HIPAA, Florida recording law, and your AI front desk
Short answer: “is this HIPAA compliant?” is three questions wearing one coat. HIPAA might not apply to your spa at all. Florida’s all-party recording law almost certainly does, and AI receptionists record by default. And a third law, which nobody asks about, governs what happens if any of that data leaks.
Not legal advice. We build automation; we’re not lawyers, and nothing here substitutes for one. This is a guide to the questions worth asking and the answers worth getting in writing — including from your own attorney, whose read on your specific setup beats any article, this one included.
Question 1: Are you even a HIPAA covered entity?
Most med spa owners assume the answer is yes. It often is, but not automatically, and the actual test is narrower than the marketing around compliance software suggests.
A health care provider becomes a covered entity when it transmits health information electronically in connection with a standard transaction — billing a health plan, checking eligibility, requesting prior authorization, and the other transaction types defined in the federal rules. So two things generally have to be true together: a licensed practitioner delivering care within a clinical scope, and at least one of those electronic transactions.
A spa that is genuinely cash-pay and never conducts one of those transactions may sit outside HIPAA. That’s a real but narrow exception, and two caveats matter:
- It’s organization-wide. Bill a plan electronically for one service and the status attaches to the practice. You don’t get to be covered for insurance clients and uncovered for cash clients.
- Falling outside HIPAA doesn’t mean falling outside the law. Questions 2 and 3 below apply either way, as do Florida medical-records rules and your practitioners’ own licensing obligations.
One honest note on the state of published guidance: a good deal of it says that simply storing client records electronically makes you a covered entity. That isn’t the statutory trigger — the standard electronic transaction is. Storing electronic health information is what you must then protect if you’re covered. The distinction gets blurred often enough in compliance marketing that it’s worth putting the question to an attorney rather than to a blog.
Question 2: Florida requires everyone on the call to consent to recording
This is the one that gets skipped, and for a Florida med spa buying an AI receptionist it is the most likely to cause an actual problem.
Florida is an all-party consent state under Fla. Stat. § 934.03. Every person on a call must consent before it is recorded. You cannot record secretly even as a participant in your own conversation. Violation is a third-degree felony — up to five years and a $5,000 fine — with civil liability on top.
Now consider what an AI receptionist does. It answers the call, converts speech to text, sends that text to a language model, and usually retains a transcript and often the audio. Recording and processing the call is the product.
Whether machine transcription that never stores audio counts as interception under the statute isn’t something we can point you to a clean answer on. But the safe practice doesn’t depend on resolving it:
- Disclose at the top of the call, before anything is processed, and give the caller a way to opt out and reach a human.
- Verify the disclosure is actually configured. Many off-the-shelf voice agents ship with it off, or with wording written for one-party-consent states. The default is not automatically legal here.
- Hear it yourself. Call your own number after go-live and listen to what a real caller hears in the first five seconds.
This costs one line of script. Omitting it is one of the few genuinely expensive mistakes available in this category, and it applies whether or not HIPAA touches you.
Question 3: FIPA, if the data ever leaks
The Florida Information Protection Act (Fla. Stat. § 501.171) applies to essentially any commercial entity that acquires, maintains, stores, or uses personal information — no revenue or headcount threshold, HIPAA status irrelevant.
The clocks are short:
- Notify affected individuals within 30 days
- Notify the Florida Attorney General if 500 or more Florida residents are affected
- Notify consumer reporting agencies at 1,000 or more
- Penalties escalate to $500,000
This covers your booking system, your CRM, and every copy of client data your AI vendor holds. Which is why the retention question below is not housekeeping — data you don’t keep is data you can’t have breached.
If HIPAA does apply: what a BAA does, and doesn’t
A vendor that creates, receives, maintains, or transmits protected health information on your behalf is a business associate, and a Business Associate Agreement is required by federal law. A vendor that hesitates to sign one has told you what you need to know.
