Dictation and HIPAA: What Actually Matters for Your Practice
HIPAA doesn't certify software. Here's what the rule actually requires of a dictation tool, which vendors sign a BAA, and how to evaluate the rest.
What HIPAA Actually Requires of a Dictation Tool
The thing to understand first: there is no such thing as HIPAA-certified software. HHS does not certify, approve, or bless products, and any vendor whose marketing implies otherwise is telling you something the regulator does not offer. Compliance is a property of your practice โ your policies, your training, your safeguards โ and software is one input to it.
What the rule actually asks of a dictation tool comes down to five things: a signed Business Associate Agreement if the vendor handles PHI, encryption in transit and at rest, access controls, audit logging, and a guarantee that patient audio is not used to train AI models. The BAA is the load-bearing one, because it is the only item on that list that is a legal instrument rather than a technical feature โ and it is the one most dictation vendors do not offer.
There is also a structural shortcut worth knowing: if audio never leaves the machine, there is no business associate to sign an agreement with. That does not make an on-device tool "compliant" โ nothing makes a tool compliant โ but it removes a vendor from the chain your reviewer has to evaluate, which is a materially different question from whether a cloud vendor's paperwork is in order.
Every time a healthcare professional dictates a patient note, that audio recording becomes Protected Health Information under HIPAA. The dictation tool processing that audio becomes a business associate, subject to federal regulations governing how PHI is handled, stored, and protected.
This guide covers what the rule requires, which vendors actually sign a BAA and which only imply it, what the penalties look like, and how to evaluate a tool your reviewer has not seen before. It does not tell you which product is compliant, because that is not a question a page like this can answer for your practice.
Key Takeaway
Dictation audio containing patient information is PHI under HIPAA. Any tool processing that audio must meet strict compliance requirements or risk penalties up to $2.07 million per violation category per year.
Key Takeaways: HIPAA Dictation Requirements
| Requirement | What It Means for Dictation | Compliance Approach |
|---|---|---|
| Business Associate Agreement | Vendor must sign a BAA before handling any PHI | Verify BAA availability before purchasing any dictation tool |
| Encryption | Audio must be encrypted in transit and at rest | On-device: not applicable (no transit). Cloud: requires TLS + AES-256 |
| Access Controls | Only authorized users can access transcriptions | Role-based access, multi-factor authentication where available |
| Audit Logging | All access to PHI must be logged and auditable | Tool must maintain access logs; organization must review them |
| No Training Use | Patient audio cannot be used to train AI models | Verify vendor's data use policy explicitly excludes training |
Which Dictation Vendors Actually Sign a BAA
This is the question most "HIPAA dictation" searches are really asking, and the answer is shorter than the marketing suggests. Verified 2026-08-11 โ re-check directly with any vendor before relying on it, because BAA availability changes with plan tier and is frequently gated to enterprise contracts.
| Tool | Signs a BAA? | The catch worth knowing |
|---|---|---|
| Dragon Medical One | Yes โ on Microsoft Azure | Sold per seat through resellers on 1โ3 year terms; priced for health systems |
| Otter.ai | Enterprise tier only | Free and Pro plans are not covered; see our Is Otter Safe? investigation |
| Wispr Flow | Yes | Captures screenshots of the active window โ in a clinical setting those may contain PHI |
| Apple Dictation | No | Apple does not offer a BAA for it, at any tier |
| Superwhisper | No | Transcribes locally but saves audio recordings to disk by default |
| Voibe | No โ we do not sign one | On-device mode transmits nothing, so there is no processor to cover; that is an architectural answer, not a substitute for a BAA |
Note what that table does not say: that the vendors in the "yes" column are compliant and the others are not. A signed BAA is necessary when a vendor handles PHI. It is not sufficient for your practice, and its absence is only disqualifying if the vendor is handling PHI in the first place.
The Five HIPAA Requirements for Dictation Software
HIPAA's Security Rule and Privacy Rule establish specific requirements that dictation tools must meet when processing Protected Health Information. These five requirements form the compliance baseline:
1. Business Associate Agreement (BAA)
A BAA is a legally binding contract between the healthcare organization (covered entity) and the dictation vendor (business associate). The BAA defines how the vendor will safeguard PHI, outlines breach notification procedures, and establishes liability. Using any dictation tool for patient work without a signed BAA is a HIPAA violation, regardless of the tool's actual security features.
2. Encryption (Technical Safeguard)
HIPAA requires that PHI be encrypted both in transit (while being sent to a server) and at rest (while stored on a server). For cloud dictation, this means TLS 1.2+ for transmission and AES-256 for storage. For on-device dictation, encryption in transit is not applicable because no audio is transmitted โ the data never leaves the device.
