Granola for regulated teams: HIPAA workspaces, retention windows, redaction and deletion

October 2

TL;DR: HIPAA support, BAA execution, and org-wide retention windows all require the Enterprise plan and are configured through Granola's sales team. You get HIPAA-compliant workspaces with a BAA via sales, org-wide auto-deletion periods, transcript redaction and deletion, and admin-enforced transparency features. Transcript redaction is a manual action.

The default answer for sensitive meetings is prohibition. "Do not record" policies exist because consumer tools are not built to enforce retention schedules, redact PII on demand, or provide evidence for compliance reviews. The cost is institutional memory: decisions vanish, action items disappear, and knowledge walks out the door when employees leave.

Granola's Enterprise plan provides built-in security and governance controls that give teams a structured way to document meetings. Admin-level settings for retention, access, and transparency mean you can capture sensitive meetings while enforcing the governance your compliance program requires.

Essential meeting governance for regulated workflows

Granola's Enterprise plan addresses four specific gaps that matter in regulated workflows: configurable retention windows, audit trails that verify when deletions occurred, the ability to redact specific PII from transcripts while preserving the rest of the record, and a Business Associate Agreement that provides contractual data protection for PHI.

Granola's admin dashboard centralizes the controls that make compliant capture possible: retention windows, access rules, transparency features, and audit settings. The following sections walk through each control, where it lives, and how to configure it for a compliance review.

The table below compares Granola's Enterprise compliance controls against three common alternatives. Each platform takes a different approach to regulated data handling.

Feature Granola Enterprise Fireflies Otter Fathom
HIPAA workspace Yes, with BAA via sales Via enterprise sales Via enterprise sales Yes, blanket BAA with SOC 2 Type II and HITRUST i1
Configurable retention windows Yes, per workspace Custom retention available on Enterprise Workspace level (Enterprise) Yes, automatic retention policies (Enterprise)
Transcript redaction Yes, manual Not documented Not documented Not documented
Admin audit logs Yes, via Audit API Enterprise only Business activity logs, full audit trails on Enterprise Not documented
Enforced transparency Chat notification and video watermark Chat message, watermark Chat message on joining Not documented
Audio storage Deleted after transcription Stored, playback available Stored, playback available Stored, playback available

Setting up HIPAA support for Granola

HIPAA compliance for AI notepads requires more than encryption and access controls. It requires a contractual commitment between your organization and Granola that defines responsibilities, breach notification procedures, and audit rights. The following sections walk through workspace designation, BAA execution, and the admin configuration that makes regulated capture possible.

What makes a workspace HIPAA compliant

Granola's Enterprise plan includes HIPAA compliance features through a Business Associate Agreement (BAA), configurable retention and access controls, and PHI handling protocols. HIPAA features require an Enterprise plan and a signed BAA between Granola and your organization. Contact Granola's sales team to initiate the process.

Enterprise plans with a signed BAA include the retention windows, access controls, and audit trail that HIPAA security reviews typically require. These features work together to protect PHI in meeting transcripts.

Basic and Business plans do not include BAA or HIPAA workspace configuration. If your organization creates, receives, maintains, or transmits PHI, the Enterprise plan is the only Granola plan that includes a BAA and the associated data handling controls. Consult your legal team on your organization's specific obligations.

Step-by-step HIPAA workspace setup

To enable HIPAA features on your Enterprise plan, contact Granola's sales team. The steps below reflect the general sequence involved, but Granola's team will guide you through the specifics for your organization:

  1. Contact sales: Reach out to Granola's sales team to request a BAA and discuss HIPAA workspace requirements. Specify that you need HIPAA compliance for your Enterprise plan.
  2. Sign the BAA: Execute the Business Associate Agreement that defines Granola's obligations to protect PHI, report breaches, and support your compliance obligations.
  3. Enable HIPAA workspace: Once the BAA is signed, Granola enables the HIPAA workspace designation in your admin dashboard. Granola's team configures the backend controls that enforce HIPAA-compliant data handling. You cannot enable this yourself.
  4. Assign users and groups: Add the specific users and groups who need access to the workspace where PHI-containing meetings are captured. Restrict membership to only those roles that require PHI access for their function.
  5. Configure retention and access rules: Set retention windows that align with your organizational policy. Shorter windows reduce exposure but limit historical analysis. Longer windows support longitudinal research but require stricter access controls.

BAA requirements for enterprise teams

Granola's sales team handles the BAA process, not self-service signup. Timeline depends on your organization's legal review and procurement process. Granola's compliance team guides you through the execution steps and ensures the BAA covers your specific HIPAA compliance use cases.

Which subscriptions support HIPAA workspaces

HIPAA workspaces require the Enterprise plan, which starts at $35 per user per month. This plan includes the BAA capability, HIPAA workspace configuration, and the admin controls necessary for regulated data handling.

The Business plan ($14 per user per month) and Basic plan ($0) do not include a BAA or HIPAA workspace configuration. No contractual data protection for PHI is in place on these plans.

