HIPAA-compliant AI voice agents, deployed for you under a signed BAA
CallSphere designs, integrates and deploys AI voice agents that answer patient calls, book and reschedule visits, verify insurance eligibility and benefits, and route urgent calls for behavioral health, dental and medical practices. Every CallSphere plan is HIPAA compliant: we sign a Business Associate Agreement (BAA) with every healthcare customer, on any plan, before any PHI is handled.
An AI voice agent on a practice's phone line handles protected health information from the first second of a call: a name, a date of birth, a member ID, the reason for the visit. The vendor behind it is a business associate, so it needs a signed Business Associate Agreement (BAA) before any PHI flows, and safeguards for that PHI wherever the call sends it: encryption in transit and at rest, role-based access, an audit trail, minimum-necessary collection and a retention limit on recordings and transcripts. HIPAA has no certifying body, so no vendor can hand you a HIPAA certificate. What you can inspect is the BAA, the safeguards, the retention setting and the log.
HIPAA compliance is a shared responsibility. CallSphere handles its side under a signed BAA; your practice still governs who has access and what is disclosed.
The safeguards behind a HIPAA-compliant voice agent
The safeguards a compliance review should find behind any AI voice agent on a patient line. Each card pairs what to look for with CallSphere's published position and the page where we state it.
A signed Business Associate Agreement
A vendor that handles PHI for your practice is a business associate. The BAA binds it to safeguard that PHI, report breaches to you, hold its subcontractors to the same terms and return or destroy the PHI when the relationship ends.
CallSphere: Every CallSphere plan is HIPAA compliant: we sign a Business Associate Agreement (BAA) with every healthcare customer, on any plan, before any PHI is handled. We send the BAA before onboarding, and your counsel can redline it.
Call audio, transcripts, recordings and the records written back to your systems all carry PHI, so each needs protection while it moves and while it is stored.
CallSphere: Data sent to and from CallSphere services is encrypted with TLS, and customer data is encrypted at rest with AES-256 on our cloud infrastructure. The public telephone leg belongs to the carrier, and no vendor controls it.
Only the people whose job needs a record should be able to open it, and administrative access should take more than a password.
CallSphere: Access to customer data is restricted to authorized personnel by job function, on the principle of least privilege, and multi-factor authentication is enforced for admin access.
The minimum necessary standard applies to the agent's script as much as to your staff: ask for what the task requires and stop.
CallSphere: The agent is scoped to the fields its task needs, agreed with you during setup, so a scheduling call does not open a problem list. On our SimplePractice and TherapyNotes integrations, the agent works with scheduling and insurance data, never clinical notes.
When a patient, an auditor or your own staff asks what happened on a call, the answer should come from a log rather than from memory.
CallSphere: Every patient interaction is written to a timestamped log: who called, what the agent did, what it wrote back and when. Administrative actions are also logged for security monitoring and audit purposes.
Recordings and transcripts hold the same PHI as the structured record, several states require every party's consent to record, and nothing should be kept longer than the practice decides.
CallSphere: Recording is on or off per line, your choice, and when it is on the greeting says so before the caller starts talking. Recordings and transcripts are retained according to your plan settings, 90 days by default. Your practice remains responsible for the consents your state requires.
Telephony, hosting and AI model providers can all sit behind one voice agent. Each should be named, and each should be held to the obligations your BAA sets.
CallSphere: CallSphere publishes its subprocessors, including AWS for hosting and storage, Twilio for telephony and OpenAI for AI language models, with the data categories each one handles. The services and integrations in your deployment determine which providers process your data, and we review the applicable providers with you.
An administrative agent must not improvise on clinical questions, and urgent calls need a route your clinicians chose in advance.
CallSphere: The agent is configured to refuse clinical advice and escalate instead. Your clinical lead sets the urgent triggers during setup, and each maps to one action: a fixed 911 instruction, a page to the on-call provider, or a live transfer.
A compliance reviewer needs documents rather than adjectives: completed questionnaires, test results and a written notification duty.
CallSphere: Completed security questionnaires such as SIG Lite or CAIQ, a summary of our most recent third-party penetration test, and our DPA and subprocessor list are available to prospective and current enterprise customers on request, under NDA where applicable. Breach notification is an obligation written into the BAA.
A BAA for a voice agent has to follow PHI everywhere a call sends it, not only into a database. CallSphere's BAA names CallSphere Inc as the business associate, and your counsel can read it before anything is signed.
Covered by the BAA
PHI handled during calls, chats, transcripts, recordings and write-backs to your systems
Administrative and technical safeguards for that PHI
Breach notification to your practice
Flow-down of the same obligations to subcontractors
Return or destruction of PHI when the agreement ends
How it is put in place
We send the BAA before onboarding rather than after, and your counsel can redline it.
No patient information moves through the agent until the BAA is executed, including during onboarding.
Every plan includes the BAA, from Lite through Enterprise.
The public demos run on synthetic data, so you can hear the workflow before any PHI is involved.
Plans and usage pricing are published on the pricing page. HIPAA compliance and the signed BAA come with every plan, so you compare plans on features and call volume alone. Compare plans
Done-for-you deployment
How we deploy a HIPAA-compliant voice agent
CallSphere is an AI deployment company. Your staff do not configure an agent or learn a builder: we design, integrate and run it, and the BAA, the safeguards and the escalation rules are set up as part of that deployment.
