HIPAA-Compliant AI Note Takers: What a BAA Actually Covers
Most tools that say “HIPAA compliant” will sign a BAA, then leave the AI features out of it. Here's how to check before patient data reaches a vendor, and where we stand on SOC 2 Type II, ISO 27001, and HIPAA.
OpenWhispr
Engineering
Table of contents
There is no such thing as a HIPAA-certified AI note taker. No agency certifies software as HIPAA compliant. When a vendor's site says “HIPAA certified,” that line came from their marketing team, not an auditor. The question that actually matters is narrower and much easier to check: will they sign a Business Associate Agreement, and does it cover the feature you want to point at patient data?
That second half is where teams get caught. Several large platforms will sign a BAA for their core product and leave the AI features out of it. Which are, of course, the features you came for.
Last updated August 2026. Vendor terms move quickly, so confirm current coverage with the vendor before you send them anything.
Where we stand: SOC 2, ISO 27001, HIPAA
We build OpenWhispr, and it is one of the tools in the table below. That is a conflict of interest, so here is our position up front — read the rest of the page with it in mind.
We are a small team. We went through SOC 2 Type II, ISO 27001, and a HIPAA readiness assessment earlier than a company our size usually would, because “trust us” is not an answer when someone asks where their patient audio goes. Concretely, this is what exists today:
- SOC 2 Type II and ISO 27001. Both assessed by an independent firm, with 66 controls monitored continuously and 13 subprocessors listed publicly. Current status is in our Trust Center.
- HIPAA, with a BAA. Available on request from the Business plan up. We are not “HIPAA certified,” because no such certificate exists, and you should be skeptical of anyone who claims otherwise.
- A third-party penetration test. Run by an external firm. We share the report with customers on request.
- A way to report problems. security@openwhispr.com, acknowledged within 48 hours. Publishing an address only helps if someone answers it.
- Local mode, which matters more than all of the above. Pick a local Whisper model and your audio is transcribed on your own machine and never sent to us. There is nothing for a BAA to cover, because we never receive the recording.
What this does not mean. An audit is a floor, not a guarantee. It says a company has controls and follows them; it says nothing about whether a particular feature fits your workflow. OpenWhispr dictates into any EHR field through a global hotkey, so Epic, Cerner, athenahealth, and web charts all work with no integration. What it does not do is write back through an API: there is no FHIR or HL7 integration, no awareness of which patient's chart is open, and no coded or structured data. It is not a clinically validated ambient scribe either. If you need notes filed against a specific encounter with coding suggestions, a dedicated scribe product will fit better than we do.
The SOC 2 report, ISO 27001 certificate, subprocessor list, and monitored controls are published in our Trust Center, and how we handle data is written out on the security page.
What HIPAA actually requires of an AI note taker
If a vendor creates, receives, stores, or transmits protected health information (PHI) for you, HIPAA calls them a business associate. That triggers a short and specific list:
- A signed BAA. This is the contract that makes the vendor legally accountable for the PHI you hand over. Without one, sending them PHI is itself a violation, however good their encryption is.
- Security Rule safeguards. Access controls, audit logging, encryption in transit and at rest, and a written incident response process.
- Breach notification. They have to tell you about a breach of unsecured PHI without unreasonable delay, so you can meet your own deadlines.
- Minimum necessary use. They can only use PHI the way the BAA allows. That rules out secondary uses, and training AI models on your patient data is the one to watch.
- Subcontractor flow-down. If your audio gets routed to a third-party model provider, that provider is a subcontractor and needs its own BAA. Ask who is in the chain.
The certification myth. HIPAA has no certifying body, so “HIPAA certified” is not a claim you can verify. The honest phrasings are “HIPAA compliant,” “we support HIPAA compliance,” or “we sign BAAs.” A vendor advertising a certificate is either shortening “we passed a third-party readiness assessment” or has misunderstood the rule. Either way, ask for the BAA, not the badge.
The trap: a BAA that excludes the AI
The common failure in 2026 is not a vendor refusing to sign a BAA. It is a vendor signing one that quietly does not cover the AI. Two of the biggest platforms work this way:
Zoom. Zoom offers a BAA on Zoom for Healthcare and eligible Business and Enterprise plans, covering Meetings, Webinars, Phone, Team Chat, and Rooms. But turning on HIPAA mode disables a set of AI Companion features, and only some of what remains, such as smart recording and meeting summary, sits inside the BAA. The compliant setup is the less capable one. Zoom's HIPAA documentation
Notion. Notion will sign a BAA, but only for Enterprise customers above a minimum seat count, and Notion AI is excluded from that coverage on every plan. You can store PHI in a Notion database. You cannot point Notion AI at it. Notion's HIPAA help page
The pattern repeats because of how these products get built. Compliance reviews the platform, the AI ships later on a different legal footing, and the carve-out never comes up in the sales call. So ask for the BAA's scope in writing, feature by feature, rather than a yes or no about the company.
