PHI boundary review · voice AI stacks

Where PHI actually leaks in a voice AI stack.

Your pilot clears legal and clinical, then stalls six weeks at the security questionnaire. Here is the map of every layer a health system will walk, and the four that usually fail it.

The call path examinecommon finding
1Telephony & transport // which products are covered? recording on?
2Speech-to-text // where processed? retained how long?
3Language model beta APIs // which surface & tier is under BAA?
4Text-to-speech missed // does spoken output contain PHI?
5Observability & logging no BAA // what sits in the trace?
6Storage & retention default on // where does audio live, for how long?
7EHR integration // what scope are you writing back?
7 layers · 1 BAA chain 4 of 7 fail on the first review

One uncovered hop is a breach, no matter how clean the other ten are.

Most teams treat HIPAA as a transcript problem: scrub names from the text and you're clear. You're not. Under the Safe Harbor standard, a voice print is one of the eighteen identifiers, so the raw audio is PHI even before a single word gets transcribed.

And your subcontractors are business associates too. The security questionnaire isn't testing whether you're careful. It's testing whether the chain of agreements is complete: from the covered entity to you, and from you onward to every vendor that touches the data.

That's a finite, answerable list. Seven questions, answered once, and you can fill in any questionnaire in an afternoon instead of letting a deal stall for two months.

Field notes

Teardowns

Plain English breakdowns of where healthcare voice AI stacks break, written from the integration side and not the sales side.

01

Where PHI actually lives in your voice AI stack

The seven layers a health system security review walks, the four places voice AI companies usually fail it, and why the fastest architecture is usually the least covered.

HIPAABAA chainarchitecture
read
02

The Epic go-live checklist nobody hands you

Read scope, write scope, audit logging, and the app-registration decision that quietly breaks your second customer. Coming soon.

EpicFHIR R4scopes
soon
2-minute self-check

Six questions. Any "no" is a finding.

Answer these honestly before a health system does it for you. Three or more gaps and the review will find them first.

Can you list every vendor from first ring to EHR write-back? All of them?
Do you have an executed BAA with each one, covering the specific products and tiers you use?
Do you know the audio retention period at every layer, including the ones you didn't configure?
Is any beta or preview endpoint sitting in your production path?
Does your observability tooling capture prompts containing patient context?
If asked for your subcontractor list tomorrow, could you produce it without a scramble?
Get the full readiness scorecard

// a two-week fix before a pilot. a two-month one after.

Who's behind this

Sanjeev Sharma

I spend my time on one narrow thing: getting voice AI and digital health products cleanly integrated with the systems that health systems actually run on, and keeping PHI on the right side of the boundary while doing it.

Eight years across Epic, Cerner, Athenahealth, NextGen, HL7v2 and FHIR R4, including production HIPAA voice systems.

Not a marketing take on compliance. The integration layer, from someone who has shipped it. If any of the above landed uncomfortably close to home, that's usually the fastest and cheapest conversation you'll have this quarter.

At a glance
focusEHR integration & PHI boundary
who I helpVoice AI & digital health vendors
standardsHL7v2 · FHIR R4
systemsEpic · Cerner · Athena · NextGen
start withA readiness audit