3. Access Controls (Technical Safeguard)
Only authorized individuals should be able to access dictated transcriptions containing PHI. This requires unique user identification, role-based access policies, and ideally multi-factor authentication. Shared accounts and generic logins violate this requirement.
4. Audit Logging (Technical Safeguard)
The dictation system must maintain logs of who accessed PHI, when, and what actions were taken. These logs must be retained and available for audit. Healthcare organizations are required to review audit logs regularly.
5. Data Use Restrictions
Patient audio must not be used for purposes beyond the original intent. This means vendors cannot use healthcare dictation recordings to train AI models, conduct research, or share with third parties without explicit authorization. Many cloud dictation services use audio for model improvement by default โ this must be explicitly disabled or contractually prohibited for HIPAA compliance.
HIPAA Dictation Tools Compared: Cloud vs. On-Device
Healthcare organizations must choose between cloud-based dictation tools that offer contractual HIPAA compliance (through BAAs) and on-device tools that achieve compliance through architecture (by never transmitting PHI). Here is how the major options compare:
| Tool | Processing | BAA Available? | Audio Transmitted? | Pricing | HIPAA Posture |
|---|---|---|---|---|---|
| Voibe | On-device or private cloud | No (does not sign one) | Only in cloud mode | $7.50/mo, $59/yr, or $149 lifetime | Zero retention, never trained on; on-device mode keeps PHI off the network |
| Dragon Medical One | Cloud | Yes | Yes | $149/mo (1-yr) to $79/mo (3-yr) | Compliant with BAA |
| Otter.ai Enterprise | Cloud | Yes (Enterprise only) | Yes | Custom (annual contract) | Compliant with BAA (Enterprise only) |
| Superwhisper | On-device (default) | No (default mode) | No | $8.49/mo, $84.99/yr, or $249.99 lifetime | Moderate โ transcribes locally but saves audio recordings by default with no option to disable |
| Apple Dictation | Mostly on-device | No | Possible (Siri opt-in) | Free | Not compliant (no BAA) |
| Wispr Flow | Cloud | No | Yes (default; off with Privacy Mode/BAA) | ~$10/mo | BAA available (self-serve in-app; signing locks zero data retention on) |
A concrete illustration of why retention defaults matter for clinical dictation: in August 2026, Wispr Flow team members published word-frequency analyses of user dictations on LinkedIn. Aggregate research over retained user content is routine for a cloud vendor โ and it is exactly the class of secondary use that a signed BAA and zero data retention exist to rule out before PHI is involved.
The on-device advantage for HIPAA: When dictation runs entirely on your Mac, no Protected Health Information enters the network. There is no audio to encrypt in transit, no server-side storage to protect, and no third-party processors to regulate. This architectural approach to compliance is inherently more secure than relying on contractual agreements alone.
Warning: HIPAA marketing claims are not the same as a signed BAA. In March 2026, the cloud dictation app Typeless publicly announced HIPAA compliance, but an independent Paubox assessment noted that Typeless did not publicly advertise a standalone Business Associate Agreement on its website. Covered entities should always obtain a signed BAA before processing any PHI through a third-party service โ a public compliance announcement alone is not sufficient. For the full case study, including a reverse-engineering analysis of what Typeless actually collects, see our Typeless privacy issues analysis.
Cost comparison (reseller-quoted, verified 2026-08-11): Dragon Medical One runs about $99 per user per month on a 1-year term ($1,188/year) or $79 per month on a 3-year term ($948/year), plus a one-time implementation fee commonly around $525 per user. That puts three years at $3,369 to $4,089 per clinician. Voibe's $149 lifetime license is $3,220 to $3,940 less over the same period โ 95.6% to 96.4%. Nuance does not publish Dragon Medical One pricing; see our cost breakdown for the line items, or the direct comparison for what the difference buys.
Important note on Superwhisper for HIPAA work: Superwhisper transcribes on-device, but saves audio recordings to disk by default with no option to disable this behavior. Recordings are stored in an iCloud Documents folder, potentially syncing to Apple's servers. This creates a local and potentially cloud-accessible record of patient audio, which complicates HIPAA compliance even though transcription itself never hits external servers. For healthcare work, Voibe's architecture โ which never writes audio to disk at all, with zero retention and no training on your data โ leaves less residual PHI to manage.
Wispr Flow is not suitable for HIPAA work: Wispr Flow offers a BAA but sends audio to OpenAI and Meta servers, and captures screenshots of the active window every few seconds. In a clinical setting, those screenshots could capture patient-identifiable information from the screen โ a significant PHI exposure risk that the BAA alone cannot fully address. For a full comparison of Dragon Medical alternatives including AI medical scribes, see our Dragon Medical alternatives guide, or compare the ambient documentation tools directly in our guide to the best AI medical scribe tools for doctors.
