HIPAA compliant AI transcription: What a BAA covers and what it does not
October 9
TL;DR: Granola supports HIPAA workloads for Enterprise customers with a signed BAA, SOC 2 Type 2 certification, and real-time transcription on macOS and Windows that processes audio without storing it. On mobile, Granola transcribes using temporarily cached audio. Third-party AI providers are contractually prohibited from training on your data. Enterprise controls include SSO/SAML, SCIM provisioning, role-based access, an Audit API for compliance reporting, and org-wide auto-deletion periods, while transparency features like an automated chat message and video watermark support participant disclosure. Consent collection, tool configuration, and HIPAA obligations beyond the vendor's safeguards remain your organization's responsibility.
Healthcare conversations generate detailed information that needs accurate capture and proper protection. A Business Associate Agreement creates legal accountability between you and your transcription vendor, but the BAA alone does not make a tool compliant. This article covers the security features Granola provides, what configuration options you control, and how Granola's architecture reduces risk by design.
What HIPAA demands of your transcription partner
The vendor becomes a business associate the moment they create, receive, maintain, or transmit protected health information on your behalf. That status triggers specific legal obligations under the HIPAA Security Rule, which mandates administrative, physical, and technical safeguards for electronic protected health information (ePHI). HHS says covered entities should understand a vendor's environment as part of their own risk analysis.
Any vendor handling PHI must implement requirements of the HIPAA Security Rule with regard to electronic PHI, according to HHS guidance. This means the vendor needs documented policies for risk analysis, workforce training, and incident response.
Identifying PHI in audio recordings
Protected health information covers any individually identifiable health information created, stored, transmitted, or received in any form, whether spoken or digital. In audio recordings and transcriptions, PHI refers to any information in the medical record or designated record set that can identify an individual and was created during the course of providing healthcare services, including names, dates, medical records, and billing information. If your organization's customer interviews, telehealth sessions, or clinical discussions contain these details, that content qualifies as PHI.
Key infrastructure for HIPAA compliance
The HIPAA Security Rule requires five technical standards under 45 CFR 164.312:
- Access controls: Restrict who can view or modify PHI through unique user identification and role-based permissions, including encryption for data at rest
- Audit controls: Generate logs of user access events and data interactions
- Integrity controls: Protect ePHI from improper alteration or destruction
- Transmission security: Secure data moving between systems using encryption and secure communication protocols
- Person or entity authentication: Verify that a person or entity seeking access to ePHI is the one claimed
Under 45 CFR 164.312, access control requires unique user identification and an emergency access procedure. Automatic logoff and encryption are addressable, meaning organizations must assess them and document their implementation decision. Under 45 CFR 164.312(b), audit controls require mechanisms that record and examine activity in systems that contain or use ePHI. Granola's Enterprise plan includes an Audit API that supports this requirement.
Physical, administrative and subcontractor safeguards
Physical safeguards limit access to systems containing ePHI through facility controls, workstation policies, and device management. Administrative safeguards require risk analysis, workforce training, and sanction policies. Business associates must ensure subcontractors sign BAAs and implement equivalent protections, extending the chain of responsibility through every layer of the technical stack.
What a BAA covers for AI transcription
A Business Associate Agreement creates a legal contract between a covered entity and any vendor that handles protected health information. It ensures the vendor safeguards PHI, restricts its use and disclosure, and reports breaches to the covered entity. The BAA must describe the permitted and required uses and disclosures of PHI by the business associate, provide that the vendor will not use or further disclose the PHI other than as permitted or required by the agreement, and require compliance with the HIPAA Security Rule.
| BAA covers | BAA does not cover |
|---|---|
| Vendor security safeguards (encryption, access controls, audit logs, authentication services) | Customer consent collection from participants |
| Breach notification, no later than 60 days (a BAA can set a shorter period) | Configuration of tool settings and permissions within your organization |
| Restrictions on how the vendor may use and disclose PHI | Classification of what constitutes PHI in your context |
| Data deletion upon account closure | Legal compliance beyond HIPAA (state laws, GDPR) |
| Subcontractor flow-down requirements | Your internal access policies and permission assignment |
A signed BAA binds the vendor immediately upon execution. The contract extends the Security Rule's mandatory technical and administrative safeguards to the vendor, but it does not transfer your responsibilities as the covered entity or customer.
How vendors must secure health data
Once signed, the BAA requires the vendor to implement appropriate safeguards to prevent unauthorized use or disclosure, covering the five technical standards above plus administrative requirements for risk analysis and workforce training. The vendor must handle your data according to the strict terms of the contract, with no latitude to treat it as general business intelligence.
