minutes

Resource

HIPAA-compliant transcription: what the rule actually requires

Every vendor in this category has a page telling you to look for encryption, SOC 2, and a signed BAA. That list is not wrong, but it skips the question underneath it: whether the vendor should be receiving your patients’ audio at all. Here is the test the rule actually applies, the three architectures it produces, and the obligations that stay yours no matter which you pick.

Last reviewed: 2026-08-10Sourced answer

Scope: this concerns HIPAA covered entities and their business associates. Not every clinician is a covered entity, since that status also depends on conducting covered electronic transactions. If HIPAA does not apply to you, state law, professional ethics rules, and your own contracts still do.

Two Things To Get Straight First

There is no official HIPAA certification. HHS says no standard requires a covered entity to certify its compliance, that it does not recognize private Security Rule certifications, and that OCR does not endorse or certify particular products. A private certification may still be meaningful evidence of diligence, and some represent substantial audits. What none of them carries is government recognition, and none prevents OCR finding a violation afterward. When a vendor leads with a HIPAA badge, the useful response is to ask what program issued it and what it examined.

Compliance is a property of the arrangement, not the software. No tool can be compliant on your behalf, because most of the obligations are about what your organization does: your risk analysis, who can access the files, how the endpoint is configured, whether staff are trained. The right question is never “is this app HIPAA compliant.” It is “who ends up holding this audio, under what contract, and have I analyzed the risk of the setup I actually have.”

The Test The Rule Applies

Vendor selection follows from one definition. Under 45 CFR 160.103, a business associate is a person who,

“On behalf of such covered entity… but other than in the capacity of a member of the workforce of such covered entity… creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter…”

Every element matters, and reducing this to “they received PHI” is the most common way to get it wrong. The party must be acting on your behalf, must be outside your workforce, and the activity must be one the rule regulates. Someone can receive PHI and still not be a business associate, most obviously another provider receiving it for treatment. A separate branch of the definition covers enumerated professional services, such as legal or accounting work, where providing the service involves disclosure of PHI.

Applied to this category the answer is usually straightforward: a transcription provider that processes identifiable patient recordings for you is ordinarily a business associate, and 45 CFR 164.502(e) then requires a written contract with satisfactory assurances before you disclose the recording.

Notice what the definition does not turn on: encryption strength, data center location, or SOC 2. Those may be useful inputs to your risk management and your vendor diligence, but none of them determines business associate status, and two of them are not HIPAA requirements at all. What the Security Rule requires is reasonable and appropriate safeguards, with encryption treated as addressable rather than mandatory in every case.

The Exclusions, And The Conduit Idea

Paragraph (4) of the definition excludes four categories, each with conditions worth reading rather than paraphrasing loosely:

  • A health care provider, with respect to disclosures by a covered entity to that provider concerning the treatment of the individual.
  • A plan sponsor, with respect to disclosures by a group health plan, or by a health insurance issuer or HMO with respect to a group health plan, to the plan sponsor, and only to the extent the requirements of § 164.504(f) apply and are met.
  • A government agency, with respect to determining eligibility for or enrollment in a government health plan that provides public benefits and is administered by another government agency, or collecting PHI for such purposes, to the extent those activities are authorized by law.
  • A covered entity participating in an organized health care arrangement that performs a function or activity described in paragraph (1)(i) for that arrangement, or provides a service described in paragraph (1)(ii) to or for it, by virtue of those activities or services.

Software vendors are not on that list, and vendors sometimes present that as ominous. It is not, and the reason matters: paragraph (4) is not the only route to not being a business associate. A vendor that never satisfies the positive definition, because it never creates, receives, maintains, or transmits PHI on your behalf, needs no exception at all. It simply is not one.

The related “conduit” idea is narrower than its reputation. OCR treats it as covering transmission-only services, storage that is temporary and incidental to transmission, and access that is transient or infrequent and necessary to that transmission or required by law. A transcription service that stores your audio or transcripts persistently is outside it, and OCR has been explicit that persistent storage defeats conduit status even where the provider holds no decryption key.

