“HIPAA-compliant” describes the paperwork around a recording, not the absence of one.

By Kyle Nelson, Founder, Fazit

Every vendor selling a HIPAA compliant AI notetaker for therapists is telling you something narrower than it sounds: they will sign a business associate agreement and safeguard the session data they hold. The part that goes unsaid is that they hold it. For the most privileged conversation in professional life, the useful question is not whether the disclosure is papered. It is whether there has to be one at all. As with everything on this blog, the primary sources are linked, and none of this is legal advice.

What the label actually promises

“HIPAA-compliant” is not a certification. HHS certifies nobody. In practice the claim means the vendor will sign a business associate agreement and represents that it meets the Security Rule’s safeguards. Under 45 CFR 164.502(e), that agreement is what makes it lawful for your protected health information to flow to the vendor at all.

Read that again from the client’s side of the room: the BAA is the legal instrument that permits their session to leave your practice. It obliges the vendor to protect what it holds and to notify you of breaches. It does not make the vendor unbreachable, exempt from legal process, or uninteresting to an acquirer. It papers the disclosure. It does not prevent it.

WHAT "HIPAA-COMPLIANT AI NOTETAKER" ACTUALLY PROMISES

promised                        not promised

vendor will sign a BAA          the session stays with you
safeguards per Security Rule    the recording never exists
breach notification duties      the transcript can't be
                                subpoenaed from the vendor
lawful basis for the vendor     your client won't mind
to hold the session             being recorded

The label describes the paperwork around a disclosure.
It does not describe the absence of one.

The therapy scribes record. That is the product.

The current wave of AI scribes built for therapy, Mentalyc, Upheal and their peers, are cloud products: the session audio or transcript is processed on their servers, under a BAA, to produce a progress note. That is a legitimate design, and for some practices the note-quality tradeoff is worth it. But it means the most sensitive artifact that can exist about your client, a verbatim record of their therapy session, now exists on infrastructure you do not control, for however long the vendor’s retention policy says.

HIPAA itself tells you how sensitive this category is. 45 CFR 164.508(a)(2) gives psychotherapy notes stronger protection than any other record type: almost every use requires the client’s specific authorization. But the definition in 164.501 covers the therapist’s own analysis, kept separate from the medical record. A verbatim transcript in a vendor database is a poor fit for that definition. The likely result is upside down: the artifact with the most detail gets less protection than the notes you keep for yourself.

And the ethics codes reach the recording itself. The APA’s Ethical Principles, Standard 4.03, requires permission before recording voices or images of clients. State consent statutes run alongside: in all-party consent states a therapy session is about as clearly a confidential communication as the law can imagine (we mapped the state rules in Is It Legal to Record Client Calls?). Consent to therapy is not consent to a recording, and your client is entitled to hear the difference explained.

Coaches: HIPAA was never your framework

For most coaches the entire HIPAA conversation is misdirection. Coaching practices are generally not covered entities, so there is no BAA to sign and “HIPAA-compliant” is a marketing phrase, not a legal status that applies to you. Your confidentiality duties are real but come from elsewhere: your client agreements, and ethics codes like the ICF Code of Ethics, which requires maintaining confidentiality with all parties and having clear agreements about how coaching information is exchanged.

Those duties collide with a cloud recording exactly the way a therapist’s do, minus the statutory backstop. If the vendor holding your sessions is breached, your client’s divorce, exit negotiation or health disclosure is in the breach, and the promise that was broken was yours. The confidentiality clause analysis we walked through for consultants applies to coaching engagements nearly unchanged (see the NDA version of this argument).

The client in the room is the real compliance officer

There is a clinical cost that never shows up in a security review: people talk differently when they believe a recording exists. Therapy works on candor. A client weighing whether to say the true thing does not parse the difference between a breached vendor and a subpoenaed one; they just know a copy of the worst hour of their year exists somewhere they cannot see. “This conversation is being processed by a third party under a compliance agreement” is a sentence that changes sessions.