The agreement also binds any subcontractors the vendor uses. If a transcription service relies on cloud infrastructure or external processing APIs, those third parties must sign BAAs and implement the same protections.
When to report a data breach
Under 45 CFR 164.410, business associates must notify covered entities without unreasonable delay and in no case later than 60 days from discovery of the breach. HHS breach notification guidance confirms this requirement applies to all unsecured PHI.
The vendor must also provide the identity of each individual whose unsecured protected health information has, or is reasonably believed to have been, affected by the breach, to the extent possible. A BAA can set a shorter notification period, but it cannot extend the deadline beyond 60 days.
Permitted uses for AI transcription data
A business associate may only use or disclose PHI as permitted or required by its contract with the covered entity. HIPAA permits business associates to use PHI to perform contracted services, to conduct data aggregation for the covered entity's healthcare operations when expressly authorized in the BAA, and for their own management and administration only when the BAA permits it and appropriate legal basis and safeguards are in place. HHS guidance states that does not include the associate's own independent purposes, except for proper management and administration.
Managing data upon account closure
At termination, the business associate must, if feasible, return or destroy all PHI received. HHS sample BAA provisions confirm this is a standard contractual requirement.
User responsibilities for HIPAA data handling
A BAA binds the vendor to security safeguards but does not eliminate your duties under the HIPAA Privacy Rule. Granola's Enterprise controls are designed to support correct configuration, but how those settings are applied within your organization determines how PHI is handled in practice.
Your role in consent collection
Granola provides transparency features including an automated chat message and a video watermark to support participant disclosure. When to use AI notetaking depends on your jurisdiction and the sensitivity of the conversation.
Defining your data access boundaries
Granola's Enterprise plan includes role-based access controls that allow organizations to limit transcript access to authorized personnel based on their function.
Securing data through user permissions
Granola's Enterprise plan includes SCIM provisioning and admin controls that help keep access aligned with your team structure as it changes over time.
Beyond the BAA: Your legal requirements
A BAA operates within the broader context of federal and state privacy laws, including two-party consent statutes and international regulations like GDPR where applicable.
The BAA creates shared accountability between you and the vendor. Granola provides the contractual framework and technical controls. Legal review of the full vendor agreement before deployment is a common step in enterprise procurement.
Auditing transcription vendor compliance
Evaluating a transcription vendor for HIPAA compliance centers on specific documentation: SOC 2 Type 2 reports, data retention policies, and the vendor's stance on AI model training. Vendors with mature compliance programs typically make SOC 2 Type 2 reports and BAA templates available to enterprise buyers under NDA at the evaluation stage.
Any vendor that handles PHI is required to operate under a BAA, and vendors that work with healthcare buyers typically have a standard BAA template ready to share during evaluation.
SOC 2 Type 2 certification
SOC 2 Type 2 is a voluntary standard that measures how well an organization safeguards customer data. Type 2 reports assess control effectiveness over a sustained observation period. A vendor with current SOC 2 Type 2 certification demonstrates operational discipline, though SOC 2 is voluntary and does not replace the need for a BAA or HIPAA-specific safeguards.
How vendors handle sensitive data
Some vendors use customer data to train AI models. This practice creates HIPAA risk because model memorization can cause PHI to resurface in other contexts.
Vendors differ in how they handle audio. Processing can happen on your device or in the cloud, and audio files may be stored indefinitely or deleted immediately after transcription. On macOS and Windows, Granola transcribes in real time without storing the audio. On mobile, Granola uses temporarily cached audio for transcriptions.
Encryption methods for HIPAA compliance
Encryption documentation for a transcription vendor typically covers the standards used for data at rest and in transit, whether backups and portable media are encrypted, and how encryption keys are managed.
Granola's security infrastructure uses modern encryption standards for data in transit and at rest. Under a signed BAA, these safeguards are contractual obligations rather than optional features.
Vendor data retention policies
Vendors vary in how long they retain transcripts and whether they offer zero-retention options. HIPAA does not specify maximum retention periods for business associates, but organizational policies and state laws may impose specific deletion timelines.
Some vendors delete data immediately upon account closure, while others maintain backups for extended periods. HHS sample BAA provisions require the return or destruction of PHI upon termination where feasible.
Essential security checks for AI tools
No government agency certifies AI transcription tools as HIPAA-compliant. HHS does not endorse or recognize any private organization's HIPAA certification. Verification therefore depends on examining the vendor's actual practices against the HIPAA Security Rule.
