SUPPORT.TWILIO.COM END OF LIFE NOTICE: This site, support.twilio.com, is scheduled to go End of Life on February 27, 2024. All Twilio Support content has been migrated to help.twilio.com, where you can continue to find helpful Support articles, API docs, and Twilio blog content, and escalate your issues to our Support team. We encourage you to update your bookmarks and begin using the new site today for all your Twilio Support needs.

Is Twilio Agent Connect (TAC) a HIPAA-Eligible Service Under BAA?

Question

Is Twilio Agent Connect (TAC) a HIPAA Eligible Service that can be covered under my Business Associate Agreement (BAA) with Twilio? I want to use the Agent Connect SDK in a healthcare workflow, configured only for Conversation Relay or for the GPT-Live-1 integration, without Conversation Memory, Conversation Orchestrator, Conversation Intelligence, or Knowledge. Does the HIPAA exclusion still apply in that case, and what can I use instead?

 

Product

Conversation Relay

 

Answer

No. Twilio Agent Connect is not a HIPAA Eligible Service. The legal notice at the top of the Twilio Agent Connect documentation states that it should not be used in workflows that are subject to HIPAA.

This notice applies to Twilio Agent Connect as a product. The documentation does not list any exceptions based on how the software development kit (SDK) is configured, such as using it only with Conversation Relay.

If your workflow involves protected health information (PHI), build directly with Twilio services that are on the HIPAA Eligible Services list instead of using Twilio Agent Connect. For voice AI, these include:

  • Conversation Relay: Twilio converts the caller's speech to text, sends it to your application, and converts your text responses back to speech. Use this option with a text-based AI model. See TwiML Voice: <ConversationRelay>.
  • Media Streams: Twilio sends the call's audio to your application in real time. Your application can then connect it to an AI model that works directly with audio (a speech-to-speech model). See TwiML Voice: <Stream>.

Both features are marked on the HIPAA Eligible Services list with a note to follow the Architecting for HIPAA on Twilio guide, which describes what you need to configure on your side.

For questions about the scope of your BAA or how it applies to a specific architecture, contact your Twilio Account Representative or Twilio Sales.

 

Additional Information 

  • Speech-to-speech models, such as OpenAI's GPT-Live-1, do not use Conversation Relay. The Twilio Agent Connect integration with GPT-Live-1 connects through Media Streams. For an example of connecting GPT-Live-1 to Twilio Voice without Twilio Agent Connect, see Build an AI Voice Assistant with Twilio Voice and Media Streams, OpenAI's GPT-Live API, and Node.js.
  • Conversation Memory, Conversation Orchestrator, and Knowledge are not on the HIPAA Eligible Services list.
  • Twilio's BAA applies to Twilio's HIPAA Eligible Services. If your workflow sends PHI to a third-party provider, such as an AI model provider, check with that provider whether its service can be covered under an agreement with them.
  • You can use services that are not HIPAA eligible, including Twilio Agent Connect, in workflows where there is no potential for PHI to be exchanged. See Twilio and HIPAA.
  • Signing a BAA with Twilio requires Security Edition or Enterprise Edition. See HIPAA Accounts.
Have more questions? Submit a request
Powered by Zendesk