Before you hand your phone line to an AI receptionist
Practices are being offered AI receptionists that promise never to miss a call, for a low monthly fee. Some are good. But a patient's call is health data, the rules around it are strict, and the practice stays responsible for whatever the system says and does. This guide explains what to check before you agree to a pilot.
“Hi, it's AoifeName, date of birth 3 March 1988Date of birth. My back tooth has been killing me since SundayHealth data · GDPR Art. 9, and it's swollenSymptom. Can you ring me back on 087 ••• 2231Phone number?”
One short call, five pieces of personal data.Two of them are about her health, which GDPR treats as special category data.
General awareness for practices in Ireland, with UK and EU context. It isn't legal advice: take your own advice, and involve your data protection officer if you have one.
What's really in a phone call
A typical morning call to a dental practice sounds harmless: a name, a date of birth, a sore tooth and a request to ring back. But within a few seconds, whoever handles that call holds personal data and information about someone's health.
Under GDPR, data about health is special category data (Article 9). It needs a specific legal basis and stronger protection. When an AI receptionist handles the call, the practice is the controller and the vendor is a processor. That means a written data processing agreement (Article 28) has to be in place before patient calls go through the system, not after the pilot.
None of this makes AI on the phone line wrong. It means the purchase deserves the same care as any other system that holds patient information.
Behind the friendly voice
Where the call actually goes
Most AI receptionists chain several services together, and each can be a different company in a different country. Pick a step to see what passes through it.
Speech to textTurns the patient's voice into a transcript
What passes through
Audio in, a written transcript out, including symptoms
Where it may be processed
Often a separate specialist company, sometimes outside the EU
Ask the vendor: Which company transcribes the audio, in which country, and is it kept?
A typical setup, simplified. Not every product uses every step, and some run several steps with one provider. The vendor's sub-processor list, part of its data processing agreement, shows who is really involved.
What can go wrong
Eight things to think through
Not reasons to say no. Reasons to ask better questions before a vendor gets your patients' calls.
01
Health data without the paperwork
Call content about symptoms and treatment is special category data under GDPR. The practice is the controller and the vendor is a processor, so a signed data processing agreement has to be in place before the first patient call. A data protection impact assessment is mandatory when processing is likely to be high risk, and HIQA's guidance points out that this is particularly relevant when new technology is introduced.
Ask: Can we see the signed data processing agreement, and will you help with our impact assessment?
02
Data leaving the EU without you knowing
Several companies usually sit behind one AI receptionist. Some vendors' own documents list sub-processors that can process data outside the EU, including in the US, under standard contractual clauses. That can be lawful, but you need to know about it, and it should match what the sales page says. Where the marketing says “EU only” and the contract says otherwise, the contract is what counts.
Ask: Which companies touch our patients' audio and transcripts, and in which countries?
03
Recordings nobody is watching
Many systems record every call by default. Callers must be told at the start, recordings must be stored securely, and they should be kept only as long as they're needed. A pile of unmanaged recordings is a risk in itself.
Case in point · home services, not healthcareIn March 2026, researchers found databases behind a US home-services company's AI voice agent left open on the internet, holding about 1.4 million call recordings and more than 54,000 chat logs.
Ask: How long do you keep recordings, who can access them, and can we switch recording off?
04
Wrong bookings in the diary
The conversation is the easy part. The hard part is writing the right appointment, for the right patient, into your practice management system. Double bookings, wrong appointment types and missing notes all land on your front desk the next morning.
Ask: How do you prevent wrong or double bookings, and how can we review what was booked?
05
Callers it can't understand
Speech recognition struggles with strong accents, background noise, unusual names and people whose speech is affected by illness. Those are often the patients who most need to get through.
Case in point · UK general practice, not dentalIn August 2026 a GP surgery near Doncaster stopped using its AI phone system after a stroke survivor tried five times to book and couldn't get through. The practice hired more reception staff.
Ask: How does it handle accents and speech difficulties, and how quickly does a person take over?
