Most teams make the clinical case for voice AI in a week. The security review takes two months. That is where most deals die. This is written from the buyer’s side on purpose. If you are a VP of Patient Access who already picked a vendor and now has to push it through IT, security, and legal, the fastest path is knowing what your reviewers will ask before they ask it. If you are the reviewer, the nine checks below separate a defensible approval from a signature you will have to defend later.
Why the bar moved
Two things changed the tenor of healthcare vendor review, and both of them predate the current wave of AI procurement.
The first is enforcement pattern. The Office for Civil Rights collected more than $9.9 million across 22 HIPAA enforcement actions in 2024, with business associate agreement deficiencies contributing to a number of them. Meanwhile business associates were the source of 77% of breached records in 2024. Reviewers have internalized that the vendor is now the likeliest breach vector.
The second is the pending Security Rule overhaul. HHS published a Notice of Proposed Rulemaking in the Federal Register on January 6, 2025 under RIN 0945-AA22, the first proposed update to the Security Rule since 2013. Comments closed in March 2025. As of mid-2026 it remains proposed rather than final, with OMB’s Unified Agenda now targeting July 2027 for final action. Nothing in it is enforceable yet.
What matters commercially is that security teams are already reviewing against it. The proposal would remove the “addressable” designation from encryption, mandate multi-factor authentication on systems accessing ePHI, require annual verification that business associates have deployed required safeguards, and add specific incident reporting timelines. Once finalized, covered entities would get 180 days with an additional window for updating business associate agreements. A contract you sign in 2026 will likely need to survive that transition without renegotiation.
The practical question in a review isn’t whether this vendor is compliant today. It’s whether this contract survives the rule once it lands.
The nine checks
1. An executed BAA, not a BAA “available on request”
The ask: send the actual business associate agreement you will sign, not a summary or a compliance page.
A complete answer: a BAA the vendor executes as a matter of course, with defined permitted uses and disclosures, breach notification obligations, and termination provisions.
Red flag: “We’re HIPAA compliant” as an answer to a question about the BAA. HIPAA compliance is not a certification anyone issues. The BAA is the contractual instrument, and OCR has pursued cases where the agreement was technically present but obligations were never flowed down.
2. Subcontractor flow-down, with the subprocessors named
The ask: list every subprocessor that will create, receive, maintain, or transmit PHI, and confirm each has an executed BAA with the vendor.
A complete answer: a named list, usually including the telephony carrier, the cloud host, the speech recognition provider, and any language model provider, plus a commitment to notify you when a new one is added.
Red flag: vagueness about the model layer. A voice AI vendor that cannot tell you which provider processes call audio has not thought about your compliance position. Under the Omnibus Rule, downstream subcontractors handling PHI are themselves business associates, and 2026 BAA templates are expected to require flow-down explicitly.
3. Encryption, stated as specifications
The ask: what encryption applies to audio in transit, audio at rest, transcripts, and structured data extracted from calls.
A complete answer: TLS 1.2 or above in transit, AES-256 at rest, with key management described.
Red flag: “enterprise-grade encryption.” The proposed rule would make encryption of ePHI mandatory rather than addressable, which means adjectives will not survive the next audit cycle.
4. MFA on every system that touches ePHI
The ask: confirm multi-factor authentication on administrative consoles, support tooling, and any interface where vendor staff can access call content.
A complete answer: MFA enforced with no password-only exceptions, including for vendor-side support access.
Red flag: MFA on the customer portal but not on internal support tooling. That gap is where a significant healthcare breach started, and it is a specific target of the proposed rule.
5. The SOC 2 report, and what kind it is
The ask: the SOC 2 Type II report under NDA, with the audit period and the auditor named.
A complete answer: a Type II report covering a defined observation window, with any exceptions and the vendor’s remediation.
Red flag: three distinct claims get blurred here on purpose across the industry. “SOC 2 Type II certified” means an audit was completed. “SOC 2 Type II in process” means it is underway. “SOC 2 aligned” or “our vendors are SOC 2” means neither. Ask which one, in writing, and ask for the report.
6. Retention, and the minimum necessary standard
The ask: how long are recordings, transcripts, and derived data retained, who decides, and can retention be configured to your policy.
A complete answer: a configurable retention window, an explanation of what is retained beyond the interaction and why, and deletion on request.
Red flag: indefinite retention “for quality purposes.” The minimum necessary standard applies to a business associate, and a reviewer who finds unbounded retention will escalate.
