Workflows

AI Is Answering Your Practice's Phone: The Call Workflow and Its Four Compliance Gates

Freed, Phreesia, and Hyro will all answer your phones now. But an inbound AI receptionist and an outbound AI caller are two different legal products — one is a HIPAA and recording-consent problem, the other is a TCPA problem worth $500 to $1,500 per call. Here is the full call workflow, the four gates where practices get hurt, and what these systems actually deflect.

By MedAI Directory · September 7, 2026

Your practice's phone is the last piece of the front office that nobody automated. Ambient scribes took the note. Portal AI took the inbox. But the phone kept ringing, and somebody kept picking it up.

That changed fast. Phreesia shipped VoiceAI in September 2025. Freed — best known for its ambient scribe — launched Front Desk in April 2026 at $149 per month per block of 250 calls, aimed squarely at single-site practices with one or two phone numbers. Hyro has been running voice agents inside multi-site health systems for years. The pitch is identical everywhere: the phone gets answered, 24/7, in any language, and your staff stop living on hold.

The pitch is mostly true. What nobody hands you is the workflow — what actually happens between the first ring and the note in your task queue, and the four points in that sequence where a voice agent creates legal exposure that a human receptionist never did.

This post is that workflow. It assumes you have already decided front-office AI is worth exploring; if you haven't, start with our guide to front-office AI and no-shows, which covers the ROI case. This one is about the call itself.

First: inbound and outbound are two different legal products

This is the single most important distinction in the category, and vendor marketing blurs it constantly because one product sells both.

The Telephone Consumer Protection Act governs calls you initiate. When a patient dials your office and an AI answers, the TCPA is not in play — your practice did not place a call. Nearly every compliance question about an inbound AI receptionist is a HIPAA question, a recording-consent question, or a state AI-disclosure question. It is not a robocall question.

The moment your agent dials out, everything changes. On February 2, 2024, the FCC adopted a Declaratory Ruling (FCC 24-17, released February 8, 2024, CG Docket No. 23-362) confirming that the TCPA's restrictions on an "artificial or prerecorded voice" cover AI-generated voices. The operative language: callers must obtain prior express consent from the called party before making a call that uses an artificial or prerecorded voice simulated or generated through AI technology.

So an AI voice agent that answers is one regulatory animal. The same agent configured to call patients back, run recall campaigns, or chase unconfirmed appointments is a different one. Many practices buy the first and switch on the second six weeks later without telling anyone.

Keep that split in mind through everything below.

The anatomy of an AI-answered call

Here is what a well-built inbound agent actually does, in order. Every vendor implements this same skeleton; they differ in how much of it they do well.

  • Ring and answer. The agent picks up on the first or second ring — the headline benefit, since it eliminates hold time by construction rather than by being fast.
  • Greeting and disclosure. A scripted opening that may or may not tell the caller they are talking to software.
  • Intent classification. The agent works out which of roughly six things the caller wants: book, reschedule, refill, billing question, records request, or clinical concern.
  • Identity verification. Before anything patient-specific is confirmed or disclosed, the agent has to establish who is on the line.
  • Action or capture. Either the agent completes the task in your system of record, or it captures a structured request for a human.
  • Escalation. Anything clinical, urgent, angry, or out-of-scope gets handed to a person — or doesn't, which is where practices get hurt.
  • Post-call summary. A structured note into a shared inbox, a task queue, or the EHR.
  • Follow-up. A callback, a text, a portal message. This is the step that quietly puts you back under the TCPA.

Four of those steps are compliance gates. Take them in order.

Gate 1: the greeting, and whether the bot has to confess

Two state laws bite here, and they bite differently depending on what the call is about.

California AB 3030 (Health and Safety Code § 1339.75, in effect since January 1, 2025) requires that when a health facility, clinic, physician's office, or group practice uses generative AI to produce patient communications pertaining to patient clinical information, the communication carries a disclaimer saying so plus clear instructions for reaching a human provider. For audio, the statute is specific: the disclaimer must be provided verbally at the start and the end of the interaction. Not once. Both ends.