A workable BAA should address:
- Security controls — encryption, access control, audit logging
- A defined breach-notification window from the vendor to you
- Subcontractor obligations
- Return or destruction of data when the contract ends
- Audit rights
The part most people miss: the entire pipeline needs coverage. A voice agent is usually several companies wearing one logo — telephony, speech-to-text, a language model, sometimes text-to-speech. Each one that touches call content needs to be under a BAA. A signed agreement with the front-end vendor means little if they route your audio through a subprocessor who never signed anything.
And what a BAA does not do: it doesn’t make you compliant. It allocates responsibility between you and the vendor. Your own obligations — minimum necessary, access controls, workforce training, risk analysis — stay yours.
What to ask a vendor before signing
- Will you sign a BAA? Can I see it before I commit?
- Which subprocessors touch call audio or transcripts, and is every one of them covered?
- Where is the recording disclosure configured, and can I hear a real call that includes it?
- What is retained — audio, transcripts, both — for how long, and can I set it shorter?
- Is call content used to train your models or anyone else’s? In writing.
- How quickly do you notify me of a breach?
- Can the agent be scoped to refuse clinical questions and hand off instead?
What to ask your attorney
- Given how we bill, are we a HIPAA covered entity? (The standard-transaction question above.)
- Does our AI receptionist’s opening disclosure satisfy § 934.03?
- Does our incident response plan meet FIPA’s 30-day clock?
- Does our consent and intake paperwork cover automated communication with clients?
The cheapest risk reduction available
Scope the AI away from clinical information entirely. An agent that books, reschedules, and answers questions about pricing, prep, downtime, parking, and hours touches vastly less sensitive data than one running intake or discussing whether a treatment is suitable. It hands anything clinical to a human immediately.
That’s the same conclusion the missed-calls guide reaches from a product angle rather than a legal one — the narrow agent is the better agent. It’s unusual and convenient for the cautious choice and the effective choice to be the same one, and here they are.
Again: this isn’t legal advice. Statutes change, and how they apply turns on facts specific to your practice. Use this to arrive at your attorney’s office with the right questions, not to skip the visit.
Want an AI front desk scoped properly from the start? We build them on-site across South Florida — narrow by design, with the disclosure configured and the handoff to a human where it belongs.
Frequently asked questions
Does HIPAA apply to my med spa?
Not automatically. A health care provider becomes a HIPAA covered entity when it transmits health information electronically in connection with a standard transaction — billing a health plan, checking eligibility, or requesting prior authorization. A spa with a licensed practitioner that is genuinely cash-pay and never conducts one of those electronic transactions may fall outside HIPAA. It's a narrow exception and worth confirming with a healthcare attorney rather than assuming either way.
If I bill insurance for some services but not others, am I covered?
Yes, organization-wide. Covered-entity status attaches to the practice, not to individual clients. You don't get to be covered for insurance patients and uncovered for cash patients.
Can my AI receptionist legally record calls in Florida?
Only with the consent of everyone on the call. Florida is an all-party consent state under Fla. Stat. § 934.03 — you cannot record a conversation secretly even as a participant, and a violation is a third-degree felony carrying up to five years and a $5,000 fine, plus civil exposure. Since AI receptionists record or transcribe by default, the disclosure has to be built into the start of the call and actually configured, not assumed.
Do I need a BAA with my AI receptionist vendor?
If you're a HIPAA covered entity and the vendor creates, receives, maintains, or transmits protected health information on your behalf, a Business Associate Agreement is required by federal law, not offered as a courtesy. The detail most people miss is that the whole pipeline needs coverage — the voice agent, speech-to-text, the language model, and the telephony provider are often different companies.
What's the simplest way to reduce compliance risk with an AI front desk?
Scope it away from clinical information entirely. An agent that books appointments and answers questions about pricing, prep, parking, and hours touches far less sensitive data than one running intake or discussing treatment suitability. Narrow scope is both the better product and the smaller legal surface.