Security & Compliance
Vapi vs Retell AI HIPAA Compliance and SOC 2 Details 2026
Sep 22, 2026
Part of AI voice agent for healthcare

Vapi vs Retell AI on HIPAA compliance and SOC 2 in 2026: what each publishes, what a BAA and an audit report actually prove, and what compliance costs.
Teams shortlisting Vapi and Retell AI usually start with the per-minute rate and meet compliance later, which is the wrong order if a single caller might mention a symptom, a prescription or a test result. The moment protected health information crosses a voice platform, the vendor becomes a business associate and the paperwork stops being a formality. This piece compares what each platform publishes, then covers what HIPAA and SOC 2 prove on their own, which is less than most procurement decks assume.
Everything quoted here about either vendor comes from their own published pages on the date shown. Pricing and posture in this category move quickly, so treat the figures as a starting point for your own diligence rather than a substitute for it. Our full Vapi vs Retell AI pricing comparison carries the same sources.
Vapi vs Retell AI HIPAA compliance and SOC 2 details 2026
The structural difference is how each platform sells compliance. One prices it as a visible line item you can add to a self-serve plan. The other folds it into an enterprise contract you have to negotiate. Neither approach is better in the abstract, but they produce very different budgets and very different buying cycles.
| Published position | Vapi | Retell AI | Centricall |
|---|---|---|---|
| HIPAA | Listed as a $2,000 per month add-on on the Build and Scale tiers | Available with a signed BAA on the enterprise plan, custom pricing | Included in the deployment, with a BAA signed for healthcare clients |
| Zero data retention | Listed as a separate $1,000 per month add-on | Not published as a priced line item | Retention set per deployment, including no-retention configurations |
| SOC 2 | Not published as a priced add-on | Pricing page states SOC 2 certification | Request the current report and scope directly |
| Route to a signed BAA | Buy the add-on, then request the agreement | Enterprise sales conversation | Part of onboarding for regulated clients |
| Where the data can live | Vendor cloud | Vendor cloud | Vendor cloud, your cloud, or your own server |
Two practical consequences follow. First, a low headline per-minute rate stops being the deciding number once a $2,000 monthly add-on lands on top, because that fee is flat and it arrives before your first patient call. Second, custom enterprise pricing means you cannot size the budget from a web page at all, so the diligence has to happen before the forecast rather than after it.
What HIPAA actually requires from a voice AI vendor
There is no government certification for HIPAA. No agency inspects a voice platform and issues a badge, so a vendor describing itself as HIPAA certified is describing its own opinion. What the rule does require is concrete, and it is worth knowing the shape of it before the sales call.
- A signed business associate agreement: a vendor that creates, receives, maintains or transmits protected health information on your behalf is a business associate, and the BAA is the contract that binds it. No BAA means no lawful handling of patient data, whatever the marketing page says.
- Safeguards across three categories: administrative, physical and technical. In a voice deployment that means documented access control, encryption in transit and at rest, audit logging, and a workforce policy covering who may open a recording.
- Minimum necessary use: the agent should collect and expose only what the task needs. A scheduling agent rarely needs clinical detail, and a transcript that captures it anyway widens your exposure for no operational gain.
- Breach notification duties that flow downstream: your vendor's incident becomes your notification obligation. Ask what the vendor commits to in hours, in writing, rather than what it hopes to do.
- Subprocessor transparency: most voice platforms chain a speech-to-text model, a language model, a text-to-speech voice and a telephony carrier. Every one of those touches the audio, so every one has to sit inside the same compliance boundary.
That last point is the one developer-first platforms hand back to you. When you bring your own model keys, you are also bringing your own compliance obligations for that provider, and an agreement with the orchestration layer does not extend to a model endpoint you wired in yourself.
What SOC 2 proves, and what it does not
SOC 2 is an attestation report produced by an independent accounting firm against the AICPA trust services criteria. It is evidence of process, not a compliance guarantee, and reading one properly means asking three questions.
- Type I or Type II?: Type I describes controls as designed at a single point in time. Type II tests whether they operated across a period, usually three to twelve months. Only the second tells you the controls survived contact with a real year.
- Which criteria are in scope?: security is mandatory. Availability, processing integrity, confidentiality and privacy are optional. A report scoped to security alone says nothing about the privacy commitments a healthcare buyer cares about.
- What sits inside the system boundary?: a report can cover a company's core platform while excluding the exact subprocessor handling your audio. Read the system description and the exceptions, not the logo.
SOC 2 and HIPAA also answer different questions. SOC 2 asks whether a vendor runs a disciplined security program. HIPAA asks whether a specific class of data is handled lawfully. A platform can hold a clean Type II report and still be the wrong place for patient data if no BAA is on offer. Treat the report as a floor for vendor quality and the BAA as the gate for patient data.
Where voice adds compliance surface that text does not
A voice deployment creates artifacts a chat integration never produces, and each one is another copy of patient data living somewhere.
- The audio recording: a voiceprint is treated as biometric data in several jurisdictions, and consent rules for recording a call vary by state. Decide whether you need the audio at all, or whether a transcript is enough.
- The transcript: usually the richest artifact, and the one most likely to be piped into analytics, a CRM and a model prompt within the same minute.
