A family calls your agency at 9 PM and, within the first minute, mentions their father's Parkinson's diagnosis, the medications he takes, and the hospital that just discharged him. That call gets recorded, transcribed, and stored somewhere. The question most elder care agency owners never ask until it's too late: where, and under what protections?
An AI receptionist that handles family intake calls for an elder care or home care agency is, in practice, handling protected health information almost every single time it picks up the phone. Diagnoses, medications, mobility limitations, and hospital discharge details come up constantly in these conversations — not because anyone asked for them, but because that's how families describe why they need help.
This guide covers what HIPAA actually requires in this situation, whether your agency is a covered entity in the first place, what separates a compliant AI receptionist vendor from one that just says the word "secure" in its sales deck, and the exact questions to ask before you sign a contract.
None of this is meant to talk agencies out of using an AI receptionist. The opposite is usually true — a properly configured AI system, with a signed BAA and documented data handling, ends up more consistent and more auditable than the mix of shared voicemail, sticky notes, and staff memory it replaces. The goal here is simply to make sure "properly configured" is a fact you've confirmed, not an assumption you're making about a vendor you haven't asked the right questions of yet.
Is Your Elder Care Agency Actually a HIPAA Covered Entity?
This is the question most agency owners get wrong, in both directions. Some assume HIPAA doesn't apply to them because they're a private-pay, non-medical home care business. Others assume every phone call is automatically regulated the same way a hospital's records are. Neither is quite right.
The practical takeaway for almost every agency: treat family intake calls as protected health information by default. It costs little to build that way from the start, and it removes the guesswork of arguing covered-entity status after a data incident has already happened.
Compliant vs. Non-Compliant AI Receptionist: What to Look For
Most AI receptionist vendors will tell you their system is "secure." Security and HIPAA compliance are not the same thing. Here is what actually separates a HIPAA-aligned system from one that just sounds reassuring in a sales call:
| Requirement | Non-Compliant Vendor | HIPAA-Aligned Vendor |
|---|---|---|
| Business associate agreement | Not offered, or buried behind a paid enterprise tier | Signed BAA included before any call data is processed |
| Call recording encryption | Stored in plain text or generic cloud storage | Encrypted in transit and at rest, access-controlled |
| Sub-processor compliance | Underlying voice/SMS/hosting vendors unverified | Every sub-processor touching PHI is also BAA-covered |
| Data retention policy | Indefinite storage with no deletion schedule | Defined retention period matching your policy, with deletion on request |
| Access controls | Any employee can pull any transcript | Role-based access with an audit log of who viewed what |
| Recording disclosure to callers | Recording happens silently, no notice given | Caller is told at the start of the call that it may be recorded |
| Breach notification process | No documented process, discovered case-by-case | Written incident response and notification timeline in the contract |
Most of these items cost a vendor nothing extra to offer if they were built with compliance in mind from the start. The ones that hesitate or charge a premium for basic items like a BAA or an audit log are usually telling you their platform was built for a different market first and retrofitted for healthcare-adjacent use later — worth knowing before your agency's call data becomes the test case.
Where PHI Shows Up in a Routine Family Intake Call
Agency owners are often surprised by how quickly a routine inquiry call turns into a call full of protected health information. A typical intake conversation touches:
None of this is unusual or avoidable — it's exactly the information your intake process needs to match a family with the right level of care. The point isn't to stop collecting it. The point is that whatever system answers the phone needs to be built to protect it the same way a human intake coordinator following your privacy policy would.
This is also where a paper intake form or a shared office voicemail box often fails a compliance review that a properly configured AI system would pass. A voicemail left on a shared line, saved indefinitely with no access log and no encryption, is arguably a bigger liability than a well-built AI receptionist with a signed BAA and a defined retention schedule. Moving to AI intake isn't automatically a compliance risk — it can be the opposite, if the underlying system is built correctly.
Call Recording Consent Laws: The Rule HIPAA Doesn't Cover
HIPAA governs how you protect health information once it's collected. It says nothing about whether you're legally allowed to record the call in the first place — that's a separate layer of state law, and it applies to every agency regardless of covered-entity status. Getting this wrong is a common blind spot for agencies that focus entirely on HIPAA and assume recording consent is already handled.
| Consent Type | What It Requires | Example States |
|---|---|---|
| One-party consent | Only one person on the call needs to know it's being recorded — your agency's knowledge is sufficient | North Carolina, South Carolina, Georgia, Texas |
| Two-party / all-party consent | Every participant on the call must be notified and, in most interpretations, must consent before recording begins | California, Florida, Pennsylvania, Illinois, Washington |
| Multi-state agencies | The strictest applicable law generally governs — a call between a two-party-consent caller and a one-party-consent agency should follow two-party rules | Any agency taking calls across state lines |
The practical fix is simple and should be non-negotiable in your AI receptionist configuration: the very first thing a caller hears is a short, natural disclosure that the call may be recorded for quality and care coordination purposes. It costs nothing to build and removes the ambiguity entirely, regardless of which state a family is calling from or which state your agency operates in.
