← Back to Blueprint Bulletin™

    Compliance · 7 min read · May 1, 2026

    What Should Owners Prepare for HIPAA Review of an AI Concierge System in a MedSpa or Wellness Practice?

    The short answer

    For professional review of an AI concierge system, organize documentation about vendor agreements, encryption, audit logs, retention, training-data use, refusal policies, and review cadence. These seven areas support preparation, not a legal compliance determination. Ask your healthcare attorney and medical director to assess the specific setup.

    Element one: a signed Business Associate Agreement

    If the AI vendor processes any protected health information on behalf of the practice, the vendor is a Business Associate under HIPAA. A BAA is not optional. Practices should refuse to deploy any AI tool that will not sign one.

    Element two: encryption in transit and at rest

    Every message between the client, the AI concierge system, and the storage layer should be encrypted using current standards (TLS 1.2 or higher in transit, AES-256 at rest). The vendor should be able to document this on request.

    Element three: audit logs

    The practice should be able to pull a log of every conversation, including who accessed it, when, and from where. Audit logs are what make breach investigations survivable.

    Element four: a documented retention policy

    Decide and document how long AI concierge system transcripts are stored. Common policies range from one month to seven years depending on the practice. The point is that the policy exists in writing and the system enforces it automatically.

    Element five: no training on client data

    The vendor must contractually agree not to use the practice's conversations to train its underlying model. This is the line between a HIPAA-aware deployment and a regulatory disaster.

    Element six: a refusal policy for PHI

    The AI concierge system should be configured to refuse to discuss specific medical conditions, diagnoses, or treatment outcomes outside its trained scope. Refusal language should redirect the client to a human team member without capturing the sensitive content.

    Element seven: review cadence

    For the first year, review the AI concierge system configuration, vendor terms, refusal patterns, and service-menu changes quarterly. After the system stabilizes, move to at least annual review, with immediate review when laws, vendor terms, or services change.

    Where to get help

    An AI build engagement creates a purpose-built AI concierge system using approved voice, services, privacy boundaries, human review, and escalation. Exact integrations, vendor agreements, and data handling depend on scope and the practice's approved systems. This supports preparation for professional review, not a compliance certification.

    Frequently Asked Questions

    Quick answers on this topic

    Can a practice use a free AI concierge system widget and still be HIPAA compliant?

    No. Free and consumer-tier AI concierge system widgets do not include a Business Associate Agreement, do not guarantee that conversations are excluded from model training, and do not provide the audit logs required for breach investigation. Document the vendor agreements and actual data handling for review by your healthcare attorney and medical director. A paid plan or custom build alone does not establish legal compliance.

    What happens if an AI concierge system accidentally captures protected health information?

    The practice is responsible for the exposure regardless of whether a human approved the capture. The mitigation is a configured refusal policy that redirects clients to a human team member the moment a message touches a diagnosis, condition, or treatment outcome outside the AI concierge system's trained scope.

    How often should a HIPAAn AI concierge system configuration be reviewed?

    For the first year, review the AI concierge system configuration, vendor terms, refusal patterns, and service-menu changes quarterly. After the system stabilizes, move to at least annual review, with immediate review when laws, vendor terms, or services change.

    Does HIPAA apply to wellness practices that do not bill insurance?

    HIPAA applies to any practice that transmits health information electronically in connection with covered transactions, which includes most modern booking and payment systems even when insurance is not billed. Cash-pay wellness practices should assume HIPAA exposure unless legal counsel has confirmed otherwise in writing.

    Ready to see what is actually broken in your business?