Skip to main content
If you’re a Covered Entity or a Business Associate and you want to dictate anything containing protected health information, the rule is short: get a BAA in place first. Email support@openwhispr.com and we’ll start it. Without a signed BAA, PHI must not go through the cloud service. That’s not fine print we’re hiding — it’s Section 14 of our DPA, and it exists to protect you as much as us.

Where we stand

We’ve written that last row the way it actually is rather than rounding it up. If you need the current state of a specific sub-processor before you sign, ask and we’ll tell you where it stands.

Getting a BAA

Email support@openwhispr.com with your organisation’s name and who should sign. Once it’s executed, the BAA governs PHI in place of the DPA wherever the two would conflict. Do this before your team starts dictating clinical content, not after.

Keeping PHI out of our cloud altogether

Some organisations would rather not send PHI to a vendor at all, whatever the paperwork says. Four of OpenWhispr’s five processing modes make that possible, because our cloud isn’t in the path: Local mode is the strongest position: the audio never leaves the machine, and it works offline once the model is downloaded. Set it per activity — dictation, note recording and audio upload each have their own engine setting under SettingsSpeech-to-Text under AI Models. Where your voice and text go explains why all three matter.
Switching Dictation to local does not move Audio Upload off the cloud. They’re separate settings on separate tabs. If you’re standing up a PHI-safe configuration, check all three tabs and confirm each one.
If you’re evaluating a clinical-grade option under your own contract, Corti is available as a bring-your-own-key provider — clinical transcription with EU-hosted cleanup and reasoning. See cloud vs local processing.

FAQ

HIPAA compliance is a property of how an organisation uses a tool, not a badge a product carries on its own. What we can tell you: we hold a HIPAA attestation, we act as a Business Associate, and we sign a BAA before any PHI is processed. With that BAA in place and an appropriate configuration, you can use OpenWhispr in a HIPAA-regulated workflow.
If PHI never reaches our servers, we’re not processing it and there’s nothing for a BAA to cover. That said, most compliance teams still want the agreement on file in case someone switches a mode later. Ask us for one.
The BAA isn’t tied to a plan — ask and we’ll go through it with you.
They’re kept locally under your retention settings, 30 days by default, and you can turn audio retention off entirely. That’s part of your own HIPAA footprint, so it’s worth setting deliberately — see what OpenWhispr stores, and for how long.