The carve-out is where this gets practical. AB 3030 expressly excludes communications about "administrative matters, including, but not limited to, appointment scheduling, billing, or other clerical or business matters." So:

  • An agent that books, reschedules, confirms, and takes payment questions is handling administrative matters and falls outside AB 3030.
  • An agent that answers "should I be worried about this rash," relays lab results, or discusses medications has crossed into clinical information and owes the caller a verbal disclaimer at both ends of the call.

The statute's other exemption — communications "read and reviewed by a human licensed or certified health care provider" — is essentially unavailable to a real-time voice agent. Nobody reviews a live conversation before it happens. Violations by a physician fall under the jurisdiction of the Medical Board of California or the Osteopathic Medical Board.

Utah's AI Policy Act (now Utah Code Title 13, Chapter 77, as reshaped by SB 226 in 2025) works from the other direction. For general consumer interactions, disclosure is only required if the person asks. But for someone providing services in a regulated occupation — which covers licensed clinicians — prominent disclosure of generative AI use is required in high-risk interactions, and it must be given verbally at the start of a verbal interaction. The Utah Division of Consumer Protection can assess administrative fines up to $2,500 per violation.

Texas has its own layer through TRAIGA and SB 1188; we covered the full multi-state picture in our guide to state AI disclosure laws in healthcare.

What about federal disclosure? In August 2024 the FCC adopted a Notice of Proposed Rulemaking (FCC 24-84, CG Docket 23-362) that would define an "AI-generated call," require callers to disclose AI use at the start of each such call, and require AI disclosure at the point consent is obtained. Those are still proposals. The comment period closed in 2024 and the rules have not been finalized. Do not let a vendor tell you a federal AI-disclosure rule already exists; do not assume it never will.

The practical answer for most practices: have the agent identify itself as an automated assistant in the greeting regardless. It costs you three seconds, it satisfies every state regime at once, and callers who are told plainly tend to be less annoyed than callers who work it out at the ninety-second mark.

Gate 2: recording, which is not the same question as disclosure

Telling a caller they are talking to AI is not telling them you are recording. These are separate legal duties, and voice agents trigger both because most of them record and transcribe by default.

Eleven states clearly require all-party consent to record a phone call: California, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington. Another handful — Connecticut, Michigan, Oregon, Vermont — are mixed or unsettled enough that careful operators treat them as all-party too. In California, Penal Code § 632.7 reaches communications involving cell or cordless phones in any combination, which in 2026 is essentially every patient call.

That § 632.7 docket is where the litigation is going. Plaintiffs' firms that spent 2024 and 2025 on website session-replay claims have moved to AI-mediated call handling, on the theory that routing a caller to a generative voice agent that records, transcribes, and stores audio — for quality assurance, auditability, or model improvement — is a recording that needs consent the caller never gave. The emerging expectation is a dual disclosure: this call is recorded, and you are speaking with an AI.

Two things to nail down before go-live:

  • Gate the recording on the consent. The recording should start after the disclosure, and your vendor should be able to produce a per-call record proving it. "We say it in the greeting" is not the same as "we can show it for this call on this date."
  • Ask what is retained, and for how long. Answers vary enormously. Freed states plainly that Front Desk does not store patient recordings. Others keep audio for months. Retention is not only a privacy question — it is a discovery question, the same one we walked through for ambient scribes in our post on patient consent and recording laws. Audio you kept is audio that can be subpoenaed.

Gate 3: verification before any PHI leaves the system

A human receptionist verifies identity by instinct and by knowing the regulars. A voice agent verifies by whatever rules you configured, and it will follow them with perfect, indiscriminate consistency.

HIPAA's requirement is at 45 CFR § 164.514(h): before disclosing PHI, a covered entity must verify the identity of the person requesting it and that person's authority to have it, if either is not already known. There is no AI exception. Your vendor is a business associate — a voice platform processing patient audio is nowhere near the conduit exception — so a signed BAA that explicitly covers recordings, transcripts, and any use of the data for model training is table stakes. Our HIPAA primer for AI tools covers what that agreement needs to say.

