guide

29 of 78 AI Support Tools Can't Take PHI, or Won't Say

Sixteen state they do not support HIPAA and thirteen do not mention it. Meanwhile the 2026 encryption requirement several vendor pages describe as current is a proposed rule that has never been finalised.

By AR · Published 5 August 2026 · 8 min

If you handle protected health information, the shortlist is not the one on the category page. Of the 78 platforms in this directory, 16 state that they do not support HIPAA and 13 do not mention it anywhere we could find.

The pattern underneath that number is the useful part. All eight voice platforms state HIPAA support. All 15 enterprise contact-centre suites do. Among the 24 chatbots — the cheap, self-serve, sign-up-this-afternoon end of the category — only 8 do.

Which means the tools you can actually buy today are, disproportionately, the tools you cannot put a patient's name through.

What this counts, and what it does not

It counts what each vendor publishes about HIPAA on its own security, trust or compliance pages. Yes means the vendor states support. No means the vendor states it does not support HIPAA or excludes PHI in its terms. Unknown means we could not find it addressed either way.

A stated claim is not a signed BAA, and this post does not pretend otherwise. We have not requested a Business Associate Agreement from 78 companies, and no row here should be read as a legal opinion or as confirmation that a given platform is compliant in your configuration. Compliance is a property of your deployment, not of a logo on a page.

States HIPAA support States it does not Says nothing

29 of 78 platforms

either say they do not support HIPAA, or do not address it at all

E-commerce Support
0/6
AI Agents & Chatbots
8/24
QA & Conversation Analytics
4/6
Help Desk & Ticketing
10/14
Agent Assist & Copilots
4/5
Voice & Phone AI
8/8
Enterprise & CCaaS
15/15
READ FROM VENDOR SECURITY AND COMPLIANCE PAGES · A STATED CLAIM IS NOT A SIGNED BAA

E-commerce is the trap

Not one of the six e-commerce support platforms states HIPAA support. All six state that they do not. That is entirely reasonable for a category built around order status and returns, and it is a problem for a specific and growing set of stores.

Online pharmacies, supplement retailers with a pharmacist on staff, medical device sellers, telehealth companies with a storefront. These businesses shop from the e-commerce category because their support problem is a Shopify problem, and the entire category is closed to them the moment a customer mentions a prescription in a chat window.

Gorgias, Zowie, Richpanel, Yuma, Siena and Mavenoid are all clear about it. The failure mode is not a vendor hiding something. It is a buyer shopping in the category that matches their store rather than the category that matches their data.

The thirteen that say nothing

PlatformCategoryCan you buy it without a call?
eesel AIAI Agents & ChatbotsYes, self-serve
ChatwootAI Agents & ChatbotsYes, self-serve
FiniAI Agents & ChatbotsYes, self-serve
IrisAgentAI Agents & ChatbotsYes, self-serve
DuckieAI Agents & ChatbotsYes, self-serve
MavenAGIAI Agents & ChatbotsNo, sales call
CoSupport AIAI Agents & ChatbotsYes, self-serve
PylonHelp Desk & TicketingNo, sales call
PlainHelp Desk & TicketingYes, self-serve
DevRevHelp Desk & TicketingYes, self-serve
AssembledAgent Assist & CopilotsNo, sales call
KaizoQA & Conversation AnalyticsYes, self-serve
EvaluAgentQA & Conversation AnalyticsYes, self-serve

Silence here is worth less than a no. A no is a decision somebody made and can explain. Silence usually means the question has not come up, which tells you what to expect when you raise it during procurement.

Note how many of these are self-serve. A platform you can put on a company card in ten minutes, with nothing published about PHI, is exactly how an unapproved tool ends up handling health data without anyone deciding that it should.

The encryption rule vendors are selling against is not in force

Several pages ranking for HIPAA and AI support describe a 2026 Security Rule update that moves encryption of ePHI from addressable to required, and at least one states it as current law.

The primary record says otherwise. HHS published it as a notice of proposed rulemaking on 6 January 2025, cited at 90 FR 898, titled HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information. The comment period closed on 7 March 2025.

