HIPAA clarifications

Wanted to clarify 3 things from the docs

  1. Use HIPAA-compliant accounts with all third-party providers (STT, LLM, TTS).
Does this just means we must select the right providers (i.e. Deepgram, OpenAI, Vapi) for our assistant, right? Do you handle BAAs with those orgs? I don't want to go wrangle BAAs & update accounts with all of them.

  1. Tool Calls / Integrations.
How does integrating with other services work with tool calling? We might be interfacing with external providers to accomplish our work over the phone (i.e. we get a patient reference number and pull in specific data for that patient) and need to be able to execute tool calls while on the phone.

  1. End of Call workflows.
Our server is compliant. We need to get end of call reports w/ transcripts to understand what happened, process the data, and share it with our clients. Is that functionality still supported in a HIPAA-enabled instance?
Was this page helpful?