Skip to content

Stratgik — technology strategy and business systems engineering.
Delivery across the USA, UK, UAE and India.

Talk about a problem

HIPAA and TCPA Rules for AI Voice Agents in US Clinics

Published 22 September 2026 · 10 min read

What US medical practices must check before deploying an AI voice agent: HIPAA BAAs, TCPA consent, state AI disclosure laws and real cost drivers.

HIPAA and TCPA Rules for AI Voice Agents in US Clinics

An AI voice agent can legally answer and place calls for a US medical practice, but three regimes must be satisfied at once: HIPAA (the vendor is almost always a business associate and needs a signed BAA), the TCPA (the FCC has ruled an AI-generated voice is an "artificial" voice, so outbound calls need consent unless a narrow healthcare exemption applies), and a growing set of state AI-disclosure and call-recording laws. Deployments that go wrong rarely fail on the technology. They fail because nobody mapped which call types are inbound, outbound, clinical, or marketing before switching the agent on.

Stratgik is a technology firm, not a law firm. This is a summary of published regulator and primary-source material to help you scope a project and brief your counsel, not legal advice. Have a healthcare attorney review your specific call flows before you go live.

Three regimes, and why they pull in different directions

Practices treat an AI receptionist as a single procurement decision. Legally it is at least three.

HIPAA governs what the vendor may do with protected health information (PHI); what matters is who touches the data and under what contract, not whether a human or a model is on the line. The TCPA governs outbound calls and texts to patients — it is indifferent to PHI and concerned with consent, dialing technology, and message content. State law increasingly governs disclosure, meaning whether you must tell the patient they are speaking with AI, and separately whether you may record the call at all.

An agent can be flawlessly HIPAA-compliant and still generate TCPA exposure on every appointment reminder it places. Scope against all three, not one.

HIPAA: your AI voice vendor is a business associate

Under the HHS definition, a business associate is a person or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity. A covered entity must obtain "satisfactory assurances, in the form of a contract or other written arrangement" before disclosing PHI to that party, and those assurances must flow down to the vendor's own subcontractors.

The "conduit exception" — for entities that merely transmit information, like a courier — almost never rescues an AI voice vendor. HHS guidance is explicit that a party accessing PHI regularly in order to perform its service is not a conduit, and an agent that transcribes symptoms, looks up an appointment, and writes a summary back to your practice management system is doing exactly that.

The practical consequence: you need a signed Business Associate Agreement with the voice vendor, and you need to know which subprocessors sit behind it. A typical voice stack involves a telephony carrier, a speech-to-text model, a large language model, a text-to-speech model, and often a separate transcript store. Each one that sees PHI must be inside the BAA chain. Ask for the list in writing; if the vendor cannot produce one, that is your answer.

Two further diligence points. Your BAA should state plainly whether call audio or transcripts may be used to train or improve models; the safe default for a clinical deployment is no. And recordings and transcripts are PHI, so an indefinite default retention period in the vendor's console is a risk you inherit.

The floor is also moving: HHS proposed a major HIPAA Security Rule overhaul in January 2025 — mandatory multi-factor authentication, asset inventories, stronger business associate oversight — which drew over 4,000 comments and has since slipped to the long-term actions agenda, with final action not anticipated before 2027. Not law today, but build as though it is coming.

TCPA: the FCC says an AI voice is an "artificial" voice

On February 8, 2024, the FCC issued a Declaratory Ruling confirming that AI-generated voices fall within the TCPA's existing restriction on calls using an "artificial or prerecorded voice." It took effect immediately, closing the argument that a synthesized voice sits outside the statute because it is neither a recording nor a live human.

That matters because the TCPA carries a private right of action with statutory damages of $500 per violation, trebled to up to $1,500 for willful or knowing violations, and violations are counted per call. A reminder campaign to a few thousand patients is not a theoretical exposure.

Crucially, inbound calls are not the problem. If a patient rings your office and an AI agent answers, the outbound-call consent machinery is not engaged. Most low-risk deployments start here — after-hours answering, scheduling, insurance and directions questions — because the compliance surface is smaller.

Which outbound calls are exempt, and on what conditions

The FCC's healthcare-specific relief survives the AI ruling, but its conditions are strict and frequently missed.

