1. Blog
  2. /
  3. AI in healthcare
  4. /
  5. Healthcare AI Security: What to Ask Any Vendor About HIPAA, SOC 2, and How AI Handles Your Data

Handling patient data is one of the most serious responsibilities in healthcare, and it shapes how we build every AI agent at Talkie. Our agents speak with patients, pull up their information in real time, and write back to the EHR, so the controls behind them have to be strong—and verifiable.

The question to ask any healthcare AI vendor is a simple one: “can I check if this is secure?” A security claim you can’t verify is just marketing.

So here’s what to ask any AI vendor handling protected health information (PHI)—covering HIPAA, SOC 2, encryption, and how AI models handle your data—with Talkie’s answer to each.

Key takeaways

  • Verify security claims yourself. Ask for the SOC 2 Type II report, BAAs, and documented controls rather than relying on a vendor’s summary.
  • HIPAA starts with a BAA, with the vendor and any subprocessor that touches PHI. Talkie signs one with every US healthcare client.
  • Ask how the AI model handles your data. Ask whose model powers the agent and whether it trains on your data. Talkie’s AI providers are contractually barred from training on customer data.
  • Voice raises unique questions—biometrics, identity checks, and recordings. Talkie prohibits generating a voiceprint from a caller’s voice.
  • Use the checklist. The 10 questions at the end work for evaluating any AI vendor.

Start with the paperwork: HIPAA and BAAs

HIPAA compliance for a vendor comes down to a few concrete things: acting as a Business Associate, limiting access to the minimum necessary, and putting a signed Business Associate Agreement (BAA) in place. The BAA is the legal instrument that makes a vendor accountable for PHI. No BAA, no deal.

Don’t forget: your vendor almost certainly relies on other vendors—cloud hosting, speech processing, telephony. If any of those can touch PHI, they need BAAs too. A chain is only as strong as its weakest signature.

Talkie acts as a Business Associate to covered-entity clients and accesses and uses only the PHI a given task requires. We execute a BAA with every US healthcare client, and with any subprocessor that may process PHI.

Ask any vendor: Will you sign a BAA? Do your subprocessors sign one too?

SOC 2 Type II: what independent auditing actually proves

Any vendor can say “we take security seriously.” A SOC 2 Type II report is what backs it up—an independent CPA firm testing a vendor’s controls.

One clarification worth having: SOC 2 produces an attestation report, not a pass/fail certificate. And Type II matters more than Type I, because Type I checks whether controls are properly designed at a single point in time, while Type II goes further and tests that they actually operated effectively over a period of months.

Talkie’s controls have been examined by an independent CPA across multiple SOC 2 Type II audits, covering all five Trust Services Criteria—Security, Availability, Confidentiality, Processing Integrity, and Privacy. Every report confirmed our controls are suitably designed and operating effectively. We share the full report under NDA on request.

Ask any vendor: Can I see your SOC 2 Type II report?

Encryption, in plain terms

Two phrases come up a lot here, and it helps to know what each one means.

  • Encrypted in transit means data is protected while it moves between systems, commonly using TLS 1.3.
  • Encrypted at rest means data is protected while it’s stored, commonly using AES-256.

Talkie encrypts confidential and highly-confidential data at rest using AES-256, and protects data in transit with TLS 1.3 across production services.

Ask any vendor: What encryption standard do you use, in transit and at rest?

The AI supply chain: whose model, and what happens to your data inside it

The questions in this section are specific to how AI systems handle data.

When your agent talks to a patient, something is processing that speech and generating responses—usually a large language model, often run by a third party. Two questions follow:

  1. Does the model provider retain or train on what you send it?
  2. How much of the patient’s data reaches the model in the first place?

Talkie governs this using the NIST AI Risk Management Framework, structured around its four functions—Govern, Map, Measure, and Manage. That’s a recognized, public standard for AI risk, and it’s worth asking whether a vendor follows any framework at all or is improvising.

Here’s how Talkie addresses these questions in practice:

  • On training: AI providers must hold a BAA or DPA matching the data they touch, and are contractually barred from training on Talkie or customer data.
  • On data flow: the model, speech, and telephony subprocessors behind each AI capability are documented per client, including where PHI enters and exits the chain.
  • On minimization: a permission matrix ties data classification to which AI tool may receive it, so the most sensitive data is restricted to the most tightly controlled routes.

Ask any vendor: Whose model powers your AI agent? Do you—or they—train on our patients' data? What data actually leaves our environment?

Voice-specific safeguards

Voice brings a couple of considerations that text-based tools don’t. Two stand out.

