Enterprise-Grade Security for Healthcare Providers
Voxanne AI is designed from the ground up to meet HIPAA (Health Insurance Portability and Accountability Act) requirements, ensuring your patient data is protected with industry-leading security measures.
Last Updated: January 30, 2026
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law enacted in 1996 to protect sensitive patient health information from being disclosed without patient consent or knowledge. HIPAA establishes national standards for the protection of Protected Health Information (PHI).
As a healthcare provider, you are legally required to:
Voxanne AI is committed to full HIPAA compliance. We understand the critical importance of protecting patient health information and have implemented comprehensive security measures across our entire platform. We work exclusively with HIPAA-compliant infrastructure providers and are prepared to sign Business Associate Agreements with all covered entities and healthcare providers.
Enterprise BAA Available
Business Associate Agreements are available for all enterprise customers. Contact our sales team at sales@voxanne.ai to request a BAA.
Protected Health Information (PHI) is any individually identifiable health information that is transmitted or maintained in any form or medium by a covered entity or its business associates. PHI includes:
Voxanne AI processes and stores the following types of PHI on behalf of healthcare providers:
Important: PHI Redaction
Voxanne AI automatically redacts certain types of PHI (such as Social Security numbers, credit card numbers, and explicit diagnoses) from stored transcripts to minimize risk. However, you should configure your AI agent to avoid asking for highly sensitive information unless necessary.
HIPAA requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect PHI. Voxanne AI adheres to all three categories of safeguards:
Administrative safeguards are policies and procedures designed to manage the selection, development, implementation, and maintenance of security measures to protect PHI.
Physical safeguards protect the physical systems, buildings, and equipment where PHI is stored.
Technical safeguards are the technology and policies that protect PHI and control access to it.
Encryption is one of the most critical technical safeguards for protecting PHI. Voxanne AI uses industry-leading encryption standards to protect data both at rest and in transit.
All PHI stored in our database is encrypted using AES-256 encryption, the same encryption standard used by banks and government agencies.
All PHI transmitted over networks (including the internet) is encrypted using TLS 1.3, the latest and most secure version of Transport Layer Security.
Phone calls between patients and our AI voice agent are encrypted from end to end:
Encryption Key Management
Encryption keys are managed using industry best practices: keys are stored in secure hardware security modules (HSMs), rotated every 90 days, and never transmitted in plaintext. Access to encryption keys is restricted to authorized security personnel only.
Access controls ensure that only authorized individuals can access PHI, and only to the extent necessary for their job functions. Voxanne AI implements multiple layers of access control:
Users are assigned roles based on their responsibilities, and each role has specific permissions:
| Role | Permissions | PHI Access |
|---|---|---|
| Practice Administrator | Full access to all features, settings, and patient data | Full access to all PHI |
| Office Manager | View patient data, manage appointments, configure AI agent | Limited to patient contact info and appointments |
| Receptionist | View call logs, listen to recordings, send follow-up messages | Limited to call data and contact info |
| Billing Staff | View patient contact info, export billing reports | No access to call recordings or medical queries |
| Read-Only User | View-only access to analytics and reports | De-identified data only (no PHI) |
All user accounts with access to PHI are required to use multi-factor authentication:
All access to PHI is logged in immutable audit trails:
To prevent unauthorized access, we enforce strict session management policies:
We adhere to the principle of least privilege: users are granted the minimum level of access necessary to perform their job functions. Access rights are reviewed quarterly and adjusted as roles change.
A Business Associate Agreement (BAA) is a written contract required by HIPAA between a covered entity (healthcare provider) and a business associate (service provider like Voxanne AI) that creates, receives, maintains, or transmits PHI on behalf of the covered entity.
The BAA ensures that the business associate:
A BAA is required whenever a business associate will create, receive, maintain, or transmit PHI on behalf of a covered entity. If you are a healthcare provider (doctor, dentist, chiropractor, therapist, etc.) using Voxanne AI to handle patient calls and appointments, you must have a signed BAA with us.
Business Associate Agreements are available for all enterprise customers at no additional charge. To request a BAA:
As a business associate, we are also required to have BAAs with our subcontractors that handle PHI. Voxanne AI has signed BAAs with the following infrastructure providers:
Important: Wallet Funding Requirement
BAAs require an active, funded account. If you are a healthcare provider subject to HIPAA, ensure your wallet is funded before processing PHI. Contact sales@voxanne.ai to discuss BAA execution and compliance requirements.
Under HIPAA, a breach is defined as the unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of the information. Examples include:
If we discover a breach of PHI, we follow a comprehensive incident response plan:
If we notify you of a breach affecting your patients, you are responsible for:
If you suspect a security incident or breach involving Voxanne AI, please contact us immediately:
We take all security incidents seriously and will investigate promptly. Do not attempt to investigate the incident yourself as this may compromise evidence.
HIPAA grants patients specific rights regarding their PHI. As a business associate processing PHI on behalf of healthcare providers, we support these rights:
Patients have the right to access their PHI, including call recordings and transcripts. Upon request from a covered entity, we will provide copies of PHI within 30 days.
Note: Patients should make access requests directly to their healthcare provider, not to Voxanne AI. The covered entity is responsible for fulfilling access requests.
Patients have the right to request amendments to their PHI if they believe it is inaccurate or incomplete. We will make amendments upon instruction from the covered entity.
Patients have the right to receive a list of disclosures of their PHI. Our audit logs capture all disclosures, and we will provide accounting reports upon request from the covered entity.
Patients have the right to request restrictions on how their PHI is used or disclosed. While we are not required to agree to all restrictions, we will accommodate reasonable requests when instructed by the covered entity.
Patients have the right to request that communications containing PHI be sent to alternative locations or by alternative means. This is managed by the covered entity.
Patients have the right to be notified if their unsecured PHI is breached. We will notify covered entities of any breaches, and the covered entity is responsible for notifying affected patients.
Voxanne AI and our infrastructure providers maintain industry-leading security certifications:
Our infrastructure providers (Supabase, Google Cloud) are SOC 2 Type II certified, demonstrating effective controls for security, availability, processing integrity, confidentiality, and privacy.
Voxanne AI is currently undergoing SOC 2 Type II audit (expected completion: Q2 2026).
All infrastructure providers have signed BAAs and maintain HIPAA-compliant infrastructure. Voxanne AI adheres to all HIPAA Security Rule and Privacy Rule requirements.
Annual security assessments conducted to verify ongoing compliance.
For European and UK customers, we comply with GDPR requirements including data subject rights, data retention policies, and international data transfer mechanisms (SCCs).
We conduct annual third-party penetration testing to identify and remediate security vulnerabilities before they can be exploited.
Last penetration test: December 2025. Next scheduled: December 2026.
For questions about HIPAA compliance, security measures, or to request a Business Associate Agreement:
For security incidents, vulnerability reports, and security-related inquiries.
For privacy policy questions, patient rights requests, and data access inquiries.
For BAA requests, enterprise contracts, and compliance documentation.
For general customer support, technical issues, and feature questions.
Voxanne AI
A product of Call Waiting AI Ltd.
Collage House, 2nd Floor
17 King Edward Road
Ruislip, London HA4 7AE
United Kingdom
Join hundreds of healthcare providers using Voxanne AI to automate patient communications while maintaining HIPAA compliance.