Yes—a medical practice can use an AI chatbot without violating HIPAA. But the honest answer splits in two, and which half you're in decides both the risk and the price. A chatbot that answers general questions holds no patient information at all, and is about as fraught as a well-written FAQ page. A chatbot that touches information about an identifiable patient is a different project, with signed agreements and real engineering behind it. In our pricing, a custom chatbot runs $3,000–$10,000.
Most practices, it turns out, want the first kind and have been quoted for the second.
Where the HIPAA line actually falls
HIPAA protects health information that identifies someone. The test isn't whether a tool is "medical"—it's whether the tool handles information about an identifiable person that relates to their care, payment, or condition.
That means a chatbot answering "Do you take Blue Cross?" is not handling patient information. Nobody has been identified; nothing about anyone's health has been disclosed. The same bot, asked "I'm Jane Doe and my knee is swollen, should I come in?", now has a name and a symptom in the same sentence. Everything downstream of that message—where it's stored, who can read it, what the AI vendor does with it—is squarely inside the rules.
The design job is to know which side of that line each feature sits on, and to build the crossing deliberately rather than by accident.
What a chatbot can safely do without touching patient information
This is a longer list than most practices expect, and it covers the majority of what actually gets asked after hours:
- Hours, location, parking, and directions
- Which insurance plans you accept
- Whether you're accepting new patients
- What to bring to a first visit
- How to reach the patient portal, and what it does
- Where to find and download intake forms
- How to request records
- What to do in an emergency—which should always be "call 911," stated plainly and early
None of that requires knowing who is asking. Built this way, the bot is a fast, patient front door that never needs to store a conversation, and the compliance conversation stays short.
What changes the moment it does
Once the chatbot collects, stores, or transmits information about an identifiable patient, three things become non-negotiable.
A signed agreement with every vendor in the chain. A company handling patient information on your behalf is a business associate, and needs a Business Associate Agreement. That means the chatbot platform, and often the AI provider behind it, and the place the transcripts land. Ask a prospective vendor for their agreement in writing. A vendor who has never been asked, or who is vague about the AI model behind their product, has told you what you need to know.
Somewhere safe for the conversation to land. Transcripts are records. They need to be stored with access controls and retention that match how you treat everything else with patient information in it—not emailed to a shared front-desk inbox, and not left indefinitely in a vendor's dashboard because nobody set a policy.
Care about what else is on the page. Federal regulators have warned about analytics and advertising trackers on patient-facing pages. A chat widget sitting alongside a stack of marketing trackers is the situation that guidance is about.
What a practice chatbot should never do
Some boundaries are worth building in from the first day, whatever the vendor's demo suggests.
It should not give clinical advice, assess symptoms, or triage. Anything clinical routes to a person on your staff, quickly and obviously, with no attempt to answer first—the same boundary that belongs around automated appointment reminders.
It should not guess. A bot that invents an insurance plan you don't take, or a Saturday clinic you don't run, costs you more than the missed message would have. Good practice bots are built to answer from your actual information and to say "let me get someone" the rest of the time.
It should not quietly become the only door. There must be an obvious path to a human, and an unmistakable emergency instruction on every path.
What it costs
Off-the-shelf chatbot subscriptions typically run $20–$500 a month, and our general chatbot cost guide covers that market. The practice-specific catch: most of those products are built for retail, and the ones willing to sign an agreement covering patient information are a much smaller list.
A custom build in our pricing runs $3,000–$10,000, plus modest monthly running costs that any honest provider discloses up front. The compliance work isn't a separate line item or a license you buy—it's scoping time, careful engineering, and paperwork with vendors.
I'm not a lawyer, and this isn't legal advice. HIPAA carries real penalties, so make sure talking to your counsel—and getting a plan they're satisfied with—is part of any chatbot project.
The honest question: do you need one?
Before pricing anything, count what a bot would actually catch. Look at a week of after-hours voicemails and unanswered form submissions. If they're mostly hours, insurance, directions, and "are you taking new patients," a general-questions bot handles them and never touches patient information—the cheap, low-risk half of this article.
If they're mostly patients wanting to reschedule, the better buy is usually scheduling automation rather than a chatbot. And if your website gets very little traffic, a bot has nobody to talk to; the problem is upstream.
That sorting is most of what we do in automation work for practices: find the repetitive thing that's actually costing money, automate exactly that, and keep patient information handled the way the law expects. Our AI and automation service starts with a free conversation, and "you don't need a chatbot" is a real possible answer.