The first is biometrics. A caller’s voice can be turned into a voiceprint—a biometric identifier with its own thicket of legal obligations. Talkie’s stance here is clear:

No tool in Talkie’s AI stack may generate a voiceprint or biometric template from a caller’s voice. Only plain speech-to-text transcription is permitted.

The second is identity—confirming the agent is speaking with the right patient before disclosing anything.

Before Talkie’s agent shares any patient information, it confirms the caller against three data points: first and last name, date of birth, and the phone number the call is coming from. The conversation only moves forward once those match.

Ask any vendor: Can the AI create a voiceprint from a patient's voice? How do you verify a caller's identity before disclosing PHI?

Transparency: patients should know they’re talking to AI

A responsible agent never pretends to be human. Beyond the ethics, being upfront builds patient trust—people engage more comfortably when they know they’re talking to an AI and can reach a person if they want one.

Talkie informs patients they’re interacting with an AI assistant, and they can ask to be transferred to a human at any point.

Ask any vendor: Are patients clearly told they're speaking with an AI, and can they reach a human?

Who can see your data, and how vendors keep themselves honest

Strong encryption is undermined if half the company can read the data behind it. The controls that matter here are unglamorous and easy to verify:

  • Access controls—multi-factor authentication, individually assigned accounts (no shared logins), and recurring reviews to confirm access still fits each person’s role.
  • Penetration testing—an independent external firm should be probing the systems on a regular cadence, with findings tracked to remediation rather than filed away.

At Talkie, remote and administrative access requires MFA and unique credentials, and permissions are reviewed on a recurring basis. An independent external provider runs penetration tests annually on a rolling schedule, with findings tracked to remediation and reviewed by leadership. The most recent cycle expanded scope to cover the web application, network perimeter, and full AWS infrastructure.

Ask any vendor: Who internally can access our data? How often are you independently penetration-tested, and what's in scope?

What happens to your data over time—and when you leave

Two lifecycle questions belong in every DPA:

  • Retention: how long data is kept, and whether you can configure it.
  • Exit: what happens to your data when the contract ends.

Talkie defines retention periods by data category and reviews them periodically, securely disposing of data once it’s no longer needed. When a customer relationship ends, documented deletion procedures apply once data reaches the end of its retention period.

Ask any vendor: How long is our data kept? Can we control it? What happens to it when we leave?

The checklist: what to ask any AI vendor about patient data

Screenshot this. Bring it to your next demo. A vendor worth trusting will answer every question—and point you to where you can verify it.

  1. Will you sign a BAA? Will your subprocessors?
  2. Can I see your SOC 2 Type II report?
  3. What encryption do you use, in transit and at rest?
  4. Whose AI model powers this, and are they contractually barred from training on our data?
  5. What patient data reaches the model, and what’s minimized or withheld?
  6. Can the AI generate a voiceprint or biometric template from a caller’s voice?
  7. How do you verify a caller’s identity before disclosing PHI?
  8. Are patients told they’re speaking with an AI?
  9. Who internally can access our data, and how often are you penetration-tested?
  10. How long is our data retained, and what happens when we leave?

We built our Security & Trust Center so you can check our answers to all of these—not take our word for them. Want the documentation? Email security@talkie.ai for our SOC 2 Type II report, BAA template, or penetration-test attestation letter, most shared under NDA within three business days.

The best way to judge a vendor’s security is to ask directly

Book a demo and we’ll show you exactly how Talkie protects patient data.

Frequently Asked Questions

  • Is Talkie a HIPAA compliant AI agent?

    Yes. Talkie acts as a Business Associate to covered-entity clients, accesses and uses only the PHI required for a given task under HIPAA’s minimum-necessary standard, and signs a Business Associate Agreement (BAA) with every US healthcare client and any subprocessor that may process PHI.

  • Is Talkie SOC 2 Type II audited?

    Yes. Talkie’s controls have been examined by an independent CPA across multiple SOC 2 Type II audits, covering all five Trust Services Criteria. The full report is available under NDA on request.

  • How is data encrypted?

    Confidential and highly-confidential data is encrypted at rest with AES-256, and data in transit is protected with TLS 1.3 across production services.

  • Are patients told they’re speaking with an AI?

    Yes. Patients are informed they’re interacting with an AI assistant and can ask to be transferred to a human at any point.

  • How do I request the SOC 2 report or other documentation?

    Email security@talkie.ai for the SOC 2 Type II report, BAA template, or penetration-test attestation letter—most shared under NDA within three business days.