Why "HIPAA compliant" is not a property a vendor can have
There is no federal body that inspects a transcription product and declares it compliant. The obligations in the Privacy and Security Rules fall on covered entities and on the business associates they share data with, and they attach to the arrangement rather than to the software. Two practices using identical software can be in completely different positions depending on what they signed and how they configured it.
That matters practically, because it means the question is not "is this vendor compliant" but "does this arrangement satisfy my obligations". A vendor can help or hinder that, but they cannot do it for you, and one claiming to has misdescribed the rule.
The questions that actually settle it
Most vendor security pages answer questions nobody asked while omitting the ones that determine whether you can lawfully use the service. These are the ones to put in writing:
- Will you sign a BAA, and can I see it before committing? Delay is the answer.
- Who else touches the audio? Name every subcontractor and model provider, and confirm each is covered by an equivalent agreement.
- Is my audio used to train models? If yes, PHI is being used for a purpose no patient authorised.
- Where is the audio stored, for how long, and can I require deletion with confirmation?
- Is access logged, and can I obtain the log? This is what lets you answer "who saw this record" after an incident.
- What happens on termination - is my data returned, destroyed, or retained?
The substitution to watch for
A specific and common move: citing the hosting provider's certifications as though they were the vendor's own. "Hosted in SOC 2 certified data centres" is a true statement about the data centre and says nothing about the vendor's own controls. A vendor that blurs that distinction on a security page is telling you something about how they handle ambiguity everywhere else.
The honest version is unglamorous and more useful. Encryption in transit and at rest, logged access, a BAA on request, and a plain statement of which certifications the vendor itself holds and which it does not.
Compliance and clinical correctness are different problems
An arrangement can be fully compliant and still produce documentation that harms a patient. A transcript with a wrong dose is a clinical problem, not a privacy one, and no BAA addresses it. Both questions have to be asked, and vendors tend to answer the first loudly and the second not at all.
The second question has a concrete form: what evidence do I get that somebody checked this? CMS audit posture treats a note signed seconds after an encounter as evidence that no review occurred, and the only affirmative defence against a negligent-documentation claim involving AI-generated content is a contemporaneous log showing the clinician reviewed the specific content before signing.
Where ScribeForms stands, stated plainly
Applying our own test to ourselves: a BAA is available on request. Data is encrypted with AES-256 in transit and at rest, access is logged, and audio is not used to train models. Our hosting providers hold SOC 2 certification; ScribeForms' own SOC 2 Type II audit is in progress and we will publish the report when it exists rather than before - which is the answer we would want from a vendor, and the one most vendors avoid giving.
On the clinical side: human review is a per-job choice at a stated rate, extraction returns per-field confidence with the supporting quote, and every approval is recorded over a digest of exactly the content the signer saw, with the elapsed time between transcript and signature. That is the artifact an audit asks for, and it is the part a BAA does not cover.
Offshore outsourcing changes the analysis
A large share of transcription work is performed outside the United States, and HIPAA does not prohibit that - but it does not stop applying either. The business associate obligations travel with the data, and so does your accountability for it. What changes is enforceability: a subcontractor in another jurisdiction is bound by a contract you would have to litigate abroad, and a breach notification obligation is only as good as the party that has to report it.
So the questions sharpen rather than change. Which countries is the audio processed in? Are the downstream agreements enforceable where those subcontractors sit? Does the vendor carry insurance that responds to a breach by a foreign subcontractor? None of these has a single right answer, and a vendor that has thought about them will answer specifically while one that has not will reassure you generally.
Sources
- 45 C.F.R. § 164.308(b)(1) (business associate contracts and other arrangements)
- 45 C.F.R. § 164.314(a)(1) (required contents of a business associate agreement)
- 45 C.F.R. § 164.312 (technical safeguards)
- 45 C.F.R. § 164.312(b) (audit controls)
Verified 19 September 2026.
The regulatory information on this page is general background compiled from public primary sources, not legal or compliance advice. Requirements change and vary by jurisdiction and by court. Verify current rules with the relevant authority or your own counsel before relying on them.