FÜR TEAMSPrivate On-Device-Diktierung für dein ganzes Team — weitere Plätze ab 15 $.
BUILT FOR HEALTHCARE & PHI

HIPAA compliant transcription that never touches the cloud

The cleanest path to HIPAA compliant dictation is to never send PHI to the cloud at all. Whisper transcribes 100% on your own device — the audio and the transcript stay with the covered entity. There's no cloud transcription vendor to sign a BAA with, because there is no cloud vendor.

PHI stays on-device

The speech model runs on your CPU/GPU. Patient audio and dictated notes stay on the machine that recorded them.

No BAA to negotiate

No cloud transcription service in the path means no vendor to sign a Business Associate Agreement with — for transcription.

Works offline

After a one-time setup, Whisper needs no internet. Suitable for restricted clinical networks and air-gapped machines.

The cloud BAA problem

Most HIPAA compliant transcription software works the same way: you speak, your audio is uploaded to the vendor's servers, a model there turns it into text, and the result comes back. That model can be compliant — but only after you've built and maintained a chain of trust around it:

  • Sign a Business Associate Agreement (BAA) with every vendor that touches the audio.
  • Trust — and keep verifying — their retention and auto-deletion settings.
  • Vet the vendor's subprocessors, the sub-vendors those rely on, and where the data is stored.
  • Accept that PHI now lives on infrastructure you don't own or control.

Every link in that chain is a place a compliance review can go wrong. Tools like Otter, Wispr Flow, and cloud AI scribes all rely on this server-side model — which is why they require BAAs and why you have to trust their settings with your patients' words.

On-device transcription: PHI never leaves your control

Whisper inverts the model. There is no upload, so there is no chain to secure.

AspectCloud transcriptionWhisper (on-device)
Where audio is transcribedOn the vendor's serversOn your own device
PHI sent to a third partyYes — audio and transcriptNo — nothing is uploaded
BAA required for transcriptionYes, with each vendorNo cloud vendor to sign one with
Retention / deletion settings to trustYes — theirs, not yoursNone — data stays on your machine
Subprocessors to vetVendor's listNone in the transcription path
Works offline / air-gappedNo — needs the cloudYes, after one-time setup

Want the full data-flow breakdown — down to the license check and model download? We lay out every byte that does and doesn't leave your machine on the security & privacy page.

The honest truth about “HIPAA compliant” tools

We won't tell you Whisper “is HIPAA certified” or slap a compliance badge on this page — because no dictation app can honestly make that claim. HIPAA compliance is a property of the covered entity's overall workflow: your policies, your access controls, your devices, your staff training. A single tool is never the whole picture.

What we can say plainly: because PHI never leaves your device, Whisper removes the biggest source of HIPAA exposure in dictation — cloud transmission and storage of patient data. It supports HIPAA-minded workflows by keeping the sensitive data where it already lives. The value here is the architecture, not a certificate.

  • No audio or transcript is ever uploaded — there's nothing on our servers to breach.
  • No subprocessors in the transcription path, so nothing for your security team to vet.
  • You keep control of retention and deletion, because the files never leave your device.

Who it's for

Clinics & medical practices

Dictate chart notes, referrals, and letters at the point of care. Patient data stays on the workstation — no cloud scribe reading every visit.

Therapists & counselors

Psychotherapy and session notes are some of the most sensitive records there are. On-device dictation keeps your clients' words local to your machine.

Physicians & compliance officers

Meet 'no PHI to the cloud' policies out of the box. Fewer vendors, fewer BAAs, and a shorter list of things a HIPAA review can flag.

Building a dictation setup for a whole practice? Our medical dictation software guide covers workflows, accuracy, and rollout for healthcare teams.

Simple, one-time pricing

$29 first seat

One-time, no subscription

+$15 each additional seat

Teams up to 100

  • 100% on-device, offline transcription — audio never leaves the machine.
  • GPU-accelerated and fast, with automatic punctuation.
  • Works on Mac, Windows, and Linux.
  • No subprocessors, no BAA to negotiate for transcription.
See pricing & get Whisper

HIPAA transcription FAQ

Is Whisper HIPAA compliant?

HIPAA compliance is a property of your entire workflow — your policies, your devices, your training — not a badge any single app can wear. So the honest answer is: Whisper is not 'HIPAA certified,' and no dictation tool truly is. What Whisper does is remove the biggest source of HIPAA exposure in dictation: it transcribes 100% on your own device, so protected health information (the audio and its transcript) never travels to a cloud transcription vendor. That makes it well suited to HIPAA-minded workflows, because the sensitive data simply stays with the covered entity.

Do I need a Business Associate Agreement (BAA) to use Whisper?

A BAA is required when you hand PHI to a vendor that processes it on your behalf. With Whisper there is no such vendor: transcription happens entirely on your machine, and neither the audio nor the transcript is ever sent to us or any third party. Because there is no cloud transcription service touching your PHI, there is no transcription vendor to sign a BAA with. (You should still evaluate your own environment and any other tools in your stack with your compliance officer.)

Does my dictation audio go to the cloud?

No. Whisper runs a local AI speech model on your CPU/GPU. The recording is transcribed on-device and is never uploaded to our servers or any external provider. After a one-time model download and license activation, transcription works fully offline — you can dictate with the network disconnected.

Is cloud transcription HIPAA compliant?

It can be, but only with more moving parts. Cloud dictation tools and AI scribes send your audio to their servers, which means you must sign a BAA with each vendor, trust their retention and deletion settings, vet their subprocessors, and accept that PHI now lives on infrastructure you don't control. Every one of those is a place a review can go wrong. On-device transcription sidesteps the whole chain because the PHI never leaves your control in the first place.

Can therapists use Whisper for session notes?

Yes. Therapists and counselors handle some of the most sensitive records there are — including psychotherapy notes. Because Whisper transcribes on your own device and nothing is uploaded, dictated session notes stay local to the machine you typed them on. There's no cloud service reading your clients' words. As always, your overall handling of those notes is what determines compliance, but the dictation step keeps the data with you.

How is this different from Otter, Wispr Flow, or a cloud AI scribe?

Those tools process your audio on their servers. That model can work, but it puts PHI on third-party infrastructure and requires a signed BAA, trust in retention settings, and a subprocessor list for your security team to review. Whisper inverts that: the transcription model runs locally, so there is no cloud pipeline, no subprocessor list, and no BAA to negotiate for transcription. The value is the architecture, not a certification badge.

Keep PHI where it belongs — on your device

On-device dictation for healthcare. No cloud vendor, no BAA to negotiate for transcription, no audio leaving the room. One-time license, from $29.