This page is for independent clinics, dental and physical therapy practices, med spas, and specialist offices whose front desk answers the same ten questions all day. Read the limits section before anything else: a general-purpose website chatbot can help a practice, but only if it stays away from patient health information.
Is Feedbot HIPAA compliant?
No. Feedbot does not sign a Business Associate Agreement (BAA) and is not designed to store protected health information (PHI). Under HIPAA, a vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate and needs a BAA. So the rule for this page is simple: the bot answers questions anyone could read on your website, and nothing about a specific patient’s health goes into the chat.
If you need symptom intake, patient portal answers, refill requests or EHR scheduling, use a healthcare-specific vendor that signs a BAA.
What do patients ask a clinic website?
| Visitor question | What the bot does | Knowledge source |
|---|---|---|
| “What are your hours on Saturday?” | Gives hours by location | Business profile |
| “Do you accept Blue Cross / Medicare / Medicaid?” | Lists networks you publish, reminds them to confirm with their plan | Insurance page |
| “Are you accepting new patients?” | Answers from your current status | Business profile |
| “How do I book?” | Shows your existing booking link or phone number | Business profile |
| “Where do I park? Is there wheelchair access?” | Gives directions, parking and accessibility details | Locations page |
| “What should I bring to my first visit?” | Lists ID, insurance card, forms link | New patient page |
| “How much is a cleaning without insurance?” | Quotes published self-pay prices, or says to call | Self-pay pricing page |
| “Do you offer telehealth?” | Explains which visit types are offered online | Services page |
| “Can I get my lab results?” | Does not discuss results. Points to the patient portal or phone | Custom instructions |
| “Is this rash serious?” | Declines medical advice, suggests booking or calling, emergency line if urgent | Custom instructions |
| “I have chest pain” | Tells them to call 911 now. No further questions | Custom instructions |
What to collect, and what never to collect
Most practice chatbots don’t need lead capture at all: the goal is getting the patient to your existing booking page. If you do want a callback flow (for cosmetic or self-pay services, for example), collect only:
- Name
- Phone or email
- Which location or service line, chosen from a short list (“new patient consultation”, “billing question”)
Do not collect date of birth, insurance member ID, reason for visit, symptoms, medications or diagnoses. A message like “I’d like a consult about knee pain” from a named person can be health information, so tell the bot to keep callback requests generic.
Contacts left in chat appear in Leads when the conversation shows intent. For a practice, turn on human handoff only if your front desk will actually answer in Telegram, and make sure staff don’t discuss patient specifics there either.
What to put in the knowledge base
- Business profile (included in every reply): locations, hours per location, phone, booking link, new-patient status, holiday closures.
- Insurance page: networks accepted, with the year, and a note that coverage depends on the patient’s plan.
- New patient page: what to bring, forms, arrival time, cancellation policy.
- Services page: what you offer and what you don’t, so the bot doesn’t send someone for a service you don’t provide.
- Self-pay price list if you publish one.
Never upload patient lists, schedules, clinical protocols written for staff, or anything from your EHR. See Knowledge base.
Limits and safety rules to write into the bot
Put these in Bot → Behavior → custom instructions and test each one before you publish:
- Emergencies: “If a visitor describes an emergency (chest pain, trouble breathing, stroke signs, severe bleeding, thoughts of self-harm), tell them to call 911, or call or text 988 for a mental health crisis, and do not ask follow-up questions.”
- No medical advice: no diagnoses, no medication or dosing guidance, no opinions on whether symptoms need care. Offer the booking link or phone number.
- No PHI: “If a visitor starts sharing health details, ask them not to share medical information in chat and to call the office or use the patient portal.”
- Attachments: visitors on Starter and up can attach files. The AI doesn’t open them, but your team would receive them. Ask visitors not to send insurance cards, photos of symptoms or medical documents.
- Insurance: always add “check with your plan,” since being in network doesn’t guarantee a service is covered.
Also review your analytics setup. HHS OCR’s guidance on online tracking technologies was partly vacated by a federal court in June 2024 for unauthenticated public pages, but it still applies to authenticated pages like patient portals. Do not install Feedbot inside a patient portal. Keep it on public marketing pages.
State laws can be stricter than HIPAA (Washington’s My Health My Data Act, for example). Ask your compliance advisor before launch.
Sample conversation
Visitor: Hi, are you taking new patients? I just moved and need a family doctor.
Bot: Welcome! Yes, Dr. Patel and Dr. Okafor at the Riverside office are accepting new patients. We’re in network with Aetna, Cigna, UnitedHealthcare and Medicare; please confirm your specific plan with your insurer. You can book a new-patient visit here: [Book online]. Or call (555) 010-2200, Monday to Friday, 8 am to 5 pm.
Visitor: Great. Also I’ve had a cough for three weeks, should I be worried?
Bot: I can’t give medical advice, but a cough that lasts several weeks is a good reason to see a doctor. You can mention it when you book, or call the office to ask for the earliest slot. If you have trouble breathing or chest pain, call 911 now.
Metrics to watch
| Metric | Where | What it tells you |
|---|---|---|
| Booking link clicks | ctaClicks in stats |
Whether chat sends patients to booking |
| Top question categories | Conversation categories | Which phone calls the bot is absorbing |
| Unanswered questions | Content gaps | Missing info on your site (often parking and self-pay prices) |
| Conversations with health details | Read transcripts weekly | Whether your no-PHI instructions work |
Set it up in 3 steps
- Create a bot and add your hours, locations, insurance and new-patient pages. Write the emergency, no-advice and no-PHI rules first.
- Install the snippet on public pages only, through your site builder’s custom code setting (install guide). Use Allowed domains so the bot runs only on your site.
- Test the edge cases: type “chest pain”, “can I double my dose”, and a message with a fake date of birth, and check the replies before going live.
See pricing. If your main need is patient support with records access, a HIPAA-eligible vendor is the right choice; Feedbot fits the public front-desk FAQ.