What we commit to
We sign a BAA
You accept our Business Associate Agreement when you create your FrontDesk Talk account, and Settings shows who accepted it and when. Need a countersigned copy? Email us.
We act as your business associate
We use and disclose PHI only to run the service for you, as the BAA and HIPAA allow. You stay in control of your patients’ information.
No sale, no marketing, no AI training
We never sell PHI, never use it for marketing, and never use it to train AI models, ours or anyone else’s.
BAAs with our vendors
We require a business associate agreement from each service provider that handles PHI for us, such as our voice AI, phone, and hosting providers.
Minimum necessary
We limit what we use, share, and ask for to what the service needs. Our staff look at call content only to support you, fix a problem, or protect the service.
Incident reporting
If PHI is used or disclosed in a way the BAA doesn’t allow, or there is a breach, we report it to you as the BAA requires so you can meet your own obligations.
Safeguards in place today
Protective notifications by default
Unless you tell us your callers don’t share health information, texts, emails, and push notifications never include a caller’s name, number, call summary, intake answers, or text message words. They say a call came in and link to the app, where the details are.
Encryption in transit
Every connection to our website, apps, and API uses HTTPS (TLS).
Encryption at rest
Our database and file storage are encrypted at rest by our hosting providers. Calendar tokens and phone account credentials get an extra layer of AES-256-GCM encryption.
Separate phone accounts
Each business gets its own Twilio subaccount, so its numbers, calls, and texts are kept apart from every other business.
Team roles
Owners, managers, and staff see and do different things. Owners can remove a person’s access at any time.
Locked-down staff access
Our admin tools require two-factor authentication, give each staff member only the permissions their role needs, and log what they do.
Private document links
Callers send documents through a private link that expires. Files are type-checked and virus scanned, stored encrypted, and every view and download is logged.
See our Security page for the full list, and the Business Associate Agreement for our exact obligations.
Your part: how to set up FrontDesk Talk for health information
Answer the health information question
After setup, the app asks whether callers will share health information with your receptionist. If they might, answer yes. Don’t answer no to get detailed texts and emails: with yes, Talk Notes and alerts leave out caller details, and you read everything in the app.
Accept the BAA when you sign up
When you create your account, check the box agreeing to the Business Associate Agreement, the Terms of Service, and the Privacy Policy. If we update the BAA, an account owner accepts the new version in the app before your receptionist keeps taking calls with health information.
Keep PHI out of your setup
Your greeting, FAQs, and instructions are for general information like hours and services. Don’t put patient details in them.
Give callers the right notice
Some states require everyone on a call to agree before it is recorded or handled by AI. Add any notice you need to your greeting.
Connect only covered accounts
If you connect a calendar, use an account covered by your own BAA with that provider (for example, Google Workspace or Microsoft 365), not a personal account. Booked events can include a caller’s name and the reason for the visit.
Manage your team
Give each person only the role they need, use strong passwords, and remove people the day they leave.
Use the upload link for documents
Ask callers to send insurance cards, forms, and records through the private upload link, never by text or email.
Keep your records in your record system
FrontDesk Talk is not an electronic health record. Copy anything you need for a patient’s chart into your own system.
Know what the AI won’t do
The receptionist takes health-related messages and intake answers, but it doesn’t give medical advice, diagnose, or triage, and it isn’t a 911 service. Set urgent-call rules so the right person hears about urgent calls.
What FrontDesk Talk isn’t
It’s a receptionist, not a clinical system. It doesn’t connect to electronic health records, keep charts, or give medical advice. If your practice needs EHR connections and clinical tools, FrontDesk Care is built for that.
Visit FrontDesk CareQuestions or a BAA copy
You accept the BAA when you create your account. Email us if you want a countersigned copy, our list of vendors that handle PHI, or answers for your compliance review. To report a security or privacy concern, email us right away.
Email help@frontdesk.talkHIPAA questions
Is FrontDesk Talk HIPAA compliant?
HIPAA compliance is shared. We meet our obligations as your business associate under the BAA and protect health information with HIPAA safeguards. You stay responsible for your own HIPAA program, including how you set up the service. There is no official HIPAA certification, for us or anyone else.
How do I get a BAA?
You accept it when you create your account, by checking the box agreeing to the BAA, the Terms of Service, and the Privacy Policy. That is your electronic signature, and you confirm you are authorized to accept it for your business. We record the version, time, person, business, IP address, and device, and Settings shows it. If the BAA changes, an account owner accepts the new version in the app. For a countersigned copy, email us your business name and account email.
What do Talk Notes look like for a practice?
If your callers may share health information, a Talk Note by text or email says only that a new or urgent call came in and how long it was, with a link. Push notifications say to open the app. The caller’s name, number, and summary are only in the app.
Do your vendors sign BAAs?
We require a business associate agreement from each service provider that handles PHI for us. Customers with a BAA can ask us for the current list.
Where is our data stored?
We host the service in the United States. See our Privacy Policy for the providers that process data for us.
Can the receptionist give medical advice?
No. It can take health-related messages, ask your intake questions, answer questions about your practice, book appointments, and transfer urgent calls. It doesn’t diagnose, triage, or give medical advice, and it tells callers to call 911 in an emergency.
Do you hold SOC 2, HITRUST, or ISO 27001?
Not today. If that changes, we will say so on our Security page. We would rather tell you exactly what we do than show a badge we haven’t earned.
How do we delete our data?
The account owner can delete the account in the app, which erases your calls, contacts, texts, and documents from our database. You can also ask us. The BAA explains how PHI is returned or destroyed when your agreement ends.
Related policies
Stop paying for voicemail.
Setup takes a few minutes. Cancel anytime.