The design question that matters: what is your agent allowed to say to an unverified caller?

Get this wrong in the permissive direction and the agent confirms to anyone who calls that Jane Doe has an oncology appointment Thursday at 2. Get it wrong in the restrictive direction and every caller gets an interrogation before the agent will book a physical. Sensible practices split the difference by tiering:

  • No verification needed: hours, location, directions, insurance plans accepted, general new-patient information.
  • Light verification (name plus date of birth): booking a new appointment, taking a callback request, general intake.
  • Strong verification: confirming or disclosing anything about an existing appointment, medication, balance, or result — and in many practices, this tier should simply route to a human.

Write the tiers down before configuration, not after the first complaint.

Gate 4: escalation, and the line the bot must not cross

Every serious deployment needs a bright line between capturing a clinical concern and responding to one. A voice agent taking down "caller reports chest pain, routing now" is doing intake. A voice agent telling that caller it is probably heartburn and offering Tuesday at 3 is practicing medicine badly, at scale, with a transcript.

Liability does not follow the software. Practices and clinicians remain responsible for care decisions; institutions that deploy poorly validated tools without governance add their own exposure on top. No vendor indemnity changes who the plaintiff names.

Build the escalation path explicitly:

  • Define the urgent-symptom triggers and what happens when one fires. Phreesia's model routes urgent after-hours needs straight to on-call physicians through a secure mobile app while capturing routine requests for the next business day — that is the shape to copy.
  • Give every caller an unconditional exit. "Let me talk to someone" must work on the first attempt, at any point, with no loop back into the menu.
  • Decide what happens when the agent fails. Not when the caller escalates — when the agent silently misclassifies. Who reviews the transcripts? On what cadence? A weekly review of the ten longest and ten shortest calls surfaces more problems than any dashboard.
  • Watch the accessibility edge. Callers with speech differences, heavy accents, hearing impairment, or relay services are exactly the population a voice agent handles worst, and your effective-communication obligations do not pause because the receptionist is software. A human fallback that triggers on repeated recognition failure is not a nice-to-have.

And then the agent calls back — welcome to the TCPA

Here is the switch that catches practices. The inbound agent works. Somebody asks whether it can also confirm tomorrow's appointments, or chase the twelve patients who no-showed last month. It can. And now you are placing AI-voice calls, and FCC 24-17 says those are artificial-voice calls requiring prior express consent.

The good news is that healthcare has real exemptions, and they are more generous than most industries get.

For wireless numbers, 47 CFR § 64.1200(a)(9)(iv) exempts calls from a HIPAA covered entity or its business associate that deliver a health care message — the rule names appointment and exam confirmations and reminders, wellness checkups, hospital pre-registration instructions, pre-operative instructions, lab results, post-discharge follow-up intended to prevent readmission, prescription notifications, and home healthcare instructions. The conditions are strict:

  • One message per day per patient, maximum three voice calls or texts combined per week.
  • Free to the end user — not charged against the patient's plan minutes or texts.
  • An easy opt-out inside every message, honored immediately.

For residential lines, § 64.1200(a)(2) permits health care messages from covered entities and business associates, and § 64.1200(a)(3)(v) allows them without prior written consent subject to the same one-per-day, three-per-week ceiling plus opt-out.

What is emphatically not covered: marketing. Service-line promotions, aesthetic offers, cash-pay program pitches, "we miss you" reactivation blasts. Those are telemarketing and need prior express written consent — and with an AI voice, the exposure is $500 to $1,500 per call in statutory damages with no aggregate cap.

That exposure is not theoretical. In Finley v. Altrua Ministries (N.D. Ill., filed April 2025), a plaintiff alleged he received prerecorded messages using AI-generated voice on his cell phone from a healthcare-adjacent marketer, without consent, intended for someone else. The case reached a tentative settlement in early 2026 covering calls placed over a nine-day window in December 2024. A nine-day campaign.

