HIPAA Compliance & Healthcare Use
Available on: Mac, Windows, iOS, Android. BAA signing: Mac, Windows, iOS. Downloading a signed copy: Mac, Windows. Enterprise HIPAA administration (BAA management, zero data retention enforcement, Local Data Policy) requires a Business or Enterprise plan and happens in the admin portal, reachable from desktop Settings → Data & Privacy.
If you dictate clinical notes, patient records, or other PHI, Wispr Flow supports HIPAA-compliant workflows: Business Associate Agreements (BAAs), zero data retention, and enterprise data controls.
Note: "Improve the model for everyone" controls whether your dictation data trains or improves AI models; Dictation Cloud Storage controls whether transcription data is stored on Wispr's servers. Zero Data Retention (ZDR) means both are off.
When to use it
Use HIPAA compliance features to:
Dictate clinical notes, patient records, or other PHI by voice with zero data retention.
Formalize data handling obligations with a signed BAA.
Enforce organization-wide privacy and data policies for your healthcare team.
How it works
Key safeguards
Wispr Flow's safeguards meet HIPAA's administrative, physical, and technical requirements.
Encryption: PHI is encrypted in transit and at rest.
Access controls and audit logging: PHI access is limited to authorized personnel and logged along with system activity.
Incident response: Breach notification procedures are in place.
Security assessments: Security reviews and updates are performed regularly.
Offline enforcement: Enterprise settings, including ZDR and data policies, stay enforced during connection problems.
BAA lock: A signed BAA is enforced on Wispr's servers; revoking in the desktop app alone does not undo it. Contact support to fully unwind a BAA.
Business Associate Agreements (BAAs)
Wispr Flow enters into BAAs with covered entities and other business associates. Each BAA covers permitted uses and disclosures of PHI, safeguarding requirements, breach notification obligations, subcontractor management, individual and covered entity rights, and termination and data return provisions.
Model improvement and Dictation Cloud Storage for PHI
For any account handling PHI, turn "Improve the model for everyone" off and Dictation Cloud Storage off:
No model training: No dictation data is used to train or improve models by Wispr or any third party.
Zero data retention: No transcription data is stored on Wispr's servers, so no PHI remains after transcription. Subprocessors are contractually bound to the same zero-retention requirements.
Note: A signed BAA locks both toggles off. Org ZDR alone locks only model improvement; Dictation Cloud Storage is locked separately by an admin setting or a signed BAA. Auto-delete transcripts is locked on only when the org's local data policy is "delete after 24 hours" or "never store."
Note: On iOS, when the app cannot confirm your organization's enterprise settings — during cold launch on an organization device or right after signing out — "Improve the model for everyone" (off), Dictation Cloud Storage (off), and Auto-delete transcripts (on) are forced and locked. Users not part of an organization are never locked this way.
Warning: Avoid submitting in-app feedback that may contain PHI. Typed feedback is treated as a deliberate, user-consented support submission and is not stripped even under ZDR or a BAA. Diagnostic logs and accessibility reports may be attached; general feedback logs are not filtered.
Notes (Scratchpad) with a BAA or data restrictions
Under a signed BAA, HIPAA/ZDR org policy, or another data-restricted configuration, server-side note storage is unavailable and notes do not sync across devices.
On iOS, the AI summary option on note cells is hidden and note content is not indexed in Spotlight, so notes cannot be found from system search. All Wispr Flow Siri Shortcuts remain available in the Shortcuts app: Create Note via Text ("Save Flow note" / "Quick Flow note") saves a note offline without opening the app, while "Create note with Flow" opens the app and starts dictation.
On Mac and Windows, organization admins can disable Scratchpad entirely for all members. When your organization disables it:
Scratchpad is removed from the Hub sidebar and navigation, the Flow Bar entry point is hidden, and Scratchpad settings and keyboard shortcut options are unavailable.
Open Scratchpad windows close, and local note reads and cloud sync stop.
If Polish would normally open Scratchpad, you get a "text not editable" notification instead.
If your organization re-enables Scratchpad, your saved notes come back and the keyboard shortcut is restored, unless you rebound that key in the meantime.
Note: If your organization has not disabled Scratchpad, it still works locally on Mac and Windows under a BAA. Contact support for help with a specific user's access.
Enterprise data controls
Enforce zero data retention: Locks "Improve the model for everyone" and Dictation Cloud Storage off for all members. Admins can enable it after a BAA is signed; it cannot be turned off while the BAA is active. Wispr may also lock it on for your organization — contact support to modify. Requires a Business or Enterprise plan; on lower tiers the control is disabled with a plan-level tag.
Org-wide HIPAA: Signing requires an Enterprise plan; non-Enterprise admins see a grayed-out "View and accept BAA" button.
