Is your dictation software actually HIPAA compliant?
The honest answer runs through BAAs, subcontractors and retention policies most vendors never show you — and it changes shape entirely once no audio leaves your machine.
"Is this dictation software HIPAA compliant?" is one of the most common questions clinicians ask before they'll type a single client detail into it — and it's usually the wrong question to lead with. HIPAA compliance isn't a badge a vendor pins to its homepage; no government body issues a "HIPAA compliant" seal for software. It's a property of your whole workflow, built on contracts, safeguards and audits. The question underneath the question is simpler: where does the audio of my session actually go after I stop talking?
For most cloud dictation apps and AI scribes, the honest answer runs through a chain of vendors, subcontractors and retention policies you may never see in full. For dictation that never leaves your machine, that chain has one fewer link — because there's no third party in the transcription step to cover with a contract in the first place. That's an architectural fact about how the software is built, not a compliance certificate. You still need to confirm the rest of your workflow with whoever handles compliance at your practice.
What does "HIPAA compliant dictation software" actually mean?
Under HIPAA, the entity that matters here is the business associate — any vendor that creates, receives, maintains or transmits protected health information (PHI) on behalf of a covered entity like a therapy practice. Before you can legally hand that vendor real patient data, you need a signed Business Associate Agreement (BAA). HHS.gov spells out what a compliant BAA must require: safeguards against unauthorized use, breach reporting, and — the part that matters most for cloud dictation — a requirement that the business associate flow those same obligations down to any subcontractors it uses.
That last clause is where cloud dictation gets complicated fast. A single AI scribe product can involve a speech-to-text engine from one company, a cloud host from another, and an LLM API for summarization from a third. Each hop is a subcontractor, and each one needs to be covered — or the chain has a gap. As one clinician-focused guide to picking dictation software puts it plainly: "marketing language is not compliance", and "if a vendor hesitates on [confirming a BAA], that's your answer."
How do you actually evaluate a cloud dictation tool before using it with patient data?
Before typing or recording a single real session into any cloud dictation app or AI scribe, get direct answers to these:
- Will they sign a BAA before you enter any patient detail? Not "we're HIPAA compliant" on a landing page — an actual signed agreement.
- Who are the subcontractors behind the product? The transcription engine, the cloud host, the model used to summarize or structure the note — every one of them needs to be covered by that BAA, not just the vendor you're paying.
- What's the audio retention policy? Deleted immediately after transcription, or kept — and if kept, where, for how long, and who can access it.
- Does the fine print allow your session data to train models? Even "de-identified" reuse is worth reading closely — see the case below.
- Where do transcripts land afterward? Auto-synced to your EHR, or sitting in a separate app you have to remember to lock down?
None of this is theoretical. It's the exact list a vendor should be able to answer without hesitating.
Why are therapists and patients pushing back on cloud AI notes?
Search r/therapists and you'll find an active, ongoing argument about whether AI notetaking belongs in the room at all — separate from whether any individual vendor is technically compliant on paper.
A thread titled "Potential clients not thrilled with therapists using AI" collects exactly what it sounds like: people describing how they reacted on learning, after the fact, that a therapist was feeding their sessions into an AI tool. The top reply cuts to the actual issue: "The therapist should've informed the client and got their consent. Using AI notes like that is a privacy violation." A separate, heavily discussed thread, "Reconsider using AI to turn your sessions into progress notes", is clinicians talking each other out of it — one reply: "I use AI to make my notes more professional but I would never record my sessions and ask AI to write them."
The underlying worry isn't hypothetical. In September 2025, Jacobin reported that TheraPro AI — a notetaking product marketed to therapists — had terms of service permitting patients' therapy records to be reused, in de-identified form, to train other AI applications. Separately, ClearHealthCosts reported in March 2025 on therapists finding AI-generated notes that fabricated details never discussed in session — mentions of suicidal ideation or substance abuse the client never raised. Different failure modes, same root cause: once a session leaves the room, the clinician no longer fully controls what happens to it.
Even the question itself isn't unique to therapy — a near-identical thread in r/AskAcademia shows researchers asking the same "is this HIPAA compliant?" question about transcription for interview data. It's a generic question with a generic, unsatisfying answer: it depends on paperwork you'd have to go verify yourself, vendor by vendor.
