We build a recording app. We are not lawyers or compliance professionals. This is a plain-English explanation of how the rules are generally understood, written because the marketing copy in this category is genuinely misleading. Your compliance officer, not a vendor's blog, decides what your organisation may use.
Key findings
- No software is "HIPAA compliant" by itself. Compliance describes how a covered entity uses a tool, not a property the tool ships with.
- The BAA is the gate. Any vendor receiving PHI is a business associate and must sign one. No BAA means the disclosure is impermissible, no matter how strong the encryption.
- Otter.ai offers HIPAA support on Enterprise only, with the BAA arranged through an account manager. Fireflies.ai is Enterprise only as well.
- Free and individual tiers essentially never include a BAA. That is the plan most clinicians are actually using.
- On-device processing avoids creating a business associate relationship, because no vendor receives the data. The Security Rule still applies to your device.
- Voxxli does not offer a BAA and is not a tool for PHI. Stated plainly because this is our own product.
A therapist emailed us last year asking whether our app was HIPAA compliant. The honest answer was no, and the more useful answer took three paragraphs, because the question itself contains a misunderstanding that the entire industry benefits from leaving in place.
Here is the version we wish someone had written for them.
HIPAA is not a software feature
There is no certification body. Nobody audits an app and stamps it HIPAA compliant. When a vendor's landing page says "HIPAA compliant," that is marketing language describing their own assessment, not a credential anyone issued them.
What HIPAA actually regulates is covered entities, meaning providers, health plans and clearinghouses, and their business associates. The obligation sits on you, the clinician or practice, not on the app. A tool can make compliance possible or impossible, but it cannot make you compliant, and it cannot be compliant on its own.
This matters practically: two therapists using identical software can be in completely different positions, because one has a signed agreement and a documented risk analysis and the other clicked through a consumer signup.
The BAA is the whole question
A business associate agreement is a contract HIPAA requires whenever a vendor creates, receives, maintains or transmits PHI on your behalf.
A transcription service that receives audio of a patient encounter is receiving PHI. That makes it a business associate. Without a signed BAA, sending it that recording is an impermissible disclosure, and the vendor's encryption, SOC 2 report and security page are all irrelevant to that specific failure. The contract is not paperwork on top of the safeguards. It is the mechanism.
So the question "is this tool HIPAA compliant" collapses into a much more answerable one: will this vendor sign a BAA with me, on the plan I am actually paying for?
That last clause is where people get caught.
What the major tools require
| Tool | BAA available | On which plan | Notes |
|---|---|---|---|
| Otter.ai | Yes | Enterprise only | Arranged through an account manager or sales |
| Fireflies.ai | Yes | Enterprise only | Publishes a dedicated BAA page |
| Purpose-built clinical tools | Usually | Standard plans | SOAP and DAP formats, EHR integration |
| Consumer and free tiers, generally | No | Not offered | Includes the free plans of tools that do offer Enterprise BAAs |
| Voxxli | No | Not offered on any plan | Do not use for PHI, see below |
The pattern is consistent across the category. HIPAA support is an enterprise upsell, because a BAA transfers real liability onto the vendor and they will not accept that for fifteen dollars a month.
Which means the practical situation for most solo practitioners is: the tool you are using has a HIPAA page, that page describes a plan you are not on, and you are not covered.
Where on-device processing changes things
This is the genuinely interesting part, and it is the reason the question is more nuanced than "buy Enterprise."
A business associate relationship exists because a third party receives PHI. If a recording is captured and transcribed entirely on a device you control, and no vendor ever receives the audio or the text, then no third party has received anything. There is no business associate, so there is no BAA to sign.
This is the same reason you do not need a BAA with the manufacturer of your filing cabinet.
What that does not do is exempt you from HIPAA. The Security Rule still applies fully to the device holding the recordings. In practice that means at minimum: device encryption enabled, a strong passcode, automatic screen lock, remote wipe capability, controlled backups, a documented risk analysis covering the device, and a plan for what happens when it is lost.
A phone full of unencrypted session recordings is a breach waiting to be reported, and "it never went to the cloud" is not a defence.
Nearly every on-device recorder also offers cloud AI summaries. The moment you use one, transcript text containing PHI leaves your device and goes to a model provider. That is a disclosure, that provider is now a business associate, and you need a BAA with them specifically. On-device recording plus cloud summarisation is not an on-device workflow.
Is Voxxli HIPAA compliant? No
Since this is our product and this article ranks for this question, we will be unambiguous rather than clever.
Voxxli does not offer a business associate agreement. Not on the free tier, not on the paid tier, not at all. If you are a covered entity handling PHI, Voxxli is not an appropriate tool and we are not going to imply otherwise to win a customer.
The architecture is genuinely local for the parts that matter: recording, transcription and storage all happen on the iPhone using Apple's on-device speech engine, and no audio is ever uploaded. But the AI features, meaning summaries, chat, flashcards and speaker labels, send transcript text to a third-party provider, and there is no BAA covering that provider. That is disqualifying for PHI, full stop.
If you handle patient information, use something purpose-built for clinical documentation that will sign a BAA with you. That is a smaller market than ours and we would rather lose the download than have a clinician learn this from a breach notification.
A five-question checklist
Before any recording tool touches a patient encounter:
- Will they sign a BAA on my actual plan? Not their enterprise tier. The one I pay for. Get it in writing.
- Which subprocessors receive the data, and are they covered? Your BAA with the vendor does not automatically cover the four companies they pass audio to. Ask how downstream vendors are handled.
- Is model training off, and is that contractual? A settings toggle is not a commitment. Several vendors default training on.
- What is the retention period, and can I delete for real? Soft deletes with 30-day windows and "legitimate business purpose" retention clauses are common.
- Have I documented this in my risk analysis? The analysis is itself a requirement, and it is the first thing anyone asks for after an incident.
If you cannot answer the first one with a yes and a document, the rest do not matter yet.
Questions people actually ask
Are AI meeting note takers HIPAA compliant?
Not on the plans most people use. Compliance is a property of how a covered entity uses a tool, not of the software. Any tool receiving PHI needs a signed BAA, and the major note takers offer one on enterprise plans only. Otter.ai provides HIPAA support on Enterprise with the BAA handled by an account manager. Fireflies.ai is Enterprise only. Free and individual tiers generally have no BAA, so using them with PHI is a violation regardless of encryption quality.
What is a BAA and why does it matter for transcription?
A business associate agreement is a contract HIPAA requires whenever a vendor creates, receives, maintains or transmits PHI on your behalf. A transcription service receiving a patient encounter is a business associate. Without a signed BAA the disclosure is impermissible, and strong encryption does not cure that.
Does on-device transcription need a BAA?
If audio is recorded and transcribed entirely on a device you control and no vendor receives the content, no business associate relationship is created, because nobody external received PHI. The Security Rule still applies to the device: encryption, access controls, screen lock, remote wipe, and a documented risk analysis. Using a cloud AI summary feature does create a disclosure and does require a BAA with that provider.
Can therapists use AI note takers for sessions?
Only with a signed BAA and consent handled properly, and psychotherapy notes get heightened protection under HIPAA beyond ordinary PHI. Purpose-built clinical documentation tools with SOAP and DAP formats and EHR integration are generally a better fit than a general-purpose meeting assistant. Ask your compliance officer, not a blog.
Is Voxxli HIPAA compliant?
No. Voxxli does not offer a BAA on any plan and should not be used to record PHI by a covered entity. Recording and transcription are fully on-device with no audio upload, but the AI summary, chat, flashcard and speaker labelling features send transcript text to a third-party provider with no BAA covering it. If you handle PHI, use a tool that offers one.