> ## Documentation Index
> Fetch the complete documentation index at: https://docs.openwhispr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# HIPAA and healthcare use

> Where OpenWhispr stands on HIPAA, when you need a BAA, and which processing modes keep PHI out of our cloud entirely.

If you're a Covered Entity or a Business Associate and you want to dictate
anything containing protected health information, the rule is short: **get a BAA
in place first.** Email [support@openwhispr.com](mailto:support@openwhispr.com)
and we'll start it.

Without a signed BAA, PHI must not go through the cloud service. That's not
fine print we're hiding — it's [Section 14 of our DPA](https://openwhispr.com/dpa),
and it exists to protect you as much as us.

## Where we stand

|                        | Status                                                                                                                                                                                      |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **HIPAA attestation**  | Held (2026, through our compliance platform)                                                                                                                                                |
| **Our role**           | Business Associate — we process ePHI on your behalf, we're not a Covered Entity                                                                                                             |
| **BAA**                | Offered on request. Required before any PHI goes through the cloud service                                                                                                                  |
| **Sub-processor BAAs** | Executed with the sub-processors that store content — our database and cloud transcription and language-model providers. Coverage of the remaining HIPAA-path sub-processors is in progress |

We've written that last row the way it actually is rather than rounding it up.
If you need the current state of a specific sub-processor before you sign, ask
and we'll tell you where it stands.

## Getting a BAA

Email [support@openwhispr.com](mailto:support@openwhispr.com) with your
organisation's name and who should sign. Once it's executed, the BAA governs PHI
in place of the DPA wherever the two would conflict.

Do this before your team starts dictating clinical content, not after.

## Keeping PHI out of our cloud altogether

Some organisations would rather not send PHI to a vendor at all, whatever the
paperwork says. Four of OpenWhispr's five processing modes make that possible,
because our cloud isn't in the path:

| Mode                   | Where the audio goes                              |
| ---------------------- | ------------------------------------------------- |
| **Local**              | Nowhere — transcribed on the device               |
| **Self-Hosted**        | Your own server on your network                   |
| **Bring your own key** | Direct to the provider you hold the contract with |
| **Enterprise**         | Your organisation's own cloud account             |

Local mode is the strongest position: the audio never leaves the machine, and it
works offline once the model is downloaded. Set it per activity — dictation, note
recording and audio upload each have their own engine setting under **Settings**
→ **Speech-to-Text** under **AI Models**. [Where your voice and text
go](/help/privacy/where-your-data-goes) explains why all three matter.

<Warning>
  Switching **Dictation** to local does not move **Audio Upload** off the cloud.
  They're separate settings on separate tabs. If you're standing up a
  PHI-safe configuration, check all three tabs and confirm each one.
</Warning>

<Note>
  If you're evaluating a clinical-grade option under your own contract, **Corti**
  is available as a bring-your-own-key provider — clinical transcription with
  EU-hosted cleanup and reasoning. See [cloud vs local
  processing](/guides/cloud-vs-local).
</Note>

## FAQ

<AccordionGroup>
  <Accordion title="Is OpenWhispr HIPAA compliant?">
    HIPAA compliance is a property of how an organisation uses a tool, not a badge
    a product carries on its own. What we can tell you: we hold a HIPAA
    attestation, we act as a Business Associate, and we sign a BAA before any PHI
    is processed. With that BAA in place and an appropriate configuration, you can
    use OpenWhispr in a HIPAA-regulated workflow.
  </Accordion>

  <Accordion title="Do I need a BAA if we only use local mode?">
    If PHI never reaches our servers, we're not processing it and there's nothing
    for a BAA to cover. That said, most compliance teams still want the agreement
    on file in case someone switches a mode later. Ask us for one.
  </Accordion>

  <Accordion title="Does the free plan include a BAA?">
    The BAA isn't tied to a plan — ask and we'll go through it with you.
  </Accordion>

  <Accordion title="What about audio recordings on the device?">
    They're kept locally under your retention settings, 30 days by default, and
    you can turn audio retention off entirely. That's part of your own HIPAA
    footprint, so it's worth setting deliberately — see [what OpenWhispr stores,
    and for how long](/help/privacy/what-we-store-and-for-how-long).
  </Accordion>
</AccordionGroup>

<Snippet file="still-need-help.mdx" />

## Related

* [How OpenWhispr is secured](/help/privacy/how-openwhispr-is-secured)
* [Answering a security review](/help/privacy/for-your-it-team)
* [Where your voice and text go](/help/privacy/where-your-data-goes)
* [Data Processing Addendum](https://openwhispr.com/dpa)