HIPAA Violation Penalties for Voice Data Breaches
HIPAA violations involving dictated voice data carry the same penalty structure as any PHI breach. The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services enforces penalties based on the level of negligence:
| Tier | Culpability Level | Penalty Per Violation | Annual Maximum |
|---|---|---|---|
| Tier 1 | Unknowing violation | $137 โ $68,928 | $68,928 |
| Tier 2 | Reasonable cause (not willful neglect) | $1,379 โ $68,928 | $137,886 |
| Tier 3 | Willful neglect, corrected within 30 days | $13,785 โ $68,928 | $344,638 |
| Tier 4 | Willful neglect, not corrected | $68,928 minimum | $2,067,813 |
Using a dictation tool without a BAA to process patient information constitutes a Tier 2 or Tier 3 violation, depending on whether the organization corrects the issue promptly. Criminal penalties under HIPAA can include imprisonment of up to 10 years for wrongful disclosure of PHI with intent to sell or use for personal gain.
The safest approach is to eliminate the risk entirely by using on-device dictation that never transmits PHI. When no patient audio leaves the device, there is no audio to breach, no server to compromise, and no third-party processor to regulate.
Warning
Using dictation software without a BAA to process patient information is itself a HIPAA violation โ even if no breach occurs. The violation is in the arrangement, not the outcome.
How to Set Up Dictation Your Compliance Reviewer Can Sign Off On
No tool arrives compliant, so the work splits in two: narrowing the technical surface, then documenting it well enough that your reviewer can evaluate it. Follow this implementation checklist:
- Reduce the number of parties before you evaluate any of them โ a tool processing on-device transmits nothing, so there is no data in transit to secure and no vendor to obtain a BAA from. Voibe ($7.50/month or $149 lifetime) runs fully on-device on Apple Silicon Macs; it does not sign a BAA, and on Windows or Intel Macs it runs in cloud mode, where that property does not apply
- If using cloud dictation, verify the BAA โ Request, review, and sign the vendor's Business Associate Agreement before any patient information is dictated. Keep the signed BAA on file.
- Disable audio data sharing โ Turn off any settings that share audio for product improvement or AI training. For Apple Dictation, disable "Improve Siri & Dictation" in Settings โ Privacy & Security.
- Implement access controls โ Ensure each clinician has a unique login and that transcriptions are only accessible to authorized personnel
- Train staff on compliant dictation practices โ Staff should understand which tools are approved for patient dictation, how to verify they're using the correct tool, and what to do if PHI is accidentally dictated into a non-compliant system
- Document your dictation policy โ Include approved tools, data handling procedures, and incident response steps in your organization's HIPAA compliance documentation
- Review annually โ Audit your dictation tools, BAAs, and practices at least annually as part of your HIPAA risk assessment
For a broader understanding of privacy considerations in dictation, see our dictation privacy guide. For Apple-specific privacy settings, see our Apple Dictation privacy guide.
A worked example of why the plan you buy matters. DictaFlow markets clinical notes on its homepage, but its consumer privacy policy states the standard service is โnot configured or offered as a HIPAA-compliant medical service.โ Its BAA-oriented build, DictaFlow Medical Pro, costs $39/user/month for 1โ4 seats or $29/user/month at 5+ โ against $69/year for the consumer plan. That gap is the difference between a tool you may use for PHI and one you may not, from the same vendor. The full data path and its seven named medical subprocessors are in is DictaFlow safe?, and DictaFlow alternatives ranks the tools that will and will not sign a BAA.
Choosing the Right HIPAA Dictation Approach
Which approach fits depends on your practice size, budget, and who carries the compliance decision. The framework below sorts by that last one, because it is the question that actually decides it โ and note that none of these paths is "compliant" on its own.