How to automate secure meeting data deletion

Configuring automated data deletion

Org-wide auto-deletion periods give admins a retention policy they can enforce without relying on individual user discipline. You set a specific timeframe (for example, 1 month, 3 months, 6 months, or 1 year), and Granola automatically deletes transcripts older than that window across the entire workspace.

To configure this, contact your Customer Success Manager or email hey@granola.so with the retention period you'd like. This is not a dropdown setting in the admin UI. It requires backend configuration by Granola's team to ensure the deletion logic applies correctly across all user accounts and historical data.

Once set, the system deletes transcripts on a rolling basis based on the configured retention window.

Tailoring policies for HIPAA workspaces

Enterprise workspaces can be configured with different retention windows to match the sensitivity of the data they contain. For example, one workspace might use a 1-month window for data requiring tighter controls, while another uses a 3-month window for lower-risk meeting content. This granularity lets you apply the strictest controls only where regulation requires them, preserving institutional memory for non-sensitive workflows.

Granola's available retention windows are: 1 day, 1 week, 1 month, 3 months, 6 months, and 1 year. These options apply to individual user settings. Enterprise workspace retention periods are configured by Granola's team based on your requirements. Contact hey@granola.so to set your org-wide window.

Retention windows should align with your organizational data retention policy, not arbitrary defaults. A 1-month window suits workflows where meeting data is synthesized quickly and no longer needs to be retained after that point. A 1-year window supports longitudinal studies or sales cycles with long enterprise procurement processes. There is no single "correct" duration. The right window matches your compliance obligations and operational needs.

Managing post-retention data removal

When the retention window expires, Granola deletes meeting data automatically. This deletion is permanent and cannot be recovered. For enterprise policies, all existing transcripts older than the retention period are deleted immediately when the policy is activated. There is no cooldown period for enterprise-level policies. If admins need more control over which meetings to remove, they can manually delete specific transcripts using the transcript deletion feature.

Individual users can set personal auto-deletion periods from their settings (1 day, 1 week, 1 month, 3 months, 6 months, or 1 year), but these include a one-week buffer before deletion starts. Enterprise policies override individual settings to ensure compliance consistency.

Redacting and deleting transcripts

Removing PII from transcripts

Transcript redaction lets you delete specific segments of a transcript while keeping the rest intact. This is a manual action rather than automated PII detection, so you control exactly what gets removed.

To redact, open the transcript within a note, select the chunk of text you want to delete, and click the delete button. Granola will prompt you to regenerate your note to ensure no mention of the deleted content remains in the summary or enhanced sections. The underlying transcript preserves the deletion, so the PII never appears in future queries or exports.

This capability matters when participants accidentally share sensitive information (a patient name, a social security number, a confidential project codename) during an otherwise valuable meeting. You preserve the business context while removing the compliance risk.

Deleting individual transcripts and notes

You can delete entire transcripts or notes when retention windows are not granular enough. This action is permanent and cannot be undone. Once you delete a transcript, it removes the source data that powers Granola Chat, folder queries, and AI enhancement.

Deletion gives compliance owners immediate control over data storage. If a meeting occurred that should never have been transcribed, or if a participant requests deletion under GDPR or CCPA, you can remove the record immediately rather than waiting for the retention window to expire.

Verifying data history for HIPAA

Granola's Audit API lets admins pull workspace audit events into their security information and event management (SIEM) tools or compliance dashboards. For the specific events your compliance framework requires, contact Granola's sales team for a current feature list.

Ensuring compliance through admin access controls

Configuring team-level access rules

Admins control sharing permissions and API access at the workspace level through the admin dashboard. You determine which teams can create shared folders, who can export transcripts, and which API scopes are available for custom integrations.

These controls prevent data exfiltration and shadow IT. By restricting API access to specific scopes, you ensure that even if a user creates an API key, it cannot access PHI-containing workspaces without explicit admin approval. Sharing controls let you disable public link sharing for sensitive workspaces while enabling it for general team meetings.

Restricting transcription access by group

Admins can restrict which groups can capture sensitive meetings through workspace assignment and access rules. You might create a dedicated workspace with strict controls and restrict folder membership to named users, limiting access to only those team members whose role requires it. Teams outside that group cannot access the folder, and general workspace members cannot create meetings within it.

This group-based restriction prevents unauthorized capture of sensitive conversations and creates clear boundaries for compliance reviews.

Letting participants know transcription is active

Granola strongly encourages using the transparency features to let participants know that transcription is active. Use Granola's in-chat notification or video watermark to inform participants at the start of every meeting. These features help maintain participant awareness and trust throughout the conversation.

Audit logs for secure meeting notes

The Audit API logs security-relevant events across your workspace. You can stream these logs into your existing security infrastructure using standard API calls.

Enterprise includes priority support and usage analytics to help you interpret these logs. If your compliance team needs to verify that no unauthorized users accessed a specific HIPAA workspace during a security incident, the audit logs provide the definitive record.

