We are currently evaluating Vapi as the orchestrat...
# general-english
b
We are currently evaluating Vapi as the orchestration layer for a healthcare voice agent application. We understand there is a $1,000/month add-on for HIPAA compliance and Zero Data Retention (ZDR) on the Vapi platform. Before we commit, we need definitive clarification on how this add-on interacts with downstream model providers, specifically regarding Business Associate Agreements (BAA). We have been unable to definitively clarify from the help docs here: https://docs.vapi.ai/security-and-privacy/hipaa Can anyone please clarify the liability in the following two scenarios? Scenario A: Vapi Managed Keys If we pay the $1,000/mo HIPAA fee and use Vapi's default/managed keys for Deepgram (STT), Anthropic (LLM), and Cartesia (TTS): Does Vapi's BAA with us cover these downstream providers as your sub-processors, and are the sub-processors required to adhere to ZDR? Or are we still required to hold our own separate enterprise contracts/BAAs with Deepgram/Anthropic/Cartesia to ensure they do not retain PHI or violate ZDR? Scenario B: Bring Your Own Key (BYOK) If we bring our own API keys for these providers to get direct pricing: Does the "HIPAA Enabled" toggle in the Vapi dashboard technically prevent these downstream providers from logging data on their end? Or is the ZDR status strictly dependent on the settings/contract associated with our specific API keys? We are trying to determine if the $1,000 fee provides a "compliance wrapper" for the entire stack, or if it only covers Vapi's orchestration logs.
2 Views