HIPAA Compliance & Healthcare Use
Last updated: August 31, 2026
Available on: Mac, Windows, iOS, Android. BAA signing: Mac, Windows, iOS. Full enterprise HIPAA controls require a Business or Enterprise plan on desktop.
If you dictate clinical notes, patient records, or other PHI, Wispr Flow supports HIPAA-compliant workflows: Business Associate Agreements (BAAs), zero data retention, and enterprise data controls.
Note: "Improve the model for everyone" controls whether your dictation data trains or improves AI models; Dictation Cloud Storage controls whether transcription data is stored on Wispr's servers. Zero Data Retention (ZDR) means both are off.
When to use it
Use HIPAA compliance features to:
Dictate clinical notes, patient records, or other PHI by voice with zero data retention.
Formalize data handling obligations with a signed BAA.
Enforce organization-wide privacy and data policies for your healthcare team.
How it works
Key safeguards
Wispr Flow's safeguards meet HIPAA's administrative, physical, and technical requirements.
Encryption: PHI is encrypted in transit and at rest.
Access controls and audit logging: PHI access is limited to authorized personnel and logged along with system activity.
Incident response: Breach notification procedures are in place.
Security assessments: Security reviews and updates are performed regularly.
Network security: Enterprise IP-allowlist enforcement is not generally available, and is not enforced on Android.
Offline enforcement: Enterprise settings, including ZDR and data policies, stay enforced during connection problems.
BAA lock: A signed BAA is enforced on Wispr's servers; revoking in the desktop app alone does not undo it. Contact support to fully unwind a BAA.
Business Associate Agreements (BAAs)
Wispr Flow enters into BAAs with covered entities and other business associates. Each BAA covers permitted uses and disclosures of PHI, safeguarding requirements, breach notification obligations, subcontractor management, individual and covered entity rights, and termination and data return provisions.
Model improvement and Dictation Cloud Storage for PHI
For any account handling PHI, turn "Improve the model for everyone" off and Dictation Cloud Storage off:
No model training: No dictation data is used to train or improve models by Wispr or any third party.
Zero data retention: No transcription data is stored on Wispr's servers, so no PHI remains after transcription. Subprocessors are contractually bound to the same zero-retention requirements.
Server-side enforcement: Model improvement, Dictation Cloud Storage, BAA status, and enterprise policy are verified on every request that touches PHI; if a protection is off when it should be on, the request is blocked.
Note: A signed BAA locks both toggles off. Org ZDR alone locks only model improvement; Dictation Cloud Storage is locked separately by an admin setting or by a signed BAA. Auto-delete transcripts is locked on only when the org's local data policy is "delete after 24 hours" or "never store."
Note: On iOS, when the app cannot confirm your organization's enterprise settings — during cold launch on an organization device, right after signing out, or while a policy refresh is in flight or failing — "Improve the model for everyone" (off), Dictation Cloud Storage (off), and Auto-delete transcripts (on) are forced and locked. Flow retries in the background and unlocks once policy is confirmed. Users not part of an organization are never locked by a failed refresh.
Warning: Avoid submitting in-app feedback that may contain PHI. Typed feedback is treated as a deliberate, user-consented support submission and is not stripped even under ZDR or a BAA. Diagnostic logs and accessibility reports may be attached; the instruct-mode attachment is dropped when data sharing is disallowed, but general feedback logs are not filtered.
Notes (Scratchpad) with a BAA or data restrictions
Under a signed BAA, HIPAA/ZDR org policy, or another data-restricted configuration, server-side note storage is unavailable and notes do not sync across devices. Notes sync independently of the Dictation Cloud Storage toggle.
On iOS, the AI summary option on note cells is hidden and note content is not indexed in Spotlight, so notes cannot be found from system search. All Wispr Flow Siri Shortcuts remain available in the Shortcuts app: Create Note via Text ("Save Flow note" / "Quick Flow note") saves a note offline without opening the app, while "Create note with Flow" opens the app and starts dictation.