06
Clinical questions it shouldn't answer
Patients describe symptoms and ask whether they should worry. The British Dental Association is clear that if AI advice is wrong, accountability rests with the dental professional, not the AI provider. HIQA's national guidance, which names dental clinics among the services it covers, puts accountability with the service using the AI.
Ask: What must it never answer, and when does it pass the call to a person or tell the caller to ring 112 or 999?
07
Patients not told it's an AI
Since 2 August 2026, the EU AI Act requires AI systems that talk to people to make clear they're an AI, unless that's obvious. HIQA's guidance adds that when someone is dealing with an AI tool, there should be a clearly signposted option to speak to a human.
Ask: What are the exact opening words, and how does a caller reach a person?
08
Another supplier to trust, and to lose
The market is crowded and young. Some sellers are months old. If a vendor closes, is bought or changes its prices, your diary and your patients' data are tied up in it. And every supplier connected to your systems is one more door an attacker can try.
Adjacent · a dental group, not an AI receptionistIn August 2026 a US dental group reported unauthorised access to its network and began investigating whether patient data was affected. Dental organisations are targets, and each connected supplier adds to the surface.
Ask: Who owns the transcripts, what happens to our data when we leave, and what if you close?
We found no verified, publicly reported data breach involving an AI receptionist at a dental practice. The cases above are from other settings and are labelled that way.
Size matters
Independent practice or group
The questions are the same. What you should expect in writing, and what's at stake, is not.
Independent practice Group or multi-site
How buying usually worksA demo, then a 7 to 30 day pilotProcurement, IT and compliance sign-off
What usually reassuresGDPR language, an EU hosting claim, AI disclosureAll of that, plus a signed agreement, the full sub-processor list and proof of hosting
What to ask forThe data processing agreement and the sub-processor listSecurity reports, audit logs, single sign-on and multi-site references
The biggest riskBuying on price and a good demoRolling one untested system out across every site
Before you pilot
Ten questions, answered in writing
A good vendor answers all ten without hesitation. Tick them off as the answers come in, or print the list and bring it to the demo.
0/10answered
Not ready for patient calls yet
Tick each question once the vendor has answered it in writing, not just on a call.
The real price
Look past the monthly fee
Extra minutes, setup, the time your team spends checking the system's work, and the cost of leaving all add up. Compare offers over the length of the contract, not by the headline price.
Try it
What a “low monthly price” costs over 24 months
The starting numbers are only an example. Put in the figures from the quotes you've received, including the time your team spends checking the system's work.
Real cost over 24 months
€9,980
Subscription€4,776
Extras€960
Setup€0
Staff time checking€3,744
Leaving€500
The advertised monthly price is 48% of the real cost in this example.
Good enough caution
What a careful rollout looks like
If you go ahead, these five habits cover most of the risk.
Paperwork first
A signed data processing agreement and an impact assessment before any patient call.
Tell people
An AI notice and a recording notice in the first seconds, and an easy way to reach a person.
Keep clinical out
Written rules for what it never answers, and when it hands over or points to 112 or 999.
Overflow, not replacement
Use it for the calls your team can't take, and keep people at the desk.
Check its work
Review what it booked every week for the first months, and keep a record.
A different first step
Two different problems
Handing your phone line to a voice bot and making your practice easy for a patient's own AI assistant to find, understand and book are different problems. More patients are starting to ask ChatGPT, Gemini or their phone's assistant to find a dentist who is open on Thursday. For that, what matters is clear prices, published opening hours and online booking that software can complete. It doesn't require sending patient audio through anyone's systems.
Whatever you decide, treat call content as health data, and treat the contract as seriously as you would for any clinical system.
DL
Written byDirk LaudonFounder, SproutMedia
AI specialist with a master's degree in Business Informatics, studied in Germany and Sweden with a focus on artificial intelligence. Dirk has spent years building software and apps, and has worked hands-on in e-commerce, affiliate marketing and social media, so he knows how customers find and choose a business online. At SproutMedia he helps businesses get ready for their customers' AI assistants and agents.
Checked on 29 September 2026. Rules and guidance change, so check the current versions before you decide. This article is general information, not legal advice, and it doesn't assess or recommend any particular product.