- The call summary: model-generated text derived from patient data is still patient data. If summaries land in a shared inbox or a sales dashboard, the boundary has already moved.
- Model training and retention: ask explicitly whether call data trains anything, and how long it is retained by every provider in the chain. Zero data retention is the setting that makes this question simple, and it is priced separately on at least one of these platforms.
- Telephony metadata: numbers, timestamps and call durations tied to a clinic can identify a patient without a word of content.
Our security checklist for connecting a voice agent walks through the access scopes, retention windows and audit trails worth settling before any of this touches production.
What compliance costs on top of the per-minute rate
Model the flat fees before the usage fees, because at low volume the flat fees dominate. On published rates verified August 12, 2026, Vapi's HIPAA add-on is $2,000 per month and zero data retention is a further $1,000, which is $36,000 a year before a single minute of audio. A practice running a few hundred minutes a month would pay more for the compliance add-ons than for the conversations. Retell's enterprise plan is custom priced, so the only honest answer there is that you have to ask.
That arithmetic is why a compliance-ready managed platform or an owned deployment often wins in regulated verticals. When an AI voice agent for healthcare arrives with the BAA, the retention controls and the escalation rules already in place, compliance stops being a separate subscription and becomes part of the product.
A diligence checklist for regulated buyers
- Will you sign a BAA, and on which plan?: get the answer in writing, with the price attached, before you build anything.
- Send the current SOC 2 report under NDA: check the type, the period, the criteria in scope and the exceptions section. Nobody reads the exceptions; they are the interesting part.
- List every subprocessor that touches audio: speech, model, voice, telephony and storage. Ask which of them sit under your agreement.
- Confirm retention and deletion: default retention, whether you can set it to zero, what deletion means technically, and how long backups keep a copy.
- Confirm data residency: which region processes the call, and whether that still holds when the platform fails over.
- Ask whether call data trains models: for the platform itself and for every model provider behind it.
- Get the breach notification window: in hours, in the contract.
- Test the escalation rules: a clinical question should reach a person, never an answer. Check that the rule exists and that it fires.
When owning the deployment is the simpler answer
For some organizations the cleanest compliance story is not a vendor's certificate at all, it is that the recordings never leave infrastructure they control. Running the stack on your own server removes the subprocessor chain, the residency question and the retention negotiation in one move, at the cost of owning the operations. Our guide to a private AI answering service covers what that deployment involves and when the trade is worth making.
Whichever route you take, settle the compliance question before the pricing question. A platform you cannot lawfully put patient data into is not cheap at any per-minute rate.
FAQs
Is Vapi HIPAA compliant?
- Vapi publishes HIPAA as a $2,000 per month add-on available on its Build and Scale tiers, with zero data retention as a further $1,000 per month add-on, verified August 12, 2026. Compliance is never a property of the platform alone: it depends on the signed BAA, your own configuration and the model providers you connect. Ask for the agreement and the current posture directly.
Is Retell AI SOC 2 compliant?
- Retell's pricing page states SOC 2 certification, and HIPAA with a signed BAA on its enterprise plan at custom pricing, verified August 12, 2026. For your own review, request the current report under NDA and check whether it is Type I or Type II, which trust services criteria are in scope, and what the exceptions section says. That applies to any vendor, including us.
What is the difference between HIPAA and SOC 2?
- HIPAA is United States law governing protected health information, enforced in vendor relationships through business associate agreements. SOC 2 is a voluntary attestation in which an independent accounting firm tests a vendor's controls against the AICPA trust services criteria. SOC 2 tells you the vendor runs a disciplined program; only a BAA makes handling patient data lawful.
Does a SOC 2 report mean a vendor can handle patient data?
- No. The two answer different questions. A vendor can hold a clean SOC 2 Type II report and still be the wrong home for protected health information if it will not sign a BAA, or if the audio is processed by a subprocessor outside the report's system boundary. Read the scope first, then ask for the BAA separately.
How much does HIPAA compliance cost on a voice AI platform?
- It depends on how the vendor sells it. On published rates verified August 12, 2026, Vapi lists HIPAA at $2,000 per month plus $1,000 per month for zero data retention. Retell places HIPAA and a BAA on its enterprise plan at custom pricing, so that figure comes from a sales conversation. Flat add-ons dominate the bill at low call volume, so model them before per-minute rates.
Do I need a BAA with my speech and language model providers too?
- If they process protected health information, yes. Developer-first platforms often let you bring your own model keys, which brings the compliance obligation for that provider back to you. An agreement with the orchestration platform does not extend to an endpoint you connected yourself, so map every subprocessor that touches the audio.
Are call recordings and transcripts protected health information?
- If they identify a patient in a care context, yes, and so are the model-generated summaries derived from them. Telephony metadata often counts too, because a number and a timestamp tied to a clinic can identify a patient with no content at all. Treat every derived artifact as in scope until your counsel says otherwise.
Which is the safer choice for a healthcare deployment, Vapi or Retell AI?
- Neither is safe or unsafe by default, because both are building blocks rather than finished healthcare products. The decision comes from your own diligence: who signs a BAA, what the current SOC 2 report covers, which subprocessors touch the audio, what retention you can set, and the total cost once compliance add-ons are included. If you would rather not assemble that yourself, a managed or self-hosted deployment scoped to healthcare removes most of the assembly.