The Three Architectures

Human transcription service

Ordinarily a business associate

The agency and its transcriptionists receive and store your audio and the finished transcript.

BAA required before PHI is disclosed

The traditional model, and where a use requires a certified transcript this is generally the route to one. Ask who subcontracts, where staff are located, and whether the agency signs BAAs with its own vendors.

Cloud AI transcription

Ordinarily a business associate

The vendor receives your audio, processes it on its servers, and usually stores the transcript.

BAA required before PHI is disclosed

Fast and inexpensive, but you are adding a party that holds PHI. Check whether your plan is one the vendor will actually sign a BAA for, since several vendors offer that only on higher tiers; the plan decides whether the required contract is even available to you.

On-device transcription

No vendor in the path, if deployed local-only

The model runs on a machine you already control, and no third party receives the audio.

No BAA with the software vendor, provided it never receives PHI

Whether this holds is a fact about your deployment, not a property of the software. Any cloud summarizer, synced folder, hosted backup, or vendor support access puts PHI back in someone else's hands and needs its own analysis. The tradeoff is that the endpoint becomes the security surface, and there is no vendor contract to fall back on.

One caution that applies to the first two: a signed BAA is necessary when a vendor is a business associate, but it is not sufficient. The disclosure still has to be permissible, still has to satisfy minimum necessary where that applies, and your own risk analysis and safeguards remain your responsibility. The contract allocates obligations; it does not discharge yours.

What On-Device Does Not Do

This is the part our own category oversells, so here it is plainly. Keeping processing local can remove one question, whether a software vendor receives PHI and therefore needs a BAA. It removes nothing else, and it creates work of its own.

  • You owe a fresh risk analysis. The Security Rule requires an accurate and thorough assessment of risks to all ePHI you hold, and recording consultations creates a new corpus of audio and transcripts on an endpoint that may never have held a designated record set before. That is a change to analyze, not a step you skip because nothing was uploaded.
  • Encryption is risk-based. Encryption is an addressable implementation specification, so the question is what your risk analysis concludes and what you document, not a universal checkbox. In practice, full-disk encryption on a portable endpoint holding patient audio is very hard to reason your way out of.
  • A lost laptop triggers an assessment, not automatic notification. Breach notification concerns unsecured PHI and requires the regulatory risk assessment. PHI encrypted to the specified standard can fall outside the notification requirement entirely, which is the practical argument for encrypting before you need it.
  • The rest of the Security Rule still applies. Access control, audit controls, integrity, authentication, device and media controls, contingency planning and backup, and secure disposal all reach these files. How long you must keep the records themselves is a separate question: the Security Rule’s six-year rule governs required HIPAA documentation, while medical record retention periods generally come from other federal or state law.
  • Privacy Rule duties follow the record. If a transcript becomes part of a designated record set, patient access and amendment rights attach to it.
  • Recording consent is a separate question. State wiretap and recording law, and professional ethics rules, apply regardless of where processing happens, and they are not the same thing as a HIPAA authorization. HIPAA permits many treatment, payment, and operations uses without individual authorization; authorization is required where the Privacy Rule does not otherwise permit the use or disclosure.
  • You lose a party to hold accountable. A business associate under contract carries obligations and liability. Your own endpoint carries none.

The honest summary: local processing converts a vendor-disclosure problem into an endpoint problem. That can be a very good trade, particularly where the endpoint is already managed to the standard your other clinical systems require. It is a trade, not an exemption, and an unmanaged personal laptop is a materially worse place for this corpus than a managed workstation.

Where Minutes Fits, And Where It Does Not

Minutes is built for the third architecture. It records on your device, transcribes locally with whisper.cpp, diarizes with local models, and writes markdown into a folder you control. In a local-only deployment, we do not receive, maintain, or transmit your PHI, and supplying software to someone who uses it that way does not by itself create a business associate relationship.