The pattern: the backlash isn't really about any one vendor's security posture. It's that clients and clinicians both realize a recording of a therapy session, once it's on someone else's server, is subject to that someone else's terms of service — which can change, and which they usually never read.
What changes when dictation runs entirely on your own device?
Inkvox is built around a different premise: don't send the audio anywhere. It runs OpenAI's Whisper large-v3-turbo, quantized, directly on your own GPU through Vulkan — NVIDIA, AMD or Intel — with a CPU fallback if there's no compatible GPU. On a mid-range card like an RTX 3070, a sentence transcribes in roughly 0.3–0.4 seconds. The audio is processed in memory and the transcript is typed straight into whatever app is already open — your EHR, a notes app, a word processor. Audio uploaded: 0 bytes. No account is required, and once the one-time ~800 MB model download finishes, Inkvox works fully offline. See how that fits into the rest of the product on our privacy page.
Here's the architectural point, stated precisely: HIPAA's test for a business associate is whether a vendor creates, receives, maintains, or transmits PHI on your behalf. If a session's audio and transcript never leave your machine, no vendor is doing any of those four things during the transcription step — so there's no business associate to sign a BAA with for that specific data flow, because that flow never crosses to a third party. That's not a compliance claim about Inkvox. It's a description of what local processing does and doesn't touch.
This is exactly why we're careful never to describe Inkvox itself as "HIPAA compliant." That phrase describes a certified state of an entire practice's operations. What we can describe honestly is the architecture: nothing about a dictated sentence leaves the device it was spoken on.
What local dictation does not solve
Removing one vendor from the chain doesn't remove the rest of the chain. A few things stay squarely the clinician's responsibility, regardless of how the dictation itself is processed:
- The device and operating system. Disk encryption, screen lock, OS updates, and whether the machine itself is physically secured are unaffected by where transcription happens.
- Where the note goes after transcription. Whether it's pasted into an EHR, saved as a local file, or synced by an auto-uploading Documents or Desktop folder into a personal cloud drive, that's a separate data flow outside any dictation tool's control — and one worth checking, since auto-sync can quietly reintroduce the exact cloud exposure local dictation avoided.
- Shared or unmanaged machines. A shared clinic workstation or an unencrypted drive undermines the privacy benefit of local processing entirely.
None of this replaces a real risk assessment. If you're evaluating dictation software for use with actual patient data, validate your specific setup with whoever handles compliance or serves as your practice's DPO before relying on any product — ours included — as part of your answer.
FAQ
Is local dictation automatically HIPAA compliant?
No. HIPAA compliance describes an entire practice's workflow — administrative safeguards, risk assessments, staff training, device security, and how protected health information is stored and accessed — not a certification a piece of software can claim by itself; there's no government-issued HIPAA compliance seal for products. What changes when dictation runs entirely on your device is narrower: no audio or transcript is sent to a vendor's servers, so there's no business associate processing PHI during the transcription step, and no Business Associate Agreement to chase down for that step specifically. Everything else in your workflow still needs its own answer. Confirm your specific setup with whoever handles compliance at your practice.
Do I still need a Business Associate Agreement if my dictation tool is local?
Generally not for the transcription step itself. A BAA exists to bind a vendor that creates, receives, maintains, or transmits PHI on your behalf. If no audio or transcript ever reaches a vendor's servers, there's no third party in that specific data flow to sign one with. But a dictation tool is one piece of a larger stack — your EHR, billing software, cloud backups and email likely still touch PHI and still need their own BAAs. Local dictation removes one link in the chain, not the whole chain.
Does switching to local dictation stop patients from objecting to AI in sessions?
Not by itself. Much of the patient pushback documented on forums like r/therapists is about consent and disclosure, not architecture — clients reacting badly to discovering AI was used without being asked first, regardless of where the processing happened. Whether your dictation tool is local or cloud, tell clients before you use it and document their consent. That's a conversation, not a settings toggle.
If dictating your notes without a recording ever touching someone else's server sounds like the right default for your practice, join the Inkvox waitlist. And if you're comparing it against cloud-first tools like Wispr Flow, or wondering what Windows' own built-in dictation actually keeps offline, see our notes on a local alternative to Wispr Flow and what Windows voice typing does and doesn't send to the cloud.