What a HIPAA-compliant AI answering service means
How Samantha protects patient information
Updated September 19, 2026
Patient calls often include names, dates of birth, appointment details, and questions for the care team. Samantha may process that information while scheduling a visit or taking a message, so privacy and security have to be part of the service from the beginning.
Before a practice goes live, we sign a Business Associate Agreement (BAA). Services that handle protected health information are selected and configured for HIPAA-eligible use under appropriate agreements. Staff notifications contain no PHI, and call details remain inside authenticated staff access.
Why a BAA is required
When Samantha handles protected health information on behalf of a HIPAA-covered medical practice, Samantha Medical acts as the practice's business associate. The BAA describes how that information may be used, requires appropriate safeguards, and sets expectations for matters such as incident reporting and subcontractors. We complete that agreement before Samantha handles live patient calls.
This follows HHS guidance on business associates and BAAs.
Where patient information is handled
A voice conversation can pass through several services: telephone connectivity, speech recognition, the language model that manages the conversation, and speech synthesis for Samantha's reply. Services that create, receive, maintain, or transmit PHI for Samantha are configured for HIPAA-eligible use and covered by the appropriate agreements.
Call records stay behind a login. Recordings, transcripts, messages, and appointment activity are available to authorized practice staff in Samantha Hub.
Staff alerts do not include PHI. A notification says that a message or booking is waiting, without including a patient name, clinical detail, or message content.
Operational logs are kept separate from call content. Diagnostic logs are designed not to reproduce caller speech or full telephone numbers.
How Samantha handles a patient call
Caller ID can help Samantha recognize a returning caller, but it is not treated as proof of identity. Before Samantha shares or changes an existing appointment, the caller must confirm their full name and date of birth. New callers can provide the information needed to register and schedule a visit.
Samantha schedules appointments and relays messages. She does not diagnose, interpret symptoms or test results, recommend treatment, or make clinical and billing decisions. Clinical questions are recorded for the practice to review. When a caller describes an emergency, Samantha directs the caller to hang up and dial 911 and can follow the practice's configured on-call workflow.
Access, logging, and retention
Access to Samantha Hub requires authentication, and activity is logged so the practice can review who accessed patient information. The practice chooses how long call recordings, transcripts, and messages are retained based on its operational, contractual, and legal requirements. Startup checks also prevent Samantha from running when required PHI-safe services or settings are missing.
What your practice still controls
A BAA and a securely configured service are only part of a practice's HIPAA program. Your practice remains responsible for its own risk analysis, policies, staff training, user access, retention choices, and clinical escalation procedures. You also decide which calendars or patient systems Samantha may access and what she is permitted to do in them.
HHS describes risk analysis as an ongoing responsibility for covered entities and business associates. Its risk-analysis guidance is a useful starting point for a practice reviewing a new service.
Questions to ask any AI answering service
These questions help a practice understand how an AI answering service handles patient information. Here is how Samantha approaches each one.
| What to ask | Samantha's approach |
|---|---|
| Will you sign a BAA before we go live? | Yes. We sign a Business Associate Agreement before Samantha handles live patient calls. |
| Which services process audio, transcripts, and model requests? | We review the complete data flow and configure services that handle PHI for HIPAA-eligible use under appropriate agreements. |
| What information appears in staff notifications? | Notifications contain no patient names, clinical details, or message content. Staff sign in to Samantha Hub to review the call. |
| How is a caller's identity verified? | Caller ID may help recognize a returning caller, but the caller must confirm their full name and date of birth before existing appointment information is shared or changed. |
| How long are recordings, transcripts, and messages retained? | The practice chooses a retention period based on its operational, contractual, and legal requirements. |
| What happens if a required security setting is missing? | Startup checks prevent Samantha from running when required PHI-safe services or settings are not present. |
Review the controls with us
We can walk your security or compliance lead through Samantha's data flow, the BAA, the services that process PHI, the contents of staff notifications, caller verification, access logging, and retention. We will also answer a security questionnaire if your organization uses one.
Prefer email? Write to info@samantha-medical.com to request the BAA or send a security questionnaire.
This page describes Samantha's product controls and is not legal advice.
Samantha Medical is operated by Sidekick Labs LLC, the legal entity that enters into the Business Associate Agreement.