Under HIPAA, a transcription service that handles patient audio for a healthcare provider is almost always a business associate. That means you need a signed Business Associate Agreement (BAA) before you send it anything. Cloud medical transcription services that sign BAAs are the usual route. The other is on-device transcription, where speech is turned into text on a phone or computer you control, so no outside company ever receives the recording. That removes the vendor from the picture but puts the device’s security squarely on you. No app is “HIPAA certified.” Compliance comes from how a tool is used inside your organization’s safeguards.
This guide is for practices and clinicians choosing a transcription service or app. Therapists dictating their own session notes will find a narrower walkthrough, with therapy note tools and a session-note workflow, in HIPAA compliant dictation software for therapists. None of this is legal advice, so check any decision with your compliance officer or privacy counsel.
When is a transcription vendor a business associate? #
The definition is in federal regulation. Under 45 CFR 160.103, a business associate is a person or organization that, on behalf of a covered entity, “creates, receives, maintains, or transmits protected health information” for a regulated function or activity. The definition also covers vendors providing legal, consulting, data aggregation, management, administrative and similar services where protected health information (PHI) is disclosed to them.
A service that receives clinical dictation or session recordings and sends back transcripts is creating and maintaining PHI on the provider’s behalf. So in practice you need:
- A signed BAA that spells out how the vendor protects, uses and discloses PHI.
- Reasonable assurance that its safeguards match what the BAA promises.
- Your own policies for who can send what, from which devices.
Three ways to handle clinical transcription #
| Approach | Who receives the audio | What you need | Trade-offs |
|---|---|---|---|
| Human transcription service | The vendor’s transcriptionists | BAA, confidentiality agreements, secure upload | Highest accuracy, slowest, per-minute cost |
| Cloud AI transcription or AI scribe | The vendor’s servers and often its AI subprocessors | BAA, clarity on retention and model training | Fast, EHR integrations, ongoing subscription |
| On-device transcription | Nobody outside your device | Device security, organizational approval | Private by design, fewer features, you manage the data |
What to ask a cloud transcription vendor #
A vendor saying it’s “HIPAA-ready” is only a start. Ask for specifics:
- Will you sign our BAA, or provide yours for review?
- Where are audio and transcripts stored, and for how long? Can we set automatic deletion?
- Is our data used to train or improve models? Can we opt out in writing?
- Which subprocessors touch the audio? Cloud hosts, AI model providers, human reviewers.
- How is access controlled and logged? Look for multi-factor authentication and audit logs.
- Is data encrypted in transit and at rest?
- Can you share an independent audit, such as a SOC 2 Type II report?
- How and how fast do you notify us of a breach?
Good vendors answer all of these readily. Sonix, for example, publishes that it’s SOC 2 Type II certified, encrypts stored data with AES-256, doesn’t use customer data for model training, and offers HIPAA compliance through a medical version of its service.
What on-device transcription solves, and what it doesn’t #
When the speech model runs on your own device, the recording isn’t disclosed to a transcription vendor at all. For a clinician dictating notes on a phone, that removes the largest risk in most workflows: a third party holding thousands of patient recordings.
It doesn’t remove your other obligations. HIPAA’s Security Rule still expects reasonable safeguards for PHI on any device you use:
- Lock and encrypt the device. Use a strong passcode and short auto-lock. Modern phones encrypt storage when locked.
- Watch backups. Phone and computer backups can copy app data to the cloud. Know what your backup includes.
- Share through approved channels. Emailing a transcript to yourself creates a copy outside your control. Move text into the EHR the way your organization approves.
- Delete what you don’t need. Once a note is in the record, delete the audio and the draft transcript.
- Get approval. Many organizations manage which apps may touch PHI. Ask before you start.
Where an offline phone app fits #
For personal dictation of clinical notes, reminders or case reflections, an on-device app keeps the audio off every server. Private Transcribe runs OpenAI’s Whisper on an iPhone or Android phone. Recordings and transcripts stay in the app’s local storage, there’s no account, and after a one-time model download it works in airplane mode. Its developer never receives your recordings or transcripts. Settings useful for clinical work:
- Keep recordings off: each recording is deleted automatically once it’s transcribed, leaving only the text.
- Custom vocabulary: add drug names, procedures and colleagues’ names so they’re spelled correctly.
- Clear All Data wipes every recording, transcript and model from the phone in one step.
Be clear about the limits. It isn’t a medical scribe, it doesn’t structure SOAP notes, and it doesn’t connect to an EHR. The free version shows ads through Google AdMob, which is a network connection on the device even though no audio is involved. The one-time Pro purchase removes ads entirely, which is the sensible choice for clinical use. As with any tool, confirm with your compliance team that it’s approved for PHI in your setting.
Human or AI transcription for clinical notes? #
- Human transcription is the most accurate for complex terminology and poor audio, and the slowest. It suits legal-sensitive records and specialist reports.
- Cloud AI is fast and integrates with EHRs. Accuracy is good on clear dictation. Check retention and training terms carefully.
- On-device AI is fast and private, with accuracy that depends on the model size and recording quality. Use a larger model and a close microphone for clinical terms, and always review before a note goes into the record.
Whatever you use, the clinician reviewing the text is the final safeguard. Automated transcripts can mishear drug names and doses, and Whisper-based models occasionally insert text that wasn’t said during long pauses.
Therapists have a specific set of concerns, covered in HIPAA-compliant dictation software for therapists. For a side-by-side with legal work, see private dictation tools for lawyers and doctors. The general privacy trade-off is in on-device vs cloud transcription. How different apps handle recordings after transcription is in speech-to-text apps that delete audio after transcription.
Frequently asked questions #
Is there HIPAA-certified transcription software? #
No. There’s no official government certification that makes software “HIPAA compliant.” Vendors can sign BAAs, pass independent security audits and build appropriate safeguards, but compliance depends on how your organization uses the tool, including devices, access and policies.
Do I need a BAA for a transcription service? #
If the service receives patient audio or creates transcripts containing PHI on your behalf, it fits the definition of a business associate, and you need a BAA in place before sharing PHI. If transcription happens entirely on your own device and no vendor receives the data, there’s no vendor to sign one. Confirm your specific setup with your compliance officer.
Is on-device transcription HIPAA compliant? #
On-device transcription avoids disclosing PHI to a transcription vendor, which removes a major risk. The device still has to meet your organization’s safeguards: encryption, passcodes, controlled backups and approved sharing. Whether a particular app is allowed for PHI is your organization’s decision.
Can I use my phone’s built-in dictation for patient notes? #
Built-in dictation on recent iPhones processes speech on the device in supported languages, and Keyboard settings show whether yours does. Android phones vary. Some dictation still uses servers, so check the setting and your organization’s policy before dictating patient details.
How long should clinical recordings be kept? #
Keep the audio only as long as you need it to verify the transcript, unless your organization’s records policy says otherwise. Once the note is reviewed and in the record, deleting the recording reduces what could be exposed if a device is lost.