That conclusion is conditional on your deployment, and it is worth being blunt about what breaks it. Configure a provider-backed summarizer, which is off by default, and transcript text goes to whichever model provider you chose, whose terms then govern. Connect an AI agent over MCP and ask it to read your meetings, and what it reads travels to that agent's provider as context. Sync your meetings folder to a hosted drive and that host is now storing PHI. Grant anyone remote access to the machine and the same applies. None of those are exotic; they are ordinary choices that change the analysis, and each needs its own review and ordinarily a BAA with that party. Our security page enumerates every case where bytes touch the network.

Where it is the wrong tool:

  • You need a certified transcript for a filing or proceeding. Requirements vary by jurisdiction and use, and that is generally a human service.
  • You want an ambient clinical scribe that writes structured notes into your EHR, suggests codes, or drafts to a SOAP template. Minutes is not a medical scribe and has no EHR integration.
  • You need centralized audit logs and administrative oversight across a practice. Local files give you ownership, not governance.
  • Your posture depends on having a business associate to hold accountable. Sometimes that contract is precisely the point.
  • The endpoint is an unmanaged personal device. Then you have moved the risk rather than reduced it.

If you are comparing named products rather than architectures, we keep a sourced vendor-by-vendor breakdown of which AI note takers can be used with PHI, and on which plan tier.

Common questions

Is there such a thing as HIPAA-certified transcription software?
Not in any official sense. HHS states that no standard requires a covered entity to certify compliance, that it does not recognize private Security Rule certifications, and that OCR does not endorse or certify specific products. A private certification can still be real evidence of diligence, but it carries no government recognition and does not prevent an OCR finding later. Treat the badge as a claim to examine, not a legal status.
Does a transcription vendor need to sign a BAA?
Ordinarily yes, if it processes identifiable patient audio for you. Under 45 CFR 160.103 a business associate is a person who, on behalf of a covered entity and other than as a member of its workforce, creates, receives, maintains, or transmits PHI for a function or activity the rule regulates. A transcription service handling your patients' recordings normally meets that test, and 45 CFR 164.502(e) then requires the written contract before you disclose. The BAA is necessary, but it does not by itself make the disclosure permissible or complete your own risk analysis.
Is on-device transcription HIPAA compliant?
Software is not compliant or non-compliant; a deployment is. What local processing can change is narrower: where the software vendor never receives, maintains, or transmits PHI, merely supplying that software does not make it a business associate, so there is no BAA to negotiate with them. That conclusion depends on the deployment actually being local-only. Enable a cloud summarizer, sync the folder to a hosted drive, or grant vendor support access to the files, and a party is receiving PHI again, which requires its own analysis and ordinarily a BAA.
What is the difference between transcription services and transcription software?
Human transcription services use transcriptionists, can produce certified transcripts where a use requires one, and are ordinarily business associates. Cloud software sends audio to a vendor's servers, which ordinarily makes that vendor a business associate too. On-device software runs the model on your own machine, so in a genuinely local-only deployment, where no separate service receives or maintains the files, no third party receives the audio. Local inference by itself does not establish that: sync, backup, upload, and remote support paths all have to be absent too. All three architectures can be appropriate; they differ in who else ends up holding the PHI and what contracts that requires.
Does the HIPAA conduit exception cover a transcription vendor?
Almost never. OCR reads the conduit concept narrowly, covering transmission-only services plus any storage that is temporary and incidental to transmission, and access that is transient or infrequent and necessary to that transmission. A service that transcribes your audio and stores the result persistently exceeds that, and OCR has said persistent storage defeats conduit status even where the provider cannot decrypt the data. Note also that a vendor which never meets the positive definition of business associate does not need an exception at all.

Next step

Sources

Informational, not legal advice. HIPAA analysis is fact-specific and turns on your actual deployment; covered-entity status, permitted uses, and state recording law all vary. Vendor terms and plan gating change. Your own counsel or compliance officer is the one who signs off, and this page is a starting point for that conversation rather than a substitute for it.