Short answer
Yes, a dental office can use an AI receptionist for booking, reminders and common questions, but the vendor handles patient information on the practice’s behalf, so the contract matters as much as the software. In the United States, a vendor that creates, receives, maintains or transmits protected health information for a covered dental practice is a business associate under HIPAA and must sign a business associate agreement with the terms set out in 45 CFR 164.504(e). In Canada, the practice stays responsible for information it sends to a vendor and must protect it by contract under PIPEDA, unless a provincial law applies instead: Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia have health information laws recognized as substantially similar, and Quebec clinics fall under a health information act that requires specific contract clauses and a public register of technology products. This guide explains which rule applies where, what to put in the contract, how to keep the receptionist away from clinical data, and twelve questions to ask any vendor. It is general information, not legal advice.
The short answer: which rule applies to your practice
The first question is not “is this tool compliant?” but “which law governs the patient information it will touch?”. The answer depends on where the practice is and how it is organized. A vendor badge does not settle it: your practice remains responsible under every regime below.
| Where the practice is | Main rule for patient information | What it means for an AI receptionist |
|---|---|---|
| United States, practice that is a HIPAA covered entity | HIPAA Privacy Rule | The vendor is a business associate if it handles protected health information for you; a business associate agreement is required (45 CFR 164.504(e)). |
| Canada, most provinces and the territories | PIPEDA | You stay accountable for information sent to the vendor and must ensure comparable protection by contract (Schedule 1, principle 4.1.3). |
| Ontario, New Brunswick, Newfoundland and Labrador, Nova Scotia | Provincial health information law, recognized by the federal Privacy Commissioner as substantially similar to PIPEDA | Check the provincial act and regulator; PIPEDA can still apply to information that crosses provincial or national borders. |
| Alberta, British Columbia | Provincial private-sector privacy law (and provincial health law where it applies) | Check with the provincial privacy commissioner which act covers your practice. |
| Quebec, clinic where dentists practise on their own account | Act respecting health and social services information (CQLR c. R-22.1) | Written vendor contract with the clauses of s. 77, and the tool listed in the clinic’s public technology register (s. 107). |
Summary by ZeniTech from 45 CFR 160.103 and 164.504 (eCFR), PIPEDA Schedule 1, the Office of the Privacy Commissioner of Canada’s page on provincial laws, and CQLR c. R-22.1, read on October 2, 2026. Not legal advice.
Is a booking request health information?
Often, yes. Under HIPAA, individually identifiable health information includes demographic information collected from an individual that is created or received by a health care provider and relates to the provision of health care to that individual, when it identifies the person or could reasonably be used to identify them (45 CFR 160.103). A name and phone number attached to “new patient, cleaning, Thursday 4 pm” at a dental practice fits that description.
Quebec’s act says the same thing in its own words: a name, date of birth or contact details become health and social services information when attached to health information or collected to register or take charge of the person (s. 2). And the clinic is still considered to hold the information when it entrusts its storage to a third party (s. 5).
Practical consequence: treat every conversation the receptionist has with a patient as patient information, not as marketing data.
What a HIPAA business associate agreement must contain
A vendor that creates, receives, maintains or transmits protected health information on behalf of a covered entity, other than as a member of its workforce, is a business associate (45 CFR 160.103). The contract with it must, among other things (45 CFR 164.504(e)):
- Set out the permitted and required uses and disclosures of protected health information, and not allow anything the practice itself could not do.
- Require the vendor not to use or further disclose the information beyond the contract or the law.
- Require appropriate safeguards, including the Security Rule for electronic protected health information.
- Require the vendor to report any use or disclosure not provided for by the contract, including breaches of unsecured protected health information.
- Require any subcontractor that handles the information to agree to the same restrictions; for an AI receptionist, that usually means the telephony, text messaging and language model providers behind it.
- Make the information available for patient access, amendment and accounting of disclosures.
- At termination, return or destroy the information if feasible, keeping no copies.
- Allow the practice to terminate the contract if the vendor violates a material term.
