An AI receptionist privacy checklist for clinics should follow the complete data path: phone carrier, voice platform, model provider, automation layer, calendar, CRM, messaging service, recordings, analytics and human users.
Do not treat a vendor’s “secure” or “compliant” badge as a substitute for reviewing the actual configuration, contracts and workflow.
1. Map the data
List every type of information the receptionist can create or receive:
- phone number and caller identity;
- reason for calling and treatment interest;
- appointment details;
- call audio, transcript and summary;
- form answers and campaign source;
- clinical or sensitive statements;
- transfer destination and staff notes;
- consent, opt-out and communication history.
Then document where each item is transmitted, stored and deleted.
2. Identify every vendor and subprocessor
Create a vendor chain that includes telephony, speech recognition, text-to-speech, language model, hosting, database, automation, messaging, calendar, CRM, monitoring and support access.
For each party, record:
- role and data received;
- storage location;
- retention and deletion controls;
- encryption and access controls;
- incident-notification terms;
- contractual role;
- subprocessor list;
- whether data is used to train shared models;
- export and termination process.
HHS states that a cloud provider that creates, receives, maintains or transmits ePHI on behalf of a covered entity may be a business associate even if it cannot view encrypted data. Read the official HHS cloud-computing guidance.
3. Minimize what the AI collects
Ask only for information needed to complete the approved next step. A receptionist that books a consultation may not need a detailed medical history. Move clinical intake into a controlled process owned by qualified staff.
For every field, ask:
- Why is it needed?
- Who uses it?
- How long is it retained?
- What happens if it is wrong?
- Can the workflow function without it?
4. Control recording and transcription
Determine where consent is required for call recording or transcription. Make disclosure language clear and jurisdiction appropriate. Provide an alternate route if the caller does not consent when necessary.
Decide whether you need full audio, full transcripts, summaries only or no retained conversation content. Shorter retention reduces exposure but must still support operational and legal needs.
5. Limit access
Use named user accounts, least-privilege roles and multi-factor authentication where supported. Separate access for administrators, quality reviewers, front desk, clinical team and external support.
Review access after role changes and remove dormant accounts. Log exports, deletions and administrative changes when the system supports it.
6. Define safe content boundaries
The AI should not reveal information about another patient, diagnose, prescribe, guarantee results or improvise private details. Add explicit rules for identity verification, restricted questions, complaints, emergencies and legal requests.
Test attempts to bypass those rules. NIST’s AI Risk Management Framework provides a useful structure for governing, mapping, measuring and managing AI risk.
7. Prepare incident response
Write down:
- who receives a security or privacy alert;
- how the clinic disables the AI or reroutes calls;
- how evidence and logs are preserved;
- how affected vendors are contacted;
- how legal notification decisions are made;
- who communicates with patients or clients;
- how the workflow is corrected before restart.
A contact list that exists only inside the affected system is not a usable incident plan.
8. Review outputs and corrections
Create a process for correcting appointment errors, inaccurate summaries and knowledge mistakes. Track repeat patterns and assign each issue an owner and deadline.
During launch, review every restricted-topic call and a representative sample of routine calls. Reduce review frequency only after accuracy is stable.
9. Verify contracts and local law
US covered entities may need appropriate business associate agreements and safeguards. EU and UK operations may have additional controller, processor, lawful-basis, transparency, data-minimization and international-transfer obligations. Recording, telemarketing and medical-advertising rules also vary.
This checklist is operational guidance, not legal advice. Use the HHS HIPAA resources, ADA HIPAA resources and qualified privacy counsel for the clinic’s actual jurisdictions.
For the broader build sequence, read how to create an AI receptionist for a clinic or enquire about an implementation review.