Compliance for regulated calls
HIPAA is a surface problem, not a feature toggle
Most voice AI stitches five vendors and prays each has a BAA. VoiceForge reduces that to one Azure BAA surface — in-house STT → LLM → TTS — with workspace isolation, encryption and audit logs on every call.
The five-vendor BAA trap
Telephony + STT + LLM + TTS + storage = five BAAs to collect. Miss one and you have no HIPAA coverage where PHI flows. Enterprise buyers ask for this on day one; agencies learn it after a clinic asks.
One pipeline, one BAA surface
VoiceForge’s in-house pipeline runs entirely on Azure (Speech + Azure OpenAI + Speech) under one BAA. OpenAI Realtime is the alternate pipeline for non-HIPAA workloads. Agent spec stays identical; pipeline choice is operational.
Minimum necessary and isolation
PHI is workspace-scoped by default: agent knowledge, calls, transcripts and tool results never bleed between workspaces. Access is per-workspace, per-role, with audit logs on every tool write and transfer.
Encryption, retention and audit
Encryption at rest/in transit, configurable retention, no training on customer data and a full per-call audit trail (transcript, events, tool activity, outcome). Hand the auditor the call ID, not a story.
Your one-page HIPAA checklist
BAA signed, encryption verified, access controls set, minimum necessary enforced, retention set, disclosure recorded. Download the checklist and attach it to the clinic’s security review.
Frequently asked questions
- Is VoiceForge HIPAA compliant?
- VoiceForge is built for HIPAA-eligible workloads: the in-house pipeline runs on Azure with BAA coverage (Speech STT, Azure OpenAI, Speech TTS) as one surface, data is workspace-isolated with encryption at rest/in transit, and every call is audit-logged. Customers should still sign a BAA and apply the checklist below — we provide a BAA and the technical controls, you control access and PHI handling.
- What do most voice AI platforms get wrong about HIPAA?
- They stitch 5 vendors (telephony + STT + LLM + TTS + storage) and collect BAAs piecemeal — one missing BAA breaks coverage. The in-house Azure pipeline reduces that to a single BAA surface; the spec-first isolation keeps PHI scoped per workspace.
- What does the HIPAA checklist include?
- BAA in place, encryption everywhere, access controls per workspace, minimum necessary PHI, no training on customer data, retention controls, audit logs per call, and disclosure where required. The guide links a one-page checklist.