Hi barelledboi,
1. **HIPAA-compliant providers**: You're correct; you need to select the right HIPAA-compliant providers (e.g., Deepgram, OpenAI, Vapi). Vapi handles the necessary BAAs with these organizations, so you don't need to set up separate agreements.
2. **Tool Calls / Integrations**: For integrating with external services during tool calls, you can build tools in your Vapi dashboard that call external APIs. Ensure that these external services are HIPAA-compliant as you transmit any PHI.
3. **End of Call workflows**: When HIPAA is enabled, Vapi doesn't store transcripts or recordings. However, an end-of-call report message is generated and stored on your server, ensuring compliance. You'll need to handle transcripts and any additional data processing using your HIPAA-compliant storage solutions.
For more details on enabling HIPAA compliance, refer to Vapi's [HIPAA documentation](
https://docs.vapi.ai/security-and-privacy/hipaa).