Answer-first · Independent · ANZ healthcare

    Is Retell AI HIPAA compliant?

    Short answer

    It depends on how the platform is configured and operated. Ask the vendor to confirm in writing whether it signs a Business Associate Agreement (BAA), on which plan, and which HIPAA controls it provides. Your organisation still owns workforce training, risk assessment and the BAA chain with downstream sub-processors.

    Below: the HIPAA detail, what you still have to configure, and what changes under Australian and New Zealand privacy law.

    HIPAA detail

    What "HIPAA compliant" actually means for an AI voice platform

    There is no HIPAA certification body. No vendor can be HIPAA-certified — the law doesn't work that way. What vendors can do is offer a Business Associate Agreement (BAA) and the controls required for a covered entity to operate a HIPAA-compliant workflow on top of the platform.

    Ask the vendor to confirm in writing which plan includes a BAA and which HIPAA Security Rule controls it provides, such as access management, audit logging, encryption in transit and at rest, and PHI handling configuration. Whether your deployment is compliant is determined by how you configure and operate it, not by the platform alone.

    The same logic applies to every AI voice platform. Ask each vendor whether it signs a BAA; the covered entity still does the compliance work around the platform. The Compliance pillar of our CAPR framework sets out this work as questions to put to each vendor.

    What you still own

    Six things the platform doesn't do for you

    1. 1

      Workforce HIPAA training and a documented access-control policy — who can see transcripts, who can edit prompts, who can pull recordings.

    2. 2

      Risk assessment of the voice workflow itself. What PHI does the agent collect? What does it write to the PMS? What does it expose to the LLM?

    3. 3

      PHI minimisation in prompts and tool calls. Don't pass fields the agent doesn't need. Mask DOB, MRN, and full address from anything the LLM sees if it doesn't need them to do the task.

    4. 4

      Call recording, transcript retention and deletion policy. HIPAA doesn't set a recording retention period — your covered-entity rules do. Configure Retell's retention to match.

    5. 5

      BAA chain with every downstream sub-processor that touches audio or transcripts — STT, TTS, LLM, transcription, analytics. A gap anywhere in the chain breaks the compliance posture.

    6. 6

      Breach notification process: who is on the rota, how a suspected breach is triaged, and how you meet the HIPAA notification deadline.

    ANZ angle · Privacy Act 1988 · APPs · My Health Records

    HIPAA is US law. Here's what ANZ healthcare actually has to clear.

    HIPAA doesn't apply in Australia or New Zealand. In Australia, look at the Privacy Act 1988, the Australian Privacy Principles (APPs), state health-records laws, the Notifiable Data Breaches scheme and, if relevant, the My Health Records Act. New Zealand has its own privacy law.

    Ask the vendor, in writing, where call data is processed and stored by default. APP 8 covers disclosure to overseas recipients and APP 11 covers security of personal information; read both on the OAIC website and check with your privacy officer. In practice, ask for a signed DPA covering APP obligations, documented data residency for anything at rest, encryption in transit and at rest, a Notifiable Data Breaches process, and a clear retention and deletion policy.

    Ask the vendor for written evidence and have your legal and privacy advisers assess it against your organisation's obligations. A HIPAA statement alone does not establish compliance with Australian requirements.

    FAQ

    Is Retell AI HIPAA compliant?

    It depends on how the platform is configured and operated. Ask the vendor to confirm in writing whether it signs a Business Associate Agreement (BAA), on which plan, and which HIPAA controls it provides. Your organisation still owns workforce training, risk assessment and the BAA chain with downstream sub-processors.

    Does Retell AI sign a BAA?

    Ask Retell to confirm in writing whether it signs a BAA and on which plan. A BAA is a precondition for handling PHI in any HIPAA-covered workflow. Confirm that your specific deployment (including sub-processors like your STT, TTS and LLM providers) is in scope of the BAA before sending any PHI through the platform.

    What do healthcare teams still have to configure themselves?

    Six things, at minimum: (1) workforce HIPAA training and access policy; (2) a documented risk assessment of the voice workflow; (3) PHI minimisation in prompts and tool calls — don't send fields the agent doesn't need; (4) call recording, transcript retention and deletion policy aligned to your covered-entity rules; (5) BAA chain with every downstream sub-processor that touches the audio or transcript; (6) breach notification process. Your organisation operates the controls, whatever the platform provides.

    Is Retell good enough for clinical workflows?

    For non-clinical workflows (booking, rescheduling, intake, billing-aware triage, after-hours capture), test the platform against your own scenario script before relying on it. For anything that crosses into clinical decision-making — symptom assessment, medication advice, triage decisions that aren't keyword-routed to a human — the platform is not the limiting factor; the design of the workflow is. Require that AI voice agents never make clinical decisions and route them to humans who do.

    How does this apply in Australia and New Zealand?

    HIPAA is US law and doesn't apply in ANZ. In Australia the Privacy Act 1988 and the APPs apply, plus state health-records laws and the My Health Records Act where relevant. New Zealand has its own privacy law. Ask the vendor for regional processing, a signed DPA and retention controls in writing before any production rollout.

    What about Australian Privacy Act compliance for Retell?

    ANZ buyers should obtain written evidence covering processing and storage regions, subprocessors, security controls, breach notification, retention and deletion, then seek their own legal and privacy advice.

    Is Retell compliant with My Health Records?

    There is no 'My Health Records certification' for AI voice platforms. If your workflow touches My Health Record, get advice on your obligations under the My Health Records Act. Ask whether the platform touches My Health Record directly or only your practice management system.

    Is there a HIPAA-compliant alternative to Retell?

    Ask each vendor whether it signs a BAA and on which plan. The difference is in the controls, sub-processor chain and operational governance. CAPR's Compliance pillar lists the questions to put to each vendor before it enters a shortlist.

    Are you reselling Retell?

    No. Cadence is a buyer-side advisor and does not resell platforms. How we're paid. You pay the fixed fees in our pricing table. If you select a platform, that vendor may also pay Cadence a success fee, at the same rate whichever platform you choose. Before an engagement starts we tell you which vendors we have fee agreements with. Platform licences are paid to the vendor directly.

    Want this scored against your specific deployment?

    The Diagnostic applies the CAPR Compliance pillar to your call profile, PMS and privacy position. You leave with a written recommendation.