Privacy, consent and compliance

AI notetakers and HIPAA: what to ask before using one

Where protected health information goes with each kind of AI notetaker, what a business associate agreement covers, and what to settle before recording.

By the Notey team at AInject · · · 8 min read

In short

An AI notetaker used in a clinical or health-plan setting can hold protected health information (PHI) in three forms: the audio, the transcript and the AI-written notes.

Under HIPAA, every outside service that creates, receives, maintains or transmits any of those on your behalf is usually a business associate, and you need a business associate agreement (BAA) with it before it gets any PHI.

So the useful question is not "is this tool HIPAA compliant?" but "where does each copy of the PHI go, and do I have a BAA with everyone on that list?" This guide goes through the rules that matter, the places PHI goes with each kind of notetaker, and what to ask a vendor.

Notey makes no HIPAA claim, and nothing in this guide should be read as one.

Who HIPAA applies to

The HIPAA Privacy and Security Rules apply to covered entities — health plans, health care clearinghouses and health care providers that conduct certain transactions electronically — and to their business associates.

A therapist in private practice who bills insurers electronically is usually a covered entity. A patient recording their own appointment is not. An employer's HR team is not a covered entity for its ordinary meetings, even when someone mentions a medical condition, though other laws may still apply. If you are not sure which side of the line you are on, settle that first; the rest of this guide assumes you are a covered entity or a business associate.

What makes a vendor a business associate

The definition is in 45 CFR 160.103. In short, a business associate is a person or company that creates, receives, maintains or transmits PHI on behalf of a covered entity, or provides certain services that involve PHI.

For a notetaker, that covers:

  • a transcription service that receives the audio;
  • an AI provider that receives the transcript to write a summary;
  • a storage or backup service that keeps recordings, transcripts or notes;
  • a meeting bot operated by the vendor, which receives the whole call.

There is a narrow exception for conduits — services such as the postal service, couriers and internet providers that only transport information and do not access it except on a random or infrequent basis. HHS has been clear that it is narrow. A service that stores data for you is not a conduit.

Encryption does not change this. HHS's guidance on HIPAA and cloud computing says a cloud service that maintains encrypted ePHI on a covered entity's behalf is a business associate even if it does not hold the decryption key. Encryption is a strong safeguard; it is not a way out of the BAA.

What a business associate agreement covers

45 CFR 164.502(e) lets you disclose PHI to a business associate only if you have "satisfactory assurances" that it will safeguard the information. 45 CFR 164.504(e) says what the contract must contain. Among other things, it must:

  • limit what the business associate may use and disclose PHI for;
  • require appropriate safeguards, including the Security Rule's for electronic PHI;
  • require it to report breaches and other unauthorised uses;
  • make its subcontractors agree to the same restrictions;
  • help you meet patients' rights to access and amend their records;
  • return or destroy the PHI when the contract ends, where that is feasible;
  • let you end the contract if it breaches a material term.

A BAA is a contract, not a certificate. It tells you what the vendor has promised, and it gives you a remedy. It does not tell you what the software actually does with the data. For that you need the vendor's own documentation and, ideally, answers in writing.

Where the PHI goes with each kind of notetaker

The number of business associates depends on how the tool hears the meeting and where it does the work.

Kind of toolAudio goes toTranscript and notes go toBusiness associates to assess
A bot that joins the callThe vendor, liveThe vendorThe vendor and its subprocessors
A desktop app with cloud transcriptionThe vendor's speech serviceThe vendor, often an AI providerThe vendor, the speech provider, the AI provider, storage
A desktop app with on-device transcriptionYour computer onlyYour computer; an AI service if you ask for notesAny AI or backup service you turn on
Your video platform's own recorderThe platformThe platformThe platform, under your agreement with it

The last row is worth noting: if your organisation already has a BAA with its video platform, its own recording and transcription may sit inside that agreement. Check which features the BAA covers; some agreements exclude newer AI features.

