Is AI Transcription HIPAA Compliant?

4 min read

Is AI transcription HIPAA compliant?

No transcription tool is "HIPAA compliant" on its own, and any vendor claiming otherwise is describing something HIPAA does not define. Compliance is a property of the arrangement between you and the vendor. The concrete requirement is that a covered entity must have a Business Associate Agreement in place before disclosing protected health information to a vendor, and a transcription provider handling PHI is a business associate. If a provider cannot produce a BAA, the question of how good their encryption is never arises.

What HIPAA actually requires of a transcription vendor

HIPAA does not certify software. There is no federal body that inspects a transcription product and declares it compliant, which is why a "HIPAA compliant" badge on a vendor website is a marketing claim rather than a credential. What the rule does is impose obligations on covered entities and on the vendors they share data with.

Under 45 CFR 164.308(b)(1), a covered entity must obtain satisfactory assurances, in the form of a written contract, that a business associate will appropriately safeguard protected health information. A transcription provider that creates, receives, maintains, or transmits PHI on your behalf is a business associate. The contract is the Business Associate Agreement, and 45 CFR 164.314(a)(1) sets out what it must contain.

The obligation flows downstream too. A business associate must hold equivalent agreements with any subcontractor that touches PHI. This matters specifically for AI transcription, because a vendor may route audio through a third-party model provider. If that provider is not covered by an agreement, PHI has been disclosed to someone outside the chain.

Encryption is necessary and not sufficient

Vendor security pages lead with encryption because it is the easiest thing to state and the hardest to argue with. AES-256 at rest, TLS in transit, and a list of certifications held by the hosting provider rather than by the vendor. All of that is worth having, and none of it answers the question HIPAA actually asks.

The Security Rule requires administrative, physical, and technical safeguards. Encryption is one technical safeguard. The administrative half — who has access, how access is granted and revoked, how incidents are handled, who is accountable — is where most of the obligation lives, and it is the half a vendor cannot demonstrate with a badge.

Watch for one specific substitution: a vendor citing their hosting provider’s certifications as though they were the vendor’s own. "Hosted in SOC 2 certified data centers" is a true statement about the data center. It says nothing about the vendor’s own controls, and a vendor who blurs that distinction on a security page is telling you something about how they handle ambiguity elsewhere.

The questions worth asking a vendor

Most vendor security pages answer questions nobody asked while omitting the ones that determine whether you can lawfully use the service. These five are the ones that matter:

  • Will you sign a BAA? A refusal, or a delay, is the answer. There is no version of this where you proceed without one.
  • Who else touches the audio? Name the subcontractors and model providers, and confirm each is covered by an agreement.
  • Is my audio used to train models? If yes, PHI is being used for a purpose your patients did not authorise.
  • Is access logged, and can I see the log? An audit trail is what lets you answer "who saw this record" after the fact.
  • How long do you retain files, and can I require deletion? Retention you did not agree to is retention you are responsible for.

Where automated-only transcription creates clinical risk

This is a separate question from compliance, and it is the one that tends to matter more in practice. An AI transcript can be perfectly compliant and still be clinically wrong.

Automated transcription is strong on ordinary speech and weak on exactly what carries risk in a clinical note: drug names, dosages, laterality, anatomical terminology, and unusual proper nouns. The failure mode is quiet. The model does not flag uncertainty; it produces a plausible word. A transcript that says "left" where the dictation said "right", or renders a drug name as a similar-sounding one, reads as clean output.

That is the argument for human review as a required step rather than an upgrade. A reviewer working against the source audio catches the class of error that a model cannot flag, because the model does not know it made one.

State rules sit on top of HIPAA, not underneath it

HIPAA is a floor, not a ceiling. State law frequently imposes stricter requirements, and where it does, the stricter rule governs. Record retention is the clearest example, and it varies more than most practices expect.

Minnesota requires a defined core of the medical record to be kept permanently rather than for a fixed term. Massachusetts treats a physician’s duty to preserve records as surviving retirement, licence lapse, and the physician’s death. Ohio has no general retention statute for physicians at all, while setting a period for facilities. Illinois sets a hospital period but has no equivalent statute for private physician practices.

None of that is visible from a vendor’s compliance page, and none of it is answered by a blanket compliance badge. Check the requirement that applies to your practice in your state, because the vendor will not know it and is not responsible for it.

Sources

  • 45 C.F.R. § 164.308(b)(1) — business associate contracts required
  • 45 C.F.R. § 164.314(a)(1) — business associate contract provisions
  • HHS.gov — Business Associates guidance
  • Minn. Stat. § 145.32 — record retention
  • Ohio Admin. Code 3701-83-11 — facility record retention
  • 210 ILCS 85/6.17 — hospital record retention

Verified 18 September 2026.

The regulatory information on this page is general background compiled from public primary sources, not legal or compliance advice. Requirements change and vary by jurisdiction and by court. Verify current rules with the relevant authority or your own counsel before relying on them.

Need transcription you can rely on?

Every file is transcribed with AI and then checked by a human reviewer before delivery. We confirm the price before work begins.