A HIPAA compliant chatbot is one that a covered entity or business associate can use with protected health information (PHI) because the vendor has signed a Business Associate Agreement (BAA) and the product, as you configure it, supports the safeguards the HIPAA Security Rule requires. There is no official "HIPAA certified" chatbot. Compliance comes from the contract, the controls, and how you set it up.
This guide gives you a buyer's checklist you can take into vendor calls, a shortlist of healthcare chatbot and patient engagement vendors that publicly state they sign a BAA, and a clear line on when a general-purpose chatbot is fine and when it is not.
A quick note before we start. This article is general information, not legal or compliance advice. Your privacy officer or healthcare counsel should make the final call on any tool that touches patient data.
Quick picks
These vendors publicly state, on their own sites, that they support HIPAA use or sign a BAA. Details, pricing, and limitations follow below.
- Hyro: best for health systems that want AI agents across phone, web chat, and SMS with deep EHR integration.
- Luma Health: best for practices and health systems that want AI-assisted patient access tied to scheduling and reminders.
- Artera: best for organizations that want text-first patient communications with AI agents layered on.
- Microsoft Copilot Studio with the healthcare agent service: best for IT-led teams already on Microsoft that want to build their own agent.
- Intercom (Fin): best for digital health companies that want a general support platform with a BAA on its top plan.
- Zendesk: best for organizations already on Zendesk that can add Advanced Compliance.
- Kommunicate: best for smaller teams that want a lighter AI chatbot and are willing to confirm BAA scope during procurement.
What makes a chatbot HIPAA compliant?
Two facts from the U.S. Department of Health and Human Services (HHS) frame everything else.
First, there is no HIPAA certification. In an FAQ on the Security Rule, HHS states that it "does not endorse or otherwise recognize private organizations' 'certifications'," and that such certifications do not absolve covered entities of their obligations. When a vendor says "HIPAA certified," treat it as marketing, and ask what they actually sign and what controls they operate.
Second, a vendor that handles PHI for you is a business associate and needs a BAA. HHS's guidance on HIPAA and cloud computing says a cloud service provider that creates, receives, maintains, or transmits electronic PHI on your behalf is a business associate, and that this is true even if it stores only encrypted data and lacks the key. A chatbot vendor that sees patient messages falls squarely into this.
So a "HIPAA compliant chatbot" really means three things together: a signed BAA that covers the specific product and channels you use, technical safeguards that meet the Security Rule, and a configuration and workflow on your side that keeps PHI where it is supposed to be.
Why the vendor side matters so much: in the HHS Office for Civil Rights (OCR) annual report to Congress on 2024 breaches, OCR received 663 reports of breaches affecting 500 or more people that occurred in 2024. Business associates filed only 16% of those reports, but those breaches affected about 206.9 million individuals, 85% of everyone affected. Your vendors are part of your attack surface.
Does your chatbot need to be HIPAA compliant at all?
Not every healthcare chatbot handles PHI. HIPAA applies to covered entities (health plans, clearinghouses, and providers who conduct standard electronic transactions) and their business associates. PHI is individually identifiable health information held or transmitted by those entities.
A chatbot on a clinic website that answers "What are your hours?" or "Do you take Aetna?" without asking who the visitor is generally is not processing PHI. A chatbot that verifies a patient's identity, looks up their appointment, or asks why they are coming in almost certainly is.
The grey zone is wider than most teams assume. Many compliance teams treat a name plus the fact that someone is seeking care from a specific provider as PHI. Website tracking has also been an active area: HHS OCR issued a bulletin on online tracking technologies, and in June 2024 a federal court in American Hospital Association v. Becerra vacated part of that guidance as it applied to certain unauthenticated web pages. HHS later withdrew its appeal. The practical lesson is to map exactly what data your chatbot collects and where it goes, and to get a compliance review before launch rather than after.
The HIPAA chatbot buyer's checklist
Use these ten questions in every vendor evaluation. A vendor that cannot answer them clearly in writing is not ready for PHI.
1. Will you sign a BAA, and what exactly does it cover?
Ask for the BAA itself, not a summary. Check which products, features, and channels are covered. BAA scope is often narrower than the product. Zendesk, for example, lists specific plans and add-ons covered by its Healthcare Agreement, and excludes early access programs and certain marketplace apps.
2. Is the BAA tied to a plan or add-on?
Many vendors only sign on a top tier or with a paid add-on. Intercom's help center states a BAA requires its Expert plan. Zendesk requires its Advanced Compliance add-on or a plan that includes it. Price the plan you will actually need, not the entry tier.
3. How is data encrypted in transit and at rest?
Look for TLS on every connection, encryption at rest for transcripts and attachments, and clear key management. Ask whether chat transcripts, uploaded files, and analytics exports are all covered.
