Bruchill1234
09/03/2025, 11:09 PMVapi Support Bot
09/03/2025, 11:10 PMhipaaEnabled flag at the organization or assistant level. Here’s a sample configuration:
json
{
"compliancePlan": {
"hipaaEnabled": true
}
}
Ensure PHI only passes through the /call endpoint and is not stored in configuration. For more details or to discuss a BAA, contact security@vapi.ai.
Note: Pricing and BAA signing details are not specified in the documentation I have found.
Source:
- [Vapi HIPAA Compliance Documentation](https://docs.vapi.ai/security-and-privacy/hipaa)Chiranjeet Mishra
09/05/2025, 5:28 PMartifactPlan.recordingEnabled is set to true
5\. Configure the recordingPath if you want to customize where recordings are stored
3\. **Important Notes**:
- Without proper cloud storage credentials, recordings won't be stored when HIPAA compliance is enabled
- You'll still receive an end-of-call report with call information
- With HIPAA enabled, VAPI won't store the recordings in their own storage
This approach ensures your call recordings are stored in your own HIPAA-compliant environment while still allowing you to benefit from VAPI's call recording functionality.