not an expert, but from my research (we have similar stack) the hippaa covers any providers you use through Vapi, however if you bring your own keys you need to sign BAAs with any sub providers (when we used our own twilio we had to sign a seperate BAA)