What a BAA does not fix
A BAA does not make a non-compliant tool compliant. It creates legal liability for the vendor, but it does not fix technical gaps in their security. If the vendor lacks proper access controls or encryption, the BAA documents that deficiency but does not resolve it.
The BAA also does not cover your configuration errors. If you misconfigure user permissions or fail to obtain consent, the vendor is not liable for your mistakes. The contract assumes both parties understand and execute their respective obligations.
Third-party AI model training policies
Using PHI to train AI models without explicit patient consent creates HIPAA risk. Granola contractually prohibits third-party AI providers from training on customer data.
Storing transcripts for HIPAA compliance
Some vendors store audio recordings indefinitely. Others delete them immediately. On macOS and Windows, Granola processes audio without storing it at any point during transcription. On mobile, Granola uses temporarily cached audio for transcription.
45 CFR 164.312(b) requires mechanisms that record and examine activity in systems that contain or use ePHI. Granola's Enterprise plan includes an Audit API that gives your organization access to this activity data for compliance reporting.
Applying HIPAA protocols to AI transcriptions
Certain architectural decisions reduce risk by design, such as real-time transcription without audio storage and no third-party training on customer data.
Granola supports HIPAA workloads for Enterprise customers who contact sales for a Business Associate Agreement. The platform provides:
- SOC 2 Type 2 certification as of July 2025
- Contractual prohibition on third-party AI providers training on your data
- Real-time transcription on macOS and Windows without audio storage
- Mobile uses temporarily cached audio for transcription
Technical safeguards for HIPAA data
Some vendors implement privacy through architecture rather than policy alone. This approach differs from storing audio for playback, which creates a permanent copy of sensitive health conversations.
Granola's transparency features support your consent obligations. You can enable an automated chat message or a video watermark to notify participants that transcription is active, supporting your disclosure process while maintaining accurate meeting documentation.
Configuring your HIPAA data settings
Configuration determines how a transcription tool applies the minimum necessary standard in practice. Granola lets organizations restrict transcript access by role and set automatic deletion policies that align with their data retention requirements.
Granola's Enterprise plan includes SSO/SAML, SCIM provisioning, admin controls for sharing, and org-wide auto-deletion periods. These settings are configured at the organization level before deployment to research or clinical teams.
Try Granola for free. Download the Mac or Windows app and run your next meeting to see it in action. You can optionally connect your Google or Microsoft calendar for automatic meeting detection.
FAQs
Does every transcription vendor need to sign a BAA?
Yes, whenever PHI is involved. If the vendor creates, receives, maintains, or transmits PHI on your behalf, they function as a business associate and HIPAA requires a signed BAA.
What happens if a vendor won't sign a BAA?
Using a vendor without a BAA creates compliance risk when PHI is involved. Enterprise customers can request a signed BAA through the Granola sales team.
Can I use AI transcription for telehealth sessions?
Granola's Enterprise plan includes a signed BAA, SOC 2 Type 2 certification, and real-time transcription on macOS and Windows without audio storage, and temporarily cached audio on mobile for transcription. How consent is obtained and how the tool is configured within your organization are decisions made at your end.
How long does HIPAA compliance certification take?
No official HIPAA certification exists from HHS or any government agency.
Is SOC 2 the same as HIPAA compliance?
No. SOC 2 is a voluntary security framework, while HIPAA is a mandatory legal requirement for protecting health information. A SOC 2 report does not discharge HIPAA Privacy Rule obligations or include the required BAA contract.
Key terms glossary
Business Associate Agreement (BAA): A mandatory legal contract between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information. It binds the vendor to HIPAA Security Rule safeguards and restricts PHI use and disclosure.
Protected Health Information (PHI): Any individually identifiable health information created, stored, transmitted, or received in any form, whether spoken, written, or digital. This includes medical records, billing information, and any health data linked to a specific individual.
Covered entity: A health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically in connection with certain transactions. Covered entities must comply with HIPAA Privacy and Security Rules.
SOC 2 Type 2: A voluntary auditing standard developed by the AICPA that measures how well an organization safeguards customer data over time. It assesses security, availability, processing integrity, confidentiality, and privacy controls.
Minimum necessary standard: Requires covered entities to make reasonable efforts to limit the use, disclosure, and request of protected health information to the least amount needed to achieve a defined purpose. This applies to internal uses and external disclosures to business associates.
This article is for general informational purposes and does not constitute legal advice. Your organization's obligations under HIPAA and other laws depend on your specific circumstances, so review any deployment with qualified legal counsel.





