"HIPAA-compliant" on a vendor's website is a marketing claim about their capability. What protects you is a Business Associate Agreement - a signed contract, covering the specific plan you're on, that makes the vendor legally accountable for the protected health information you send them.
Those two things come apart more often than you'd expect. The most useful thing this article can tell you is how to check.
| Tool | Category | Self-serve? | Notes |
|---|---|---|---|
| Dragon Medical One | Clinical dictation | Via reseller | HIPAA with BAA; ~$79–99/user/mo |
| Freed | Ambient scribe | Yes | HIPAA; $39–119/mo; 26,000+ clinicians |
| Abridge | Ambient scribe | Health system only | Best in KLAS 2025 and 2026 |
| Suki | Ambient scribe | Quote only | Bidirectional EHR integration |
| DeepScribe | Ambient scribe | Enterprise sales | Notes arrive hours later |
| Nabla | Ambient scribe | Free tier exists | Free tier reportedly has no BAA |
| Heidi Health | Ambient scribe | Yes, free tier | Confirm BAA coverage on your plan |
| Augmedix | Ambient scribe | Enterprise sales | Commure subsidiary since Oct 2024 |
| INVOX Medical | Clinical dictation | Demo only | Can deploy on your own servers |
| Krisp | Meeting notes | Yes | HIPAA and GDPR on Pro |
| Wispr Flow | General dictation | Enterprise | HIPAA-ready BAA on Enterprise only |
| Willow Voice | General dictation | Business+ | HIPAA enforced only from Business up |
Filter the directory by the HIPAA collection.
This is the failure mode that catches individual clinicians and small practices.
Nabla offers a free tier at a reported 30 consultations a month, and it reportedly comes without a BAA. Its paid plans - around $119 a month for Starter, $239 for Pro - are HIPAA-compliant. Same product, same infrastructure, different contractual position. Using the free tier with real patient data is a HIPAA problem regardless of how secure the servers are.
Heidi Health has an unusually generous free tier - unlimited basic consults and dictation, with ten Pro Actions a month. Confirm in writing which plans its BAA covers before you use it clinically.
The same pattern appears outside clinical tools. Wispr Flow offers a HIPAA-ready BAA on Enterprise only; its $12-a-month Pro tier doesn't have one. Willow Voice states SOC 2 Type II and HIPAA, but enforces it only from the Business tier up.
If a vendor's HIPAA page doesn't say which plans are covered, that's the question to ask first.
Under HIPAA, a covered entity - you, your practice, your hospital - may share protected health information with a business associate that performs a service on your behalf, provided there's a written agreement. The BAA obliges the vendor to safeguard the information, use it only as permitted, report breaches, and pass the same obligations to their own subcontractors.
Without one, disclosing PHI to that vendor is impermissible. The vendor's security posture doesn't change that. This is contract law, not engineering.
Practical steps:
SOC 2 Type II audits security controls over a period. Genuinely meaningful, and held by Wispr Flow, superwhisper, and Willow Voice. It is not HIPAA compliance and doesn't substitute for a BAA.
ISO 27001 is an information security management standard. Same logic - Wispr Flow holds it.
"HIPAA-ready" or "HIPAA-capable" means the vendor believes their product can be used compliantly, usually once a BAA is signed and the right tier is purchased. Read it as an invitation to ask, not an answer.
GDPR compliance is a different jurisdiction and a different framework. Krisp Pro states both HIPAA and GDPR.
Partly, and it's worth understanding exactly how far.
If audio never leaves your machine, there's no business associate to contract with - no third party receives PHI, so no BAA is needed for that step. That's a real simplification, and it's why INVOX Medical's on-premises deployment option appeals to hospitals with strict data residency rules.
But HIPAA also covers storage, access control, audit logging, encryption at rest, and breach notification. A local dictation app on an unencrypted laptop is not compliant just because the transcription happened offline. And in practice, clinical workflows need EHR integration that general local dictation apps don't provide.
The realistic use of a local tool in clinical work is dictating notes that you then place in a compliant system yourself, on a managed, encrypted device. See cloud vs on-device dictation.
General meeting assistants are not appropriate for patient encounters. Otter.ai, Fireflies.ai, Fathom, Granola, and the rest are built for business meetings, and most don't offer a BAA at any tier.
Krisp is the exception in that category, stating HIPAA and GDPR compliance on its Pro tier at $8 a month. Even so, for a clinical encounter you want a clinical tool - see the best AI medical scribes.
If you're recording multidisciplinary meetings that discuss patients, treat that as PHI and apply the same standard.
There's no HIPAA equivalent for legal privilege, but the obligation is comparable and less codified. Sending privileged client material to a third-party transcription service may breach your professional conduct rules or a client engagement letter, regardless of the vendor's security.
The tools built for this treat it as a workflow problem. BigHand handles legal dictation with routing and delegation, at a reported $3,000–4,000 per attorney per year. Philips SpeechLive starts at $12.90 per user per month, with speech recognition a $25.90 add-on. Dragon Legal is part of the active Dragon line.
For sensitive matters, local transcription with MacWhisper, Buzz, or Vibe avoids the third-party question entirely.
A vendor that can't answer the first two quickly and in writing is not a vendor for clinical work.
A signed Business Associate Agreement covering your plan, plus appropriate safeguards for transmission, storage, access control, and breach notification. A "HIPAA-compliant" claim on a website is not sufficient on its own.
Otter.ai is a general business meeting tool and is not appropriate for protected health information. Use a clinical scribe such as Freed, Abridge, or Dragon Medical One.
Be very careful here. Heidi Health has a free tier but you must confirm BAA coverage for it. Nabla's free tier reportedly has no BAA. Transcribing locally with MacWhisper, Buzz, or Vibe avoids the business associate question, though your other HIPAA obligations remain.
No. SOC 2 Type II is a security controls audit. It's meaningful evidence of a vendor's security practice, and it does not substitute for a BAA.
Not for the transcription step, because no third party receives the information. You still need to meet HIPAA's requirements for storage, encryption, access control, and audit on that device.
Freed - HIPAA-compliant, self-serve, $39–119 a month, seven-day trial with no card. See the best AI medical scribes.
This article explains how vendors describe their compliance posture. It is not legal advice - confirm any arrangement with your own compliance officer or counsel.
Last verified: 10 August 2026.