Note: On Mac and Windows, the Scratchpad still works locally under a BAA. These restrictions are determined on-device from BAA and org policy status; contact support to re-enable them for a specific user.
Enterprise data controls
Enforce zero data retention: Locks "Improve the model for everyone" and Dictation Cloud Storage off for all members. Admins can enable it after a BAA is signed; it cannot be turned off while the BAA is active. Wispr may also lock it on for your organization — contact support to modify. Requires a Business or Enterprise plan; on lower tiers the control is disabled with a plan-level tag.
Org-wide HIPAA: Requires disabling Notetaker (see Notetaker and HIPAA). Non-Enterprise admins see a grayed-out "View and accept BAA" button; signing requires an Enterprise plan.
Local Data Policy: Choose normal storage, automatic deletion after a set period, or never storing data locally. It covers locally stored AI polish and rewrite data, command-mode history, and transcription history, and is separate from Dictation Cloud Storage, which governs server-side storage. Enterprise policy acts as a floor: Flow always applies whichever of your local setting or the org policy is more restrictive, so you can pick a stricter option but never a looser one, and a locally relaxed setting cannot weaken enforcement. The dropdown is fully disabled with a "managed by organization" tooltip only when the org sets "Never store"; with a looser floor such as "Delete after 24 hours," you can choose a more restrictive option but not "Store normally." Requires a Business or Enterprise plan.
Hide Improve Model: Prevents data sharing for model improvement across all members regardless of individual toggle state. Managed by Wispr support.
SSO / SAML: SAML single sign-on is available on Business and Enterprise plans; SCIM-provisioned users authenticate through your identity provider. SSO enforcement requires an active Business or Enterprise subscription.
SCIM provisioning: Manage team membership through your identity provider. Provisioning respects your seat cap — if the cap is exceeded the user is not added and is not notified; if provisioning fails, a standard email invitation is sent instead. While directory sync is active, manual member management in the admin portal is disabled, though Wispr support can remove members on your behalf.
Note: Zero data retention enforcement and Local Data Policy can be changed only by Admin, SuperAdmin, or IT Admin roles. The IT Admin role is for IT staff who manage enterprise settings without dictating: it includes no product access and consumes no paid seat, and IT Admin seat holders see a blocked screen in the Hub confirming no product access.
Note: Org plans display as "Growth" (business billing tier) or "Enterprise" (legacy/sales-led). Both include the same enterprise feature set — HIPAA-ready BAA compliance, SSO/SCIM, audit logs, free IT admin seats, dedicated support, usage analytics, and org-wide model-training opt-out.
How to sign a BAA
Individual users sign in the app; enterprise administrators sign in the admin portal. Viewing the BAA document requires an internet connection.
Individual users (Mac and Windows)
Open Wispr Flow and go to Settings → Data & Privacy.
Click "View and accept" next to the HIPAA BAA option.
Review the BAA, enter your legal name, and click "I Agree." The button stays disabled until you enter your name.
On success, "View signed BAA" and "Revoke BAA" buttons appear.
Business and Enterprise administrators (Mac and Windows)
Open Wispr Flow and go to Settings → Data & Privacy.
Click the BAA button next to the HIPAA BAA option to open the admin portal.
Review and sign the BAA in the admin portal.
The button label depends on your role and signing state: "Open admin portal" for non-admin organization users, "Sign in portal" for admins who have not signed, "View signed BAA" and "Manage in Portal" for admins who have signed, and "View and accept" for non-organization individuals who have not signed.
iOS
Open Wispr Flow and go to Settings.
Tap the HIPAA BAA option in the Data & Privacy section.
Review the document, enter your legal name, and tap "I Agree."
The screen is titled "HIPAA" and embeds a PDF of the agreement, which is why an internet connection is required. "I Agree" is disabled until you enter a legal name and while the request is in flight. Dismiss the success alert to close the sheet; errors keep the sheet open so you can retry.
