Compliance
Can an AI assistant work for telehealth? Yes — if it never tries to be a doctor
The clinical boundary costs a telehealth practice almost nothing, because the questions losing them sign-ups are not medical ones. What an agent can answer, what it must refuse, and where HIPAA actually bites.
A telehealth operator asked us a fair question: can a website agent built for consultative sales work for us, when it plainly cannot practise medicine? Their own framing was that it could only ever function as an FAQ. That is half right — and the half that is wrong is the half worth money.
Telehealth passes two of our three tests easily
A consultative sale is a purchase the buyer researches alone before they ever make contact, where specific unanswered questions block the decision, and where one customer is worth $5,000 or more. Telehealth passes the first two emphatically. Patients research harder here than in almost any category: they read for days, compare programmes, and arrive at conclusions nobody ever corrects.
The third criterion is the real filter, and it turns on lifetime value rather than the first transaction. A $49 urgent-care visit does not clear the bar and we would say so. Weight management, hormone therapy, fertility, behavioural health, addiction treatment and chronic-care subscriptions routinely do, once you count a retained patient over twelve to twenty-four months. If you are assessing fit, that is the question to ask — not what the first consult bills.
The questions that lose a telehealth sign-up are not medical
Look at what actually stops someone completing a sign-up. Are you licensed in my state? Do you take my insurance? What does it cost without insurance? How quickly can I be seen? Do you prescribe that category at all? What actually happens on the visit? Is this a subscription, and can I cancel? Do I need labs first? Will my employer find out?
Not one of those is medical advice. Every one of them is a live reason somebody closes the tab. The clinical boundary removes questions the agent was never going to be asked at the top of the funnel anyway — which is why "it can only be an FAQ" undersells it. An FAQ is static, generic, and the same for everybody. What we run is specific to the person reading, changes the page around them, and remembers them when they come back. It simply never leaves non-clinical ground.
Three compliance lines, not one
People tend to collapse this into a single worry. It is three separate questions with three separate answers.
The first is scope of practice. The rule we hold to is no symptom intake, no diagnosis, no treatment recommendation, no triage of urgency, and no view on whether a given drug suits a given person. General, non-individualised information has long sat outside medical-device regulation. Worth noting that the FDA revised its clinical decision support guidance in January 2026, and commentators have observed that it addresses clinician-facing software and stays largely silent on consumer-facing chatbots and symptom checkers. We would not claim a clean safe harbour there. We claim a design that never enters the territory.
The second is HIPAA, and the question is not "is it automated" but "does identifiable health information reach it". Answering "do you treat this in Texas" without capturing who is asking is a different thing from capturing a name, an email and a stated condition. The second is individually identifiable health information held on behalf of a covered entity, and that needs a business associate agreement in place first.
The third is disclosure. The agent must be plainly identified as automated, and anything resembling an emergency has to route to emergency services rather than being assessed. Several states have moved on AI disclosure in healthcare settings; that is a question for your counsel and your jurisdiction, not one a vendor should answer for you.
What the 2024 ruling changed, and what it did not
Prospects sometimes cite the most aggressive reading of HIPAA and online tracking. It is worth knowing where that stands. In June 2024 a federal court in the Northern District of Texas vacated the portion of the Office for Civil Rights guidance that treated an IP address combined with a visit to an unauthenticated public page about a health condition as protected health information, finding it exceeded the agency’s authority. HHS withdrew its appeal that August, and the guidance covering user-authenticated pages was left intact.
That removes the most expansive reading for public marketing pages. It does nothing for you if your agent collects a name alongside a condition — that is a different fact pattern, and the analysis there has not changed.
What a clean deployment looks like
Marketing pages only, to begin with. Answers drawn solely from approved, non-clinical knowledge: your licensure map, insurance and pricing, what happens on a visit, timelines, what you do and do not treat. A hard refusal list covering symptoms, dosage, suitability and urgency. Capture limited to contact details plus the name of the programme someone is interested in, rather than a condition. Immediate handoff to a human on anything clinical, with no clinical content retained. And an automated-agent disclosure the visitor cannot miss.
Deployed that way, the agent is doing commercial work on commercial ground, and the clinical conversation starts where it should — with your clinicians.
What we will and will not sign
We would rather say this early than have it surface in week one of a security review. SentientWeb is not currently SOC 2 certified, and we do not offer a blanket business associate agreement for every pilot. HIPAA-aligned handling is available for scoped deployments after legal and security review. Until a BAA or equivalent is signed, a pilot stays limited to approved website content, non-PHI qualification, and human escalation. Our full position is on the trust and security page, and it is the version that governs.
None of this is legal advice, and we are not lawyers. Your counsel needs to sign off on where the PHI boundary sits for your practice and what your states require on disclosure before anything goes live. What we can tell you is that the boundary is workable — and that on the evidence of what telehealth buyers actually ask before they sign up, it is not where your revenue is leaking.