In healthcare, a HIPAA-compliant PAL video session is a live patient conversation where the audio, video, transcript, model inputs, logs, and storage controls are treated as electronic protected health information (ePHI) from the moment the patient shares identifiable health information. Every component that touches PHI, from speech recognition through the video pipeline, must operate under the Security Rule's safeguards and a signed Business Associate Agreement (BAA).

HIPAA compliance is deployment-specific: vendor infrastructure, your configuration, policies, and staff training all matter. The U.S. Department of Health and Human Services (HHS) recognizes no certification that makes a technology compliant on its own.

For teams evaluating that deployment-specific architecture, Tavus is the human computing company, building PALs that see, hear, understand, remember, and respond in live conversations. In a clinical check-in, that live two-way conversation is PHI from the patient's first sentence, so the perception layer and the compliance layer have to be designed together.

Because a PAL carries context from turn to turn, PALs that feel human can be scoped to support a clinical check-in as one continuous exchange. The video feed, the audio, the transcript, and data derived from them can sit inside HIPAA's definition of PHI when they contain individually identifiable health information.

The shift toward real-time AI video in healthcare

Workforce projections indicate a national physician shortage by 2038, so patient questions keep multiplying while the hours available to answer them do not. That pressure is why some teams are evaluating clinical AI for bounded workflows that can be governed, audited, and escalated.

When automation moves into a patient conversation, it has to feel different from a phone tree. In a governed pilot, a face and a voice can serve as design surfaces for conveying hesitation or fear. In a PAL pilot, teams can scope machine-mediated work first: hold queues, phone trees, and portal messages that sit unanswered overnight.

Core HIPAA requirements AI video vendors must meet

Any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate, and no PHI may lawfully flow until a BAA is signed.

Under HHS's sample BAA provisions, the contract must specify permitted uses and disclosures, require compliance with Security Rule safeguards, mandate breach reporting, require return or destruction of PHI upon termination, and extend the same obligations to every subcontractor.

The HIPAA Security Rule sets three layers of safeguards. The required-versus-addressable split should drive your vendor questions. Person or entity authentication, audit controls, and unique user identification are required under 45 CFR § 164.312, so any system that contains or uses ePHI must record activity and allow you to examine that record.

Transmission security is a standard whose implementation specifications, integrity controls and encryption are addressable. Declining one means documenting why.

Administrative safeguards begin with an accurate, thorough risk analysis. For a PAL pilot over video, that analysis has to cover components your last one may not have included: the speech recognition service, the model layer, and the video pipeline. Because escalated conversations land on named staff, security training must reach the people who review transcripts and handle clinical escalations.

Physical safeguards cover facility access, workstation use, and the disposal of the media that held recordings, and the HIPAA compliance policies must be retained for 6 years from creation or their last effective date.

The proposed Security Rule update would mandate encryption and multi-factor authentication, but it has been delayed to July 2027 at the earliest, and the 2013 rule remains enforceable until then.

Video and voice inside the compliance picture

HIPAA protects individually identifiable health information "in any form or media, whether electronic, paper, or oral," and both voice prints and full-face photographic images appear on the Safe Harbor list of identifiers. A live patient video conversation, therefore, can't be de-identified in real time.

Unauthorized filming of patients is a serious breach of privacy, especially when people outside the care team can capture patients in clinical settings.

California AB 3030 requires generative AI communications about a patient's clinical information to carry a disclaimer, displayed prominently throughout a video interaction, plus instructions for reaching a human provider; California places that duty with the healthcare delivery organization. Several states, including California, Illinois, and Florida, require the consent of every party before a conversation is recorded.

Before a PAL discusses PHI, 45 CFR § 164.514(h) requires verifying who is on the other end, and it prescribes no method, so verification can be built into the conversation flow.

Security and compliance features to look for in a vendor

Marketing labels can't substitute for verification, so confirm each of the following before any pilot touches PHI:

  • A BAA that matches the deployment: A vendor can market itself as HIPAA-compliant and still refuse to sign a BAA, rendering it unusable for PHI. Confirm the signed agreement covers the services you'll use.
  • SOC 2 Type II, read carefully: A Type II report attests to controls operating over time. Security Rule conformance still requires a separate review. Check which subservice organizations are carved out and which controls fall to you.
  • Encryption and audit logging: TLS for signaling and SRTP for media in transit, encryption at rest, and tamper-evident logs.
  • Retention and deletion controls: Confirm configurable retention periods, documented media disposal, and whether zero-data retention is available.
  • A documented subprocessor chain: Every speech-to-text engine, large language model (LLM) provider, and video rendering component that touches ePHI needs its own BAA.

Work the list with the vendor's own documentation open, because each answer should come with a document you can file; this HIPAA compliance evaluation guide works through the same BAA, SOC 2, encryption, audit, retention, and subprocessor questions.

Against the same BAA, SOC 2, encryption, audit, retention, and subprocessor criteria, Tavus holds SOC 2 Type II certification and offers HIPAA compliance on appropriate Enterprise plans, with BAAs and compliance reports. Zero data retention is available for conversations on eligible enterprise plans. Guardrails define what a PAL may discuss and when it must hand off.