4. What access controls exist?
You want role-based permissions, single sign-on, enforced multi-factor authentication, and the ability to limit which staff see which conversations. Zendesk's published security requirements for healthcare-enabled accounts, for instance, require two-factor authentication or SSO for agent access.
5. Are there audit logs?
The Security Rule's technical safeguards include audit controls. Confirm the product logs who accessed or changed conversations, configuration, and exports, and that you can retrieve those logs.
6. Can you control retention and deletion?
Ask how long transcripts are kept, whether you can set retention periods, and how deletion works. Zendesk's healthcare configuration notes, for example, state that AI agent conversations not handed to a human are still stored, and that it is the customer's responsibility to delete them. Details like this matter.
7. Which AI model provider processes the messages, and under what terms?
This is the question most buyers miss. If the chatbot sends patient messages to a large language model, that model provider is a downstream subcontractor. OpenAI's help center says API use with PHI requires a BAA, and its healthcare addendum limits eligible services to specific configurations. Anthropic's privacy center says its BAA covers specific HIPAA-ready services and excludes some features. Ask your vendor which model providers they use, and confirm the vendor's own BAA flows down to them.
8. How does the product minimize PHI?
HIPAA's minimum necessary standard applies to most uses and disclosures. Good tools let you avoid collecting what you do not need, redact or mask sensitive fields, and keep clinical details out of free-text fields where possible.
9. Which channels are covered?
Web chat inside a covered product is one thing. SMS, WhatsApp, and standard email are another. Some platforms support these channels but note that they are not covered or not secure by default. Confirm channel by channel.
10. What happens when the bot should not answer?
A healthcare chatbot needs firm guardrails against giving medical advice, a clear path to a human, and an emergency message for urgent symptoms. Zendesk's healthcare terms, for example, state its AI features should not be used to provide medical advice or diagnosis. For more on designing escalation well, see our guide on when AI should hand off to a human.
How we chose
We included vendors that publicly state HIPAA support or BAA availability on their own websites, and we linked or described that statement rather than relying on third-party review sites. We favored tools with a real conversational product (chat, SMS, or voice) rather than general compliance software. We did not test each product with PHI, and a public statement is not a guarantee of fit for your use case. Pricing is as of September 2026 and changes often.
Healthcare chatbot and patient engagement vendors
Hyro
- Best for: health systems that want AI agents across the call center, website, and SMS.
- Key features: provider and location search, appointment scheduling and rescheduling, prescription refill requests, password resets, and call-to-text deflection. Hyro describes integrations with EHRs including Epic.
- HIPAA stance: Hyro's healthcare pages describe its platform as HIPAA-compliant conversational AI and state that it redacts PII and PHI in conversations.
- Pricing: not published. Contact sales.
- Limitations: built for larger health systems, so expect an enterprise sales process and an integration project rather than a same-day setup.
Luma Health
- Best for: practices and health systems focused on patient access, scheduling, and reminders.
- Key features: Navigator, an AI concierge that handles routine patient requests over phone and SMS, switches languages, and hands over to staff. It runs on Luma's broader patient success platform.
- HIPAA stance: Luma's product materials describe HIPAA-compliant patient verification and PHI protection, and state the company is ISO 27001:2022 certified, HITRUST CSF r2 certified, and SOC 2 Type II attested.
- Pricing: not published. Contact sales.
- Limitations: Navigator is phone and SMS centric. If your priority is a website chat widget, confirm what web chat options exist.
Artera
- Best for: organizations that want text-first patient communication with AI agents added over time.
- Key features: two-way patient messaging, self-scheduling and waitlists, digital intake and payments, AI voice and text agents, and EHR integration via API, FHIR, and HL7v2.
- HIPAA stance: Artera's site states its AI agent features meet SOC 2 Type 2, are HITRUST certified, and are HIPAA compliant, and that it does not use PHI or PII to train models.
- Pricing: not published. Contact sales.
- Limitations: a full communications platform, which may be more than a small practice needs.
Microsoft Copilot Studio with the healthcare agent service
- Best for: IT-led teams on Microsoft 365 or Azure that want to build and control their own agent.
- Key features: Copilot Studio for building agents, plus the healthcare agent service (formerly Azure Health Bot) with healthcare-specific safeguards, credible-source fallback, consent management, audit trails, and configurable conversation log retention.
- HIPAA stance: Microsoft Learn states Copilot Studio is covered under Microsoft's HIPAA BAA, while noting it is not intended for use as a medical device.
- Pricing: see vendor site. Pricing depends on Microsoft licensing and consumption.
- Limitations: a build-it-yourself platform. You need people who can design, test, and maintain the agent.
