This is a practical guide, not legal or compliance advice. Your obligations depend on your practice, your state and your agreements; a compliance professional should confirm anything you rely on.
Start with the honest question
Software cannot be “HIPAA certified”. There is no such certificate — HIPAA places obligations on you as a covered entity, and on any vendor that handles protected health information on your behalf. So the real question is not “is this app compliant?” but “does using this app create a disclosure I have to account for?”
That reframing sorts the market into two groups very quickly.
Group one: cloud dictation with a BAA
A cloud transcription service receives your audio, processes it on its servers and stores the result. That is a disclosure of PHI to a business associate, so you need a Business Associate Agreement in place before you use it for session notes.
If you go this route, check all of the following, and get answers in writing:
- Will they sign a BAA at your plan level? Several vendors offer one only on enterprise tiers, which means the plan you were about to buy is not the one you can legally use.
- Is your audio used to train their models? Some policies permit training on “de-identified” recordings. De-identification lowers risk; it does not undo the disclosure, and audio is unusually hard to de-identify because a voice is itself identifying.
- Where is it retained, and for how long? Look for a deletion guarantee with a timeframe, not “as long as necessary”.
- Who else can reach it? Sub-processors, support staff, and any third-party AI model the vendor sends your text to.
- What happens at breach? Their notification duty to you, and your resulting duty to your clients.
None of this is a reason to avoid cloud tools. It is the work they require.
Group two: on-device dictation
If transcription happens entirely on your own computer, there is no transmission, no vendor copy and no business associate — which removes the whole branch of questions above rather than answering it.
Built for HIPAA-sensitive workflows. Altypist doesn't transmit, store, or process any audio or text outside your Mac. Because nothing is ever sent to a server, Altypist removes the cloud-transmission risk that HIPAA compliance programs are built to prevent — there's no Business Associate Agreement to negotiate, because there's no data processor to negotiate one with.
Altypist is a local software tool, not itself a HIPAA-covered entity or service — this describes the architecture, not a compliance certification.
On-device tools have real limits, and you should know them before choosing one. They need a reasonably recent machine, they cannot join a video call to take notes for you, and they do not share a transcript with colleagues automatically. For writing your own notes, none of that matters. For team meeting minutes, it does.
What stays your responsibility either way
Choosing on-device software moves the risk; it does not delete it. The notes now live on your Mac, so the ordinary safeguards are the ones that matter:
- FileVault on, so the disk is encrypted at rest.
- A real login password and a short auto-lock.
- Care about where the finished text goes — your EHR is protected, a personal notes app synced to a consumer cloud is not.
- Consent practices for recording, where your state requires them.
A short checklist
| Ask | Good answer |
|---|---|
| Where is the audio processed? | On my device — or, on their servers under a signed BAA |
| Is my audio used for training? | No, in writing |
| Does it need an account? | Not necessarily a problem, but it is another data holder |
| Does it work without internet? | Tells you whether audio is leaving |
| Can my compliance reviewer inspect it? | Published architecture, ideally an open recognition engine |
Altypist in one line: dictation that runs on your Mac, inserts text where your cursor is, and never uploads anything. 7-day trial, every feature, no credit card and no account.