Summary of 45 CFR 164.504(e)(2) read on eCFR on October 2, 2026. Not legal advice.
In Canada: accountability stays with the practice
PIPEDA’s first principle makes an organization responsible for personal information in its possession or custody, including information transferred to a third party for processing, and requires it to use contractual or other means to provide a comparable level of protection while the third party processes it (Schedule 1, principle 4.1.3).
The Office of the Privacy Commissioner explains that PIPEDA does not prohibit transferring information to an organization in another jurisdiction for processing, that the transferring organization remains accountable, and that a contract cannot override the laws of a foreign jurisdiction. Ask where each subprocessor stores and processes the data, and tell patients in your privacy notice.
Where a provincial law applies instead, the same logic generally holds: the practice chooses the vendor, writes the contract and answers to its regulator. In Quebec, the health information act goes further and voids a vendor contract that lacks the clauses of section 77.
Keep the receptionist away from clinical data
The simplest privacy measure is to give the AI receptionist less to protect. Scheduling needs very little.
| Information | Does the receptionist need it? | Where it should stay |
|---|---|---|
| Name, phone, email | Yes, to book and confirm | Receptionist and CRM, with a retention period |
| Date of birth, new or existing patient | Often, to find or open the file | As little as your intake sheet requires |
| Type of appointment (exam, cleaning, emergency) | Yes, to pick the right slot | Short, closed choice; no free-text symptoms |
| Insurance yes or no | Sometimes, to tell the patient what to bring | No policy numbers in chat |
| Symptoms, medical history, medications | No | Your practice software, collected by your team |
| Charts, X-rays, treatment plans | No | Your practice software |
Grid by ZeniTech to illustrate data minimization; adapt it with your privacy officer.
Twelve questions to ask any AI receptionist vendor
- 1. United States: will you sign our business associate agreement, or show us yours, before we share any patient data?
- 2. Quebec: how does your contract answer each clause of section 77 of the health and social services information act?
- 3. Which subcontractors touch the data (telephony, text messaging, language models, hosting), and are they bound by the same terms?
- 4. Are conversations or recordings ever used to train your models or anyone else’s?
- 5. In which countries is the data stored and processed?
- 6. How long are conversations, recordings and transcripts kept, and can we set that period?
- 7. Who on your side can read our conversations, and is access logged?
- 8. How fast will you tell us about a security incident, and how?
- 9. Can we limit exactly what the receptionist asks and stores?
- 10. How do you stop it from giving clinical advice, and can we review every conversation?
- 11. What happens on an emergency call, and who writes that protocol?
- 12. When we leave, how do we get our data back, and how do you prove it was deleted?
Reminder and recall texts
Canada: under CASL, a message that solely confirms a transaction the patient already agreed to, such as a booked appointment, does not need consent (s. 6(6)(b)). A patient who bought a service from the practice in the past two years has an existing business relationship with it, which gives implied consent for recall reminders (s. 10(10)(a)). Every commercial message must identify the practice and include an unsubscribe mechanism (s. 6(2)).
United States: the FCC treats text messages as calls under the Telephone Consumer Protection Act. Ask for the patient’s agreement to receive texts when they book and confirm federal and state rules with counsel.
In both countries, keep texts neutral: the practice name and the appointment time, never the reason for the visit.
What ZeniTech does, and what it does not claim
Luna is ZeniTech’s AI receptionist for dental clinics. According to her page, she answers the phone with an AI voice and replies to texts and website messages, books into the slots your clinic defines, sends confirmations and reminders, fills cancellations from the waitlist and sends recall reminders. She never gives medical advice or a diagnosis; clinical questions go to your team, and anyone in danger is directed to 911 or the local emergency number. Clinical records stay in your practice management software, every conversation can be reviewed, and your data is never used to train a third party’s model.
ZeniTech does not claim HIPAA, PHIPA or any other compliance or certification. Before you sign, we put in writing what Luna stores and where it goes, so your privacy officer or advisor can decide whether it fits your obligations. Pricing is a one-time setup, then a monthly plan; the full price list is on zenitech.dev/en/pricing.
