Is AI Note-Taking HIPAA Compliant? What Therapists Need to Know
AI can draft your progress notes in seconds, but the moment a session involves a client, you are handling protected health information (PHI). So the real question is not "does it work?", it is "is it HIPAA compliant?" The honest answer: it can be, but only if the tool is built and contracted for it. A general consumer chatbot is not.
1. There must be a Business Associate Agreement (BAA)
Under HIPAA, any vendor that touches PHI on your behalf is a "business associate" and must sign a BAA with you. If a tool will not sign a BAA, you cannot lawfully put client information into it, full stop. This is the single most important test. A compliant provider should also hold BAAs with its own subprocessors (cloud, database, AI model), so the whole chain is covered.
2. PHI must be encrypted, in transit and at rest
Look for TLS for data in transit and strong encryption (for example AES-256) for data at rest, ideally with per-account keys so one breach cannot expose everyone.
3. What happens to the audio matters
Session audio is highly sensitive. The safest design is one where audio is never written to disk at all, held only in transient memory, transcribed once, then discarded. Ask specifically: "Do you store the recording? For how long? Can I delete it?" No stored recording means no archive to leak.
4. Data minimization and access controls
A compliant tool collects only what it needs. Fewer PHI fields, role-based access, two-factor authentication, automatic logoff and audit trails all reduce your risk surface, and support your own HIPAA risk analysis.
5. Compliance is shared
Even with a perfect vendor, HIPAA compliance is also an obligation on your practice: your risk analysis, policies, workforce training and client consent remain yours to maintain. The right tool gives you the technical safeguards and the paper trail to support them.
Questions to ask any AI note vendor
- Will you sign a BAA, and do you hold BAAs with your subprocessors?
- Is PHI encrypted at rest and in transit, and who holds the keys?
- Do you store session audio, and can I purge my data on demand?
- Do you offer two-factor authentication and audit logs?
- Is my data ever used to train AI models? (It should not be.)
How NotedTherapy approaches it
Here is how NotedTherapy answers each of the questions above:
- Will you sign a BAA, including with subprocessors? Yes. A BAA is executed and timestamped at sign-up before any client information can be entered, and we hold signed BAAs across the technology chain, Google Cloud, MongoDB Atlas and BastionGPT, so every provider that could touch your data is covered.
- Is PHI encrypted, and who holds the keys? Yes. PHI is encrypted at rest with AES-256-GCM under a unique per-account data key and travels over TLS 1.2+ in transit. Each account's data key is itself wrapped with a master key that NotedTherapy holds in its server environment, separate from the database, so the stored records are unreadable on their own without that key, and one account's records can never be read with another account's key.
- Do you store session audio, and can I purge my data? No audio is stored, it is transcribed once in memory and then discarded, and you control retention on demand, from purging a single client to bulk-deleting your entire record set.
- Two-factor authentication and audit logs? Yes. Two-factor authentication is available on every account, backed by access controls and audit trails, automatic logoff after inactivity, and one active session per account.
- Is my data used to train AI models? No. Your data is never used to train AI models.
You can read the full detail on our Security & HIPAA page or review the Business Associate Agreement before you enter any client information.