Definition

HIPAA (the Health Insurance Portability and Accountability Act of 1996) is the U.S. federal law whose Privacy, Security, and Breach Notification Rules govern how covered entities and their business associates use, protect, and disclose protected health information.

HIPAA applies to covered entities (health plans, healthcare clearinghouses, and providers that conduct standard electronic transactions) and to the business associates that handle PHI on their behalf. It is enforced by the HHS Office for Civil Rights. The Privacy Rule's minimum-necessary standard requires limiting PHI use and disclosure to what a task requires.

On a patient call, HIPAA shapes two moments in particular. Identity has to be verified before any protected detail is spoken, since disclosing a diagnosis or appointment to the wrong person can be an impermissible disclosure. And what the call discusses, records, and transcribes has to stay within the minimum necessary. With AI voice agents, a third question appears: whether PHI should reach a general-purpose language model at all, which some state laws further restrict.

How Consig handles it

Consig operates in compliance with HIPAA, and healthcare customers sign a Business Associate Agreement before sharing PHI. Context firewalls keep sensitive data out of the model's reach, and identity data stays out of the conversation layer, transcripts, and any third-party LLM in the call path.