On-device transcription shortens the list. It does not empty it. The moment a transcript is sent to an AI service, or a meeting is backed up to someone else's server, that service is on the list again. Where does your meeting audio go? turns this into a full set of vendor questions.

Questions to settle before recording

Take these to your privacy or compliance officer.

  1. Should this meeting be recorded at all? Recording creates a new copy of PHI that has to be protected, retained and eventually destroyed. Sometimes notes written afterwards are enough.
  2. Has the patient or client agreed? HIPAA is not the only rule. State recording laws and professional ethics codes may require consent to record; see is it legal to record a meeting?.
  3. Which services receive PHI? List them: transcription, AI notes, storage, backup, email of summaries.
  4. Do you have a BAA with each? If a vendor will not sign one, do not send it PHI.
  5. Where is the device, and how is it protected? Local storage puts the security burden on your computer: disk encryption, a login password, screen lock, and who else uses it. The Security Rule's safeguards apply to your laptop too.
  6. How long do you keep each part? Decide retention for audio, transcript and notes separately. Many teams keep the clinical note and delete the recording once the note is checked.
  7. Does the recording become part of the record? A transcript kept to support care may be part of the designated record set that patients can ask to see. Ask how your organisation treats it.
  8. Is the AI output checked? An AI summary can be wrong. Anything that goes into a record should be reviewed by the clinician who signs it.

Therapists have extra questions, including how HIPAA's separate category of psychotherapy notes interacts with a transcript. Recording therapy sessions covers those.

How Notey fits into this

Notey makes no HIPAA claim, and this section describes what the software does so you can assess it, not a conclusion that it is suitable for PHI.

  • Audio stays on your Mac. It is written to your disk and transcribed there with Apple's on-device speech recognition. No transcription service receives it. The privacy policy says there is no fallback, debug mode or crash report that sends audio.
  • Recording, transcription and search work with no account and no network. Used that way, nothing about the meeting leaves the Mac, and the security of the data is the security of that Mac.
  • AI notes send transcript text. When you ask for a summary or other note, or when a meeting ends with automatic write-ups turned on, the transcript text and the names you gave speakers go to Notey's service and on to OpenAI, which processes it as a data processor and does not train on it. Notey does not retain it after the response. If the transcript contains PHI, that is a disclosure to both services, and your compliance officer needs to assess it before you use the feature. Leaving AI notes off keeps the transcript on the Mac.
  • Sync between your own Macs is optional and off until you set it up. Meetings are encrypted on your Mac with a key only your Macs hold, and recordings are never uploaded, not even encrypted. Per the HHS cloud guidance above, the fact that the synced copy is encrypted does not by itself settle the HIPAA question for the service storing it.
  • Deleting a meeting removes its recording, transcript and notes, and with sync on, from every one of your Macs.

Summary

HIPAA does not ask whether a tool is compliant; it asks whether you have protected PHI and have a BAA with everyone you share it with. Count the places each copy goes. On-device transcription removes one of them. Every AI service and every backup that receives PHI still needs its own answer.

Frequently asked questions

Is there such a thing as a HIPAA-compliant notetaker?

Not as a property of software. HIPAA places duties on covered entities and their business associates. A tool can make those duties easier or harder to meet, and a vendor can sign a business associate agreement, but compliance depends on how you use it.

Do I need a BAA with an AI notetaker vendor?

If the vendor creates, receives, maintains or transmits protected health information on your behalf, HHS treats it as a business associate and you need a BAA before sharing PHI with it. Your compliance officer should make that call for each vendor.

Does on-device transcription remove the need for a BAA?

It removes the transcription vendor, because the audio is not sent anywhere to be transcribed. Any other service that receives the transcript, notes or backups still has to be assessed on its own.

Is encrypted cloud backup exempt from HIPAA?

Not according to HHS. Its cloud computing guidance says a service that stores encrypted ePHI on your behalf is a business associate even if it does not hold the decryption key.

Does HIPAA apply to me?

HIPAA applies to covered entities (health plans, clearinghouses and most health care providers that bill electronically) and their business associates. If you are unsure whether you are one, ask before you record anything clinical.