Notice of proposed rulemaking; notice of Tribal consultation.Federal Register, document 2024-30983, published 6 January 2025

As of 5 August 2026 we can find no final rule. Compliance vendors report that final action is now targeted for 2027; we have not verified that against a primary source and it is repeated here as a claim rather than a fact.

The proposals are worth reading and worth preparing for. Encryption at rest and in transit is good practice whatever the rule says. But a page that tells you a requirement is already binding, and sells you the thing that satisfies it, has made your compliance calendar into a sales tool.

The question that decides it, and almost nobody asks

Most support platforms do not run their own models. The AI layer is frequently an API call to OpenAI, Anthropic or Azure, which makes that provider a subprocessor handling whatever was in the ticket.

So the question is not whether the vendor will sign a BAA. It is whether the coverage extends down the stack, and what happens to PHI at the layer the vendor does not own. A platform BAA that stops at the platform boundary is not the protection it appears to be.

  • Will you sign a BAA, and does it name your model providers as subprocessors?
  • Which model provider handles the inference, in which region, and is there a BAA in place between you and them?
  • Is PHI excluded from model training, by contract rather than by policy page?
  • What is the retention period for conversation data at every layer, including the model provider's logs?

Any vendor genuinely selling into healthcare answers all four in one email, because they have answered them before. A vendor that has to go and find out is telling you where you sit in their roadmap.

How to shortlist if you handle PHI

Start from the categories where HIPAA support is near-universal — voice, enterprise, agent assist and QA — rather than from the price. Then accept the consequence, which is that almost everything in those categories is sales-led and you are not buying it this week.

If budget forces you toward the self-serve end, the shortlist is short: the chatbots and help desks that state HIPAA support, with the BAA questions answered before any real ticket touches the system. Ten of the 14 help desks state support, which makes that the most workable category for a small team with health data.

Every row behind this post is on the tool pages with its date. If a vendor has published a clearer position since we read it, send it over and the record gets corrected.

Frequently Asked

Which AI customer service tools are HIPAA compliant?

Forty-nine of the 78 we track state HIPAA support, and they cluster heavily: all 8 voice platforms, all 15 enterprise contact-centre suites, 10 of 14 help desks, but only 8 of 24 chatbots and none of the 6 e-commerce platforms. Treat a stated claim as a starting point rather than an answer — compliance depends on a signed BAA and on your configuration, not on a badge on a marketing page.

Is a chatbot vendor saying it is HIPAA compliant enough to use it with patient data?

No. You need a signed Business Associate Agreement, and you need to know whether it covers the model provider underneath. Most support platforms call an external model API, which makes that provider a subprocessor handling whatever was in the ticket. Ask whether the BAA names them, which region handles inference, and whether PHI is excluded from training by contract rather than by policy page.

Did HIPAA make encryption mandatory in 2026?

Not as of August 2026. HHS published a notice of proposed rulemaking on 6 January 2025, cited at 90 FR 898, which would move encryption of ePHI from addressable to required. The comment period closed on 7 March 2025 and no final rule has been published. Several vendor and compliance pages describe the requirement as though it were already in force. Encrypting anyway is sensible; treating it as current law is wrong.

Can I use Gorgias or another e-commerce support tool for a pharmacy or telehealth store?

Not for anything touching protected health information. All six e-commerce support platforms in the directory state that they do not support HIPAA. This catches online pharmacies, supplement retailers and medical device sellers, who shop the e-commerce category because their store runs on Shopify and find the whole category closed to them the first time a customer mentions a prescription.

What should I ask a vendor before putting health data through their AI?

Four questions, in one email: will you sign a BAA and does it name your model providers as subprocessors; which provider handles inference and in which region; is PHI excluded from training by contract; and what is the retention period at every layer including the model provider's logs. A vendor that sells into healthcare answers all four immediately. One that has to go and find out has told you something useful.

Tools Mentioned

Full reviews, pricing tiers and where each one breaks.

You Can Also Look Into

WRITTEN BY AR · UPDATED 2026-08-05

I read the fine print. Vendor pricing pages, billing definitions, terms, funding filings and acquisition notices — then I do the arithmetic nobody publishes: what a platform actually costs at your volume, what its headline metric is really counting, and who owns it now. I do not run benchmarks, and no page here pretends otherwise.

How we work · About the author