AI note-taking and transcription tools have changed how many small practices work. Instead of spending 20 minutes after each session typing notes, a clinician speaks, the AI listens, and a draft note appears. The time savings are real.
The compliance risk is also real. And most practices using these tools have never asked the question that matters most: does this tool have a Business Associate Agreement?
Why a BAA matters for AI transcription
Under HIPAA, any company that handles Protected Health Information (PHI) on your behalf is a Business Associate. A Business Associate Agreement (BAA) is the contract that makes them legally responsible for protecting that data.
When you use an AI transcription tool during a patient session, the audio and the resulting text almost certainly contain PHI. The patient's name, their symptoms, your clinical observations. All of it. If that data flows through a third-party tool that hasn't signed a BAA with you, you've created a HIPAA violation, whether or not anything ever goes wrong.
The key question to ask any AI vendor: "Will you sign a Business Associate Agreement with my practice?" If the answer is no, or if they don't know what that means, stop using the tool for anything involving patient data.
How to check if your tool is compliant
The process has three steps and takes less than 15 minutes per tool.
Step 1: Check the vendor's website for a HIPAA page
Search the vendor's site for "HIPAA," "BAA," or "Business Associate Agreement." A compliant vendor will have a dedicated page explaining their HIPAA posture. If nothing comes up, that's a red flag worth taking seriously.
Step 2: Request a BAA directly
If you find a HIPAA page, it should explain how to request a BAA. Some vendors (especially enterprise-tier tools) require you to be on a paid plan before they'll sign one. Some offer it automatically to healthcare customers. A few tools offer a HIPAA-eligible tier as an upgrade.
Step 3: Read the BAA before you sign
A BAA is a legal document, but it doesn't need to be long or complex. Look for: who is responsible for breach notification, how data is stored and encrypted, whether the vendor can use your data to train their models, and what happens to your data if you stop using the service.
Common tools and their HIPAA status
The landscape changes frequently, so always verify directly with the vendor. That said, here's the general picture as of 2026:
- Microsoft Azure AI / Copilot for M365: BAA available through Microsoft's standard HIPAA agreement for qualifying Microsoft 365 plans.
- Google Workspace: BAA available. Covers Google Meet recordings and transcripts for healthcare customers on eligible plans.
- Otter.ai: Offers a HIPAA-compliant Business plan with BAA. Not included on free or standard tiers.
- Whisper (OpenAI): OpenAI does not currently offer BAAs for consumer API access. Not suitable for PHI without a separate enterprise agreement.
- Nabla, Freed, Heidi, Abridge: Healthcare-specific AI scribes designed for clinical use. All offer BAAs. Verify current terms before signing.
Caution on AI model training: Some transcription tools use your audio and transcripts to improve their models. Even tools with BAAs may do this. Check the data processing terms explicitly, and opt out if available. Patient data should not be used to train commercial AI models.
What to do if your current tool isn't compliant
You have two options: upgrade to a plan that includes a BAA, or stop using the tool for patient sessions. There's no middle ground under HIPAA.
If you stop mid-stream, delete any patient data stored in the tool and document that you did so. If the tool won't let you delete your data, that's worth noting and potentially reporting to the vendor.
The good news: compliant tools exist and they work well. The switch is usually less disruptive than practices expect. The harder part is knowing which tools need to be checked in the first place, which is why an AI tool audit is worth doing before a problem surfaces.
Not sure which of your AI tools are safe to use?
The free Cyber Health Score includes questions about AI tool usage and flags common compliance gaps in 5 minutes.
Get your free Cyber Health Score