> ## Documentation Index
> Fetch the complete documentation index at: https://docs.autocalls.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# HIPAA Mode

> Designate individual sub-accounts as HIPAA accounts for healthcare clients

HIPAA mode turns a single sub-account into a healthcare-ready account. Once it is on, that account can only reach the vendors covered by a Business Associate Agreement, and the features that run through vendors without one are switched off.

<Note>
  HIPAA mode has to be unlocked for your platform first. Once it is, a **Enable HIPAA** action appears on every sub-account row in your **Users** table. Contact us if you do not see it and you have healthcare clients to onboard.
</Note>

## What changes on a HIPAA account

Everything below is enforced by the platform, not by policy. Your client cannot switch back to an uncovered vendor by editing an assistant, calling the API, or using the MCP connector.

| Area                      | On a HIPAA account                                                                                |
| ------------------------- | ------------------------------------------------------------------------------------------------- |
| Transcription             | Gladia only                                                                                       |
| Voices                    | ElevenLabs only                                                                                   |
| Language models           | Azure OpenAI only, including the realtime (speech-to-speech) models                               |
| Call recording            | Off by default on every assistant                                                                 |
| Phone numbers             | SIP trunk only — buying a number from the platform and linking a Twilio caller ID are unavailable |
| WhatsApp                  | Unavailable (senders, templates, campaigns and the text fallback)                                 |
| Messenger & Instagram     | Unavailable                                                                                       |
| Automation platform       | Unavailable                                                                                       |
| Two-factor authentication | Required, and cannot be switched off                                                              |

Assistants, calls, campaigns, leads, knowledge bases, mid-call tools, webhooks and the MCP connector all keep working as usual.

## Enabling it for a sub-account

1. Open the **Users** table in your administration panel.
2. Find the sub-account and click **Enable HIPAA**.
3. Read the confirmation dialog — it lists exactly what will change — and confirm.

The row then shows a **HIPAA** badge with the activation date. That date is the record of when the account became a designated HIPAA account, so keep it in mind when your client asks for their paperwork.

### Before you can enable it

The action refuses to continue while either of these is still on the account, and tells you what to remove:

* **Platform phone numbers.** Numbers bought through the platform run on a carrier without a BAA. Release them and connect the client's own carrier with a SIP trunk instead.
* **WhatsApp senders.** Delete them first.
* **Facebook / Instagram connections.** Delete them first.

## Assistants on a HIPAA account

Existing assistants keep working. The first time each one runs after activation, any uncovered provider is replaced with the covered equivalent for that call, so nothing has to be rebuilt by hand.

New assistants are built from the covered set automatically, in both the simple and the advanced editor:

* Where the language has an ElevenLabs voice, the assistant keeps the engine it would normally use, with Gladia for transcription and Azure OpenAI as the model.
* Where the language has no ElevenLabs voice, the assistant is created in speech-to-speech mode on the Azure realtime model, which speaks the language natively.

Call recording is switched off on every existing assistant at activation, and new assistants start with it off. Your client can turn it back on per assistant if they have the consent to record.

## Phone numbers

HIPAA accounts connect telephony through a **SIP trunk**, using the client's own carrier and their own agreement with that carrier. See the SIP trunk guides under Phone Numbers for the provider-specific steps.

## Turning it off

**Disable HIPAA** on the same row returns the account to the standard provider set and gives WhatsApp, Messenger, Instagram, number purchase, caller ID and the automation platform back. Existing assistants keep whatever settings they have at that point — including recording, if it was turned back on.
