We are currently evaluating Vapi as the orchestration layer for a healthcare voice agent application. We understand there is a $1,000/month add-on for HIPAA compliance and Zero Data Retention (ZDR) on the Vapi platform.
Before we commit, we need definitive clarification on how this add-on interacts with downstream model providers, specifically regarding Business Associate Agreements (BAA). We have been unable to definitively clarify from the help docs here:
https://docs.vapi.ai/security-and-privacy/hipaa
Can anyone please clarify the liability in the following two scenarios?
Scenario A: Vapi Managed Keys
If we pay the $1,000/mo HIPAA fee and use Vapi's default/managed keys for Deepgram (STT), Anthropic (LLM), and Cartesia (TTS):
Does Vapi's BAA with us cover these downstream providers as your sub-processors, and are the sub-processors required to adhere to ZDR?
Or are we still required to hold our own separate enterprise contracts/BAAs with Deepgram/Anthropic/Cartesia to ensure they do not retain PHI or violate ZDR?
Scenario B: Bring Your Own Key (BYOK)
If we bring our own API keys for these providers to get direct pricing:
Does the "HIPAA Enabled" toggle in the Vapi dashboard technically prevent these downstream providers from logging data on their end?
Or is the ZDR status strictly dependent on the settings/contract associated with our specific API keys?
We are trying to determine if the $1,000 fee provides a "compliance wrapper" for the entire stack, or if it only covers Vapi's orchestration logs.