parents as personal representatives of minors with three exceptions: (1) minor consents to care that does not require parental consent under state law and does not request parental involvement; (2) minor obtains care at the direction of a court or person appointed by the court; (3) parent agrees to confidentiality between minor and provider. State law governs which services minors may consent to themselves — most states permit minor consent for STI, contraception, mental health, and SUD treatment at varying ages.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent in your browser — 60 seconds, no signup.
OCR has named parental access to children's medical records an enforcement priority and signaled it will use civil monetary penalties for noncompliance. 45 CFR 164.524 governs the right of access — parents acting as personal representatives have the same right.
COPPA at 16 CFR 312 governs collection of personal information from children under 13 in commercial digital services. COPPA 2.0 proposes raising the threshold to 16 and adding biometric, voice, and geolocation data. Healthcare providers fall under HIPAA primarily, but COPPA can apply to direct-to-consumer apps and portal features serving under-13 users.
CallSphere's Healthcare Voice Agent runs pediatric flows through the verify_caller_relationship, apply_minor_policy, and route_pediatric_request tools — 3 of 14 healthcare tools. Caller identity is verified with two identifiers; relationship to the patient is captured and validated against the EHR (parent of record, legal guardian, custodial parent, other authorized adult). The minor policy table is loaded per state and per service type — the agent knows that California permits 12+ to consent to mental health, that Texas requires parental consent for most services, that Washington permits 13+ to consent to mental health. Adolescent confidential services are not surfaced to parents calling on the adolescent's behalf. Where the request is for a pediatric service that requires parental consent, the agent captures verifiable parental consent on the call. For under-13 portal interactions, the agent runs a COPPA-aligned consent flow. Every call is captured in post-call analytics with sentiment (–1.0 to +1.0), lead score (0–100), AI summary, and audit trail in the encrypted healthcare_voice PostgreSQL database (1 of 115+ tables). HIPAA and SOC 2 aligned, 37 agents and 90+ tools across 6 verticals. Pricing on /pricing; start with 14-day trial; healthcare overview at /industries/healthcare.
Can a parent get a child's portal access? Yes for most under-12 children where the parent is a personal representative under 45 CFR 164.502(g). Adolescent portals typically require dual-account design — parent has access to general items, adolescent has access to confidential items.
Still reading? Stop comparing — try CallSphere live.
CallSphere ships complete AI voice agents per industry — 14 tools for healthcare, 10 agents for real estate, 4 specialists for salons. See how it actually handles a call before you book a demo.
Can the AI agent refuse to disclose to a parent? When state law gives the minor consent rights and the minor has not authorized parental involvement, yes — 45 CFR 164.502(g)(3) provides the basis.
What about non-custodial parents? HIPAA defers to state custody law. The EHR should reflect custody orders; the agent applies what is in the record.
Does COPPA apply to a pediatrician's portal? COPPA primarily targets commercial websites and online services directed at children. Healthcare provider portals operating under HIPAA generally fall outside COPPA's commercial scope, but DTC pediatric apps do.
Is voice biometrics on a child a COPPA issue? Yes if collected from under-13 users in a commercial service. Healthcare providers should treat child voice prints as the most sensitive identifier in the workflow and limit retention.
Written by
Sagar Shankaran· Founder, CallSphere
Sagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
Using GPT-Realtime-2 for healthcare voice agents. BAA scope, PHI handling, retention, logging, and why a managed platform usually wins this build.
The 2024 NPRM proposes mandatory penetration tests every 12 months and vulnerability scans every 6 months. Here is how an AI voice agent should be tested in 2026.
AWS HealthScribe became the open scribe layer EHR vendors built on top of in 2026. Here's the API surface, the per-encounter pricing, the BAA terms.
Apollo, Manipal, and Narayana scaled AI agents across Bangalore in 2026. Here's the deployments across radiology, intake, and follow-up, the costs.
Notable's AI agents now handle scheduling, intake, and revenue cycle for 6,000+ clinics in 2026. Here's the multi-agent architecture, the per-clinic pricing.
Abridge raised $250M in April 2026 at a $2.7B valuation. We break down the deployment numbers, the EHR integrations across Epic and Cerner. The Q2 2026 buyer briefing.
© 2026 CallSphere LLC. All rights reserved.