In a busy medical practice, hospital department, or healthcare network, meetings happen constantly — clinical case reviews, administrative planning sessions, billing discussions, care coordination calls, staff meetings that touch patient populations. AI meeting transcription tools promise to make these meetings more efficient by automatically generating summaries and action items.

The problem is that healthcare meetings frequently involve Protected Health Information. And when PHI enters a consumer AI tool — even accidentally, even in passing — it creates potential HIPAA liability that many organizations have not thought through.

This article is written for compliance officers, practice administrators, healthcare IT directors, and anyone responsible for evaluating technology tools in a healthcare setting. Our goal is not to create alarm — it is to help you ask the right questions before you adopt a tool that could expose your organization.

Why healthcare meetings are a HIPAA risk area

HIPAA's Privacy Rule and Security Rule cover Protected Health Information — individually identifiable health information in any form. This includes information that could be used to identify a patient in connection with their health condition, care, or payment.

Healthcare meetings are a constant source of PHI. Consider how often the following comes up in a typical healthcare organization's meetings:

In each of these situations, if a meeting is being recorded and that recording is sent to a consumer AI service for transcription, PHI may be leaving your organization's control — potentially without a Business Associate Agreement in place and potentially without adequate security protections.

⚠ HIPAA Risk

Under HIPAA, any vendor that receives, creates, maintains, or transmits PHI on behalf of a Covered Entity is a Business Associate. Business Associates must sign a Business Associate Agreement before processing any PHI. Using a transcription service without a signed BAA when PHI is involved is a HIPAA violation — regardless of whether a breach occurs.

The Business Associate Agreement requirement

This is the most immediate and concrete HIPAA issue with consumer AI meeting tools: the Business Associate Agreement, or BAA.

Under HIPAA, a Business Associate is any person or entity that performs functions or activities on behalf of a Covered Entity that involve the use or disclosure of PHI. When you use a transcription service to process recordings of your healthcare meetings, that service is almost certainly a Business Associate — because it is receiving and processing information that may include PHI on your behalf.

Before any Business Associate can process PHI, you must have a signed BAA with them that meets HIPAA's specific requirements. The BAA must:

"The question is not whether your meetings contain PHI. Most healthcare meetings do. The question is whether your transcription vendor is a signed Business Associate — and whether they can actually fulfill that role."

Most consumer AI meeting tools do not offer BAAs on their standard plans. Some enterprise tiers offer BAAs, but these come with additional requirements, costs, and contractual complexities that many healthcare organizations have not navigated. And signing a BAA does not by itself guarantee that the tool is an appropriate choice — the BAA is the floor, not the ceiling.

The AI training problem in healthcare

Beyond the BAA requirement, healthcare organizations face a second, distinct problem with consumer AI meeting tools: the use of recordings for AI model training.

Many consumer transcription services use customer recordings to improve their AI models. This is how the technology gets better over time — by learning from real-world audio. The problem for healthcare organizations is straightforward: if your meeting recordings contain PHI, and those recordings are used as AI training data, you have a potential HIPAA violation that is separate from and in addition to the BAA issue.

HIPAA's minimum necessary standard requires that PHI only be used or disclosed to the minimum extent necessary to accomplish the intended purpose. Using patient-related discussions from your meetings to train an AI company's models is not a permitted use under HIPAA — even if it is buried in a terms of service.

⚠ Legal Alert

A class-action lawsuit was filed in 2025 against a major consumer meeting transcription service, alleging that the company used customer recordings — which may have included healthcare discussions — to train AI models without adequate consent, potentially in violation of federal privacy laws. Healthcare organizations that used consumer transcription tools during this period should consult legal counsel regarding their potential exposure.

The shadow IT problem in healthcare

In our experience working with healthcare organizations in Northern California, the most common situation is not a deliberate decision to use a consumer meeting tool. It is shadow IT — individual clinicians, department heads, or administrative staff who have adopted a free or low-cost consumer tool on their own, without IT or compliance involvement.

A physician records patient case reviews with a consumer transcription app on their phone. A practice manager uses a free meeting bot to transcribe billing discussions. A department head uses a browser extension to capture clinical coordination calls. None of these individuals intended to create a HIPAA problem. But each of them potentially has.

The challenge for healthcare compliance teams is that shadow IT adoption of AI meeting tools is nearly invisible. These tools are easy to sign up for, often free to start, and feel benign. The risk is not obvious until something goes wrong.

What HIPAA-appropriate meeting transcription looks like

The good news is that AI meeting transcription can be done appropriately in a healthcare setting. The technology is not inherently incompatible with HIPAA — the deployment model is what matters.

HIPAA evaluation checklist for AI meeting transcription

Business Associate Agreement available. The vendor must be able to sign a BAA that meets HIPAA's requirements before you process any PHI through their service.
No AI training on your recordings. The vendor must commit — contractually, not just in a policy — that your recordings will never be used to train AI models. This commitment must survive changes to terms of service.
Data processed on controlled infrastructure. Your recordings should be processed on infrastructure the vendor controls and can specifically account for — not shared consumer cloud services.
Audio deleted after transcription. Raw audio files should be automatically deleted after processing. PHI should not be retained in audio form any longer than necessary.
Encryption in transit and at rest. All PHI must be encrypted during transmission and while stored, using industry-standard encryption.
Documented security practices. The vendor should be able to provide documentation of their security controls — not just a marketing page, but substantive evidence of security practices.
Breach notification procedures. The vendor must have documented procedures for identifying and reporting breaches to you as required by HIPAA.
Consumer-grade terms of service. Any vendor whose terms of service are written for general consumers — with broad rights to use your data for product improvement — is not appropriate for healthcare use regardless of what they say verbally.

