# HIPAA phone calls

> How phone calls work for healthcare workspaces. Airhug does not send patient calls through Twilio; the protected route uses Amazon Chime SDK and LiveKit under AWS's BAA. Current availability and what to do now.

Source: https://docs.airhug.ai/channels/hipaa-phone
Last updated: 2026-09-29

A healthcare workspace has HIPAA compliance on. That changes the phone path, because patient calls are protected health information (PHI) and every system that touches them needs a signed Business Associate Agreement (BAA).

## Why the phone path is different

- **Twilio has no BAA with Airhug.** Airhug does not carry HIPAA calls on Twilio.
- **The protected route is Amazon Chime SDK Voice Connector plus a self-hosted LiveKit media server, running on AWS.** AWS's BAA covers the AWS services. The AI voice model for HIPAA workspaces runs on Microsoft Azure under Microsoft's BAA.
- Call recordings go to encrypted storage in AWS.

```text
Caller → Chime phone number
       → Chime Voice Connector (TLS + SRTP)
       → LiveKit SIP → LiveKit room
       → Airhug voice agent (BAA-covered AI)
       → Recording to encrypted AWS storage
```

## Availability today

> [!WARNING]
> **Phone calls for healthcare workspaces are in limited availability.** The Chime and LiveKit route is built and being brought into production. AWS has to lift a restriction on Chime voice for Airhug's account before phone numbers, porting and calls can go live for everyone. Until it is live, do not tell patients that their calls are running on the protected route.

What this means for you:

- **Numbers.** Chime phone numbers and porting into Chime are not generally available yet. Contact [hello@airhug.ai](mailto:hello@airhug.ai) to be told when your workspace can be enabled.
- **Other channels.** Email runs on AWS mail services under AWS's BAA. Website chat runs on BAA-covered AI for healthcare workspaces. Texting for healthcare workspaces moves to AWS messaging and needs carrier registration first, which takes 1 to 4 weeks.
- **Pricing.** Healthcare pricing applies from the moment you choose a healthcare category. See [plans](https://docs.airhug.ai/billing/plans.md).

## How calls will work once live

- **Inbound only.** The AI answers inbound calls. The only outbound leg is transferring a caller to a staff member's phone number.
- **Warm transfer through LiveKit.** Chime does not support SIP REFER, so transfers are done by LiveKit bridging the staff member's call into the room. The [transfer rules](https://docs.airhug.ai/setup/call-handling.md) work the same as for standard workspaces.
- **Forwarding.** You can still forward your existing number to a Chime number. The [call forwarding](https://docs.airhug.ai/channels/call-forwarding.md) codes are the same.
- **Porting.** Moving a number into Chime has no carrier API, so Airhug files the port for you. You upload the letter of authorization and a copy of your bill. Progress shows as it does for standard ports.

## What this page does not promise

Airhug does not claim SOC 2 or third-party certification. HIPAA compliance means the systems that touch patient information run under signed BAAs and the workspace is treated as protected. See [security and privacy](https://docs.airhug.ai/help/security-and-privacy.md).
