An AI receptionist is not automatically HIPAA compliant because it answers dental calls or offers a business associate agreement. First establish your practice's HIPAA status and the patient information the service will handle. Then verify the contract, data flow, recording setup, booking connection and human handoff before using real patient calls. This guide gives you a vendor evidence checklist and fictional call tests, with separate checks for Florida practices. It is general buying guidance, not a legal determination about your practice or a vendor.
Buyer guides. By Chleb AI Editorial (AI-assisted, reviewed). Published 2026-09-25. 7 min read.

Write the proposed job in one sentence: answer inbound calls, collect a callback request, book into an approved calendar, or route callers to staff. Those are different scopes. Do not let a successful greeting demo stand in for evidence that the booking and handoff work.
Next draw the actual path: caller, phone provider, transcription, language model, call summary, storage, calendar and staff notification. Ask the vendor to name each service that handles patient information and show a fictional record at each destination. Include recordings, transcripts, backups and support access in that discussion.
For each step, record what information enters, who can access it, how long it stays and how it is removed. An answer such as "everything is encrypted" does not tell you where a receptionist summary is copied or who receives it.
HHS explains that a healthcare provider is a HIPAA covered entity when it conducts specified electronic transactions, such as covered billing transactions. Have your compliance adviser establish your practice's status. Do not assume every dental business has the same HIPAA obligations.
If a covered practice hires an outside provider to perform functions involving protected health information, the provider will generally be a business associate. Review the actual functions and information flow with your adviser and put the required business associate agreement, or BAA, in place before sharing PHI. HHS guidance describes the applicable relationships and exceptions.
HHS cloud guidance distinguishes transmission-only conduits from services that maintain electronic PHI. A cloud provider storing that information can be a business associate even without a decryption key. A receptionist vendor should explain its actual processing and storage, rather than treating encryption or a phone-carrier label as an exemption.
Use HHS's business associate contract guidance with your adviser. Review permitted uses and disclosures, safeguards, reporting of breaches and security incidents, subcontractor obligations, support for applicable patient rights, HHS access to relevant records, and termination provisions. Return or destruction at termination is subject to feasibility and the required continuing protections; do not reduce it to an unconditional deletion promise.
Ask who is responsible for agreements with downstream services. The contractual chain matters; it does not necessarily mean your practice signs directly with every subcontractor. Get the service names and responsibilities in writing.
Then request evidence beyond the contract: the approved data-flow diagram, access roles, retention settings, incident contact, export process and a demonstration of the configured workflow. HHS says cloud use also requires applicable risk analysis and risk management. A signed BAA alone does not establish that your deployment complies.
Keep a decision record with these fields: requirement, vendor document or demonstration, unresolved question, practice owner and acceptance date. Mark an unanswered item unresolved instead of recording a sales assurance as a completed check.
HHS says the minimum-necessary standard generally limits uses, disclosures and requests for PHI to what the purpose requires. It has exceptions, including disclosures to or requests by healthcare providers for treatment, disclosures to the individual, and certain authorized or legally required uses. Your adviser should classify each workflow; do not label all receptionist activity treatment to avoid the rule.
As a practical design choice, begin with a callback or scheduling task and justify each requested field. Decide when staff should take over instead of having the AI gather a medical history or insurance identifier. There is no universal list of fields that makes every dental call compliant.
Write down where each approved field may go. A calendar note, email, text notification and transcript are separate destinations to review. Test that an unapproved detail does not appear in a staff notification merely because a caller volunteered it. Confirm the actual handling and retention policy rather than promising the model will never hear sensitive information.
Florida Statutes section 934.03 generally prohibits interception and expressly permits it when all parties give prior consent. The statute also contains exceptions. For ordinary patient calls, have counsel approve the consent process, including what happens if a caller declines. A notice played at the start is not, by itself, proof that every recording or transcription arrangement is lawful.