Call typeConsent standardKey conditions
Artificial/prerecorded healthcare message to a residential landline, from a HIPAA-covered entityExempt from consentContent must be healthcare-related; no marketing or billing content
Healthcare call or text to a wireless number (treatment, appointment, prescription)Prior express consent — not prior express written consentMax one call/text per day and three combined per week; calls one minute or less; texts 160 characters or less; no telemarketing, solicitation, advertising, or billing content; easy opt-out honored immediately; caller must identify itself
Marketing or solicitation call using an AI voice (recalls framed as offers, service promotions, plan sales)Prior express written consentWritten consent must be specific to the caller and to autodialed/artificial-voice marketing calls
Billing, collections, or payment reminder callsNot covered by the healthcare exemptionTreat as ordinary TCPA-regulated calls; content excluded from the exemption by rule

Two nuances. Courts have generally held that a patient providing their phone number during treatment gives prior express consent for healthcare calls to that number — but that is consent for treatment communication, not marketing. And the exemption tests whether a message is "inarguably health-related," tied to an established treatment relationship, and addressed to that individual's care. Insurance solicitations dressed as health reminders have not passed.

Separately, the FCC's revocation-of-consent rules largely took effect on April 11, 2025, requiring callers to honor revocation requests made through reasonable means. The most demanding piece — "global revocation," where an opt-out from one message type applies to all unrelated future robocalls from the same caller — has been repeatedly delayed and currently stands at January 31, 2027, with an open rulemaking examining whether healthcare and financial communications should be treated differently. Build opt-out handling for the global standard now; retrofitting consent state later is expensive.

State law: disclosure and recording

Two distinct state-level obligations catch practices out.

AI disclosure. California's AB 3030, effective January 1, 2025, requires health facilities, clinics, and physician practices to attach a disclaimer to generative-AI-created patient communications about clinical information. For audio interactions the disclaimer must be given verbally at the start and end, stating the communication was AI-generated and explaining how to reach a human provider. If a licensed or certified provider reviews the communication before it reaches the patient, the requirement does not apply. Enforcement runs through facility licensure actions and physician discipline.

Utah took a different route. Under SB 226, effective May 7, 2025, general suppliers must disclose generative AI use only when a consumer clearly asks — but professionals in state-licensed "regulated occupations," including medical and mental health practice, must disclose proactively and prominently in high-risk interactions that collect sensitive data and inform significant personal decisions. SB 332 extended the AI Policy Act's sunset to July 2027. Other states are moving and several AI statutes have had effective dates pushed, so check the current position for every state you call into.

Call recording. Federal law (18 U.S.C. § 2511) is one-party consent, but twelve states require all-party consent: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania, and Washington. Most AI voice agents record and transcribe by default. If you take calls from any of those states — and if you have a toll-free number, you do — your greeting needs a recording notice, and it needs to play before the agent starts capturing audio.

What it actually costs

Vendor pricing is usually a single per-minute figure, which hides where the money goes. Component list prices are public and worth knowing, because they show how much margin and engineering sits inside a quoted rate.

ComponentPublished list price (indicative)What drives it
Inbound telephonyTwilio: $0.0085/min local, $0.0220/min toll-free, plus $1.15–$2.15/month per numberCall volume and duration; toll-free carries a premium
Outbound telephonyTwilio: $0.0140/min local or toll-freeCampaign volume
Speech-to-text (streaming)Deepgram Nova-3: $0.0048/min monolingual, $0.0058/min multilingualMinutes of audio
Text-to-speechDeepgram Aura-2: $0.030 per 1,000 charactersHow much the agent says, not how long the call is
Language model reasoningVaries widely by model and providerConversation turns, context size, tool calls
Integration and buildOne-time engineeringEHR/PMS integration is usually the largest single line
Compliance and assuranceOne-time plus ongoingBAA review, consent mapping, logging, legal sign-off

These prices change often; use them to interrogate a quote, not as a budget. The pattern is consistent: raw inference and telephony are cheap, and the real cost of a US clinical deployment is integration with your practice management system plus the compliance work above. A quote that is almost entirely per-minute usage, with no integration or assurance line, is a quote for a demo rather than a deployment. Our AI automation opportunity scanner helps rank which call types are worth automating first.

