Data Residency, Call Recording, and AI Training: What DSOs Should Ask Their AI Vendors
Three questions are coming up more often in DSO vendor reviews: is the call recorded, is patient data used to train AI models, and where does that data actually live. Here's how to think through each one.
Quick Answer
Three questions are increasingly central to how DSOs should evaluate AI vendors: is the call recorded or processed and discarded in real time, is patient data ever used to train the vendor's own AI models, and where does patient data actually live once it reaches the vendor. These matter because HIPAA compliance alone doesn't answer any of them, a vendor can be fully compliant while still recording indefinitely, training on customer data, or holding a full copy of your patient database. Marea's answers: audio is never stored, patient data is never used to train models, and your chart stays in your own PMS rather than being copied into a separate database.
Key Takeaways
- Three questions are showing up more often in how DSOs evaluate AI vendors: is the call recorded or just processed and discarded, is patient data used to train the vendor's AI models, and where does patient data actually live once it reaches the vendor.
- These aren't new legal requirements. They're practical due diligence questions that matter regardless of what a vendor's compliance paperwork says, because HIPAA compliance and data minimization are related but different things.
- A 2025-2026 federal lawsuit involving a large DSO's AI phone vendor (ultimately dismissed in the vendor's favor) is a useful real-world illustration of why these questions get asked: it centered on exactly these three issues, recording without clear disclosure, data used to train a vendor's own models, and where patient data was processed.
- DSOs carry more exposure than individual practices on all three questions. A single vendor decision applies across every affiliated practice, so a single disclosure gap or data-handling choice scales into enterprise-wide exposure rather than a one-office problem.
- "Data residency" often gets reduced to a legal checkbox about server location. The more useful everyday version of the question is simpler: does your patient's chart get copied into a new place at all, not just where that place happens to be.
Why These Questions Matter More for DSOs
A solo practice evaluating an AI phone or scribe vendor is thinking about its own patients. A DSO evaluating the same vendor is making one decision on behalf of every practice, and every patient, in its network, often without each individual patient ever being told which AI vendor is handling their call. The efficiency of standardizing on one AI vendor across a DSO is exactly what turns a single disclosure gap or a single data-handling decision into enterprise-wide exposure rather than a single office's problem.
A recent federal case illustrates why this is getting more attention. In Lisota v. Heartland Dental, LLC and RingCentral, Inc., a patient alleged that an AI-powered phone system used across Heartland Dental's 1,700-plus affiliated practices recorded and analyzed her calls without consent, and, in an amended complaint, that the vendor used patient call data to train its own AI models. A federal court ultimately dismissed the case in the defendants' favor, finding the AI functionality was a core, necessary part of the vendor's phone service. The ruling was narrow (it turned on one specific statutory exception) and it doesn't mean these practices are risk-free generally. What's useful about the case isn't the outcome, it's that a federal court spent about a year examining exactly the three questions below, which is a reasonable signal that they're worth answering clearly before a patient, a regulator, or a plaintiff's attorney asks for you.
Related read: The HIPAA question every dentist asks us.
Question One: Is the Call Recorded, or Processed and Discarded?
This is a more specific question than "is it HIPAA compliant," and it's worth separating from that broader claim entirely. A vendor that stores call audio has created a recording, retained somewhere, of a patient conversation, regardless of how securely that recording is stored. A vendor that transcribes in real time and discards the audio immediately has created a transcript or summary, not a stored recording. Both can be accurately described as "AI-powered call analysis." Only one of them has an audio file that exists somewhere after the call ends.
The practical difference shows up in a few places: what's technically possible to produce in response to a subpoena, what could be exposed in a breach, and what consent framework actually applies, since recording a call and transcribing it in real time without retention are treated differently under some state wiretapping and consent laws. Ask any vendor directly: is audio stored, for how long, and is that retention period something you can see in writing rather than take on faith.
Related read: Is AI Dental Software HIPAA Compliant? What to Actually Ask Vendors.
Question Two: Is Patient Data Used to Train AI Models?
This is a different question from basic compliance, and it's one that's easy to assume the answer to without actually asking. A vendor can be fully HIPAA compliant, encrypted, BAA-covered, and still use de-identified or aggregated customer data to improve its own models, unless its contract specifically prohibits it. "De-identified" and "aggregated" are doing a lot of work in that sentence; ask what those terms mean in the vendor's specific case, not just whether the general policy uses them.
This question gained real attention through the amended complaint in the Heartland Dental case, where the plaintiff added an allegation that the AI vendor used patient call data to train its own models, not just to serve the dental practices it contracted with. That specific claim wasn't the basis for the court's ultimate ruling, but it reflects where scrutiny is heading: not just whether a tool works well, but what else the data it processes gets used for. Ask for a flat, written answer: is patient data used to train models in any form, full stop, not a qualified answer about anonymization or aggregation.
Question Three: Where Does Patient Data Actually Live?
"Data residency" usually gets defined narrowly, as which country or region a vendor's servers are physically located in, a question that matters for cross-border data transfer rules. That's a real consideration, but for a dental practice or DSO, a more immediate version of the question is simpler and matters sooner: does your patient's chart get copied out of your PMS into a new place at all?
