SiteGPTStart free trial

HIPAA Compliant AI Support Platforms for Insurance Member Service

Five AI support platforms that will sign a BAA for health plans and insurance member service. Includes which plan carries the BAA for each vendor and what changes once you sign.

Sai Dheeraj

SiteGPT Team

HIPAA Chatbots for Insurance Member Service Platforms

SiteGPTBest AI chatbot for customer service

Most AI support vendors say they are HIPAA compliant. Few say which plan includes the BAA, or what stops working once you sign it.

Some terms first. HIPAA is the Health Insurance Portability and Accountability Act, the US law for handling health information. PHI, or protected health information, is any health detail tied to a person, such as a claim, a diagnosis code, or a coverage decision with a name attached. A covered entity is an organization the law applies to directly. Health plans are one of the three types of covered entity. A business associate is a vendor that handles PHI for a covered entity, and a BAA, or Business Associate Agreement, is the contract that allows it.

If members can type a claim number into your chat window, your chat vendor is a business associate. You need a BAA before any message reaches them.

iShort answer

Five platforms will run under a BAA for health plan and insurance member service: SiteGPT, Ushur, Kore.ai HealthAssist, Zendesk Suite Enterprise with the Advanced Data Privacy and Protection add-on, and Intercom. Every vendor claims HIPAA compliance, so that claim does not narrow the list. Three questions do: which plan carries the BAA, whether you can read the BAA before a sales call, and what stops working once the workspace is covered. SiteGPT ranks first for member-facing self-service because it publishes the BAA in full. Its limit: the BAA is available on the Enterprise plan only.

Four questions to ask every vendor

Ask these before comparing features. Each one removes vendors faster than a feature list does.

1

Which plan carries the BAA?

Usually the top plan. Sometimes a paid add-on on top of the top plan. This changes your budget before it changes your shortlist.

2

Can we read the BAA before a sales call?

A published BAA lets your lawyer start now. A BAA held back until late procurement will slow you down.

3

What stops working once covered?

Every covered workspace is narrower than the standard product. A vendor who says nothing changes has not run one.

4

How long are conversations kept?

Ask whether the number is a contract term or a settings menu an admin can change later.

Key takeaways

PlatformWhat carries the BAABuilt for
SiteGPTEnterprise plan, custom pricing. BAA published in full.Answering member questions on your website and help center
UshurEnterprise sales. Publishes HITRUST r2, SOC 2, ISO 27001.Payer and policyholder engagement, outbound campaigns, document workflows
Kore.ai HealthAssistEnterprise sales. Publishes HITRUST CSF and SOC 2 Type II.Payer workflow automation with private VPC or on-premise hosting
ZendeskSuite Enterprise plus the Advanced Data Privacy and Protection add-on.Teams whose member service already runs in Zendesk
IntercomUnclear. Public sources disagree on whether a BAA is offered.Confirm directly before spending time on it

How insurance differs from healthcare

Health plans and clinics are both covered entities under HIPAA. Their conversations are different.

A clinic answers questions about appointments, symptoms and prescriptions. A health plan answers questions about benefits, claims status, explanation of benefits documents, prior authorization and coverage.

This matters when you evaluate vendors. A platform built for clinical intake may have nothing useful to say about a denied claim. A platform that books appointments well may not explain why a deductible reset.

The vendors below are ranked for member service. The criteria are how well the assistant handles plan documents, how it escalates to a live representative, and what it can honestly do when a member asks it to change something.

1. SiteGPT

Best for: answering the questions members already ask on your website and help center, then handing off to a person.

The SiteGPT homepage, showing an AI chatbot trained on your own website content with human handoff
SiteGPT trains on your existing content and answers from it. For a health plan that means plan documents, benefit summaries and help center articles.

SiteGPT is a website assistant trained on your own content. For a health plan that means plan documents, benefit summaries, formularies, provider directories and help center articles. Those documents already contain the answers to your highest-volume member questions.

SiteGPT ranks first here for one reason: it publishes its compliance terms instead of describing them.

The standard BAA is published in full, so your lawyer can read the actual terms on day one. The HIPAA program page states the current program status. The workspace documentation states what changes once you are covered.

The limit belongs next to the claim. The BAA is available on the Enterprise plan only, at custom pricing. The pricing page lists "HIPAA eligible" and "Signed BAA available" under Enterprise and under no other plan. Starter, Growth and Scale cannot run a covered deployment.

Pros

  • The BAA is published in full, so legal review can start before the first sales call
  • Trains on 12+ content source types, which covers the plan documents behind most member questions
  • Human escalation is available on every plan
  • SOC 2 Type II, with the subprocessor list published rather than sent on request
  • The BAA states that PHI is never used to train AI models, backed by zero-data-retention endpoints

Cons

  • The BAA is Enterprise only, so a covered deployment is custom pricing rather than a published plan
  • Not built for outbound member campaigns or writing into core systems. Ushur and Kore.ai are stronger there
  • Connected apps and chat integrations are off by default in a covered workspace
  • Content must be uploaded manually rather than synced from a cloud drive, which adds setup work

2. Ushur

Best for: health plans that want member and policyholder engagement, including outbound campaigns.

