Selling voice AI into healthcare or running outbound campaigns creates obligations that no dashboard switch can remove. HIPAA applies to protected health information. The Telephone Consumer Protection Act, or TCPA, governs certain calls and texts, including calls that use artificial or prerecorded voices.
VoiceAIWrapper can support an agency's compliance work at the platform layer. It does not make the agency's entire service compliant by itself. The agency must map every system that receives sensitive data, sign the required contracts, configure each provider correctly, document consent, and keep evidence of those controls.
This guide compares the published positions of Vapi, Retell AI, and ElevenLabs Agents. It also explains where VoiceAIWrapper's HIPAA framework, TCPA framework, and subprocessor list fit.
This page provides operational information, not legal advice. Have qualified counsel review your use case, consent language, contracts, call flows, and record-retention policy.
First, separate HIPAA from TCPA
HIPAA focuses on how covered entities and their business associates handle protected health information, often shortened to PHI. A Business Associate Agreement, or BAA, defines permitted data use and each party's safeguards. A BAA is necessary in many healthcare workflows, but it is not proof that the full deployment is compliant.
TCPA obligations depend on the type of call, the technology used, the recipient, and the purpose of the communication. In February 2024, the US Federal Communications Commission confirmed that AI-generated voices fall within the TCPA's restrictions on artificial or prerecorded voice calls. The caller still needs the applicable consent and must follow other federal and state requirements.
These regimes can overlap. A healthcare appointment reminder can involve PHI and telephone-consent rules at the same time. Treat them as separate workstreams in the launch checklist.
Provider comparison
Provider | HIPAA and BAA position | Published security posture | TCPA controls or guidance | What the agency must verify |
|---|---|---|---|---|
Vapi | Vapi says customers must sign a BAA before enabling HIPAA mode. Its documentation places HIPAA on Enterprise or a separate add-on and requires HIPAA-eligible providers. | Vapi states that it is SOC 2 Type II compliant. | Vapi publishes TCPA consent guidance and an Enterprise recording-consent feature. | Confirm plan eligibility, sign the BAA, enable HIPAA mode, select compliant downstream services, and document the required call consent. |
Retell AI | Retell says it supports HIPAA use cases and lets customers self-sign a BAA and DPA through its compliance portal. | Retell states that it holds SOC 2 Type I and Type II reports. | Retell publishes an outbound voice AI TCPA playbook and platform guidance. | Sign the required agreements, verify every connected model and telephony service, configure retention, and have counsel validate outbound workflows. |
ElevenLabs Agents | ElevenLabs states that BAAs are limited to Enterprise customers. Its HIPAA configuration requires Zero Retention Mode and restricts the language models used in regulated workflows. | ElevenLabs states that it maintains SOC 2 Type 2 controls. | ElevenLabs documents consent, do-not-call, calling-window, and recordkeeping considerations. | Confirm Enterprise eligibility, sign the BAA, enable the required retention setting, use permitted models, and implement consent and suppression controls. |
Provider claims and plan terms change. Verify them directly before processing PHI or launching calls. Read the official Vapi HIPAA documentation, Vapi TCPA consent guidance, Retell AI compliance documentation, Retell AI TCPA playbook, ElevenLabs HIPAA documentation, and ElevenLabs TCPA documentation.
What VoiceAIWrapper covers
VoiceAIWrapper sits between the agency, its clients, and the connected voice AI providers. Its platform controls include account access, branded client workspaces, provider connections, client billing tools, and activity records. Review the current VoiceAIWrapper features, VoiceAIWrapper security policy, and current provider and data-processor list when you map the data flow.
A VoiceAIWrapper Business Associate Agreement is available only after a paid Pro subscription has been activated. It is not available during the free trial or on Growth or Scale. The agreement covers the VoiceAIWrapper platform layer. It does not replace a required BAA with Vapi, Retell AI, ElevenLabs, a telephony provider, a model provider, or the agency's healthcare client. Review the HIPAA-compliant voice AI page for agencies for the commercial platform requirements.
This is a shared-responsibility model. VoiceAIWrapper is responsible for its defined platform controls. The agency remains responsible for the full client solution, including provider selection, account configuration, consent, data minimization, retention, staff access, contracts, monitoring, and incident procedures.