A tool that reads your PMS in real time and writes results back, without ever creating a second, standing copy of the patient record, has a fundamentally different residency story than a tool that imports and stores your patient database on its own servers, wherever those servers happen to be. The first approach means there's no second copy to lose track of, to secure separately, or to be breached independently of your own systems. The second means there is, and "where" that copy lives becomes a real question with real stakes, not a formality. Less data copied and held, in fewer places, is a smaller target by definition, independent of how well any single location is secured.
Related read: Which Dental PMS Systems Integrate With AI Software.
How Marea Approaches All Three
A few specifics, each verifiable on Marea's security page:
Call audio is never stored. Across both Receptionist and Scribe, audio is transcribed in real time and discarded the moment the call ends or the note is generated. There's no recording to play back, and no audio to produce in response to a subpoena or expose in a breach, because it was never written to disk in the first place.
Patient data is never used to train models. Marea operates under a signed Business Associate Agreement with every customer. Patient data is not used to train external models, sold to third parties, or shared outside the workflow that produced it.
Your patient chart stays in your PMS. Marea reads what it needs from your practice management system in real time and writes outcomes back; it doesn't migrate or replicate your patient database into a separate copy. What Marea does retain is narrow: call summaries, generated letters, and completed form submissions, encrypted, exportable, and deletable on request.
The practical effect on breach exposure: if Marea's systems were ever compromised, there's no audio to find and no copy of patient charts to expose. What would be exposed is encrypted call summaries, letters, and form submissions, a materially smaller set of data than platforms that store recordings or replicate full patient records.
Bring your IT or compliance team. Book a walkthrough built for DSO-level review: recording, training, data residency, and what actually happens in a breach scenario. Book a Free Demo.
What to Ask Before You Sign
- Ask whether call audio is stored or discarded, and get the retention period in writing if anything is stored.
- Ask directly, in writing, whether patient data is ever used to train the vendor's own models, in any form, including anonymized or aggregated.
- Ask whether the vendor creates a standing copy of your patient database, or reads and writes without replicating it.
- Ask what a breach would actually expose, specifically, not a general "we take security seriously" answer.
- If you're a DSO, ask how a single vendor decision scales across your full network, and whether disclosure obligations differ by state for your patient population.
- Have your own counsel review how a vendor's answers here map to your specific state's wiretapping and privacy statutes; this varies by state and isn't something a vendor's marketing page can answer for you.
Frequently Asked Questions
What's the difference between a vendor being HIPAA compliant and not recording calls?
They're related but separate questions. HIPAA compliance covers encryption, access controls, and a signed BAA, baseline requirements that most established vendors meet. Whether a vendor records and retains call audio, versus processing it in real time and discarding it, is a separate architectural choice that HIPAA compliance alone doesn't answer. A vendor can be fully compliant while still storing months of call recordings.
Can an AI vendor use patient data to train its models if the data is anonymized?
It depends entirely on the vendor's specific contract and practices, which is exactly why this is worth asking directly rather than assuming. "Anonymized" and "aggregated" can mean very different things between vendors, and a general compliance claim doesn't tell you whether your specific data, in any form, is used to improve a vendor's own models. Ask for a flat written answer rather than accepting qualified language.
What does "data residency" mean for a dental practice, practically?
Beyond the formal question of which country a vendor's servers are in, the more immediate question is whether your patient's chart gets copied out of your practice management system into a new, separate database at all. A vendor that reads and writes to your PMS without creating a standing copy has a simpler, smaller-footprint data residency story than one that imports and stores your patient database on its own infrastructure.
Why does this matter more for DSOs than individual practices?
A DSO's vendor decisions apply across every affiliated practice at once, which is also what can turn a single disclosure or data-handling question into exposure across the entire network rather than one office. The scale that makes a shared AI vendor efficient for a DSO is the same scale that makes vendor-selection questions higher-stakes.
What happened in the Heartland Dental case mentioned above?
A patient sued a large DSO and its AI-powered phone vendor, alleging the system recorded and analyzed her calls without consent, and, in an amended complaint, that the vendor used patient call data to train its own AI models. A federal court dismissed the case in the defendants' favor in 2026, finding the recording and analysis were a core, necessary part of the vendor's phone service under a specific statutory exception. The ruling was narrow and case-specific; it isn't a general statement that these practices carry no risk, which is why the underlying questions are worth asking any vendor directly.
Sources & Further Reading
On the Heartland Dental case (mentioned above)
- When AI Answers the Phone: Heartland Dental's Impact, Sheppard Mullin
- Court Upholds 'Ordinary Course of Business' Exception for AI Call Analytics Under ECPA, Troutman Pepper
- Key ECPA Decision Outlines Important Exceptions to the Wiretap Act, Freeman Mathis & Gary
- Recent GenAI Class Actions Build on Early Successes and Break New Ground, Holland & Knight
- Judge Dismisses AI Lawsuit Against Heartland Dental, Becker's Dental Review
- Dental Office Admin Providers End AI Transcription Privacy Suit, Bloomberg Law
- Case docket: Lisota v. Heartland Dental, LLC, 1:25-cv-07518, CourtListener
Marea resources
More from the Marea blog
Marea is the clinical documentation platform for dental practices. Marea Documentation writes the note, the letter, and the perio chart. Marea Inbound answers the call and completes intake — on the PMS you already use.