Skip to main content

Aria books injectables, laser, body, IV, and memberships — and we build the marketing that fills those columns.

BotoxDysportLip fillerCheek fillerSculptraKybellaLip flipHydrafacialChemical peelMicroneedlingPRPMorpheus8Laser hair removalIPLLaser resurfacingCoolSculptingEmsculptBody contouringCryotherapyIV therapyNAD+Myers cocktailGlutathioneVitamin B12Hormone therapyGLP-1Weight lossPeptide therapyHyperbaricMembershipsGift cardsConsults

JournalSecurity

2026-08-31 · 10 min

What a HIPAA BAA has to cover before a med spa Voice AI goes live

A buying list for spa owners: signed BAA before live traffic, no foundation-model training on identifiable calls, encryption, transcript access, and a human path for clinical.

Velzyx AI Inc. · Newport Beach, California

A medical spa that records a name, a number, and a treatment interest on a phone call is handling information that may be protected health information. If a Voice AI vendor creates, receives, maintains, or transmits that information on your behalf, they are in business-associate territory. The contract that names that relationship is a Business Associate Agreement.

This is not a rewrite of the product security page or the HIPAA notice. Those are what Aria states about itself. This article is the buying list an owner can walk before any Voice AI — ours or someone else’s — sits on a live practice line. It is not legal advice. Counsel still reviews the agreement.

The U.S. Department of Health and Human Services publishes what a business associate is and sample Business Associate Agreement provisions. Those two pages are the primary source. Marketing homepages are not.

Why a med spa line is not “just aesthetics”

Cosmetic does not mean casual. Pregnancy status, blood thinners, a recent filler, a bruise concern, a photo sent after a visit — that is medical intake, even when the next sentence is about lips. An answering service that will not sign a BAA is not cheaper coverage. It is a different risk. An AI vendor that will not sign one is the same risk with a better demo.

Owners sometimes hear “we are HIPAA compliant” as if it were a badge. Compliance is not a sticker. It is a contract plus controls plus a human path when the model should stop talking. If the vendor cannot show the agreement before live traffic, stop the rollout.

Demand this before a single live call

A signed BAA before live traffic

Not after the first week. Not “we will send the PDF once you are happy with the voice.” Before identifiable content hits their systems. If they need a sandbox with fake names first, that is a scoping environment — not production.

No foundation-model training on identifiable content

Ask for a written statement that recordings, transcripts, and client identifiers from your suite are not used to train a foundation model. “We may improve our product” is not an answer. “We de-identify and then train” is a legal conversation with counsel, not a verbal shrug on a demo.

Encryption in transit and at rest

TLS on the wire. Encryption at rest on recordings, transcripts, and backups. You do not need a vendor to invent a new algorithm. You need them to say where the audio lives and who can pull it.

Access control on transcripts

The dashboard is not a group chat. Least privilege. Named operators. A way to see who opened a recording. If every vendor engineer can browse last night’s injectables calls for fun, that is not observability. That is gossip with a login.

A human path for anything clinical

No diagnosis. No prescribing. No script that stays on the line through an unhappy-result call. The night layer escalates, with the transcript, to a human who owns the relationship. Ask what happens in the first thirty seconds of that call. If the answer is “she reassures them,” they failed.

What the sample BAA language is actually for

HHS publishes sample provisions so covered entities and vendors have a shared outline: permitted uses, safeguards, breach notification, subcontractors, termination, and return or destruction of PHI. You are not expected to draft that from a blog post. You are expected to refuse a vendor who has no agreement that covers those topics.

Subprocessors matter. The speech vendor, the host, the transcript store — anyone who can see identifiable content on your behalf. The BAA conversation includes who they are and whether they are bound before a message is routed. Aria’s security page states the product posture: BAA before PHI, encryption, no foundation-model training on identifiable spa content, clinical hard stops. Counsel still reads the paper.

Questions that belong in scoping, not after go-live

  • Where do recordings and transcripts live, and for how long?
  • Who on your side can hear a call, and how is that access logged?
  • What happens when the write to the book fails — is that a stored recording with a name still attached?
  • If a caller asks whether they are speaking to AI, what does the agent say?
  • Which subprocessors touch audio or text, and are they bound before routing?
  • How do you revoke access when an employee leaves the spa?

If those answers only exist as a slide, you do not have a security review. You have a deck.

HIPAA does not replace the book test

A signed BAA does not mean last night’s consults are on the calendar. A missing BAA does not mean the voice was bad. Grade them separately. The Wednesday book test asks whether a hold exists. This page asks whether you should have let the vendor hear the call at all.

Print the blank call-to-book worksheet for the operational half. Bring the BAA draft for the contract half. Thirty minutes. An engineer, not a script. Aria is offered under a BAA. That sentence is a starting point for counsel — not a substitute for one.

Product: AI receptionist · answering service comparison · websites & SEO · Calendar & PMS · call-to-book worksheet

If this is your desk, let’s look at the call log.

30 minutes. Your numbers. An honest scope.

Get a walkthrough