Step 1
Map the calls and the PHI
We document the calls you want covered, the fields each one needs, the systems involved and who receives escalations, working with your team and your clinical lead.
Step 2
Execute the BAA
The BAA goes to your counsel before onboarding. No patient information moves through the agent until it is signed.
Step 3
Connect and test
We connect your EHR, practice management system or calendar through its API where one is available, or a shared calendar and task queue where it is not, then test real scenarios, including unavailable staff and failed updates.
Step 4
Launch supervised, then expand
The agent starts on a narrow set of calls under supervised coverage. Your team reviews the call records, and coverage expands once the results meet your expectations.
HIPAA-compliant voice agents by practice type
The safeguards are shared; the workflows are not. Each deployment runs the full call: the agent books the visit, checks coverage, routes what needs a person and writes the record back. The practice pages cover each workflow in depth, with a live demo that uses clearly labelled synthetic data.
Behavioral health & therapy
Books intake, checks benefits and follows the practice's crisis handoff script.
Tell us at setup which parts of the practice are a federally assisted substance use disorder program, and those lines run the stricter 42 CFR Part 2 script on top of HIPAA.
You write the crisis script and the agent reads it verbatim: 988, your local mobile crisis team, 911 and your on-call rotation, in the order you set.
CallSphere is an administrative tool, not a clinical or crisis service, and makes no representation that it can detect every emergency.
Books visits, verifies eligibility and escalates under the practice's rules.
Your clinical lead sets the urgent triggers: a fixed 911 instruction, a page to the on-call provider, or a live transfer.
Where your EHR is open, the agent writes back through its API or an HL7/FHIR endpoint; where it is closed, it works a shared calendar and a task queue.
The agent is a receptionist, not a clinician, and refuses clinical advice.
Put these questions to every vendor you evaluate, including us. HIPAA has no certificate to show you, so the answers, the BAA and the log are the evidence. Our answer to each one is in the safeguards above, with the page where we publish it.
1
Will you sign a BAA before any PHI reaches the agent, and can our counsel review and redline it first?
Yes. Every CallSphere plan is HIPAA compliant: we sign a Business Associate Agreement (BAA) with every healthcare customer, on any plan, before any PHI is handled. That compliance rests on TLS encryption in transit, AES-256 encryption at rest, role-based access, a timestamped interaction log and a retention limit on recordings and transcripts. HIPAA has no certifying body, so no vendor can hand you a HIPAA certificate; what you can review is the BAA and those safeguards. Compliance is shared: we handle our side under the BAA, and your practice still governs who has access and what is disclosed.
Will CallSphere sign a BAA for an AI voice agent?
Yes, on every plan. Healthcare customers receive the BAA before onboarding, and your counsel can redline it. It names CallSphere Inc as the business associate and covers PHI handled during calls, chats, transcripts, recordings and write-backs, including safeguards, breach notification, subcontractor flow-down, and return or destruction of PHI when the agreement ends. No patient information moves through the agent until it is executed.
Can an AI receptionist or AI answering service be HIPAA compliant?
It can, when the vendor signs a BAA, protects PHI wherever the call sends it and collects only what each call needs. The difference from a message-taking answering service is the work that gets finished: a CallSphere agent books the visit, checks coverage, routes urgent calls to your on-call provider and writes the record back to your systems, all under the same BAA.
Does the voice agent see clinical notes?
The agent is scoped to the fields its task needs, agreed with you during setup. On our TherapyNotes integration, CallSphere accesses only scheduling, insurance and patient demographic data, never clinical notes, treatment plans or session documentation. On SimplePractice, it touches scheduling and insurance data, never clinical notes.
Are patient calls recorded, and how long is the data kept?
Recording is on or off per line, your choice, and when it is on the greeting says so before the caller starts talking. Your practice remains responsible for the consents your state requires. Recordings and transcripts are retained according to your plan settings, 90 days by default, and are encrypted at rest like the rest of the record.
Which third parties process call data?
Our published subprocessor list names each provider, its purpose and the data categories involved, including AWS for hosting and storage, Twilio for telephony and OpenAI for AI language models. A listed provider does not necessarily receive every type of information your practice handles: the services and integrations in your deployment determine the processing, and we review the applicable providers with you.
What happens when a caller has an emergency or is in crisis?
The agent is an administrative tool, not a clinician or a crisis service, and it is configured to refuse clinical advice. Your clinical lead defines the urgent triggers during setup, and each maps to one action: a fixed 911 instruction, a page to the on-call provider, or a live transfer. Behavioral health practices write a crisis script, including 988, that the agent reads verbatim. CallSphere makes no representation that it can detect every emergency, so crisis handling is configured and supervised by your practice.
Can we try it before any PHI is involved?
Yes. The live industry demos use clearly labelled synthetic data, so you can hear the workflow without sharing patient information. Real patient calls begin once your BAA is executed, whichever plan you choose.
How much does a HIPAA-compliant AI voice agent cost?
Starting at $50/month. Lite is a basic Q&A plan. Booking, CRM write-back, and outbound automation begin on higher tiers; AI-token, telephony, and some integration usage are billed separately. Every plan, Lite included, is HIPAA compliant and comes with the signed BAA.
Deploy a HIPAA-compliant voice agent for your practice
Walk us through your calls, your systems and your BAA requirements. We deploy and run the agent; your practice keeps control of escalation, access and what is disclosed.