Numbers terminating in your environment
Provisioned or ported so the call path ends inside your boundary rather than in a vendor's platform that then forwards it onward.
Locations
In a hosted voice pipeline every component that touches the audio is another party your compliance team has to paper. Self-hosting collapses that chain to nothing.
The basics
A hosted voice pipeline routes your audio through several components, and under US health rules each one that touches protected information is another party to paper. That is the real reason regulated American organisations end up self-hosting, and it is worth stating in those terms rather than in the usual language about security posture. Health information rules extend down the chain: a business associate that subcontracts a function involving protected health information needs its own agreement with that subcontractor, establishing a documented chain of custody back to the covered entity. Financial institutions carry an analogous duty to select, contract with and periodically assess their service providers. Running the platform inside your own environment does not improve your posture against that requirement so much as remove the thing being assessed.
In short
The market
The pattern in regulated American organisations is remarkably consistent. A department identifies a genuine problem — an appointment line that overwhelms staff, a member services queue nobody can hire their way out of — runs a successful pilot, and then hits a vendor risk review. The review is not hostile; it simply asks who else touches the audio. The answer usually involves several components and a couple of names nobody in the room recognises, and from that point the project is not rejected so much as it stops. A year later somebody proposes it again and the same thing happens.
What unblocks it is changing the answer rather than improving the paperwork. When the platform runs on infrastructure the organisation has already assessed, the review stops being about third parties and becomes a set of internal questions with internal answers: which environment, whose credentials, what retention, what monitoring. Compliance teams are generally good at those questions. What they cannot do quickly is take on responsibility for a chain of external processors they did not choose and cannot audit, which is what a hosted deployment asks them to do.
Downstream
How far health-information agreements reach
Where a business associate subcontracts a function involving protected information, a further agreement is required with that subcontractor to establish a chain of custody.
Oversee
What financial institutions owe on providers
The Safeguards Rule requires selecting and retaining only capable service providers, contracting with them to maintain safeguards, and periodically assessing them.
Jan 2027
How far one state AI act has now moved
Colorado's 2024 act was repealed and re-enacted in May 2026 with the effective date pushed to January 2027, and enforcement paused pending rulemaking.
Who is calling
Where the business-associate chain is the whole obstacle, and removing it rather than documenting it is what gets a project through review.
Banks, credit unions and insurers carrying a continuing duty to assess every service provider that touches customer information.
Firms whose confidentiality obligations make an external processor in the call path a conversation with the client rather than with IT.
Institutions running their own infrastructure and their own review boards, with admissions lines that spike predictably every year.
What the rules require
One is about health information, one about financial customer information, and one about the fact that this area of law will not sit still.
HIPAA business associate obligations
Under the health information rules, a business associate that subcontracts a function involving protected health information must have its own agreement with that subcontractor before disclosing the information, and those downstream subcontractors are themselves business associates bound by the terms of their agreements — a documented chain of custody running back to the covered entity. A cloud provider that stores protected information in that chain is a business associate too. In a hosted voice pipeline, the components handling audio, transcription and generation each sit somewhere on that chain. A self-hosted deployment does not shorten it; it removes it, because there is no external party in the path at all.
FTC Safeguards Rule
Financial institutions covered by the Safeguards Rule must oversee their service providers: selecting and retaining only providers capable of maintaining appropriate safeguards, contracting with them to implement and maintain those safeguards, and periodically assessing them. The obligation stays with the institution regardless of what a vendor promises, which is what makes each additional processor in a call path a recurring cost rather than a one-off approval. Removing the processors removes the recurring assessment along with them, which is usually a larger saving over a few years than the licence difference.
State AI legislation, and its instability
State AI law is moving faster than most vendor documentation. Colorado's 2024 act was repealed and re-enacted by legislation signed in May 2026, with the effective date pushed to January 2027 from an already-extended June 2026 date, and the Attorney General has indicated no intention to enforce it or its replacement until rulemaking concludes. Other states have narrowed or widened obligations on similar timescales. An organisation that controls its own deployment can adjust disclosure and handling directly when a rule lands, rather than waiting for a vendor's roadmap to catch up with a statute that has already taken effect.
Recording consent across state lines
Worth stating plainly so it is not lost: self-hosting does not alter the recording rules. States disagree about whether one party or all parties must consent, and a national organisation therefore reads a notice on every call regardless of where the software runs. What self-hosting does change is what happens to the recording afterwards — retention, access and deletion all become internal controls under your existing programme rather than settings you configure in someone else's product and then verify by asking them.