Section 501.171 addresses security and breach notice for covered personal information. Individual notice is generally due as expeditiously as practicable, no later than 30 days after determining a breach or having reason to believe one occurred, subject to statutory conditions and exceptions. Department notice has a 500-Florida-individual threshold. A third-party agent's notice to the covered entity generally has a 10-day outer limit; it is not a 10-day patient-notice rule.
Ask counsel to map the Florida and HIPAA duties to your actual vendor relationship. Set the incident contact, escalation process and contractual reporting time before launch. These checks concern inbound answering and information handling. Outbound campaigns and automated texts need a separate review of the rules that apply to them.
Use invented patient details and a test calendar approved by the practice. Agree on expected outcomes before calling. Save the observed result, not just a pass label. These are proposed acceptance tests, not results from a Chleb customer deployment.
New appointment: request an allowed appointment type. Check the offered time against the actual test calendar, the resulting record and the staff notification. Repeat with an unavailable time. If the connection fails, the system should follow your approved fallback and must not claim a booking was confirmed.
Change or cancellation: ask to move an appointment using fictional details. Verify the practice's identity-check process and whether the integration can actually update or cancel a record. A new calendar entry is not evidence that the old appointment was removed.
Urgent caller: have the clinical lead provide the test wording and approved escalation instructions. Confirm the intended staff destination answers, then test an unanswered transfer. The system should follow the practice's approved fallback without improvising diagnosis or treatment advice.
Insurance or payment question: test a request the system cannot verify. Require the agreed staff callback or approved factual answer; a confident guess about coverage is a failed test. Recording refusal: test the counsel-approved path and inspect whether storage and transcription match it.
Access and retention: inspect which staff roles can view the fictional record, where copies were sent, and the documented deletion or retention behavior. Test with the front-desk lead, not only the vendor. Retest affected scenarios when the script, integration or underlying services change.
Proceed only when the practice's responsible reviewers accept the scope, applicable agreements, information handling, recording process, integration and fictional-call results. Keep a named owner for unresolved issues and a fallback staffed process. A persuasive demo is not a substitute for those decisions.
Ask each provider to quote the same work: inbound coverage, approved call types, calendar or practice-management connection, human escalation, usage charges and ongoing changes. Require a clear distinction between a confirmed appointment and a request awaiting staff action. Do not assume that a general calendar connection proves compatibility with your practice-management system.
For Chleb, start with a scope review for your practice. Our current security page says BAAs are available for qualifying healthcare clients and that we hold no third-party security certification. Those are Chleb's published statements, not independent validation of your deployment. Confirm eligibility, the specific services and agreements, and the proposed data flow in writing before providing patient information.
Bring the fictional scenarios above to the review. Ask us to show the actual connection and staff handoff you would use, identify what still needs implementation, and document the acceptance criteria. If the required workflow cannot be demonstrated or the necessary terms are unresolved, keep real patient calls on your existing process.
Written with AI assistance and reviewed by the Chleb AI team before publishing. Every factual claim links to its source above. Illustrations are AI-generated, not photographs; cover cards are set in type; charts and diagrams are built from the public data they cite. This is general information, not legal, financial or tax advice. Found an error? Tell us at chleb@chleb.ai or through the contact page and we will correct it and note the correction on this page.
No. Evaluate the practice and provider roles, information handled, applicable agreements, safeguards and actual configuration. A BAA or a vendor label alone does not establish a compliant implementation.
Establish whether the practice is a HIPAA covered entity and whether the provider performs a business-associate function involving PHI. Have the responsible adviser classify the relationship and exceptions before patient information is shared.
HHS says a cloud provider maintaining electronic PHI can be a business associate even without the decryption key. Encryption alone does not remove that relationship or its applicable obligations.
Require a demonstration with your specific system and approved test records. Verify availability, the created record, rescheduling, cancellation and failure handling. General calendar support does not prove a particular practice-management integration.
Have counsel approve the consent and refusal process for your arrangement, then test it. Confirm what happens to audio, transcripts and summaries. Do not assume an announcement alone resolves every consent question.
The clinical lead should define the escalation and fallback instructions. Test the approved route with fictional calls, including an unanswered transfer, without allowing the system to improvise clinical advice.