Consider on-device dictation (Voibe) if:
- You would rather remove a vendor from the chain than evaluate one โ nothing transmitted means nothing to cover by agreement
- You work in a solo or small practice without an IT department to manage BAAs
- You need to dictate in environments without reliable internet (home visits, rural clinics)
- You want the lowest cost option ($149 lifetime vs. $1,188+/year for cloud solutions)
Choose cloud dictation with BAA (Dragon Medical One, Otter Enterprise) if:
- Your organization requires specific EHR integrations that only cloud tools provide
- You need real-time collaboration features (shared transcription, team notes)
- Your IT department can manage BAA compliance, encryption verification, and audit logging
- Budget is not a primary constraint
Avoid for HIPAA work:
- Apple Dictation (no BAA available)
- Wispr Flow (BAA available but captures screenshots of the active window every few seconds โ in a clinical setting, those screenshots may include patient-identifiable information visible on screen; for the full safety walkthrough including the March 2026 Delve compliance scandal and Wispr's A-LIGN remediation, see our Is Wispr Flow safe? investigation)
- Otter.ai Free or Pro plans (BAA only available on Enterprise โ and even Enterprise inherits the consent-model class-action exposure documented in our Is Otter safe? investigation)
- Superwhisper (transcribes locally, but saves audio recordings to disk by default with no way to disable โ creates a persistent local record of patient dictation that may sync to iCloud)
- Any dictation tool that does not explicitly offer a BAA or process and immediately discard audio on-device
For professionals in other regulated fields, our voice data privacy guide covers the broader regulatory landscape beyond HIPAA. For tool-by-tool comparisons tailored to your profession, see our guides on dictation software for doctors and dictation software for lawyers. For the per-product safety analysis of every cloud dictation product mentioned in this guide, see our 'is X safe?' series โ Is Wispr Flow Safe?, Is Superwhisper Safe?, Is Aqua Voice Safe?, Is Otter Safe? (including the pending federal class action), and Is Dragon Safe? (Microsoft-owned product line, Dragon Medical One BAA framework). For practices currently using Rev.com for clinical or medical-legal transcription, see Rev.com alternatives for doctors (the dictation-vs-AI-scribe-vs-transcription category split with HIPAA BAA analysis) and Rev.com alternatives for lawyers (privilege exposure for medical-malpractice and personal-injury matters). Lawyers handling medical-legal matters should also read our AI and attorney-client privilege analysis on the SDNY's US v. Heppner ruling โ the same third-party-disclosure logic that breaks privilege also breaks HIPAA when audio touches a vendor without a BAA. For the broader picture beyond dictation โ which AI assistants and coding tools train on user data, sign BAAs, or offer zero data retention โ see our AI Tool Privacy Tracker. Healthcare providers who themselves have carpal tunnel, RSI, arthritis, or post-surgery hand recovery โ clinicians using dictation as both a documentation tool and an accessibility accommodation โ should also see our accessibility dictation hub, best dictation software for carpal tunnel, best dictation software for arthritis (joint-protection framing for RA, OA, PsA โ relevant for clinicians on biologics or DMARDs), and best dictation software for hand pain for tooling that addresses the activation-model barrier in addition to the HIPAA architecture.
Radiologists face a specialty-specific version of this architecture decision: an enterprise reporting platform runs the worklist, while a personal dictation layer handles everything else they write. Our guide to the best dictation software for radiologists maps the HIPAA question onto that two-layer stack โ including what the August 2026 PowerScribe 360 retirement changes for radiology groups.
Dictation is rarely the only AI in a clinical workflow. If your team also uses Claude for drafting or administrative work, Anthropic documents a BAA for its first-party API and Enterprise plans โ with named exclusions and a HIPAA-readiness path that replaces ZDR. We keep those details current, with dates and sources, in the Claude API data retention guide.
One detail worth checking before you sign a BAA: whether the agreement locks the vendor's zero-retention setting on, or merely permits it. Wispr Flow's BAA locks Privacy Mode on irreversibly; not every vendor does that. Our guide to zero data retention sets out the five-question test to run before PHI touches any voice app.
For one specialty in particular, the rule goes further: dictation for therapists and psychiatrists covers the psychotherapy-notes carve-out at 45 CFR ยง 164.501, which treats session content as a separate category from the rest of the medical record. For the workflow side โ getting dictated text into web EHRs, Citrix sessions, and remote desktops without routing audio across the network โ see our EHR dictation guide.
Frequently Asked Questions
What makes dictation software HIPAA compliant?
Is Apple Dictation HIPAA compliant?
Is Dragon Medical still available for Mac?
Can I use Voibe for HIPAA-compliant dictation?
What are the penalties for HIPAA violations involving voice data?
Does Otter.ai offer HIPAA-compliant dictation?
What is a Business Associate Agreement (BAA) and why do I need one?
Is cloud-based dictation safe for healthcare?
Is there such a thing as HIPAA-certified dictation software?
Which dictation apps offer a HIPAA BAA?
Ready to type 5x faster?
Voibe is the fastest, most private dictation app for Mac and Windows. Try it today.
- On-device or private cloud
- Free to try
- No subscription
- Mac + Windows
- 90+ languages
Prefer to go Pro? Save 20% on any plan with code VOIBE20 View pricing โ
Related Articles
DictaFlow Pricing
Consumer Pro against the Medical Pro seat price.
Dictation Privacy Hub: The Complete Guide to Protecting Your Voice Data
Your voice is biometric data that can never be changed. Explore our complete library of dictation privacy guides covering HIPAA, voice data, Apple Dictation, and more.
I Tested 7 DictaFlow Alternatives โ Here's the One I Trust with Sensitive Work
DictaFlow markets itself for clinical notes and legal drafts, so I tested seven alternatives and read every privacy page. Here's the one I'd trust with a patient's name โ and the one you actually need a signed BAA for.