HIPAA launch checklist for agencies
Draw the complete data flow, from the caller through telephony, the voice AI provider, language models, storage, integrations, VoiceAIWrapper, and the client system.
Identify where PHI can enter, appear in logs, remain in recordings, or pass to another service.
Use paid Pro and complete the VoiceAIWrapper BAA before PHI enters the platform.
Sign a separate BAA with every provider that handles PHI when one is required.
Enable each provider's HIPAA or zero-retention settings. A signed agreement without the required configuration is not enough.
Apply least-privilege access, multi-factor authentication, and an offboarding process across the agency and client accounts.
Set recording, transcript, log, and backup retention to the shortest period the use case permits.
Document incident contacts, notification duties, and evidence-retention procedures before launch.
Run a test with synthetic data. Do not use real PHI until the contracts and controls pass review.
For plan limits and the Pro requirement, compare VoiceAIWrapper plans. For provider-specific setup, review the Vapi white-label page and Retell AI white-label page.
TCPA launch checklist for agencies
Classify the call type, purpose, recipient, dialing method, and voice technology with counsel.
Capture the required consent before the call. Store the consent source, wording, timestamp, scope, and revocation status.
Scrub the applicable federal, state, and internal do-not-call lists before each campaign.
Enforce permitted calling windows using the recipient's local time, not the agency's time zone.
Identify the calling party clearly and provide a working opt-out path.
Process revocations and opt-outs across every connected system without delay.
Keep the campaign brief, script version, consent evidence, suppression results, call logs, and complaint handling record.
Test calls, transfers, voicemail behavior, and failure paths before increasing volume.
Read the VoiceAIWrapper TCPA framework before an outbound launch. Also check reliability and provider status on the voice AI uptime page, because retries and failover behavior can change how a campaign behaves.
A practical review before launch
Do not ask only whether a provider is "HIPAA compliant" or has "TCPA features." Ask whether the exact plan, configuration, model, telephony route, retention mode, contract chain, and client workflow meet the requirements for this deployment.
A safe review produces evidence: a data-flow diagram, signed agreements, configuration screenshots, consent records, access lists, retention settings, test results, and named owners for incidents and opt-outs. If one layer cannot supply the needed evidence, stop PHI processing or outbound calling until the gap is resolved.
Browse more voice AI insights and implementation guides before planning the client rollout.
Need the platform layer for a regulated client?
Compare Growth, Scale, and Pro. HIPAA workloads require a paid Pro subscription and separate provider agreements.
Frequently asked questions
Does VoiceAIWrapper make my agency HIPAA compliant?
No. VoiceAIWrapper can cover its defined platform layer under a BAA after paid Pro activation. Your agency must still sign any required agreements with the client and each provider, configure the full system correctly, train staff, and maintain its own compliance program.
Can I process PHI on the $79 Growth plan?
No. VoiceAIWrapper's BAA is not available on Growth, Scale, or during the free trial. Do not process PHI through VoiceAIWrapper until a paid Pro subscription is active and the BAA process is complete.
Do I need separate BAAs with Vapi, Retell AI, or ElevenLabs?
If those services handle PHI in your deployment, you may need separate agreements with them. VoiceAIWrapper's BAA applies only to the VoiceAIWrapper platform layer and does not extend another provider's contractual coverage.
Are AI-generated voices covered by the TCPA?
The FCC confirmed in February 2024 that AI-generated voices fall within the TCPA's restrictions on artificial or prerecorded voice calls. The consent standard and other obligations depend on the call and jurisdiction. Ask qualified counsel to review the campaign.
Is a SOC 2 report the same as HIPAA compliance?
No. SOC 2 assesses controls against selected trust-services criteria. HIPAA creates legal duties for covered entities and business associates handling PHI. A provider can have a SOC 2 report and still require a separate BAA and HIPAA-specific configuration.
What should an agency keep as launch evidence?
Keep the data-flow map, signed agreements, provider configurations, access list, retention policy, consent records, suppression checks, test results, script version, and incident contacts. Match the evidence to the actual systems used for each client.
Suggested author bio: Raj Baruah is the founder of VoiceAIWrapper, where he works with agencies building and operating branded voice AI services across multiple providers.
Like this article? Share it.