Features from zenitech.dev/en/ai-agents/dental-clinics, read on October 2, 2026. Prices are published on zenitech.dev/en/pricing.
Frequently asked questions
Can a dental office use an AI receptionist under HIPAA?
Yes, if the vendor is treated as what it is. A vendor that creates, receives, maintains or transmits protected health information for a covered dental practice is a business associate, and HIPAA requires a written business associate agreement that limits use and disclosure, requires safeguards and breach reporting, binds subcontractors and covers return or destruction of the data. Ask for it before sharing any patient data.
Does an AI receptionist vendor need to sign a BAA?
If it handles protected health information on behalf of a covered practice, yes: it meets the definition of a business associate in 45 CFR 160.103. That usually includes call recordings, transcripts and booking details. The agreement must also flow down to its subcontractors, such as the telephony and language model providers it uses.
What privacy law applies to a dental clinic’s AI receptionist in Canada?
It depends on the province. PIPEDA applies in most provinces and the territories. Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia have health information laws recognized as substantially similar for personal health information; Alberta, British Columbia and Quebec have their own private-sector laws, and Quebec clinics of professionals fall under its health and social services information act. In every case, the practice remains responsible for what the vendor does with the data.
Is the name and phone number of a patient who books an appointment health information?
Often, yes. Under HIPAA, demographic information received by a health care provider and related to the provision of care is individually identifiable health information when it identifies the person. Quebec’s act says a name or contact details become health information when attached to health information or collected to take charge of the person. Treat booking conversations as patient information.
What should a dental AI receptionist never collect?
Anything scheduling does not need: symptoms in free text, medical history, medications, insurance policy numbers, charts or X-rays. Those stay in your practice software and are collected by your team. A receptionist that asks closed questions (new patient, type of appointment, preferred slot) has much less to protect.
Can patient conversations be processed outside Canada?
PIPEDA does not prohibit it, but the practice stays accountable and must ensure comparable protection by contract, and the Privacy Commissioner notes a contract cannot override foreign law. Quebec’s health information act is stricter: before a vendor contract that sends information outside Quebec, the clinic needs a privacy impact assessment showing adequate protection (s. 78). Ask every vendor where each subcontractor stores and processes the data.
Are appointment reminder texts legal?
Generally yes. In Canada, CASL does not require consent for a message that only confirms an appointment the patient agreed to, and a purchase in the past two years gives implied consent for recall reminders; each commercial message needs the practice’s identification and an unsubscribe option. In the United States, texts are calls under the TCPA, so collect the patient’s agreement to texts when they book. General information, not legal advice.
Is ZeniTech’s AI receptionist HIPAA or PHIPA compliant?
ZeniTech does not claim HIPAA, PHIPA or any other compliance or certification. Luna handles scheduling and general questions, clinical records stay in your practice software, every conversation can be reviewed and your data is never used to train a third party’s model. Before you sign, we put in writing what Luna stores and where it goes, and your privacy officer decides.
Related
Free consultation
Get a fixed price for your project in 30 minutes.
We look at what the project has to achieve, tell you what it costs, and tell you when you do not need it.
Book a call →+1 581-748-7017Sources
- eCFR: 45 CFR 160.103, definitions (business associate, covered entity, individually identifiable health information)
- eCFR: 45 CFR 164.504(e), business associate contracts
- Justice Canada: PIPEDA, Schedule 1 (principle 4.1.3)
- Office of the Privacy Commissioner of Canada: guidelines for processing personal data across borders
- Office of the Privacy Commissioner of Canada: provincial laws that may apply instead of PIPEDA
- LégisQuébec: Act respecting health and social services information (CQLR c. R-22.1)
- Justice Canada: Canada’s Anti-Spam Legislation (S.C. 2010, c. 23)
- FCC Enforcement Advisory No. 2016-06: text messages and the TCPA