Intercom (Fin AI Agent)
- Best for: digital health and health-adjacent companies that want a mature support platform plus an AI agent.
- Key features: Fin AI Agent over chat and email, shared inbox, help center, workflows, and handoff to human agents.
- HIPAA stance: Intercom's help center says it has completed a HIPAA attestation examination and can sign a BAA, which requires the Expert plan. Its terms prohibit sending PHI without a signed BAA.
- Pricing: Intercom lists the Expert plan at $132 per seat per month, with Fin charged from $0.99 per outcome (pricing as of September 2026).
- Limitations: per-seat plus per-outcome pricing adds up for large teams, and you need the top plan for a BAA. Channels like SMS and WhatsApp need separate review.
Zendesk
- Best for: organizations already running support on Zendesk.
- Key features: ticketing, messaging and live chat, help center, voice, and AI agents, with HIPAA-enabled add-ons including AI Agents - Advanced.
- HIPAA stance: Zendesk's help center says customers with the Advanced Compliance add-on (or a plan that includes it) can sign a Healthcare Agreement, and it publishes required security configurations for HIPAA-enabled accounts.
- Pricing: see vendor site. Covered plans are listed as Suite Professional or Enterprise, plus the add-on.
- Limitations: the healthcare configuration requirements put real responsibility on you, including deleting AI conversations that are not turned into tickets.
Kommunicate
- Best for: smaller teams that want an AI chatbot across web, WhatsApp, and email at a lower entry price.
- Key features: AI agents, live chat handoff, integrations with Zendesk and Freshdesk, and API and webhook access on higher plans.
- HIPAA stance: Kommunicate's healthcare content says deployments involving PHI can run under a signed BAA with scoped access controls. Its public pricing page does not say which plan includes a BAA, so confirm this during procurement.
- Pricing: Starter is listed at $40 per month and Professional at $200 per month on monthly billing, with Enterprise on request (pricing as of September 2026).
- Limitations: confirm BAA scope, model provider terms, and channel coverage in writing before any PHI flows through it.
Where a general-purpose chatbot fits
Plenty of healthcare website questions contain no PHI at all: office hours, directions and parking, which insurance plans you accept, what to bring to a first visit, how to request records, or how new patient registration works. A general-purpose AI chatbot can answer these, as long as it does not ask visitors to identify themselves or describe symptoms.
Bund AI is one of those general-purpose tools, and we want to be clear about the boundary. Bund AI is not HIPAA compliant, does not sign BAAs, and should not be used to collect, store, or process PHI. Its healthcare configuration is built to decline medical and clinical questions and hand them to your team, and it can answer administrative questions from your own published content. That makes it a fit for anonymous FAQ traffic, not for identity-verified patient workflows.
If you want to route appointment requests through any chatbot, check with your privacy officer first. Many teams treat a named appointment request at a healthcare provider as PHI, which would require a vendor with a BAA. A common, safer pattern is to let a general chatbot answer the public questions and link patients to your HIPAA-covered scheduling system or patient portal for anything personal.
You can see how this vertical is scoped on our healthcare page, and how handoffs work on the escalation and handoff page. If you are still deciding between a scripted bot and an agent that takes actions, our explainer on chatbots versus AI agents covers the difference.
Frequently asked questions
Is there such a thing as a HIPAA certified chatbot?
No. HHS does not certify products as HIPAA compliant and does not recognize private "certifications." What you can get is a signed Business Associate Agreement, documented security controls, and in some cases third-party attestations like SOC 2 or HITRUST. You are still responsible for how you configure and use the tool.
Does using ChatGPT or another AI model make a chatbot non-compliant?
Not automatically. Model providers such as OpenAI and Anthropic offer BAAs for specific services and configurations. The question is whether your chatbot vendor uses a covered configuration and whether its BAA with you flows down to that model provider. Ask for this in writing.
Do I need a BAA if my chatbot only answers general questions?
If the chatbot never collects individually identifiable health information, you may not be sharing PHI with the vendor. But visitors often volunteer details you did not ask for, and tracking and analytics can add identifiers. Get a compliance review of the actual data flows before deciding.
Can a healthcare chatbot give medical advice?
It should not be positioned that way. Most vendors, including those with BAAs, restrict their AI from diagnosis or treatment advice. A well-designed healthcare chatbot answers administrative questions, routes clinical questions to staff, and shows emergency guidance for urgent symptoms.
Is Bund AI HIPAA compliant?
No. Bund AI does not sign BAAs and is not suitable for PHI. It can answer anonymous, public questions for a practice, such as hours, location, and accepted insurance, from your own content. For anything involving patient identity or health details, use a vendor that signs a BAA.