Which AI note takers will sign a BAA
Status as of August 2026, from each vendor's published documentation. The last column is the one that matters most and the one pricing pages answer least often.
| Tool | Signs a BAA? | Required plan | AI features covered? |
|---|---|---|---|
| OpenWhispr | Yes, on request | Business plan and above | Yes, or no PHI leaves the device |
| Otter.ai | Yes | Enterprise only | Yes, under the BAA |
| Fathom | Yes | Enterprise only | Yes, under the BAA |
| Fireflies.ai | Yes, on request | Healthcare tier | Yes, under the BAA |
| Zoom AI Companion | Partial | Healthcare / eligible plans | Only some features |
| Granola | No | — | No |
| Notion AI | Partial | Enterprise, 100+ seats | No, AI is excluded |
OpenWhispr
A BAA is available on request from the Business plan up, a lower bar than the Enterprise-only gate Otter and Fathom apply. In local mode the question does not arise: transcription runs on your machine with open-source Whisper models and the audio is never sent to us. Gizmo Labs, which builds OpenWhispr, holds SOC 2 Type II and ISO 27001 and runs HIPAA and GDPR programs.
Otter.ai
Otter announced HIPAA compliance in July 2025 after an independent assessment and signs a BAA covering the use and disclosure of PHI. Only Enterprise qualifies. Basic, Pro, and Business customers cannot get one, so the compliant tier is a real jump in price.
Compare OpenWhispr and Otter.aiFathom
HIPAA compliance backed by a BAA at the Enterprise level. Fathom's model providers — Anthropic, OpenAI, and Google — are contractually barred from training on Fathom user data, which is the subcontractor question answered properly.
Compare OpenWhispr and FathomFireflies.ai
Fireflies launched a healthcare offering in September 2025 with a HIPAA-compliant tier. The BAA is not automatic: default plans are not covered and you have to ask. Fireflies says it has signed BAAs with its own vendors barring ePHI training and storage.
Compare OpenWhispr and Fireflies.aiZoom AI Companion
The BAA covers Zoom's core products, but HIPAA mode switches off a range of AI Companion features and only a subset stays in scope. Check feature by feature before relying on it for clinical documentation.
Granola
Granola does not currently offer HIPAA compliance or a BAA. Good product, but not an option for PHI until that changes.
Compare OpenWhispr and GranolaNotion AI
Notion Enterprise signs a BAA covering pages, databases, wikis, and file uploads, but Notion AI sits outside it on every plan. Fine for storing documentation, unusable as an AI scribe for PHI.
Compiled from vendor documentation in August 2026. Plan names, tiers, and BAA scope change often, so treat this as a starting point for your own diligence rather than a substitute for it. Confirm current terms with the vendor and your compliance counsel.
Five questions to ask before you record PHI
Most vendor security pages answer the easy questions and skip the ones that decide whether you can use the product at all. Put these five in writing:
- Will you sign a BAA, and on which plan? If the answer is “Enterprise only,” get the price before you get attached. The compliant tier is often several times the number you were first quoted.
- Does the BAA name the AI features? Not “is the product covered” but whether transcription, summarization, and any AI chat or agent features are each in scope. This is exactly where Zoom and Notion diverge from their own marketing.
- Which subprocessors receive PHI? If audio goes to OpenAI, Anthropic, Google, or a hosted speech service, each is a subcontractor that needs its own BAA and a no-training commitment. Ask for the list, not a reassurance.
- Is our data used for training or product improvement? “We don't sell your data” is a different and much weaker promise. You want a contractual ban on training and on humans reviewing your recordings.
- How long is audio kept, and can we set it to zero? Real-time processing with immediate deletion is not the same as ninety-day retention with a delete button. Retention you cannot configure is retention you will have to defend in an audit.
Why local processing changes the math
Every question above exists because PHI is leaving your organization and landing on someone else's servers. When the audio never leaves the device, most of the analysis stops applying:
- No disclosure to a business associate, because the vendor never receives the PHI.
- No subprocessor chain to audit, because no third-party model provider is in the path.
- No retention policy to negotiate, because there is no server-side copy.
- No exposure to a vendor changing its policy later, because the model runs on hardware you control.
- Works with no network access, which matters in facilities where clinical machines are deliberately offline.
The trade-off is real and worth stating. Local models need a reasonably modern machine, the largest and most accurate ones are slower on older hardware, and you give up the convenience of a meeting bot that joins calls on your behalf. For a lot of clinical dictation that is a good trade. For high-volume ambient scribing across a large practice, it may not be.
This is the design OpenWhispr is built around, and it is the reason we think the local option matters more than any certificate we hold.
SOC 2 and ISO 27001 are not HIPAA
These three get bundled together in procurement conversations, and they answer genuinely different questions. Knowing which is which saves time on both sides of a security review:
- SOC 2 is a report, not a certificate. An independent auditor produces it against the Trust Services Criteria. Type I looks at how controls are designed on one date. Type II tests whether they actually worked over a period, usually three to twelve months, and it is the one worth asking for. Anyone calling themselves “SOC 2 certified” is describing a document that does not work that way.
