Data handling & HIPAA

HIPAA is a system of responsibilities, not a badge on an AI receptionist.

A production dental call workflow can involve protected health information. MedStack scopes the data flow, contracts, vendors, access, retention, and incident path before that workflow goes live.

The practical standard

Start with the exact call workflow and map every place the information goes.

The U.S. Department of Health and Human Services explains that a cloud provider that creates, receives, maintains, or transmits ePHI for a covered entity or business associate is itself a business associate, even when the data is encrypted and the provider lacks the decryption key.

That is why MedStack does not treat HIPAA as a single software toggle. The deployment process identifies the parties, the permitted purpose, the minimum data needed, the systems and subcontractors involved, the contract path, and the safeguards required for the practice’s use case.

Practices remain responsible for their own legal and compliance obligations. MedStack’s role and responsibilities are documented in the services agreement, BAA when required, and the approved implementation scope.

Authoritative reference

Read HHS guidance on HIPAA and cloud computing and business associate agreements.

Before production

Six decisions made in writing.

  1. 01

    Minimum necessary scope

    Enable only the call types, data fields, and downstream actions required for the agreed workflow.

  2. 02

    Business associate agreements

    When MedStack acts as a business associate and the production scope involves PHI, the required BAA is executed before PHI is handled.

  3. 03

    Role-based access

    Production access is limited to the people and systems that need it for implementation, support, and the practice-approved workflow.

  4. 04

    Defined retention

    Call recordings, transcripts, summaries, and logs receive an explicit retention and deletion plan; recording is not treated as a default requirement.

  5. 05

    Vendor review

    Any subcontractor that may create, receive, maintain, or transmit ePHI is reviewed for the role it plays and the agreements that role requires.

  6. 06

    Incident path

    The production plan documents who is notified, how an incident is investigated, and what contractual and legal reporting duties apply.

Public demo vs production

Do not use the website demo for real patient information.

The public demo helps a visitor hear the pacing, tone, clarification, and handoff style. It is not a dental practice’s production system, is not connected to a live practice record, and should not receive personal medical information.

A production workflow is configured separately for one practice. It has approved knowledge, defined routing, data fields, escalation rules, vendor configuration, access, and retention. Those details are reviewed before testing with real calls.

  • Separate practice-specific configuration
  • Approved call and escalation scope
  • Documented data and vendor flow
  • Contract and BAA path where required
Direct answers

What dental practices usually ask first.

These answers describe the public operating approach. A signed agreement and implementation plan control an actual production deployment.

01

Is an AI receptionist automatically HIPAA compliant?

No. HIPAA compliance depends on the complete workflow: the covered entity, the business associate relationship, contracts, vendors, configuration, access, policies, and day-to-day operation. A product label by itself does not make a deployment compliant.

02

Will MedStack sign a business associate agreement?

When MedStack acts as a business associate and the production workflow involves protected health information, the required BAA is executed before that information is handled. The exact responsibilities and permitted uses are defined in the agreement and implementation scope.

03

Are calls always recorded?

No. Recording is a configuration and legal decision, not an automatic requirement. The practice and MedStack define whether recording is needed, how callers are notified, where data is processed, who can access it, and when it is deleted.

04

Can someone share medical information in the public demo?

They should not. The public website demo is for evaluating the conversation experience and asks visitors not to share personal medical or other sensitive information. Production workflows use a separate, practice-specific configuration and agreement.

05

Where is patient information processed?

The data flow and vendors depend on the approved production design. Before launch, MedStack documents the systems involved, the purpose of each transfer, applicable agreements, access, retention, and the practice’s requirements rather than making a blanket promise on this public page.

Review the real workflow

Bring your data-handling requirements to the first call.

Book a 15-minute review