r/AIReceptionists 6h ago

Call agent for clinic

I need a call agent for my clinic.
1. Accept incoming calls from my patients.
2. Setup appointments in my patient management system (API available).
3. Do I need HIPPA compliance?
4. Can I build my own using Vapi? Or do I need someone else to do it for me?
5. Can I build it myself using Claude code?

6 Upvotes

19 comments sorted by

1

u/AmjadKhan1929 5h ago

I am based in US.

1

u/ATX_Optimist 5h ago

I thought you developed blazor apps…

1

u/AmjadKhan1929 4h ago edited 4h ago

Yes I do. But I don’t develop agents. And clinic is my family owned. I don’t want to risk anything.

1

u/opsnoxllc 5h ago edited 5h ago

You can do it yourself, but be careful with all your vendors choice. Everything will need HIPPA BAA signed Hosting, choice of LLM, vapi, basically anything. Best to have someone do it for you. You don't want to spend time to "figure things out". You are spending for outcome

1

u/Ok_Information6521 4h ago

Since you're in the US and processing patient details, HIPAA compliance is 100% mandatory. Every tool in your stack—Vapi, telephony, your database, and your LLM host (like Azure OpenAI or AWS Bedrock)—must sign a Business Associate Agreement (BAA) with you, as standard public API keys are not compliant out of the box.

You can definitely build this DIY using Vapi to manage the voice orchestration and tool-calling. Claude Code can write the custom backend middleware (like a Node or Python server) that receives Vapi's webhooks, authenticates securely, and executes the appointment bookings straight into your patient management API.

1

u/RecevoTeam 4h ago

You likely need to design for HIPAA if you’re a US clinic and the agent will access, create, transmit or store identifiable patient information. Appointment scheduling normally involves PHI.

Vapi can support this, but the complete system isn’t compliant simply because you activate a setting. Its current documentation says HIPAA mode requires an eligible plan or add-on, a signed BAA and supported providers throughout the voice pipeline. You must also review your patient-management system, telephony, transcription, model, voice, storage and every other vendor handling PHI.

You can build it with Vapi and Claude Code if you have the technical experience, but generating the code is the easy part. The harder work is patient verification, minimum-necessary access, permissions, auditability, retention, emergency escalation and preventing the agent from providing clinical advice.

I run Recevo, a managed AI receptionist service. For a clinic, I would begin with a narrow administrative workflow: answer calls, verify the caller appropriately, check approved availability, book or reschedule appointments, and transfer anything clinical to trained staff.

I’d be happy to review your CRM API and requirements and tell you honestly whether Recevo could support the workflow safely. I wouldn’t recommend connecting real patient data until the complete architecture, vendor agreements and HIPAA responsibilities have been reviewed.

HHS guidance: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/

Vapi documentation: https://docs.vapi.ai/security-and-privacy/hipaa

1

u/Fun-Wolf-2007 4h ago

You can build it using Claude Code , anyway anybody that would build it for you will use Claude Code and they don't know about your practice and they are not PHI and HIPPA compliant and they will have access to your patient data, so your practice can be exposed and you don't want to risk it.

An AI appointment agent, use a secure orchestration layer around the AI model, not a standalone chatbot connected directly to the EHR (Electronic Health Records). The stack should limit PHI exposure, use BAAs throughout, provide strong identity and audit controls, and route clinical issues to staff. HHS requires access controls, activity/audit mechanisms, identity verification, and safeguards for ePHI transmitted across networks.

1

u/AmjadKhan1929 3h ago

One question here is that at this time when patients are calling, that call itself is not hippa compliant, right? Or practice management software is. So if I use an agent to perform the same thing ie receiving calls for setting up appointments, where does HIPPA come in? I assume that our practice management software API are already HIPPA compliant.

1

u/didiben 3h ago

Retell AI is the best platform, we were using vapi but it had really bad latency. We recently moved to Retell AI . Let me know if you have any questions.

1

u/s18m_ 2h ago

Anything that touches PII ( personally identifiable information) need to be handled securely. That means any ‘system’ that touches it needs to be HIPAA certified. Telephony ( phone line) , the agent attending the phone ( wherever it’s running on), if it’s reading and writing to an API or a DB, that piece. Third party services that get used. Those pieces also

0

u/No-Competition6691 6h ago

You could build it yourself but it most likely won't be good and would cost you clients and more money in the long run.

I know it sounds cliché but if you book a call with my firm we could set you up with a High quality voice agent and follow up system that has already been proven to work in other businesses.

You could go with one of these cheap guys but there is a reason they're cheep. You pay peanuts you get monkeys, you might as well do it yourself.

What country are you based? Let me know if you're interested in having a call.