- ISO 27001 really is a certification. An accredited body certifies an organization's information security management system against the standard, on a three-year cycle with surveillance audits. Ask for the certificate number, who issued it, and above all the scope statement, which tells you what is actually covered.
- HIPAA is a law, with no certificate at all. Compliance is an ongoing obligation you demonstrate through safeguards, policies, risk analysis, and signed BAAs. SOC 2 and ISO 27001 are good evidence that a vendor runs a serious security program. Neither one replaces a BAA.
Frequently asked questions
Is Otter.ai HIPAA compliant?
Yes, but only on the Enterprise plan. Otter announced HIPAA compliance in July 2025 after an independent assessment and will sign a BAA covering the use and disclosure of PHI. Basic, Pro, and Business customers cannot get a BAA, so Otter is not HIPAA compliant on those tiers. Contact Otter's sales team to start the process.
Is Fathom HIPAA compliant?
Yes, at the Enterprise level, backed by a BAA. Fathom's AI providers — Anthropic, OpenAI, and Google — are contractually barred from training on Fathom user data. Lower tiers are not covered, so confirm your plan qualifies before recording anything clinical.
Is Notion HIPAA compliant?
Partly. Notion signs a BAA for Enterprise customers above a minimum seat count, covering pages, databases, wikis, and file uploads. Notion AI is excluded from that coverage on every plan, so you cannot use Notion's AI features on protected health information even as an Enterprise customer with a signed BAA.
Is Zoom AI Companion HIPAA compliant?
Only in part. Zoom signs a BAA for Zoom for Healthcare and eligible Business and Enterprise plans, but enabling HIPAA mode disables several AI Companion features. Some, such as smart recording and meeting summary, are in scope; others are not. Confirm the specific features you need are covered before using it for clinical documentation.
Is Fireflies HIPAA compliant?
Yes, on its healthcare tier. Fireflies launched a HIPAA-compliant offering in September 2025, but you have to request the BAA explicitly, as default plans are not covered. Fireflies also reports signing BAAs with its own subprocessors barring them from training on or storing ePHI.
Is Granola HIPAA compliant?
No. Granola does not currently offer HIPAA compliance or a Business Associate Agreement, so it should not be used to record or process protected health information.
What is the best HIPAA-compliant AI note taker for therapists?
It depends on whether you need a meeting bot. Solo and small practices are often best served by on-device dictation, where session audio never leaves the laptop and no BAA is needed for that step. If you need a bot that joins telehealth calls, Otter Enterprise, Fathom Enterprise, and the Fireflies healthcare tier all sign BAAs. Whichever you pick, check the retention setting and the subprocessor list, since therapy notes are among the most sensitive records HIPAA covers.
Do I need a BAA if transcription runs locally on my computer?
Generally no, for that step. If audio is transcribed entirely on-device and never sent to the vendor, the vendor is not creating, receiving, storing, or transmitting PHI for you, so it is not acting as a business associate in that flow. You still need your own safeguards: device encryption, access controls, and a policy for where the resulting notes live. Confirm the analysis with your compliance counsel.
Does SOC 2 or ISO 27001 mean a tool is HIPAA compliant?
No. SOC 2 is an auditor's report on security controls and ISO 27001 certifies an information security management system. Both are meaningful evidence of a serious security program, but neither creates the contractual relationship HIPAA requires. Only a signed BAA does that.
What is the difference between HIPAA compliant and HIPAA certified?
“HIPAA certified” is not a real status, because no government agency or accreditation body certifies software against HIPAA. Vendors using the phrase usually mean they completed a third-party readiness assessment. What you can verify is whether they sign a BAA, what that BAA covers, and which safeguards they have documented.
Is there a free HIPAA-compliant AI note taker?
OpenWhispr's local mode is free and open source, and because the audio never leaves your device there is no disclosure to cover. If you want our cloud instead, a BAA is available from the Business plan up. Most cloud-based note takers tie their BAA to Enterprise pricing, so a free cloud tier is almost never usable with PHI. Check the plan requirement before assuming the free option works.
Can AI note takers train on patient data?
Not under a properly drafted BAA. The agreement should explicitly bar the vendor and every subprocessor from using PHI for model training or product improvement. Ask for that language in writing. A privacy-policy line about not selling data is a much weaker promise than a contractual ban on training.
This is general information about how vendors are set up, not legal advice. Your own HIPAA obligations depend on your organization, your risk analysis, and your counsel.
Dictation and meeting notes that stay on your machine
OpenWhispr runs open-source Whisper models locally, so your audio never has to leave your device. A BAA is available from the Business plan up if you do need our cloud. Free, open source, and available for macOS, Windows, and Linux.