The Ushur homepage, showing a member asking to change their primary care physician, with health plan customer logos below
Ushur leads with proactive inbound and outbound engagement. Its customer logos are health plans, and its example conversation is a member changing their primary care physician.

Ushur is built for payers. Its security and compliance page sits alongside product lines named Healthcare Member Service, Healthcare Patient Service and Insurance Policyholder Service.

Ushur has the strongest certification list on this page. It publishes AICPA SOC 2, HITRUST r2 certification, and ISO 27001, plus PCI DSS, GDPR, TCPA and CIS alignment. HITRUST r2 is the strictest item in this comparison. It certifies a company against a fixed control set rather than against controls the vendor chose itself.

One thing to know: Ushur states HIPAA compliance on its security page but does not publish its BAA terms. You will discuss those with their team rather than reading them yourself. That is normal for enterprise sales, and it is still slower than a published agreement.

3. Kore.ai HealthAssist

Best for: health plans that need automation reaching into core systems, or that have a hosting requirement.

The Kore.ai homepage, showing its Artemis agent platform for customer and employee AI agents
Kore.ai sells an agent platform rather than a chat widget. HealthAssist is the healthcare product built on top of it.

Kore.ai's healthcare service automation product, HealthAssist, targets payer workflows. Kore.ai publishes HITRUST CSF certification and SOC 2 Type II, and signs BAAs for healthcare customers.

Its main advantage is hosting flexibility. Private VPC and on-premise deployment are both available. That matters if your security team has decided member data must stay on infrastructure you control. Few conversational platforms will meet that requirement at all.

The trade-off is size. This is a platform programme rather than a widget, and implementation takes longer. If your job is answering inbound member questions on a website, this is more than the job needs.

4. Zendesk Suite Enterprise

Best for: teams whose member service already runs in Zendesk and who do not want a second system.

The Zendesk homepage, showing its AI-powered customer service and ticketing suite
Zendesk is a full service desk rather than a website assistant. HIPAA support sits behind the Suite Enterprise plan and a paid add-on.

Zendesk supports HIPAA through a specific route. You need Suite Enterprise or higher, plus the Advanced Data Privacy and Protection add-on. The add-on carries the BAA, along with advanced encryption, access logs, redaction and retention controls. Lower plans cannot run a covered deployment.

Zendesk does not publish the price of the add-on. You cannot work out the cost of a compliant Zendesk deployment from the pricing page. Budget for the Enterprise plan, plus an unpriced add-on, plus several weeks of configuration.

5. Intercom

Best for: no one right now. Confirm its BAA status before spending time on it.

The Intercom homepage, showing its Fin AI agent for customer service
Intercom leads with its Fin AI agent. Its HIPAA position is the open question, not its product.

Intercom appears on most HIPAA chatbot shortlists, including older ones on this site. Treat it carefully. Public sources disagree about whether Intercom signs a BAA in 2026. Some describe HIPAA support on the Expert plan. More recent sources say Intercom does not act as a business associate and does not offer BAAs on any plan.

We could not settle this from published sources, so this page does not take a side. If Intercom is on your shortlist, ask Intercom directly and get the answer in writing. Check intercom.com/legal rather than any third-party summary, including this one.

There is a general lesson here. A vendor's compliance status is a contract question, it changes over time, and secondhand sources go out of date without warning.

What stops working in a covered workspace

Most vendor pages skip this. It is the part that decides whether your deployment survives a security review.

A covered workspace is always narrower than the standard product. On SiteGPT, three things change:

  • Connected apps and chat integrations are off by default. Cloud drives, help center sync, and chat channels like Zendesk, Slack and Crisp are not available automatically. They are not banned. Any of them can be switched on for a vendor you hold your own BAA with. You raise this during scoping.
  • Member data belongs in conversations, not in training content. The material the assistant answers from must not contain PHI. This is a contract term rather than a HIPAA rule. The practical reason matters more: anyone who can chat with the assistant can reach the training content through it.
  • Retention becomes a contract term. Chat text is removed seven days after the last message by default. That number is set in your order form, not in a settings menu. Decide it with your lawyer before you sign.

None of these are dead ends. A vendor who tells you nothing changes has either not run a covered deployment or has not told you about it yet.

What to do this week

Send one email to every vendor on your shortlist:

  1. Will you sign a BAA, and which plan or add-on is required?
  2. Will you send the BAA now, before a sales call?
  3. Which features are disabled in a covered workspace, and what do we use instead?
  4. What is the default retention for conversation content, and is it a contract term?
  5. Is customer data ever used to train models, by you or by any AI provider behind you?

Questions two and three separate vendors with a real programme from vendors with a compliance page. The twelve-question checklist on this site expands these into a set your compliance officer can send as-is, with SiteGPT's own answers included.