Practical steps for healthcare compliance teams

If you are responsible for HIPAA compliance at a healthcare organization, here is a practical action plan:

  1. Inventory all AI meeting tools in use. Survey your organization — including individual departments, clinical teams, and administrative staff — to identify every AI meeting transcription tool currently in use. This includes mobile apps, browser extensions, and desktop software, not just enterprise deployments.
  2. Classify each tool's HIPAA status. For each tool identified, determine whether a signed BAA is in place. If not, and if any meetings involving PHI have been recorded through that tool, consult legal counsel.
  3. Establish a policy for AI meeting tools. Define which tools are approved for use in healthcare settings, under what circumstances, and with what documentation requirements. Make it clear that consumer tools without BAAs are not approved for any meeting that may involve PHI.
  4. Address shadow IT proactively. Educate clinical and administrative staff about the HIPAA implications of consumer meeting tools. Make the compliant alternative easy to access — if the approved tool is harder to use than the free consumer alternative, shadow IT will continue.
  5. Review vendor contracts. For any tool you intend to continue using, obtain and review the BAA carefully. Verify that it meets HIPAA's requirements and that the vendor's actual data practices match their contractual commitments.
  6. Document your decisions. Maintain records of your tool evaluation process, the BAAs you have in place, and the security assessments you have conducted. This documentation is your first line of defense in a HIPAA audit or investigation.
💡 From the Field

NSAG has worked with Northern California healthcare organizations on security assessments and technology evaluations. The pattern we see most often is a compliance team that is unaware of AI meeting tools being used in clinical departments — tools that individual clinicians or managers adopted without IT involvement. A simple survey of department heads is often the most important first step.

A note on "HIPAA compliant" marketing claims

Many AI tool vendors claim their products are "HIPAA compliant." This phrase requires careful scrutiny. HIPAA compliance is not a certification — there is no government body that certifies products as HIPAA compliant. When a vendor says their product is "HIPAA compliant," what they typically mean is that their product can be used in a HIPAA-compliant manner if configured correctly and if the appropriate BAA is in place.

The questions to ask are not "is this product HIPAA compliant" but rather:

Any vendor unwilling or unable to answer these questions clearly should not be trusted with your healthcare meeting recordings.

The cost of getting this wrong

HIPAA violations carry significant financial and reputational consequences. The HHS Office for Civil Rights can impose civil monetary penalties ranging from $100 to $50,000 per violation, with annual caps up to $1.9 million per violation category. Willful neglect violations — where an organization was aware of a risk and failed to address it — carry the highest penalties.

Beyond financial penalties, a HIPAA breach involving AI meeting tools creates reputational exposure, potential state attorney general action under California's CMIA and CCPA, and the operational burden of breach notification to affected patients.

The cost of evaluating and selecting an appropriate meeting transcription tool is a fraction of the cost of responding to a HIPAA investigation.

Conclusion

AI meeting transcription offers genuine value for healthcare organizations — improved documentation, better follow-through on action items, more accessible meeting records. None of that value requires accepting HIPAA risk.

The path forward is to adopt tools that were built for the accountability standards healthcare operates under — tools with proper BAAs, documented security practices, no AI training on your data, and operators who understand what it means to handle health information responsibly.

That is the standard NSAG Meeting Intelligence is built to meet. Contact us to discuss your organization's specific requirements, including Business Associate Agreement execution.

Built for organizations that handle sensitive information

NSAG Meeting Intelligence processes all data on NSAG-controlled infrastructure in California. No AI training on your recordings. Audio deleted after transcription. Contact us to discuss BAA requirements for your healthcare organization.

Start Free — No Card Required

Healthcare inquiry? Call 707.452.3015 or email support@nsag.ai

Frequently Asked Questions

Is Otter.ai HIPAA compliant?
Otter.ai offers a HIPAA plan for enterprise customers that includes a Business Associate Agreement. Standard consumer and business plans do not include HIPAA protections. Additionally, a class-action lawsuit filed in 2025 alleged that Otter.ai used customer recordings to train AI models without sufficient consent. Healthcare organizations should carefully evaluate any consumer transcription tool and consult legal counsel before processing PHI.
Do I need a Business Associate Agreement for AI meeting transcription?
If your meetings involve Protected Health Information and you use a third-party service to process recordings, that service is likely a Business Associate under HIPAA and you need a signed BAA before processing any PHI. Using a transcription service without a BAA when PHI is involved is a HIPAA violation.
What happens if a consumer meeting tool used our recordings for AI training?
If PHI was included in recordings that were used for AI training without a BAA and appropriate safeguards, this may constitute a HIPAA breach. You should consult with healthcare legal counsel to evaluate your organization's specific situation and potential obligations, including breach notification requirements.
What is the safest AI meeting transcription tool for healthcare?
Healthcare organizations should choose transcription tools that process data on controlled infrastructure, never use recordings for AI training, provide Business Associate Agreements, delete audio after transcription, and are operated by organizations with documented security practices. Contact NSAG to discuss BAA requirements for your organization.
Can individual clinicians use their own meeting transcription apps?
Individual use of consumer meeting tools for any meeting that may involve PHI creates HIPAA risk for your organization. Shadow IT adoption of AI meeting tools is a significant and often undetected compliance gap. Organizations should establish clear policies about approved tools and provide compliant alternatives that are easy to use.