HIPAA questions
# support
c
Hello, I'm with a digital health startup working on implementing a voice assistant feature with VAPI to help us streamline end-user interactions. We follow internal HIPAA-tight security rules, and we need your help finding a suitable VAPI configuration. The main configuration we are trying to solve at the moment is the audio storage and the audio download URLs for voice assistant calls. The default configuration is giving us public (no-auth) download URLs, i.e. "https://storage.vapi.ai/---.wav". We would like to have these URLs secured, behind an authentication scheme. We are aware of the option to integrate with AWS S3 and the HIPAA add-on, but we need some clarification. Here are some specific questions: Is there a way to have private VAPI-hosted-storage URLs, without configuring a custom private storage (e.g. AWS S3)?, If we set "artifactPlan.recordingUseCustomStorageEnabled: true", does this mean that no audio is stored on VAPI servers, but only in the S3 bucket configured with "artifactPlan.recordingPath"?, Eventually we will enable the HIPAA add-on. If the configuration from question 2 is what we need for a private storage, is the HIPAA add-on interfering with these settings?, As we understand it, when HIPAA settings are applied, audio files are not saved on your end and are only available via web callback. If the web callback happens to fail in the moment, is there a way to retrieve that file with a subsequent call?, We have also had issues with our voice agent speaking with an inconsistent pacing, where it will seem to speed up or slow down without any particular reason (using Cartesia Sonic 3 model). Do you have any idea why that might be happening? Thanks, Chris
c
Our [Enterprise plan](https://vapi.ai/pricing) includes unlimited concurrency, higher rate limits, and features like hands-on support, a shared Slack channel, HIPAA BAA and SOC 2 certifications, Single Sign-On (SSO) support (Okta, Azure AD, SAML, OIDC), and Role-Based Access Control (RBAC). If this sounds like it could meet your needs, please contact our sales team via this link: . Once submitted, our sales team will reach out after reviewing your requirements!
c
We've seen that plan, but that doesn't really answer our specific questions. We also sent an email to your team 6 days ago and hadn't heard back.
t
Hi Chris, I can help clarify the VAPI storage and HIPAA setup to ensure your audio URLs are secure and compliant. Typically, private URLs require custom storage like S3, and enabling recordingUseCustomStorageEnabled directs recordings there instead of VAPI servers—this works smoothly with the HIPAA add-on. Regarding web callbacks, we can discuss reliable retry strategies to avoid missed files. For the pacing issue with Cartesia Sonic 3, I’d need a bit more context on how the audio is being processed. Could you share your current implementation flow for the voice agent? @Chris
c
Hello, thanks for the clarification. For the pacing issue, currently we are testing the assistant and making calls just through the VAPI's web interface, so it's not using any processing on our end. This is using Google Gemini 2.5 Flash as the model and Cartesia Sonic 3 as the Voice. Would the specific assistant ID be helpful?
t
Thanks for the additional details — that’s helpful. The assistant ID can provide some signal, but issues like pacing with Gemini + Cartesia are often tied to runtime behavior and configuration nuances rather than a single setting. I can definitely help you dig into this further; it would be best to discuss it more privately and then schedule a few focused sessions together to review call behavior and fine-tune the setup. @Chris
v
Our Sales form has been updated - please use this NEW link: https://vapi.ai/sales