Setting retention by team workflow

Configuring retention for team workflows

Some teams handle data sensitive enough to require shorter retention windows. Others work with lower-risk content where longer retention supports institutional memory. Admins can create separate workspaces with distinct retention windows to match each team's data sensitivity level.

Each workspace operates as a separate compliance zone with its own deletion schedule and access rules. This separation prevents the "lowest common denominator" problem where strict HIPAA requirements force you to delete valuable non-sensitive data prematurely, or where loose retention policies for general meetings create risk for sensitive research.

Compliance workflows for transcribed meetings

A typical configuration workflow includes enabling HIPAA features through the sales team, configuring the retention window via Customer Success, restricting access to specific team groups, enforcing transparency features so participants know transcription is active, and connecting the Audit API to your security tools for verification.

This configuration gives you the controls to document meetings while maintaining the data governance your organization requires. You can capture research insights your product team needs while enforcing retention, access, and transparency policies.

Compliance checklist for regulated teams

Use this checklist to configure Granola for regulated workflows:

  1. Verify Enterprise plan: Confirm you are on the Enterprise plan ($35/user/month). Basic and Business plans do not support HIPAA workspaces or BAAs.
  2. Execute BAA: Contact Granola sales to initiate the Business Associate Agreement. Do not process PHI before this agreement is signed.
  3. Enable HIPAA workspace: Work with Granola's compliance team to activate the HIPAA workspace designation in your admin dashboard.
  4. Configure retention window: Contact hey@granola.so to set your org-wide auto-deletion period (1 day, 1 week, 1 month, 3 months, 6 months, or 1 year).
  5. Restrict access: Assign users to the HIPAA workspace only if their role requires PHI access. Remove general employee access.
  6. Enforce transparency: Turn on automated chat notifications or the video watermark to inform participants that transcription is active.
  7. Train on redaction: Show admins how to delete specific transcript sections to remove PII without deleting entire records.
  8. Connect audit logs: Integrate the Audit API with your SIEM or compliance dashboard to maintain evidence of all deletion and redaction activities.

Try Granola for free. Download the Mac or Windows app, connect your calendar, and run your next meeting to see it in action. For HIPAA workspaces and a BAA, contact Granola's sales team.

FAQs

Do I need Enterprise to get a BAA?

Yes. HIPAA workspaces and BAAs are available on the Enterprise plan only. Contact Granola's sales team to start the BAA process.

Can I set different retention windows for different teams?

Yes. Admins can create separate workspaces with different retention windows to match different team needs.

What happens to existing meetings when I enable auto-deletion?

For enterprise policies, all existing transcripts older than the retention period are deleted immediately when the policy is activated. There is no cooldown period for enterprise-level policies. Admins can also manually delete specific meetings if needed.

How long does the BAA process take?

The BAA process timing depends on your organization's legal review and procurement process. Granola's compliance team guides you through the steps.

Can users override admin retention policies?

No. Retention windows are enforced at the admin level and cannot be changed or overridden by individual users.

Does Granola store audio recordings?

No. Granola transcribes audio in real time and deletes it immediately, which means audio playback is not available.

Can I redact PII from transcripts automatically?

No. Transcript redaction is a manual action. You select the specific text to delete, and Granola prompts you to regenerate the note to remove any mention of the deleted content.

What events does the Audit API log?

Granola is actively developing its access logging capabilities. For specific audit log requirements, including the event types your compliance framework needs, contact the sales team for a current feature list and roadmap timeline before finalizing procurement.

Is Granola SOC 2 certified?

Yes. Granola achieved SOC 2 Type 2 certification in July 2025. You can access the full SOC 2 report and other compliance documentation through the Trust Center.

How do transparency features work?

Granola offers two transparency features: an automated chat message that posts when transcription starts, and a video watermark that displays an indicator on your video feed. Admins can enforce these features org-wide to ensure participants always know when Granola is active.

Key terms glossary

HIPAA workspace: HIPAA compliance features available on Granola's Enterprise plan, including a Business Associate Agreement (BAA), and retention, access, and audit controls for PHI handling. Granola is HIPAA compliant for Enterprise customers. HIPAA support and BAAs are not available on Basic or Business plans. Contact sales@granola.so to enable HIPAA on your Enterprise plan.

Business Associate Agreement (BAA): A legal contract required under HIPAA that defines Granola's obligations to protect PHI, report breaches, and support the covered entity's compliance. Handled through sales.

Retention window: The configured period after which Granola automatically deletes meeting data. Admins set retention windows per workspace (1 day, 1 week, 1 month, 3 months, 6 months, or 1 year) to align with organizational policy.

Transcript redaction: The manual deletion of specific text segments from a transcript while keeping the rest intact. Gives compliance owners control over what is stored without deleting entire records.

Audit API: An interface that streams workspace security events (deletions, access, configuration changes) into external compliance and SIEM tools for verification and review.

Auto-deletion: The automatic, permanent removal of transcripts when they exceed the configured retention window. For enterprise workspace policies, all existing transcripts older than the retention period are deleted immediately when the policy is activated, with no cooldown period. For individual users, a one-week cooldown applies before deletion begins.

Share