Skip to content
Answers

Is an AI receptionist HIPAA compliant for a dental practice?

Compliance belongs to the practice, not to the software. The dental practice is the covered entity. Humbrook signs a business associate agreement before the phone agent handles any patient information, and the build stores no clinical records.

Who the rule actually binds

HIPAA binds two kinds of party: the covered entity, and the business associate it hires to handle patient information on its behalf. A dental practice is a covered entity. Software is neither, which is why no vendor can hand a practice compliance as a feature and no product can carry it in a box. The question worth asking is not whether a phone agent is compliant standing on its own. It is whether the practice can put this system on its main line and still meet the obligations it already had.

The moment a vendor handles patient information for a practice, it becomes a business associate, and that relationship has to be written down before the handling begins. Humbrook signs a business associate agreement first. Not after a trial week, not once the number is already live and the practice has grown attached to it. Before the phone agent takes a call for the practice at all. A vendor that offers to sort the paperwork out later is telling a practice manager something useful about how the rest of the work will go.

What the agent hears is the part nobody controls. Callers volunteer clinical detail unprompted. Somebody rings on a Saturday morning to say the temporary crown on the back left came off and the edge is sharp, and no script prevents that sentence. Humbrook does not ask a caller for a diagnosis, a medication list or an insurance number, because a phone agent that collects them has taken on a risk the practice gains nothing from. What it does with what it hears anyway is the honest answer: the name, the callback number and the reason for calling in the caller's own words go to the practice, and the build keeps no clinical record of its own.

Minimum necessary is the design constraint, not a policy line added afterwards. The agent captures what a callback needs and stops. A recording is patient information the moment it sits next to a name and a number, and so is a transcript, so whether calls are recorded at all is the practice's decision, made before the number goes live rather than discovered in a settings panel later. The retention window for anything kept is set in that same conversation. A vendor default is the wrong place for either choice to be made.

What stays with the practice is most of it. The policies, the staff training, the notice of privacy practices, the risk analysis. And an agreement with every other vendor that touches the same information: the carrier the number lives on, the voice platform, the model provider, the scheduling software, whatever sends the text messages. Because Humbrook opens those accounts in the practice's own name, those agreements are the practice's to sign directly. That is more paperwork, and it is also the reason nothing here sits inside an account the practice cannot see or close.

There is no certificate to show at the end of this. HIPAA certifies no product and issues no seal, so a vendor holding one up is describing something the rule does not offer. What can be shown is the signed agreement, a plain list of what the agent captures, where each piece of it goes, and how long anything is kept. That list is what a practice's own compliance review asks for, and Humbrook writes it down before the build starts rather than assembling it under a deadline.

Where this comes up

  • Dental practices

    How the receptionist handles a practice line: the new patient call, the cancellation, the caller asking about a bill, and what the front desk sees afterwards.

The rest of what a practice asks

The dental page walks through the calls a front desk actually loses, what the agent does with each one, and how far it can reach into the software a practice already runs on.