exma Try exma free

Guide

Is AI transcription HIPAA-compliant? The BAA, safeguards & vendor checklist that actually decide it

By the exma team · August 6, 2026 · 8 min read

TL;DR: AI transcription is not automatically HIPAA-compliant, and no official "HIPAA certification" exists — any badge claiming otherwise is marketing. Compliance is decided by the vendor's practices: a signed Business Associate Agreement (BAA), encryption in transit and at rest, access controls with audit logs, a contractual promise never to train AI models on your audio, and retention and deletion you control. Consumer note-takers typically fail several of these; purpose-built tools like exma are designed around them.

When HIPAA applies to a recording

HIPAA governs protected health information (PHI) — individually identifiable health information held or transmitted by a covered entity (providers, health plans, clearinghouses) or its business associates. A recording doesn't need to be a clinical dictation to qualify. If the audio identifies a person and touches their health — a telehealth visit, a care-team meeting, an independent medical examination, a workers'-comp interview, a peer-review committee, an insurance claim call — the recording and its transcript are PHI.

The moment you hand that audio to a transcription service, the service is processing PHI on your behalf. Under HIPAA, that makes the vendor a business associate — and that classification, not the vendor's marketing page, is what triggers the obligations below.

The four non-negotiables

1. A signed Business Associate Agreement

The Privacy Rule requires a written BAA before PHI is shared with a business associate. The BAA binds the vendor to safeguard PHI, restrict its use to the contracted service, report breaches, and flow the same obligations down to its own subcontractors (such as the cloud and speech-recognition providers underneath). A vendor that won't sign a BAA is a hard stop — using them for PHI is a violation on its own, however good their security happens to be.

2. Encryption in transit and at rest

Audio uploads and live streams should travel over TLS, and stored recordings and transcripts should be encrypted at rest. Encryption is technically an "addressable" specification under the Security Rule, but in practice it is the baseline every credible vendor meets — and unencrypted PHI is what turns a lost laptop or leaked bucket into a reportable breach.

3. Access controls and audit logs

Unique accounts, role-based access, multi-factor authentication, session timeouts — and an audit trail recording who accessed which recording and transcript, when. The Security Rule expects it, and it's also how you answer the question every incident review starts with: who has seen this file?

4. No training on your data — and retention you control

Two questions AI adds on top of classic HIPAA diligence. First, does the vendor use your audio or transcripts to train models? For PHI the answer must be a contractual no — "de-identified" training claims deserve scrutiny, because audio is hard to truly de-identify. Second, who controls retention? You should be able to delete recordings and transcripts, set retention windows, and get PHI returned or destroyed when the contract ends — that last part belongs in the BAA.

The "HIPAA certified" myth

Neither HHS nor any government body certifies software as HIPAA-compliant. There is no official seal, and the Office for Civil Rights has fined organizations that relied on vendors waving one. What you can verify:

The vendor checklist

HIPAA diligence for an AI transcription vendor
QuestionDisqualifying answer
Will you sign a BAA?No, or only on an enterprise plan you don't have
Is audio encrypted in transit and at rest?Anything but yes, for both
Do you train AI models on customer audio or transcripts?Yes, or an opt-out buried in settings
Who can access recordings, and is access logged?No role-based controls, no audit trail
Can we delete data and set retention windows?Indefinite retention you can't control
Where is data processed and stored?Vendor can't say, or won't name subprocessors
What are your breach-notification commitments?Nothing in writing, or slower than the 60-day rule
Do you have an independent security audit (e.g., SOC 2)?"We take security seriously" with nothing to show

This is the healthcare-specific slice of a broader vendor review — for the full 12-point security checklist covering any confidential audio, see Is your AI transcription tool safe for confidential audio?

Why consumer note-takers don't clear the bar

Most free and consumer-grade transcription apps fail this checklist at the first or third row: no BAA, and training rights over your audio. Some also retain recordings indefinitely, sync them to consumer cloud accounts, or route audio through subprocessors they won't name. None of that is sinister for a podcast interview — all of it is disqualifying for a patient conversation. The same divide shows up in legal work; we've written about it in exma vs. consumer AI note-takers.

Rule of thumb: if a conversation would belong in the chart, its recording belongs only in tools operating under a BAA.

Beyond HIPAA: the adjacent rules

Frequently asked questions

Is AI transcription HIPAA-compliant?

Not by default. Compliance depends on the vendor: a signed BAA, encryption in transit and at rest, access controls with audit logs, no model training on your data, and retention you control. With those in place, AI transcription can be used compliantly.

Do I need a BAA with a transcription vendor?

Yes — if you're a covered entity or business associate and the audio contains PHI, the vendor is your business associate and a written BAA is required before any PHI moves.

Is there an official HIPAA certification?

No. No government body certifies software as HIPAA-compliant. Verify a signed BAA, SOC 2-type audits, and written data-handling policies instead of trusting a badge.

Can I use a consumer AI note-taker with patients?

Generally no — no BAA, possible training rights over your audio, and retention you don't control. Use purpose-built tools operating under a BAA.

What if the vendor has a breach?

The Breach Notification Rule applies: the vendor must notify you without unreasonable delay (60 days at the outside), and you must notify affected individuals and HHS. Your BAA should set the timelines and duties — read it before signing.

This article is general information, not legal advice. HIPAA obligations depend on your role, your state, and the specifics of your data flows — consult your privacy officer or counsel for decisions about PHI.

Transcription built for data-sensitive work

exma encrypts audio and transcripts in transit and at rest, never trains AI models on your data, logs access, and supports the workflows regulated teams rely on. Try it in your browser.

Create your free workspace