A HIPAA AI voice agent is a chain of five contracted layers — platform, LLM, speech-to-text, text-to-speech and telephony — but the number of business associate agreements you personally sign is not five. It is however many of those layers you contract directly. Across thirteen vendors read on their own pages on 18 September 2026, that count ranged from one to five.
General information about published regulations and vendor terms, not legal advice, and about United States HIPAA only — Australian practices have a different regime entirely, covered in AI receptionist privacy for Australian dental and medical practices.
What HIPAA actually requires you to sign, and from whom
Two sentences decide the whole question and almost no vendor comparison quotes them. 45 CFR 164.308(b)(1) requires a covered entity to obtain satisfactory assurances before letting a business associate handle ePHI, then adds: “A covered entity is not required to obtain such satisfactory assurances from a business associate that is a subcontractor.” Paragraph (b)(2) puts that duty on the business associate instead, and the Privacy Rule mirrors both at 164.502(e)(1).
So the chain is a tree, not a list, and your position in it is set by who signs the purchase order, not by who touches the audio. 45 CFR 160.103 defines a subcontractor as “a person to whom a business associate delegates a function, activity, or service, other than in the capacity of a member of the workforce of such business associate” and pulls it inside the business associate definition in its own right, and 164.504(e)(2)(ii)(D) makes the flow-down compulsory.
That is the correction this page exists to make. The widely repeated framing — that the buyer must source and maintain an agreement at every link independently — holds only where the buyer contracts every link independently. Where the platform picks and contracts the model and speech providers, they are its subcontractors and the flow-down is its obligation. Both topologies are sold side by side.
The five layers, and who is holding PHI at each one
We have already walked this same call for geography in data residency for AI voice agents, hop by hop, which names eight hops and quotes each supplier on storage versus processing. This page walks the identical call for signatures — a different axis, because a hop can be perfectly in-region and contractually uncovered. Vendors also straddle layers: Deepgram supplies transcription and synthesis, ElevenLabs supplies synthesis and a full agents platform, so one agreement can cover two links. A bare count of five misleads in both directions.
The BAA matrix: what each vendor publishes on its own page
Every row was read on the vendor’s own documentation, trust or legal page on 18 September 2026. No cell comes from a comparison blog, an aggregator or a rival’s claim about a competitor, because the secondary sources contradict each other on precisely the tier question. Where a vendor does not publish the answer, the cell says so and the next section says where we looked.
| Layer | Vendor page read 18 Sep 2026 | Signs a BAA, in its own words | The gate |
|---|---|---|---|
| Platform | Vapi | Yes. The dashboard emails a BAA for signature | “a paid compliance add-on with Usage only or any Success Package”. Organisation-wide, no per-assistant exception, not enableable through the API |
| Platform | Retell AI | Yes. “available for self-signing at click-agreements.retellai.com” | No tier stated. “There is no additional fee to sign these agreements” |
| Platform | LiveKit | Yes. “HIPAA BAAs available for Scale and Enterprise customers” | Plan tier: Scale or Enterprise |
| Platform, TTS | ElevenLabs | Yes, for ElevenLabs Agents as a HIPAA-eligible service | “only available for Enterprise tier subscriptions”, and Zero Retention Mode must be engaged |
| LLM | OpenAI | Yes, via the Healthcare Addendum and BAA, v.111124 | Eligible Services are the Zero Retention API and ChatGPT Enterprise, plus any service OpenAI later identifies in writing; access through an Approved Org ID, to a Zero-Retention-eligible endpoint |
| LLM | Anthropic | Yes, covering “our first-party API or Enterprise plans” | An organisation Primary Owner accepts it in settings. “the BAA only covers the single organization that accepted it” |
| LLM, STT, TTS | Google Cloud | Customers “must review and accept Google’s Business Associate Agreement” | Covered-products list only; “The BAA is not subject to modification”; and no Pre-GA offerings with PHI |
| LLM, STT, TTS | Microsoft Azure | Offers “a HIPAA BAA as part of the Microsoft Product Terms … to all customers who are covered entities or business associates” | No separate signature or tier stated; in-scope services only |
| STT, TTS | Deepgram | “We can provide our Business Associate Agreement to such customers upon request” | Contact-gated. No tier or fee stated on that page |
| STT | AssemblyAI | Yes. AssemblyAI “is considered a business associate under HIPAA, and we offer a standard Business Associate Addendum (BAA)” | Paid plan only. Reviewed and signed self-serve on the dashboard Data Controls page by an Owner or Admin, “at no additional cost”; signing permanently opts the account out of model improvement |
| TTS | Cartesia | States compliance, not signature: “Cartesia is GDPR, SOC 2 Type II, PCI-DSS service provider, and HIPAA compliant” | No BAA terms published on any Cartesia page we could read; the docs route detail to a trust centre that returns no readable text. Ask them directly |
| Telephony | Twilio | Yes, as an addendum to the Terms of Service | “HIPAA Accounts require Twilio Security Edition or Enterprise Edition”, through an account manager |
| Telephony | Telnyx | No, by design. “In general, Telnyx’s services fall within this conduit exception under HIPAA, and therefore there is no need for Telnyx to sign a BAA” | The conduit exception, not a tier (article dated 29 January 2026) |
The Telnyx row is a legitimate published position, not a gap. HHS described that exception in the 2013 Omnibus Rule preamble as covering entities “that act as mere conduits for the transport of protected health information but do not access the information other than on a random or infrequent basis” (78 FR 5566, at 5571). The operative test is access, not transport, so switching on recording, transcription or storage at that carrier changes the facts the argument rests on.
