HIPAA Compliant AI for Med Spas: What the Badge Doesn't Tell You
A HIPAA badge in a website footer is a graphic. It is not a certification, there is no certifying body, and any vendor can add one in about four minutes. Here is what to ask instead.
There is no such thing as HIPAA certification
HIPAA compliance is a programme, not a credential: administrative, physical and technical safeguards, documented policies, a risk analysis, workforce training, and agreements with anyone who handles protected health information on your behalf. No government body issues a certificate, and no third-party audit substitutes for the underlying obligations.
This means a badge tells you nothing. Documentation tells you everything.
Business Associate Agreements, and how many are needed
Where a vendor processes protected health information for your practice, it acts as a Business Associate and needs an agreement with you. But the chain does not stop there — that vendor's own subprocessors typically need equivalent agreements.
In a modern AI voice stack that can mean several separate relationships: the voice platform, the speech and language model providers, the telephony carrier, the database, the hosting provider, and any monitoring or logging service that could see patient data in transit.
The question that gets a real answer
Ask the vendor to send you a list of every subprocessor that touches patient data, and confirmation that an agreement is in place with each. A vendor running a genuine compliance programme will have this ready, because enterprise buyers ask for it constantly. A vendor who has not thought it through will send you a paragraph about encryption instead.
Self-hosting is not compliance
Some vendors emphasise that they self-host parts of their stack. That can be a sound architectural decision, but it does not by itself make anything compliant. Under HHS guidance, cloud providers that process, store or transmit electronic protected health information on behalf of a covered entity or business associate generally require an appropriate agreement, alongside the full set of safeguards. Architecture and compliance are different questions.
Data minimisation is a real control
Ask what the vendor actually stores. A system that holds contact details, appointments and consultation outcomes carries meaningfully less risk than one holding clinical notes and treatment photography. If a vendor collects more than their function requires, ask why — and what happens to it if they are breached.
Outbound messaging is a separate legal question
HIPAA governs how patient information is handled. It does not govern telemarketing. If a system contacts your patients, US consumer protection rules around consent, calling hours and opt-outs apply independently, and the exposure sits substantially with your practice as the party on whose behalf the contact is made.
Ask how consent is captured and timestamped, how opt-outs propagate across channels, how contact hours are set by the recipient's time zone, and whether suppression lists persist. And treat automated voice contact as a distinct and more complex question from text.
What good looks like
A vendor who says 'here is the subprocessor list, here are the agreements, here is what we store and for how long, here is our data-flow diagram, and here is where our counsel drew the line' is a different proposition from one who says they are fully compliant. The first can be verified. The second is a sentence.
Key takeaways
- There is no HIPAA certification — a badge is decoration, documentation is evidence
- A modern AI voice stack may need several separate Business Associate Agreements
- Ask for the subprocessor list and confirmation of agreements with each
- Self-hosting is an architecture choice, not a compliance status
- Outbound messaging carries separate obligations that HIPAA does not cover
See what your consultations are worth
Five numbers you already know, and the one figure nobody has shown you. Free, and yours whether or not you become a client.
Run My Consult Audit