Elena is three days post-discharge from a heart failure admission, mid-check-in with a PAL. When she asks whether she can double her diuretic, Guardrails keep the conversation clear of dosing advice and escalate to a human clinician, which is a basic PAL safety control in regulated deployments. Function Calling routes the structured clinical data to her EHR, and her nurse calls that afternoon.

Escalation handles the clinical-risk boundary; visible steadiness handles a different requirement in sensitive disclosures. Phoenix-4, the real-time facial behavior engine, renders a PAL's listening behavior across controllable emotional states, including the micro-expressions that keep appearing while the patient is still talking. Those expressions are rendered from the emotional and attentional signals the LLM layer feeds it, not from independent judgment on Phoenix-4's part. It renders at 40fps and 1080p.

Back in her check-in, when Elena hesitates before admitting she skipped two doses, that face stays steady and non-judgmental, still generating listening behavior while she talks. Presence, in a check-in like hers, is a face designed not to flinch while a patient admits something she is embarrassed about. In that workflow, the missed-dose signal can be routed for care team review.

Patient conversation use cases for HIPAA-compliant AI video

Common pilot candidates include intake and triage. In a pilot plan, these workflows can be scoped for after-hours interviews, record review, and telehealth scheduling.

Teams can also define whether the PAL may ask about symptoms and how each answer routes to virtual visits, appointments, urgent care, or a human clinician. For a pilot, a narrower script gives teams a clearer escalation map to test before expanding the workflow. Pre-procedure preparation and medication-adherence check-ins are the adjacent surfaces I would scope next, since both are scripted and high-volume.

These chat and voice workflows run without real-time video; real-time conversational video adds perception on top. In healthcare intake and navigation deployments, teams can specify whether a PAL should detect patient distress signals mid-conversation and adjust its tone. Teams can also evaluate structured clinical data routing to the EHR before a clinician opens the case.

Raven-1, the multimodal perception system, keeps perceptual context no more than 300ms stale, with sub-100ms audio perception. When a patient says "I'm managing" in a flat voice while her eyes drop, Raven-1 fuses tone with gaze and describes the mismatch in natural language the LLM layer can reason over.

Evaluating a HIPAA-compliant AI video partner

For a clinical pilot, prioritize four checks during evaluation. Ask for published floor-prediction benchmarks, perception latency, retrieval speed against your own documents, and the escalation logic that ties each signal to a named clinician. Each benchmark should come back as a figure with a source.

Tavus's Conversational Video Interface (CVI) is API infrastructure your team builds on, with the option to bring your own large language model through OpenAI-compatible endpoints, white-labeled so the patient sees your product.

Sparrow-1 governs conversational flow, Raven-1 fuses the patient's emotional and attentional signals, the LLM layer reasons about what to say next, and Phoenix-4 renders the responsive facial behavior.

Sparrow-1, the conversational flow model, predicts floor ownership at the frame level on raw audio. Published conversational AI response latency tests across 28 challenging real-world conversational samples measured 55ms median prediction latency, 100% precision and recall, and zero interruptions. When a patient pauses to hunt for a medication name, Sparrow-1 holds the floor open while the patient searches.

The Knowledge Base is a proprietary retrieval-augmented generation (RAG) model that queries your clinical documents in roughly 30ms; the Knowledge Base RAG retrieval docs note that English-language content only is supported, a constraint for multilingual planning. Any vendor should be able to hand over floor-prediction benchmarks, perception latency, retrieval speed, and escalation-routing logic.

Bringing secure, human-centered conversations to healthcare AI

Every safeguard here exists for a moment like Elena's: a question that couldn't wait, a face that held steady while she admitted the missed doses, and a system that knew when to call her nurse. She got presence at the moment she needed it, and the compliance work is what makes that moment possible.

See it for yourself. Book a demo.

Frequently asked questions

Is AI video inherently HIPAA compliant?

No. HIPAA compliance belongs to the deployment: the signed BAA, configured safeguards, provider policies, staff training, and risk analysis. HHS recognizes no certification that would make a technology compliant on its own.

What's the difference between "HIPAA-eligible" and "HIPAA-compliant"?

HIPAA-eligible means a service is built so it can be used with PHI under a BAA; AWS states that customers do not automatically inherit compliance by using eligible services. HIPAA-compliant describes the whole system, including customer-side configuration, meeting the Security Rule.

Does a BAA cover recorded patient video?

Electronic recordings of patient conversations that contain individually identifiable health information are ePHI, so the BAA must govern how they are stored, encrypted, accessed, and returned or destroyed at termination. HIPAA's six-year retention rule covers compliance documentation.

Who is responsible for compliance, the vendor or the healthcare provider?

Both. The vendor, as a business associate, is directly liable for safeguarding ePHI and for BAAs with its own subcontractors, and the covered entity must execute the BAA before any PHI flows.