Give Your Business an AI Voice to Answer Customer Calls 24/7Try it for free and get launch perks.
Click here to registerChatley AI supports HIPAA-aligned deployments for healthcare customers, enabling secure handling of Protected Health Information (PHI) through third-party cloud infrastructure and configuration controls.
The Health Insurance Portability and Accountability Act (HIPAA) sets the standard for protecting sensitive patient data. Chatley AI supports HIPAA-compliant deployments for healthcare organizations by providing the appropriate infrastructure, configuration controls, and contractual protections required under HIPAA.
Our voice telephony connects through third-party infrastructure providers that maintain SOC 2 Type II and HIPAA security attestations. Healthcare customers who enable HIPAA mode and execute a Business Associate Agreement (BAA) with Chatley AI can deploy AI voice agents for patient-facing interactions in a HIPAA-aligned configuration.
| Topic | Status | Notes |
|---|---|---|
| HIPAA mode | Required for PHI | Enable at the agent configuration level before processing PHI. |
| Business Associate Agreement (BAA) | Required | Execute with Chatley AI before any PHI is processed. |
| Voice infrastructure | HIPAA-eligible | Underlying provider maintains HIPAA-aligned controls; your configuration must remain compliant. |
Chatley AI's HIPAA-aligned deployment posture is achieved through qualified third-party infrastructure and customer configuration controls. There are two requirements before any PHI is processed:
1. HIPAA Mode Enabled The HIPAA compliance flag must be enabled at the agent configuration level. This activates HIPAA-compliant handling in our underlying voice infrastructure. HIPAA mode is available exclusively on Enterprise plans.
2. Business Associate Agreement (BAA) Signed A BAA must be executed between Chatley AI and your organization before any PHI is processed. Chatley AI also maintains a BAA with our voice infrastructure provider, covering the underlying processing layer. Contact security@chatley.ai to request a BAA.
| Control area | Description |
|---|---|
| Minimum necessary | PHI is processed only as needed to deliver the features you enable and configure. |
| Access & transmission | Technical controls and secure channels are used in line with HIPAA mode and provider requirements. |
What the BAA covers:
To request a BAA: Contact security@chatley.ai with your organization name and the name of your authorized signatory. We will route you to our legal team.
In the event of a potential PHI breach:
| Step | Summary |
|---|---|
| Assessment | We investigate to determine whether a breach of unsecured PHI occurred and the scope of impact. |
| Notification | Where required, affected individuals and regulators are notified in accordance with HIPAA timelines and your BAA. |
For questions about our HIPAA compliance posture or to request a Business Associate Agreement:
Email: security@chatley.ai
Chatley AI, Inc. 252 NW 29th St Miami, FL 33127
Important: HIPAA compliance for your Chatley AI deployment requires both enabling HIPAA mode at the agent configuration level and executing a BAA with Chatley AI. Deploying agents that may handle PHI without both of these steps in place is not a HIPAA-compliant configuration. If you are unsure whether your deployment requires HIPAA compliance, consult your legal counsel.