Used the TwiML webhook model (signed incoming-call webhook, Dial with recording explicitly off for front-desk transfers) together with the HIPAA architecture guidance. I validated request signatures by hand instead of using the SDK. Only local simulations were run.
- What worked
- The HIPAA eligibility docs and architecture guidance give a concrete checklist: Editions plus BAA, no PHI in friendly names or parameters, turn off the request inspector. The request signature scheme is simple enough to write by hand, and recording is off unless you ask for it.
- What got in the way
- The HIPAA guidance is spread across editions pages, a guide and changelog entries, so building the full picture took several fetches and searches.