A pre-deployment checklist

  • Inventory every call type and label each inbound or outbound, clinical or marketing, PHI-touching or not.
  • Start with inbound — it avoids the TCPA consent question and delivers most of the after-hours value.
  • Obtain a signed BAA covering the vendor and its subprocessors, with the subprocessor list in writing.
  • Confirm in the contract that call audio and transcripts will not be used for model training.
  • Set an explicit retention period for recordings and transcripts; do not accept the platform default.
  • For outbound campaigns, document the consent basis per number and check it against the one-per-day / three-per-week, one-minute, no-billing-content conditions.
  • Strip marketing and billing content out of anything running under the healthcare exemption.
  • Capture opt-outs back to your source of record within one business day, and design for global revocation now.
  • Add an AI disclosure to the opening — and, in California, the closing — of the call, with a clear route to a human.
  • Play a recording notice before capture begins if you take calls from all-party consent states.
  • Define hard escalation triggers: clinical symptoms, emergencies, distress, and any request for a human.
  • Log consent basis, disclosure played, and escalation outcome for every call, so audits are answered from data.
  • Have a healthcare attorney licensed in your states review the call flows before launch.

Frequently asked questions

Does the FCC ruling mean AI voice agents are illegal for medical practices?

No. The February 2024 ruling classifies AI-generated voices as "artificial" voices under the TCPA, which means outbound calls using them require the same consent as any other artificial or prerecorded voice call. It places no restriction on an AI agent answering inbound calls, and the existing healthcare exemptions still apply to outbound treatment-related calls that meet their conditions.

Do we need a BAA if the agent never discusses clinical details?

Almost certainly yes. PHI is not limited to diagnoses. The fact that a named individual is a patient of your practice, is calling about an appointment, or has a scheduled visit is itself protected health information. If the vendor's systems receive or store that, it is a business associate and the conduit exception does not apply.

Can we use an AI voice agent for appointment reminders without written consent?

Potentially, under the wireless healthcare exemption, which requires prior express consent rather than prior express written consent — and a patient who supplied their number during treatment is generally treated as having given it. But the conditions are strict: no more than one message per day and three per week, calls of one minute or less, no marketing or billing content, immediate opt-out, and clear caller identification. Exceed any of those and you lose the exemption for that call.

Must we tell patients they are talking to an AI?

It depends on the state, and the trend is toward yes. California's AB 3030 requires it for generative-AI clinical communications unless a licensed provider reviewed the message first, with verbal disclosure at the start and end of an audio interaction. Utah requires proactive disclosure by licensed professionals in high-risk interactions. Disclosing on every call is simpler than maintaining state-by-state logic, and patients respond better to a clear disclosure than to discovering it mid-call.

What is the safest first deployment for a small practice?

Inbound after-hours and overflow call handling for scheduling, directions, hours, and insurance questions, with immediate escalation on anything clinical. It sidesteps TCPA consent, needs a smaller integration footprint, and shows results quickly through fewer missed calls. Outbound campaigns should follow only once consent records and opt-out handling are verifiably in place.

If you are weighing an AI voice deployment for a US practice or a multi-state provider group, the sequence that works is: map the call types, settle the consent and disclosure position, then choose the vendor — not the other way around. Our US privacy compliance page covers the wider federal and state data protection picture, the United States hub sets out how we work with US clients, and a technology decision sprint is built for exactly this kind of scoped build-or-buy question. The full range of automation work is on our solutions page.

Sources:FCC, "FCC Makes AI-Generated Voices in Robocalls Illegal" (February 8, 2024); HHS, Business Associates guidance; California AB 3030; Future of Privacy Forum, Overview of Utah's 2025 Enacted AI Legislation; Bass, Berry & Sims, TCPA Exemptions for Healthcare Companies; Twilio US voice pricing; Deepgram pricing.

Written by the Stratgik team. Stratgik is a technology strategy and AI automation firm headquartered in Gurugram, India, working with clients in the United States and other markets. We are not a law firm and this article is not legal advice.

Tell us what isn't working.

One process, one system, one decision you are stuck on. We will come back with how we would approach it, what it would take, and whether it needs building at all.

The Stratgik model

Strategy first. Technology that follows through.

Four stages, in order. Most businesses need them one at a time.