Two more mechanics to configure on day one:

  • Revocation. Under § 64.1200(a)(10), a patient may revoke consent by "any reasonable method," including saying stop, quit, or end — and you must honor it within a reasonable time not exceeding ten business days. Your agent must recognize a spoken opt-out mid-call, not just a texted STOP.
  • Cross-channel revocation. The rule that a revocation on one topic applies to all future robocalls and robotexts from that caller on unrelated matters has been under a limited waiver; the FCC's Consumer and Governmental Affairs Bureau issued a second extension in January 2026 pushing compliance to January 31, 2027. Build for it now rather than retrofitting a cross-channel suppression list in a panic.

What these systems actually deliver

Set expectations against real numbers, not sales decks.

Vendors typically quote 60–80% call containment. That figure is usually measured on scheduling calls alone. Across a full inbound mix — scheduling plus billing plus refills plus records plus clinical — 30–50% deflection is the honest range, because your call mix caps you long before the technology does. Seventy percent containment on scheduling is only 28% total deflection if scheduling is 40% of your volume.

The published deployments are consistent with that:

  • Intermountain Health, running Hyro across web, mobile, and call centers, reported an 85% reduction in call abandonment, a 79% improvement in speed to answer, 91% routing accuracy, and 44% of repetitive calls automated. That last number is the honest one. They also found 27% of inbound patient inquiries arrived outside business hours — the volume a phone tree was never answering at all.
  • Freed reports Front Desk handling 79% of calls autonomously in its own case data, with a 60% reduction in after-hours calls.
  • Phreesia cites a urology practice whose call abandonment rate dropped to zero after VoiceAI.

Treat all vendor-published figures as vendor-published. But notice the pattern: the metrics that move hardest are abandonment, wait time, and after-hours coverage — not headcount. The realistic case for a small practice is that the phone stops being a bottleneck and stops leaking patients at 6pm, not that you eliminate a front-desk role.

Questions to ask before you sign

  • Will you sign a BAA that explicitly covers call audio, transcripts, and any model-training use?
  • Are recordings retained? For how long? Can we turn retention off entirely?
  • Can you produce a per-call artifact showing the disclosure was delivered before recording started?
  • Can the greeting be configured per state, so California callers get the start-and-end disclaimer?
  • How is caller identity verified, and what can the agent disclose at each verification tier?
  • What triggers escalation to a human, and what happens after hours when no human is there?
  • Does "let me talk to someone" work on the first request, from any point in the call?
  • If we enable outbound: how do you track consent, honor spoken opt-outs, and enforce the one-per-day/three-per-week healthcare limits?
  • What happens when speech recognition fails repeatedly on one caller?

The bottom line

An AI voice agent is the highest-leverage front-office tool available to a small practice right now, and the least forgiving. It is high-leverage because inbound phone volume is the one workload where being answered instantly is most of the value. It is unforgiving because it speaks in your name, to your patients, about their health, hundreds of times a week, with perfect consistency — including perfectly consistent mistakes.

The practices that do this well treat it as a workflow project with four compliance gates, not a software purchase. Disclose in the greeting. Gate the recording on consent and know what is retained. Tier what the agent may say before identity is established. Draw a hard line at clinical judgment and route across it. Then, before anyone switches on outbound, read the TCPA section again.

Comparing vendors? Start with AI patient communication tools and AI scheduling in the directory — including Hyro, Phreesia, Klara, and Notable — or narrow to patient communication tools for small medical clinics and scheduling tools for small clinics. If the portal inbox is your bigger fire, our patient-message inbox workflow covers that channel instead.


This article is informational only and is not legal or medical advice. TCPA, HIPAA, state recording-consent, and state AI-disclosure requirements change frequently and vary by state and by fact pattern — confirm current obligations with qualified counsel before deploying a voice agent, and verify all product capabilities, pricing, and data-handling practices directly with the vendor.

Tags
ai-voice-agentsai-receptionisttcpapatient-communicationfront-officecall-recordinghyrophreesiacompliance2026