Written from published regulator guidance and the analyses linked below, and not legal advice. The point of this page is to help you frame the internal review accurately, not to tell you what your own compliance function should conclude.
Numbering
Self-hosting changes where the software runs. The telephone network still has to reach it, and that part looks familiar.
Provisioned or ported so the call path ends inside your boundary rather than in a vendor's platform that then forwards it onward.
The agent sits behind the numbers and trunks you already operate, which is usually what makes the change manageable for a telecom team.
Reminder and notification calls dial from numbers belonging to the deployment, which protects answer rates on exactly the calls patients and members most need to receive.
Recording, transcription and summarisation all execute inside your environment, which is the property that makes the review straightforward.
Capabilities
Functionally identical to the hosted product. What changes is that the audio never leaves your boundary and the agent can reach systems a hosted deployment never could.
Record systems, scheduling platforms and member databases that were never going to be exposed to an outside vendor at any price.
Produced, stored and deleted within your environment, on a retention schedule your own programme sets and audits.
When a state rule lands you adjust the script directly rather than raising a request and waiting for a vendor release.
Including the on-premise systems that are the reason this deployment shape was on the table to begin with.
Call volume, resolution rates, and outcomes in one dashboard, so every conversation turns into a decision.
Greets and serves callers in their own language, detected automatically and switched mid-call, with no multilingual team to staff.
Coverage
The markets our regulated US conversations come from. As with the Canadian equivalent, the location that matters here is your infrastructure rather than any city named below.
The build is delivered remotely and handed over. After handover the deployment runs where you put it, on credentials you hold, under monitoring you already operate.
Further reading
The licence: deployment shapes, what is included, what you operate. The commercial detail lives there rather than here.
The questions worth asking any vendor before this reaches a review board, hosted or otherwise.
The comparison worth doing properly before deciding to license rather than build one internally.
Rules change, and court decisions change them faster than regulators republish. Every statement above was read from the source shown on the date shown. Confirm the current position with your own counsel before relying on it.
FAQ
What US compliance and security teams ask before this reaches a review board.
It removes the sub-processor chain, which is usually the expensive part. Under the health information rules a business associate that subcontracts a function involving protected information needs its own agreement with that subcontractor, and those downstream parties are business associates too — a documented chain running back to the covered entity. When the platform runs inside your environment there is no external party in the call path to place on that chain. Your own counsel should confirm what the licensing relationship itself requires, but the recurring assessment burden across multiple processors is what goes away.
The continuing oversight duty is the thing worth costing. The Safeguards Rule requires you to select and retain only service providers capable of maintaining appropriate safeguards, to contract with them to do so, and to assess them periodically — and that obligation stays with you no matter what a vendor asserts. Every additional processor in a call path is therefore a recurring assessment rather than a one-time approval. Removing them removes the recurring work, which over a few years is frequently a larger number than the difference in licence cost.
Control the disclosure and handling directly rather than through a vendor's release cycle. Colorado is the clearest illustration: its 2024 act was repealed and re-enacted in May 2026 with the effective date moved to January 2027 from an already-extended date, and the Attorney General has said enforcement waits on rulemaking. Any organisation whose deployment can only change when a supplier ships is structurally behind that. A self-hosted deployment lets your own team adjust the script and the handling in the same week a rule lands.
Capacity, patching, backups, monitoring and access management — the ordinary cost of running software you control. For an organisation with an established platform team this is usually absorbed without a new hire, and the trade is generally considered worth it because the alternative is an annually recurring vendor assessment. For an organisation without that capability, the honest recommendation is the hosted product with a properly documented review rather than a self-hosted deployment nobody has time to operate.
Yes, and for some organisations that sequencing is the right call: prove the call flows and the value on the hosted product with a limited, non-sensitive set of calls, then move the deployment inside once the business case is settled. What is worth deciding early rather than late is which record systems the agent will eventually need to reach, because the ones that never face the internet are exactly the integrations that will drive the move — and knowing that upfront shapes how the first phase is scoped.
Connect with our experts
Tell us which environment you would deploy into and which record systems the agent needs to reach, and we will scope the architecture and the handover before quoting anything.
Book a discovery call