The two cells that nearly stayed blank, and the route that filled them
AssemblyAI. Its public security page names SOC 2 Type 2, TLS 1.2 or better in transit, AES-256 at rest, annual third-party penetration testing and an opt-out from model training, and contains no occurrence of HIPAA, PHI or “business associate” as at 18 September 2026. Its subprocessor link and its trust centre are the same Vanta-hosted application, which returns a title and no readable body text. The answer is published, just not there: the documentation FAQ carries the question verbatim in the AssemblyAI BAA FAQ entry, and its Data Controls page supplies the gate. A security page is not a vendor doc set, and the marketing-facing security page is the least likely place in it to find contract terms.
Cartesia. Four direct routes failed on 18 September 2026: docs.cartesia.ai/resources/security returned HTTP 429, cartesia.ai/security returned 404, trust.cartesia.ai returns a title and no body text, and the privacy policy contains no occurrence of HIPAA or “business associate”. The documentation index at docs.cartesia.ai/llms.txt lists no security or compliance page at all, and the only statement we found anywhere is one line inside the enterprise Zero Data Retention page. That line is a compliance claim, not BAA terms, and the two are not the same thing: of the thirteen vendors here, Cartesia is the only one whose signature conditions we could not find published. Unread is not absent. Ask them directly.
The rule we now apply to a blank cell: when a vendor page does not answer a contract question, try the documentation FAQ, the docs index and the plain-text or markdown form of the docs before concluding anything. A filled cell you cannot trace is worth less than an empty one you can, and an empty cell you did not chase hard enough is worth less than either.
What “zero retention” actually means, per provider
This is the finding that changes how you configure a stack, which is why we named it. The Retention Coupling Rule: before enabling zero retention anywhere in the chain, check whether the BAA at that layer requires it, forbids it, or is voided by it. All three exist, and two of them exist inside one vendor.
| Vendor | Relationship between zero retention and the BAA | The vendor’s own words |
|---|---|---|
| OpenAI | Zero retention is required | Eligible Services are defined as “(a) OpenAI’s Zero Retention API, (b) ChatGPT Enterprise”; API use “not to an endpoint eligible for Zero Retention” is excluded |
| ElevenLabs | Zero retention is required, and dropping it removes cover | Forgoing Zero Retention Mode means “such agent is no longer deemed a covered service for purposes of the BAA”. ZRM also “applies to API use only” — web UI and playground traffic is not covered |
| Anthropic | Both directions, in one vendor | “Covered Models require 30-day data retention and aren’t available with zero data retention (ZDR) enabled”, while “Some services, like Claude Code, are only covered under the BAA when ZDR is enabled” |
| Vapi | Mutually exclusive | “HIPAA mode and Zero Data Retention (ZDR) are mutually exclusive. Disable one before enabling the other.” |
A buyer applying “always turn on zero retention” as a rule of thumb will, on this evidence, satisfy OpenAI, satisfy ElevenLabs, disqualify their choice of Anthropic model and silently break HIPAA mode at Vapi. The rule of thumb is the defect.
Three ways to contract the chain, and who each one is wrong for
The decision is not which vendor is “HIPAA compliant” but which of three contracting topologies you are buying. Google puts the underlying point plainly on its own HIPAA compliance page: “there is no certification recognized by the US HHS for HIPAA compliance”. Nobody holds a HIPAA certificate, so a badge is never the criterion. Signature topology is.
| Topology | BAAs you sign | Who flows down | Wrong for |
|---|---|---|---|
| 1. Single-vendor managed stack. The platform picks the model and speech providers from its own allow-list (Vapi HIPAA mode, ElevenLabs Agents with ZRM) | One | The platform, under 164.502(e)(1)(ii) | Anyone needing a specific model: Vapi rejects configuration changes selecting a non-compliant provider while HIPAA mode is on, and ElevenLabs restricts you to LLM providers it already holds a BAA with. Also wrong if you need transcripts and call logs for QA, which these modes suppress |
| 2. Bring-your-own-keys composition. The platform orchestrates, you contract the model or speech vendor directly | Two to five | Nobody automatically; each link is yours | Small teams with no contracts function. It also does less than expected: Vapi states that even with your own compliant provider keys “it remains your responsibility not to store PHI via Vapi’s endpoints”, so the key does not cover the platform hop |
| 3. Hyperscaler-native. Model, STT and TTS from one cloud under one agreement (Azure, Google Cloud) | One, plus telephony | The cloud provider, in-scope services only | Anyone whose preferred voice or model is off the covered-products list, or whose feature is Pre-GA, which Google instructs customers not to use with PHI unless it expressly notes otherwise. Also wrong if you need bespoke terms: “The BAA is not subject to modification” |
Six questions that expose a broken chain
Each is derived from something a vendor in the matrix publishes about itself, so each is answerable rather than rhetorical. Our voice-AI vendor security questionnaire covers the twelve general security questions; these six are the HIPAA additions.