After signing, the HIPAA row subtitle changes to "View Business Associate Agreement" — tap the row to reopen the signed BAA.
Tip: Contact your account representative for help with BAA signing.
How to get a copy of your signed BAA
What you can retrieve depends on whether the BAA was signed by an organization or by you as an individual.
Business and Enterprise organizations
Open the admin portal organization settings. In Wispr Flow on Mac or Windows, go to Settings → Data & Privacy and click "Manage in Portal."
Open the HIPAA BAA management view.
View the signed agreement, then save or print it from there.
Only Admin, SuperAdmin, and IT Admin roles can reach this view. If you are a member rather than an admin, ask your organization's admin for the copy.
Individual accounts
You can reopen and read your agreement at any time:
Mac and Windows: Settings → Data & Privacy → "View signed BAA."
iOS: Settings → Data & Privacy → tap the HIPAA row, now labeled "View Business Associate Agreement."
Note: Individual (non-enterprise) accounts cannot yet download a copy of the BAA showing the countersignature and signature date. The in-app view lets you read the agreement, but it is not a dated, executed copy suitable for an audit file. We are working on adding a downloadable signed and dated copy.
Tip: If you need a signed and dated copy for a compliance review, security questionnaire, or vendor file before that is available, contact support with the email on your account and the legal entity name that should appear on the agreement.
How to revoke a BAA
Warning: Revoking ends your HIPAA-compliant workflow: "Improve the model for everyone" and Dictation Cloud Storage are no longer locked, and dictation data may be stored or used for model improvement depending on your settings. Revoking removes the lock but does not restore the values forced at signing — to resume model-training contribution or server-side transcript storage, turn both on in Settings → Data & Privacy.
Individual users (Mac and Windows)
Open Wispr Flow and go to Settings → Data & Privacy.
Click "Revoke BAA" next to the signed BAA.
Revocation is immediate, with no confirmation dialog; a success or error message confirms the result.
Business and Enterprise administrators (Mac and Windows)
Admins revoke in the admin portal; desktop settings has no inline "Revoke BAA" button for admins.
Open Wispr Flow and go to Settings → Data & Privacy.
Click "Manage in Portal" to open the admin portal organization settings.
Open the HIPAA BAA management view.
Select the revoke action and confirm.
Other desktop unlock paths: non-admin organization users get a "Request access" button that shows "Access requested" once tapped; users who turned Dictation Cloud Storage off themselves get a "Turn on Dictation Cloud Storage" button.
iOS
There is no in-app revoke on iOS. Once signed, the HIPAA screen becomes read-only and states "This action cannot be undone. Use of data to improve models and dictation cloud storage are turned off for your account." Contact support to unwind a BAA.
Notetaker and HIPAA
Notetaker is not compatible with HIPAA. Org-wide HIPAA requires that Notetaker be disabled for your organization.
Note: Individual users with a signed personal BAA are fully gated from Notetaker. Individuals without a signed BAA who are not part of an organization can use Notetaker regardless of their Dictation Cloud Storage setting. Organization members' access is governed by their organization's enterprise settings and BAA status.
How to set model improvement and Dictation Cloud Storage
Note: The "Improve the model for everyone" toggle also appears during initial app setup, locked off for organization users under zero data retention enforcement. Onboarding lock notices include "Private Cloud Sync is locked off while HIPAA protections are active.", "Data Sharing is turned off by your HIPAA or organization privacy settings.", and "Your organization has disabled the use of your data for model improvement."
Mac and Windows
Open Wispr Flow and go to Settings → Data & Privacy.
Turn off "Improve the model for everyone" to stop your audio, transcripts, and edits from being used to evaluate and improve AI models.
Turn off Dictation Cloud Storage to stop server-side storage of transcripts, audio, dictation history, and personalized speech models.
iOS
Open Wispr Flow and go to Settings → Data & Privacy.
Turn off "Improve the model for everyone" to stop your audio, transcripts, and edits from being used to evaluate and improve AI models.