7. Whether your PHI trains anyone’s model
The ask: is call content used to train, fine-tune, or evaluate models, either the vendor’s or a third party’s.
A complete answer: a clear no by default, with any opt-in isolated, contractual, and de-identified to a stated standard.
Red flag: a yes buried in the terms of service, or an answer about the vendor’s own models that says nothing about the upstream model provider’s terms. This is one of the most common gaps in AI vendor review, because the vendor’s answer can be true while their subprocessor’s terms make it moot.
8. Incident response and notification timing
The ask: the notification clock in the BAA, and the runbook behind it.
A complete answer: a defined notification window measured in hours, named contacts, and a tested process. The proposal contemplates specific incident reporting timelines, so a contract that says “without unreasonable delay” is already behind.
Red flag: no tested runbook. Ask when the last tabletop exercise was.
9. Risk analysis documentation and annual verification
The ask: the current risk analysis, penetration test summary, and how the vendor will support your annual verification obligation.
A complete answer: a recent risk analysis, an annual third-party penetration test, and a stated process for producing verification evidence on your cycle. The proposed rule’s annual business associate verification requirement is the most operationally underestimated piece of it: you would document the verification, not keep the BAA on file.
Red flag: a vendor who has never been asked for this.
Three questions generic security reviews miss
Standard SaaS questionnaires were written for software that stores records. Voice AI listens, so three additional questions matter.
Does the system create voice biometric data, and if so, what governs it? Voiceprints can fall under state biometric privacy laws independently of HIPAA. If the platform does speaker verification, that is a separate legal analysis, and your privacy counsel needs to know.
Where does the audio physically go during the call? Real-time speech processing often means audio transits a provider outside your primary cloud region. Ask for the data flow diagram, not the architecture slide. Data residency commitments matter more here than in a records system because the processing is synchronous.
Who on the vendor side can listen to a call, and is it logged? QA and tuning require human review of some interactions. That is legitimate. What matters is whether access is role-limited, logged, and reviewable by you.
How BrainCX answers these
Stated plainly, because procurement teams check.
- BAA: executed as standard practice, not on request.
- Encryption: TLS 1.2 or above in transit, AES-256 at rest.
- HIPAA: BrainCX operates under a signed BAA. BrainCX does not retain PHI beyond what the interaction requires, and where the deployment allows it, data stays in client infrastructure.
- SOC 2 Type II: BrainCX has successfully completed the audit process. Our reports are available for review under NDA. This verification confirms that we meet all industry-standard security controls. You can rest assured that our compliance posture is fully validated.
- TCPA: certified process. GDPR and CCPA: compliant.
- FERPA: planned for higher education deployments.
- Deployment: 30 to 45 days from signed to live, with the security review typically running in parallel rather than after.
The reason the compliance posture is specified before the conversation design, rather than bolted on afterward, is that BrainCX was built by operators who ran contact centers in industries where a mishandled call carries regulatory consequences. The controls and escalation logic that follow from that are described in the platform overview, and the background behind the approach sits on the about page.
Questions procurement teams ask
1. Is there such a thing as a HIPAA-certified voice AI vendor?
No. HHS does not certify vendors and no accredited body issues HIPAA certification. What exists is a signed BAA, documented safeguards, and independent audit evidence such as a SOC 2 Type II report. Any vendor claiming HIPAA certification has told you something useful about their rigor.
2. Do we need a BAA if the AI never hears clinical information?
Almost certainly yes. A patient’s name plus the fact of an appointment with a named provider is PHI. Scheduling calls are squarely in scope, which is why appointment-only deployments still require an executed agreement.
How long should a healthcare security review of a voice AI vendor take?
Two to four weeks when the vendor can produce the BAA, SOC 2 report, subprocessor list, data flow diagram, and penetration test summary on request. It stretches to months when when the vendor has to create any of the five for the first time. Ask for all five in the first meeting and you will know which situation you are in.
What changes if the proposed Security Rule is finalized?
Expect to re-paper business associate agreements within the compliance window, evidence encryption and MFA rather than assert them, and run documented annual verification of your business associates. Contracts written now should already anticipate this, since the compliance clock runs from the final rule’s effective date, not from when you get around to it.
Should the security review run before or after the pilot?
Start it in parallel with the pilot. A pilot that touches real PHI needs the BAA in place first, and running the review concurrently is what turns a four-month cycle into a six-week one.
Want the security package before the first call? Request it from the BrainCX team