Hi Philip,
For HIPAA compliance with Vapi, you have the option to use your own HIPAA-compliant cloud storage. Vapi supports integration with several providers, including Amazon S3 and Google Cloud Storage, to ensure recordings are stored properly in a compliant manner. If HIPAA compliance is enabled, Vapi won’t store recordings or logs on its own platform.
Regarding data in webhooks, when HIPAA compliance is active, you must ensure that PHI is only processed through compliant channels, like the call pipeline. The data sent through the webhook should not include any PHI as per your compliance plan.
For more detailed guidelines, you can refer to the [HIPAA Compliance documentation](
https://docs.vapi.ai/security-and-privacy/hipaa).