FIELD NOTES

HIPAA Voice Agents: The Plain-English Guide for Builders & Operators

Most 'HIPAA-compliant' voice AI vendors don't know what they're claiming. Here's the actual difference between Covered Entity and Business Associate, what a BAA covers, where most stacks leak PHI, and the BAA + DPA combo you actually need.

How the post opens

Half the voice-AI vendors I've seen list "HIPAA compliant" on their pricing page. The phrase has been so abused it's borderline meaningless. There's no such thing as a "HIPAA-certified" product — HIPAA is a law, not a certification. What exists is a chain of legal agreements (BAAs) and a stack of technical controls that, taken together, make it lawful for a covered healthcare entity to use the product without breaking the law. I build voice agents for healthcare clients at TrainYourAgent.

What it argues

I build voice agents for healthcare clients at TrainYourAgent. We've signed BAAs with five healthcare providers in 2026 alone. This is the guide I wish existed when we started — plain English, no lawyer-speak, what actually matters when you're building or buying. What HIPAA actually is HIPAA (1996, updated by HITECH 2009) regulates how Protected Health Information — PHI — can be created, stored, shared, and destroyed by entities that handle it. PHI is any health information tied to an identifiable individual.

Filed under

Why this one exists

Most 'HIPAA-compliant' voice AI vendors don't know what they're claiming. Here's the actual difference between Covered Entity and Business Associate, what a BAA covers, where most stacks leak PHI, and the BAA + DPA combo you actually need. It is filed under AI Infrastructure because that is where operators looking for this problem actually start, and it is written from production work rather than from a content calendar.