Buyer guide · HIPAA & security
HIPAA-compliant speech-to-text: what a security review will actually ask
Compliance in this category is an evidence problem. This guide lists the artefacts, the clauses and the answers that stall deals when they are missing.
Short answer
What makes a speech-to-text vendor HIPAA compliant?
Four things, in order: a signed business associate agreement before any PHI is transmitted; encryption in transit and at rest with a configurable retention window, ideally zero-retention; a written commitment that your PHI is not used to train the vendor's models, with subprocessors disclosed; and audit evidence a customer can inspect, typically a SOC 2 Type II report or HITRUST certification. No product is 'HIPAA certified' — HIPAA has no certification scheme, so any vendor claiming one is a warning sign.
Cite as: HIPAA-compliant speech-to-text guide, Compare Healthcare API, last reviewed 2026-09-01.
Key findings
- There is no such thing as HIPAA certification. Vendors that claim it are describing SOC 2 or HITRUST, or nothing at all.
- Zero-retention configuration is the single most effective control for reducing your breach surface in a speech pipeline.
- 'We do not train on customer data' must be in the contract, not the FAQ; marketing pages change without notice.
- Subprocessor disclosure matters more in AI pipelines than in traditional SaaS, because model inference is frequently subcontracted.
- Your customers' security reviews will ask for artefacts, not assurances. Collect them before your first enterprise deal, not during it.
The BAA and what it must cover
A vendor processing PHI on your behalf is a business associate, and the BAA is the instrument that makes the arrangement lawful. Read it for four specifics: permitted uses of PHI (especially any carve-out for product improvement), breach notification timelines, subcontractor flow-down obligations, and the return or destruction of PHI at termination.
A BAA offered only on an enterprise plan is a real constraint for a startup, because it means you cannot pilot lawfully with PHI. Confirm the plan level at which the BAA is available before you build.
Retention and training
Default retention in speech APIs exists for debugging and model improvement, and it is often longer than teams assume. Ask what the default is, whether it can be set to zero, whether zero-retention disables features you depend on, and how deletion is verified.
On training, the only acceptable answer for a health software vendor is a contractual commitment that customer audio and transcripts are not used to train or fine-tune models without explicit, revocable opt-in. Anything softer will fail a health system's review and should fail yours.
Audit evidence and frameworks
SOC 2 Type II reports describe controls tested over a period and are the most common artefact requested. HITRUST CSF certification is heavier and more common among vendors selling to large health systems. Neither is HIPAA compliance in itself; both are evidence that controls exist and were examined.
For AI-specific risk, the NIST AI Risk Management Framework provides vocabulary your customers increasingly use — model documentation, evaluation, monitoring and incident response. Being able to speak that language shortens reviews even where no certification exists.
Your obligations, not just theirs
The vendor's posture is half the picture. Your own product must handle access control, minimum necessary access to notes and audio, audit logging, breach response and — for ambient capture — consent. A perfect vendor cannot compensate for an application that lets any staff account open any recording.
Treat the compliance checklist as a joint artefact: vendor controls in one column, your controls in the other. That table is the fastest way to answer a security questionnaire without improvising.
Frequently asked questions
- Is any speech-to-text API HIPAA certified?
- No. HIPAA has no certification programme. Vendors demonstrate posture through a signed BAA plus audit evidence such as SOC 2 Type II or HITRUST certification, and through documented retention and training commitments. Compliance checklist.
- Do I need a BAA for de-identified audio?
- If data is properly de-identified under HIPAA it is no longer PHI, but audio is extremely difficult to de-identify because voice and content carry identifiers. In practice, treat encounter audio as PHI and get the BAA. De-identification, defined.
- Can the vendor train on our clinical audio?
- Only if your contract permits it. Require a written commitment that customer audio and transcripts are excluded from training and fine-tuning absent explicit opt-in, and check the subprocessor list for inference providers with different terms. See who discloses this.
- What evidence will a health system ask us for?
- Typically: the vendor BAA, a SOC 2 Type II report or HITRUST certification, a subprocessor list, retention and deletion settings, encryption details, an access-control and audit-log description, incident response commitments, and a statement on model training. Work the checklist.
- What makes a speech-to-text API HIPAA compliant?
- An executed BAA, a documented retention window you can shorten or zero, an explicit exclusion of PHI from model training, a disclosed subprocessor list, encryption in transit and at rest, access logging, and breach-notification terms. The endpoint is never compliant on its own — the contract and configuration make it so. Full control checklist.
- Which speech-to-text vendors sign a BAA?
- AWS, Microsoft, Deepgram, AssemblyAI and Speechmatics all support BAAs for healthcare use, generally on specific plans or account configurations. Confirm your own plan and region are covered — a BAA offered on an enterprise tier does not cover your self-serve key.
- How long do speech APIs keep my audio?
- Defaults range from zero retention to weeks for abuse monitoring and model improvement. Ask for the default in writing, whether it is configurable to zero, whether transcripts follow the same rule as audio, and how deletion is verified.
- Do I have to tell patients an AI is involved?
- Consent-to-record obligations are jurisdictional and separate from HIPAA, and disclosure expectations from professional bodies are tightening. Build the disclosure and consent record as product features rather than policy text, since your customers will be audited on them. Jurisdiction index.
- What will my customer's security review ask for?
- The BAA, SOC 2 or HITRUST evidence for you and every subprocessor, a data-flow diagram, retention and deletion controls, PHI-training exclusions, access-control and logging design, incident response, and a penetration-test summary. Assemble the pack once and reuse it — this is what actually sets your sales cycle length.
Evidence & sources
Every factual claim on this page traces to one of the primary references below. Each entry records what it supports and its evidence tier, so documentation can be told apart from judgement.
U.S. Department of Health & Human Services · Regulation · Tier A — primary documentation
Supports: What a covered entity and its business associates may do with PHI, and why a signed BAA is a precondition rather than a feature.
U.S. Department of Health & Human Services · Regulation · Tier A — primary documentation
Supports: Administrative, physical and technical safeguards a vendor handling recorded encounter audio must implement.
U.S. Department of Health & Human Services · Regulation · Tier A — primary documentation
Supports: The contractual clauses a documentation vendor's BAA must contain.
AICPA · Standard · Tier A — primary documentation
Supports: What a SOC 2 Type II report does and does not attest to during a vendor security review.
- [5]HITRUST CSF
HITRUST Alliance · Standard · Tier A — primary documentation
Supports: The certification many health systems require of documentation vendors handling PHI at scale.
NIST · Standard · Tier A — primary documentation
Supports: A defensible structure for governing an AI documentation feature you ship to clinicians.
NIST · Standard · Tier A — primary documentation
Supports: Control-level guidance auditors reference when reviewing PHI-handling architecture.
U.S. Department of Health & Human Services, OCR · Regulation · Tier A — primary documentation
Supports: Breach reporting obligations that flow to you as the covered entity's business associate.
Amazon Web Services · Vendor documentation · Tier A — primary documentation
Supports: Which services are covered by the AWS BAA — the basis of our AWS compliance score.
Microsoft · Vendor documentation · Tier A — primary documentation
Supports: BAA coverage for Azure services processing PHI.
Source tiers are defined on the methodology page. Outbound links are unaffiliated and carry no commercial relationship.
Continue
- Compliance readiness checklistVendor controls beside your own.
- Vendor Transparency IndexWho publishes what, audited.
- AI speech to text in healthcareRisk tiers and where general APIs fit.
- Recording consent indexConsent regimes by jurisdiction.
- RFP question setSecurity questions in procurement form.
- MethodologyHow compliance is scored here.