6 Questions to Ask an AI Receptionist Vendor Before You Sign
Will you sign a business associate agreement before any call data is processed?
This should be a yes-or-no answer delivered in writing, not a conversation that gets deferred to 'legal will follow up.' If a vendor hesitates here, that's the clearest signal you'll get before signing anything.
Where is call audio and transcript data physically stored, and for how long?
Get the specific cloud region and retention period in writing. 'We use enterprise-grade cloud infrastructure' is not an answer — ask for the actual policy document.
Are your own sub-processors — voice, SMS, and hosting providers — BAA-covered?
A vendor can have a clean BAA with your agency while running on infrastructure that isn't compliant underneath it. Ask them to name their sub-processors and confirm each one separately.
Who inside your company can access raw call transcripts, and is that access logged?
Role-based access and audit logging should be standard, not a premium add-on. Ask to see a sample audit log during your evaluation, not just a description of the feature.
Does the AI disclose that calls may be recorded at the start of every interaction?
Most states require this independent of HIPAA. Listen to a live demo call and confirm the disclosure is actually spoken, not assumed to be covered by a privacy policy link nobody reads.
What happens to our data if we cancel the contract?
Get a written data return-or-destruction commitment with a specific timeline. Vendors that go quiet on this question during evaluation tend to go quiet on it after you've left too.
None of these six questions require legal expertise to ask — they require a vendor willing to answer them in writing. Agencies that get vague answers, deflections to a future call, or a generic security page instead of a specific policy document should treat that as the answer itself and keep evaluating other options.
Case Study: Charlotte NC Skilled Home Health Agency, Compliance Review Passed on First Attempt
Client Story
A Medicare-certified skilled home health agency in south Charlotte was already running an AI receptionist for after-hours family intake when a referring hospital system scheduled a routine vendor compliance review as part of renewing the referral agreement. The agency's office manager realized, days before the review, that no one had confirmed whether their AI vendor had signed a BAA or could produce a data handling policy in writing.
Leadra.io audited the existing AI receptionist contract, confirmed the vendor's BAA status and sub-processor coverage, documented the encryption and retention policy in a one-page summary the agency could hand to the hospital's compliance team, and added role-based access controls that hadn't previously been configured on the account.
The hospital's compliance review was completed with no findings against the AI intake system, and the referral agreement renewed on schedule. The agency now includes the one-page data handling summary as a standing document reviewed annually with every referral partner, rather than waiting to be asked.
Compliance findings
BAA coverage confirmed
Referral agreement
Review outcome
Compliance review requests rarely announce themselves far in advance. The agencies that pass them without scrambling are the ones that confirmed their AI vendor's data handling in writing before there was ever a call for it — the same system that handles 24/7 family intake and crisis triage can and should meet this standard from day one.
FAQ: AI Receptionist HIPAA Compliance for Elder Care
Does HIPAA apply to a non-medical elder care or home care agency?
It depends on what your agency bills and who it works with. A private-pay, non-medical home care agency that never bills Medicare or Medicaid and doesn't transmit claims electronically is usually not a HIPAA covered entity on its own. But the moment that agency receives referrals from a hospital, works under a Medicare-certified home health license, or signs a business associate agreement with a healthcare partner, HIPAA-level data handling requirements typically follow — either directly or through contract. Most compliance-minded agencies choose to treat every caller's health information as protected regardless of technical covered-entity status.
What makes an AI receptionist HIPAA compliant for elder care calls?
A HIPAA-aligned AI receptionist signs a business associate agreement (BAA), encrypts call audio and transcripts in transit and at rest, restricts data access with role-based permissions and audit logging, stores data only as long as your retention policy requires, and gives families clear notice when a call is being recorded. It should also run on infrastructure from vendors that themselves sign BAAs — a compliant AI layer on non-compliant infrastructure isn't actually compliant.
Can an AI receptionist record and transcribe calls that mention a client's medical condition?
Yes, but the recording and transcript become protected health information the moment a caller mentions a diagnosis, medication, or care condition, and need to be handled accordingly — encrypted storage, access limited to authorized staff, and a defined retention and deletion schedule. Most states also require one-party or two-party consent for call recording independent of HIPAA, so the AI system should disclose that calls are recorded at the start of every interaction.
What should I ask an AI receptionist vendor before signing, if compliance matters to my agency?
Ask for a signed business associate agreement before any PHI touches their system, ask exactly where call data is stored and for how long, ask whether their underlying voice, SMS, and hosting providers are themselves BAA-covered, ask who at their company can access raw call transcripts, and ask what happens to your data if you cancel. If a vendor can't answer these in writing within a day, treat that as a disqualifying signal.
Related Reading
For Elder Care Agencies
Get an AI Receptionist Your Referral Partners Will Trust
Leadra.io builds AI receptionist systems for elder care and home care agencies with a signed BAA, documented data handling, and full audit logging from day one. Tell us your platform and referral partners — we'll show you exactly what compliance looks like for your setup.