Compliance Answer

Is Retell AI HIPAA Compliant?

A free BAA on every plan, and a privacy policy that tells a different story about training.

The Verdict

Retell AI signs BAAs on all plans at no fee, including pay-as-you-go, and requires one before PHI flows. The trap is elsewhere, Retell's privacy policy grants itself the right to use customer data to train its AI models by default, and the vendor's own enterprise guide advises negotiating an explicit no-training clause.

BAA yes; default data terms, read them.

Fact table (sources checked 2026-07-12)
BAAAll plans, self-serve signing, no fee
Trains on your dataYes by default per privacy policy; negotiate no-training in the DPA
Enterprise controlsPer-agent retention (1 day to 2 years), storage scoping, signed-URL recording access; SOC 2 Type I and II
Sourcesdocs.retellai.com/general/compliance; retellai.com privacy policy and compliance blogs

The Catch

This is the directory's clearest example of why the training column exists. The compliance page and the privacy policy tell two different stories, and the contract is where they get reconciled.

If Your Staff Use It

Retell is builder infrastructure for voice agents, so usage means someone is building patient-facing automation. That is a governance-committee item, not a tool-list item.

The Policy Question Comes Before The Build Question

Whether it is Retell AI or another voice-agent platform, the first control is a policy your staff can follow. Generate a healthcare-ready draft in minutes, then decide which tools earn a place in it.