Turn off Dictation Cloud Storage to stop server-side storage of transcripts, audio, dictation history, and personalized speech models. Turning it off prompts a confirmation ("Turn off dictation cloud storage?" → "Disable dictation cloud storage"); turning it on applies immediately.
Note: The separate iOS Dictation Cloud Storage toggle is part of a staged rollout and may not appear in your build; when it is absent, cloud-storage behavior is described in the "Improve the model for everyone" description instead.
Android
Open Wispr Flow and go to Settings.
Turn off "Improve the model for everyone" in the Data & Privacy section to stop audio, transcripts, and edits from being used to evaluate and improve AI models.
Use the Dictation Cloud Storage option in the same section to change server-side storage.
Note: If your admin has locked data sharing, the toggle appears locked off with a generic reason such as "Dictation cloud storage is turned off because your organization has enforced it" or "...because a HIPAA BAA is signed" — your organization name is not shown. Privacy settings sync with Wispr's servers each time you open Settings, keeping them consistent across devices. On Android, Dictation Cloud Storage stays user-controllable under zero data retention enforcement unless locked by a signed BAA or admin policy.
FAQs
Can I download a signed and dated copy of my BAA?
If your BAA was signed by a Business or Enterprise organization, yes. An admin can open it from the admin portal and save or print it. For individual (non-enterprise) accounts, not yet: you can reopen and read the agreement in the app, but a downloadable copy showing the countersignature and signature date is not available. We are working on adding it. If you need an executed copy in the meantime, contact support with your account email and the legal entity name that should appear on the agreement.
How does Wispr Flow handle subprocessors?
All subprocessors that may access PHI sign BAAs and maintain HIPAA-compliant security controls. For the current list, see the Subprocessors & Third-Party Security article.
What happens if there's a data breach?
Wispr Flow follows HIPAA-aligned breach notification procedures. Covered entities are notified without unreasonable delay and no later than 60 days after discovery, including the identities of affected individuals and details needed for covered entity notifications.
Does Wispr Flow support individual rights under HIPAA?
Yes. Wispr Flow supports covered entities in fulfilling individual rights, including access to PHI, amendment requests, an accounting of disclosures, and requests for restrictions.
How does Wispr Flow handle the minimum necessary standard?
Wispr Flow limits PHI use, disclosure, and access to the minimum necessary to accomplish the intended purpose, consistent with HIPAA requirements and BAA obligations.
What training do Wispr Flow employees receive?
All employees complete security and privacy training on hire, annual HIPAA refresher training, and role-specific training for personnel with PHI access.
Limitations and notes
BAA signing works on Mac, Windows, and iOS. Revocation works on Mac and Windows only — individual users in Data & Privacy settings, admins in the admin portal.
Individual (non-enterprise) accounts cannot yet download a signed and dated copy of their BAA. The agreement can be reopened and read in the app, and a downloadable executed copy is in progress. Business and Enterprise admins can already view, save, and print theirs from the admin portal.
The "Improve the model for everyone" toggle is available on Mac, Windows, iOS, and Android. Android has no BAA signing or in-app revocation, but its settings rows support locked states with two reasons — "locked, managed by your organization" and "locked, required by a signed compliance agreement" (e.g. HIPAA BAA) — shown with a lock icon and disabled switch.
Full HIPAA features (zero data retention enforcement, Local Data Policy, BAA management, SAML SSO) require a Business or Enterprise plan and are administered from the desktop app.
Notetaker is not compatible with HIPAA — see Notetaker and HIPAA for who is gated.
Organizations using SCIM directory sync manage users entirely through their identity provider.
On iOS, Wispr can re-enable note sync, the AI summary button, and Spotlight indexing together for individual users — contact support.
Still need help?
Contact your account representative for BAA or compliance questions — include your organization name and plan.
Request a signed and dated copy of an individual BAA from support — include your account email and legal entity name.
Request HIPAA compliance documentation under NDA.
Review the Data Processing Addendum for data handling details.