Legal · HIPAA Compliance

HIPAA compliance,
handled for you.

Frontis is built with HIPAA compliance as a foundation, not an afterthought. Here is exactly what we do to protect your patients' data.

Every Frontis plan includes a signed BAA, encrypted storage, and HIPAA-compliant infrastructure. You do not need to do anything extra — it is all included.

What HIPAA requires from an AI receptionist

When an AI answers patient calls, it may receive Protected Health Information — patient names, dates of birth, symptoms, insurance details, appointment history. Under HIPAA, any vendor handling this information must:

Frontis satisfies all of these requirements on every plan at no extra cost.


Technical safeguards

RequirementHow Frontis handles it
Access controlUnique credentials per practice, role-based access, automatic session expiry
Audit controlsAll access to PHI logged with timestamp, user, and action type
Integrity controlsRecordings and transcripts checksummed; modifications detectable
Transmission securityTLS 1.3 on all data in transit; no PHI over unencrypted channels
Encryption at restAES-256 on all PHI stored in AWS S3
Backup and recoveryDaily encrypted backups, 30-day retention
Breach notificationAutomated alerting; practice notified within 60 days of confirmed breach

Administrative safeguards


Subprocessors

VendorRoleBAA status
Amazon Web Services (AWS)Cloud infrastructure and encrypted storageSigned
Vapi.aiVoice AI orchestrationSigned (Business plan)
TwilioPhone number provisioning and call routingSigned
ResendTransactional email delivery of call summariesSigned
ElevenLabsVoice synthesis (text only — no PHI processed)N/A

Questions about HIPAA compliance?

We are happy to answer specific questions, provide documentation for your own compliance review, or discuss custom requirements for larger practices or DSOs. Contact us at hello@frontis.ai.

© 2026 Frontis AI, Inc.
HIPAA CompliantBAA Included