Private Notetaker
← All articles

HIPAA and AI note takers: what compliance actually requires

There is no government HIPAA certification, SOC 2 is not HIPAA, and most notetakers gate their BAA behind an enterprise plan. What a practitioner actually needs, and why local processing changes the question rather than answering it.

Ben Claybrook 6 min read

If you are a therapist, clinician or anyone else handling protected health information, the search for a “HIPAA compliant AI note taker” runs into a wall quickly: every vendor says yes, and the word means different things to each of them.

This post is about what HIPAA actually requires of a notetaker, so you can evaluate the claims yourself. It is not legal advice, and if you are in doubt, your malpractice carrier or a healthcare attorney is the right call.

There is no such thing as HIPAA certification

Start here, because it invalidates a lot of marketing.

HHS does not certify or endorse anyone as HIPAA compliant. There is no government programme, no registry, no badge. When a vendor says “HIPAA certified”, they mean they hired an auditor to assess them against a framework, which is useful evidence and is not a certification in any regulatory sense.

SOC 2 is not HIPAA. They overlap in the controls they examine, but a SOC 2 Type II report says an auditor tested a company’s stated controls. It says nothing about whether that company has entered the contractual obligations HIPAA requires. A vendor can hold a spotless SOC 2 report and still be unusable for PHI.

The thing that actually matters is the BAA

Under HIPAA, a business associate is any entity that creates, receives, maintains or transmits PHI while performing a function or service for a covered entity. If a notetaker uploads your session audio, it is doing exactly that.

When that is the case, you need a Business Associate Agreement: a signed contract binding the vendor to safeguard the PHI, limit its use, report breaches, and flow the same obligations down to its own subcontractors.

The BAA is the compliance artefact. Not the encryption, not the audit report, not the reassuring paragraph on the security page. If you handle PHI with a vendor and there is no signed BAA, that is a gap, and under HIPAA it is your gap, because the obligation sits with the covered entity.

Why the plan you are on matters

Here is where practitioners get caught, and it is worth checking today if you use one of these tools.

Vendors routinely gate HIPAA coverage behind their most expensive plan. Fireflies is the clearest example and publishes it openly: HIPAA compliance, the signed BAA, private storage and custom data retention are Enterprise features, listed at $39 per seat per month billed annually as of September 2026. The free, Pro and Business plans do not include them.

A solo therapist on a Pro plan has a tool that is marketed as HIPAA compliant, is genuinely HIPAA capable on a different tier, and is not covered for them. The compliance did not travel with the software. It travelled with the contract.

Ask two questions of any vendor, in writing:

  1. Will you sign a BAA for the plan I am on?
  2. Which subprocessors receive PHI, and do you have BAAs with them?

That second question is the one that separates serious vendors. Fireflies, for instance, states it has signed BAAs with its language model and speech recognition vendors and enforces zero-day retention with them. That is the right shape of answer.

The tools built for this

If you need PHI in the cloud, use something designed for it. Upheal, Mentalyc, Blueprint, AutoNotes and SimplePractice are built around clinical documentation: they will sign a BAA as a matter of course, they produce the note formats clinicians actually file, and they integrate with practice management and EHR systems.

A general-purpose meeting notetaker will not produce a SOAP or DAP note, will not sync to your EHR, and was designed for sales calls. If your requirement is clinical documentation, buy a clinical documentation tool. That is a genuine recommendation, not a hedge.

Where local processing changes the question

Now the part relevant to what we build, stated carefully.

If a tool runs entirely on your own computer, and the vendor never creates, receives, maintains or transmits PHI, then the vendor is not a business associate under the definition above. There is no disclosure to a third party, so there is no BAA to sign, because there is no relationship for a BAA to govern.

That is an argument about the definition, and it is why the local architecture is interesting in a clinical setting. It is emphatically not a claim that Private Notetaker is HIPAA compliant or certified. We do not make that claim, no one could certify it anyway, and any vendor telling you their product makes you compliant is selling you something HIPAA does not sell.

Your obligations do not go away. They move. With PHI on your own machine, the HIPAA Security Rule still applies to you, and now the safeguards are yours to implement:

That list is not lighter than vendor management. It is different. Some practitioners would much rather hold the risk themselves on a machine they control than distribute it across a vendor and its subprocessors. Others would rather pay a specialist vendor to carry it. Both are defensible.

The short version

Private Notetaker records, transcribes and summarises on your own computer with no upload and no bot. What that means for HIPAA is the argument above, made honestly: it removes the vendor from the PHI path. It does not make you compliant, and we will not tell you it does.

If you want to understand how to verify a local processing claim rather than take one on trust, we wrote up the tests in local AI transcription on a Mac.

Checked 5 September 2026. Not legal advice. Vendor plans and coverage change frequently, so confirm the BAA and the plan in writing before entering any PHI.

Frequently asked questions

Is using AI for notes HIPAA compliant?
It can be, but not because of the software alone. If a vendor creates, receives, maintains or transmits protected health information on your behalf, it is a business associate and you need a signed BAA with it. Without that contract in place, using the tool with PHI is a compliance gap regardless of how good the vendor's encryption is.
Which AI therapy notes tool is most HIPAA compliant?
There is no ranking, because HIPAA compliance is not a score. The practical questions are whether the vendor will sign a BAA, on which plan, and what its subprocessors do with the content. Tools built specifically for clinicians, such as Upheal, Mentalyc, Blueprint and SimplePractice, are designed around signing a BAA and integrating with clinical records, which general-purpose meeting notetakers usually are not.
Is there a free HIPAA compliant note taking app?
Very rarely, because the BAA is the expensive part. Fireflies, for example, restricts HIPAA coverage and its BAA to the Enterprise plan at $39 per seat per month billed annually as of September 2026, while its free and mid tiers are not covered. Treat a free tier advertising HIPAA compliance with scepticism and ask for the BAA in writing before entering any PHI.
Is there a HIPAA compliant ChatGPT?
OpenAI will sign a BAA for eligible API and enterprise arrangements, but the consumer ChatGPT product is not covered by one. Pasting a session transcript into ChatGPT to summarise it is a disclosure of PHI to a vendor you have no BAA with, which is one of the more common accidental violations in practice right now.