- Does your BAA require zero retention, forbid it, or void without it? All three answers exist in the table above.
- Which features inside the covered service are excluded? Anthropic marks connectors and organisation search as usable but not covered for sending data to third parties; OpenAI excludes Third Party Services entirely.
- If I bring my own model key, whose BAA covers that hop? ElevenLabs says you must arrange to sign directly with that LLM provider.
- Are you a business associate at all, or claiming the conduit exception? Ask the telephony layer in those words, then ask what recording changes.
- Does the agreement cover the web console as well as the API? ElevenLabs states Zero Retention Mode applies to API use only.
- Which organisation or account does the signature bind? Anthropic binds the single organisation that accepted it; Vapi binds every assistant in the organisation, with no exception.
What running this yourself actually costs
The method above is complete and you can execute it without us. The economics: topology 2 means two to five separate legal reviews with their own redlines, plus a standing obligation, because 164.504(e)(1)(ii) makes a covered entity non-compliant if it knew of a pattern of breach by a business associate and did not cure or terminate. That is an annual re-read of every agreement in the chain, plus a configuration audit, because an allow-list that changes, a workspace spun up outside the bound organisation or a feature promoted out of preview can each move a hop outside cover with nobody signing anything. Topology 1 collapses that to one relationship, at the price of the vendor allow-list and usually your call logs. Which trade is right depends on whether your binding constraint is legal capacity or model choice, and most teams find out three weeks into a US launch — the stage our US AI voice agent go-live timeline covers, with the broader control set in our compliance architecture for AI sales agents in regulated industries.
Where Zian sits, plainly: Zian AI is an autonomous sales agent platform running live phone, SMS, email and WhatsApp outreach across 30+ languages, with SmartReach AI™ orchestrating channel and timing and PrecisionPitch AI™ split-testing scripts. Zian is in partnership-application beta and holds no HIPAA certification, attestation or independent audit, and this page is not an offer to enter a business associate agreement. One structural point: private model deployment on customer infrastructure changes the subcontractor question rather than answering it. A model running on your own infrastructure is not a disclosure to a third party at that hop, which removes a link — and leaves every other link exactly where it was.
Frequently asked questions
How many business associate agreements does a HIPAA AI voice agent need?
Between one and five, depending on who signs the purchase orders. If the platform selects and contracts the model and speech providers, they are its subcontractors and 45 CFR 164.308(b)(1) states that a covered entity is not required to obtain satisfactory assurances from a business associate that is a subcontractor. If you contract each layer directly, each one is yours.
Does turning on zero retention make a voice agent HIPAA compliant?
No, and it can do the opposite. OpenAI defines its Eligible Services for PHI as the Zero Retention API and ChatGPT Enterprise, so zero retention is mandatory there. Vapi documents that HIPAA mode and Zero Data Retention are mutually exclusive, so enabling one disables the other. Check the coupling at every layer before setting it anywhere.
Which AI voice vendors publish BAA terms without a sales call?
As at 18 September 2026, Retell AI documents self-signing of its BAA with no additional fee, and Anthropic documents in-product acceptance by an organisation Primary Owner. AssemblyAI documents self-serve signing from its dashboard on a paid plan at no additional cost. Vapi sells HIPAA as a paid compliance add-on with a BAA emailed from the dashboard. Twilio, Google Cloud and ElevenLabs route the agreement through an account manager or an enterprise tier.
Why do some telephony providers refuse to sign a BAA?
Because they rely on the HIPAA conduit exception. Telnyx states that its services generally fall within that exception and that there is therefore no need for it to sign. HHS described the exception in the 2013 Omnibus Rule preamble as covering entities that transport protected health information but do not access it other than on a random or infrequent basis. Recording or storing calls changes that analysis.
Is there such a thing as a HIPAA certified voice AI platform?
No. Google states on its own compliance page that HHS does not recognise any certification for HIPAA compliance. Vendors can be HIPAA eligible, meaning they will sign a BAA and the service is in scope for it, and they can hold SOC 2 or ISO certifications. A HIPAA certificate is not a thing that exists.
Next step
Take the matrix into your next vendor call and ask for the columns by name: whether they sign, what gates it, which features are excluded, and how zero retention interacts with the agreement. A supplier who cannot answer those in writing has given you your answer. To run the same questions against Zian, Apply For Partnership.