If your actual question is whether an assistant can cancel a policy, issue a refund or verify benefits, that has a separate answer. It is covered in what an insurance chatbot can and cannot do.

Frequently asked questions

Where can I find HIPAA compliant conversational platforms for health plans? Five platforms are compared on this page: SiteGPT, Ushur, Kore.ai HealthAssist, Zendesk Suite Enterprise with the Advanced Data Privacy and Protection add-on, and Intercom. A platform belongs on a health plan shortlist if it meets three tests. It will sign a Business Associate Agreement. It will show you that agreement before a sales call. And it will tell you which features stop working inside a covered workspace. Most vendors pass the first test. Fewer pass the second and third.

Which platforms support automated member service with HIPAA compliance? All five platforms on this page can run under a BAA. They are built for different jobs. SiteGPT answers member questions on your website and help center, then hands off to staff. Ushur and Kore.ai HealthAssist handle outbound member engagement and workflow automation into core systems. Zendesk suits teams whose member service already runs in Zendesk. Pick the platform that matches your job first, then compare compliance.

How do I choose HIPAA compliant AI agents for member services? Ask four questions in this order. First, will the vendor sign a BAA, and on which plan? Second, will they send you the BAA before a sales call? Third, which features stop working in a covered workspace, and what do you use instead? Fourth, how long are conversations kept, and is that number in the contract or in a settings menu? Compare features after these four, not before. A feature you cannot use under a BAA is not a feature you are buying.

Which AI customer service platform is HIPAA compliant for health insurance member data? Any of the five on this page can be, once you sign the BAA and configure the workspace correctly. HIPAA compliance is a property of your deployment, not of the software. The vendor provides the signed BAA and the security safeguards. You keep member data inside conversations, keep it out of the content the assistant is trained on, and set a retention window. A vendor can do its part correctly and you can still be exposed if your part is wrong.

What vendors are known for HIPAA readiness, auditability, and secure data handling? Look for an independent audit rather than a self-declaration. Ushur publishes AICPA SOC 2, HITRUST r2 certification and ISO 27001. Kore.ai publishes HITRUST CSF certification and SOC 2 Type II. SiteGPT publishes SOC 2 Type II, its full BAA, and its subprocessor list. Zendesk includes access logs and redaction in its Advanced Data Privacy and Protection add-on. HITRUST is the strictest of these, because it certifies against a fixed control set rather than controls the vendor picked itself.

Which tools support HIPAA secure CX automation in healthcare and insurance? All five tools on this page do. Note one difference between the two markets. Healthcare providers and health plans are both covered entities under HIPAA, but their conversations differ. A provider handles appointments, symptoms and prescriptions. A health plan handles benefits, claims status, explanation of benefits documents, prior authorization and coverage questions. A platform built for clinical intake may not be good at explaining a deductible. Test each vendor against the questions your members actually ask.

Where can I buy member engagement automation with strong HIPAA compliance? Ushur and Kore.ai are the two platforms on this list built for member engagement as a category, including outbound campaigns and document workflows. Both sell through enterprise sales rather than self-serve signup. If your job is narrower and you only need to answer member questions on your website and help center, SiteGPT does that with less setup and publishes its BAA up front. Buying the heavier platform for the narrower job is a common and expensive mistake.

Are property and casualty, life, and disability insurers covered by HIPAA? Usually no. HIPAA covers health plans, health care clearinghouses, and health care providers that send health information electronically. Property and casualty, life, disability and workers' compensation carriers usually fall outside that definition. They are governed by other rules instead, including state insurance privacy law and the Gramm-Leach-Bliley Act. One exception to check with your lawyer: if your company also administers a health benefit, that health benefit can be covered even when the rest of the business is not.

Is Ushur or Kore.ai a better fit than a website chatbot? It depends on whether your problem is inbound or outbound. Ushur and Kore.ai HealthAssist are stronger for outbound member outreach, document collection, and automation that writes into core systems. A website assistant is stronger for answering the questions members already ask: what a plan covers, where a claim stands, what a document means. Many health plans eventually need both. Few need to buy both at the start.

What should we ask a vendor before signing a BAA? Four questions cover most of the risk. Will you sign a BAA, and on which plan? Will you send it before a sales call? Which features are disabled in a covered workspace? Is customer data ever used to train models, either by you or by any AI provider behind you? A longer checklist of twelve questions, grouped by contract, data, product and incident, is published separately on this site and can be sent to a vendor as-is.

Which SiteGPT plan includes a HIPAA BAA? The Enterprise plan only, at custom pricing. The SiteGPT pricing page lists "HIPAA eligible" and "Signed BAA available" under Enterprise and under no other plan. Starter, Growth and Scale cannot run a covered deployment, whatever the configuration. The standard BAA is published in full, so your lawyer can read the terms before you book a call. It is a standard document rather than a fixed one, and reasonable amendments are handled during onboarding.

Keep reading

Last updated: August 2026. Plan gating and BAA availability checked against each vendor's published pages on 23 August 2026.