HIPAA

The US Health Insurance Portability and Accountability Act, which sets national rules for protecting patient health information (PHI) — including how it may be recorded, transcribed, stored and shared by healthcare providers and their vendors.

Updated

HIPAA governs any handling of protected health information (PHI) by US healthcare providers and the vendors who work with them. Audio of a clinical conversation is PHI, so transcribing it is covered: the recording, the transcript and any derived notes all fall under the rules.

In practice that leaves two compliant paths. Use a cloud vendor that will sign a BAA and meet its terms, or use an on-prem tool that keeps audio on infrastructure you control, so PHI never leaves the organisation and a BAA may not be needed at all. Either way, compliant setups also expect access controls (MFA), audit logs, encryption in transit and at rest, and a documented retention policy.

For a buyer’s-eye view of which tools fit regulated work, see best transcription for HIPAA, legal & privacy.