“I take notes on my own computer, nothing is recorded and nothing leaves this room” is a different sentence. It is also, with the right architecture, simply true.

Every safeguard HIPAA imposes on a business associate exists because the business associate has your client’s data. The strongest position available is the one where nobody does.

Where Fazit sits, stated plainly

Fazit is not a HIPAA-certified product, does not sign BAAs, and this page is not a compliance opinion. The claim is narrower and architectural. Fazit captures the call without a bot, transcribes it on your Mac, and writes the note with a local model, so neither audio nor transcript reaches us or any third party. The audio itself is never written to disk: it lives in a fixed-size RAM ring buffer and is destroyed on every exit path, which is why each note carries audio_retained: false in its frontmatter (the full argument is in Why “Never Records” Is Not Marketing).

For session content, the business associate question does not get answered. It does not arise, because no third party receives PHI to be an associate about. What survives the session is one Markdown note in your own files, governed by your existing records practice, deletable by you, producible by you, on your schedule. The same logic is why the GDPR analysis comes out simple for EU practitioners (see the GDPR version).

The caveats: models download once from public CDNs on first run; account, licensing and payment use our servers and are a separate lane from call content, described on the security page; Fazit is macOS only and early-stage, with no SOC 2 or HIPAA certification to point at. Your consent conversation with the client, and your ethics code, are unchanged by any of it. Note-taking has never required a consent form. Recording is what does.

Neighbouring reading: the privilege version of this question for lawyers, the recordkeeping version for financial advisors, and the criminal-statute version for tax preparers.

FAQ

Do therapists need a HIPAA-compliant AI notetaker?

If you are a covered entity and the tool receives protected health information, then yes, HIPAA requires a business associate agreement with the vendor and the vendor must meet the Security Rule. But notice what that structure assumes: the session leaves your hands and lands with a business associate. A tool that processes everything on your own machine and sends nothing to any vendor never creates a business associate relationship for the session content, because no third party ever receives PHI.

Is a BAA enough to protect therapy session recordings?

A BAA makes the disclosure lawful and obliges the vendor to safeguard the data and report breaches. It does not prevent the recording from existing, being breached, being retained under the vendor's schedule, or being subpoenaed. Legal process reaches stored records wherever they sit. The only recording that is fully outside that reach is the one that was never made.

Are session recordings psychotherapy notes under HIPAA?

Generally no. HIPAA gives special protection to psychotherapy notes, but the definition in 45 CFR 164.501 covers the therapist's own analysis kept separate from the medical record, and it expressly excludes items like medication records, session start and stop times, and results. A verbatim recording or transcript held in a vendor's database is a poor fit for that definition, which means the strongest protection HIPAA offers likely does not attach to the most sensitive artifact a notetaker creates.

Do coaches need HIPAA-compliant tools?

Usually HIPAA does not apply to coaching at all: coaches are typically not covered entities, so there is no BAA to sign and 'HIPAA-compliant' is marketing rather than a legal category. Your confidentiality duties come from your client agreements and ethics codes such as the ICF's. Those duties still collide with a cloud recording, because a breach or subpoena of the vendor is a breach of your promise, whatever the tool's label says.

Can a therapy session transcript be subpoenaed?

Stored records are reachable by legal process, and therapist-client privilege is not absolute: it has exceptions, it varies by state, and it can be waived. A transcript sitting in a vendor's cloud is a record someone else holds and you do not control. A note you wrote, held in your own files under your own retention policy, is the artifact clinicians have always managed under privilege. The difference between those two is architectural, not contractual.

Every regulation and ethics standard on this page was checked against its primary source on 3 August 2026 and linked above. If something here is wrong or has moved, tell us at hello@re-entry.ai and we will correct it. If you would rather the disclosure never happened at all, see how the capture pipeline works or early access pricing.