Local Data Policy: Choose normal storage, automatic deletion after a set period, or never storing data locally. It covers locally stored AI polish and rewrite data, command-mode history, and transcription history, and is separate from Dictation Cloud Storage, which governs server-side storage. Flow applies whichever of your local setting or the org policy is more restrictive, so you can pick a stricter option but never a looser one. The dropdown is disabled with a "managed by your organization" tooltip whenever your organization enforces a local data policy. "Never store" and "Auto-delete after 24h" require confirming a dialog ("Delete all" / "Enable auto-delete"); "Store normally" applies immediately. Requires a Business or Enterprise plan.
Disable Scratchpad: Turns off Scratchpad for all organization members on Mac and Windows — see Notes (Scratchpad) with a BAA or data restrictions above.
Hide Improve Model: Prevents data sharing for model improvement across all members regardless of individual toggle state. Managed by Wispr support.
Context Awareness: Organizations can disable context awareness for all members; the toggle then shows a "managed by your organization" tooltip and cannot be changed.
SSO / SAML: SAML single sign-on requires an active Business or Enterprise subscription; SCIM-provisioned users authenticate through your identity provider.
SCIM provisioning: Manage team membership through your identity provider. Provisioning respects your seat cap — if the cap is exceeded the user is not added and is not notified; if provisioning fails, a standard email invitation is sent instead. While directory sync is active, manual member management in the admin portal is disabled, though Wispr support can remove members on your behalf.
Note: Only Admin, SuperAdmin, and IT Admin roles can change zero data retention enforcement and Local Data Policy. The IT Admin role is for IT staff who manage enterprise settings without dictating: it includes no product access and consumes no paid seat.
Note: Org plans display as "Growth" (business billing tier) or "Enterprise" (legacy/sales-led). Both include the same enterprise feature set — HIPAA-ready BAA compliance, SSO/SCIM, audit logs, free IT admin seats, dedicated support, usage analytics, and org-wide model-training opt-out.
How to sign a BAA
Individual users sign in the app; enterprise administrators sign in the admin portal. Viewing the BAA document requires an internet connection.
Individual users (Mac and Windows)
Open Wispr Flow and go to Settings → Data & Privacy.
Click "View and accept" next to the HIPAA BAA option.
Review the BAA, enter your legal name, and click "I Agree." The button stays disabled until you enter your name.
On success, "Download signed BAA" and "Revoke BAA" buttons appear.
Business and Enterprise administrators (Mac and Windows)
Open Wispr Flow and go to Settings → Data & Privacy.
Click the BAA button next to the HIPAA BAA option to open the admin portal.
Review and sign the BAA in the admin portal.
The button label depends on your role and signing state: "Open admin portal" for non-admin organization users, "Sign in portal" for admins who have not signed, "View signed BAA" and "Manage in Portal" for admins who have signed, and "View and accept" for non-organization individuals who have not signed.
iOS
Open Wispr Flow and go to Settings.
Tap the HIPAA BAA option in the Data & Privacy section.
Review the document, enter your legal name, and tap "I Agree." The button is disabled until you enter a legal name and while the request is in flight.
Dismiss the success alert to close the sheet; errors keep the sheet open so you can retry. After signing, the HIPAA row subtitle changes to "View Business Associate Agreement" — tap the row to reopen the signed BAA.
Tip: Contact your account representative for help with BAA signing.
How to get a copy of your signed BAA
Business and Enterprise organizations
Open the admin portal organization settings, or in Wispr Flow on Mac or Windows go to Settings → Data & Privacy and click "Manage in Portal."
Open the HIPAA BAA management view.
View the signed agreement, then save or print it from there.
Only Admin, SuperAdmin, and IT Admin roles can reach this view. Members should ask their organization's admin for the copy.
Individual accounts
Open Wispr Flow on Mac or Windows and go to Settings → Data & Privacy.
Click "Download signed BAA" next to the HIPAA setting. The file saves as HIPAA-BAA-signed.pdf.
The button appears only when a signer name was recorded at signing; without one, no PDF can be generated — contact support.
The PDF is available immediately after signing and appends a Signature Record page showing the name it was signed under, the account email, and the date and time of signing.
On iOS, open Settings → Data & Privacy and tap the HIPAA row, labeled "View Business Associate Agreement," to reopen and read the agreement. iOS has no download option — sign in to the Mac or Windows app with the same account to download the PDF.
Important: The Signature Record page is for reference only and is not a legal certificate. It records your electronic signature, not a countersignature by Wispr, and the PDF may not match the agreement text at the time you signed. If a compliance review, security questionnaire, or vendor file requires a countersigned executed copy, contact support with your account email and the legal entity name that should appear on the agreement.
Note: Generating the PDF requires an internet connection. If the download fails, an error appears and no partial file is saved. Retry once your connection is restored, or try a different network.
How to revoke a BAA
Warning: Revoking ends your HIPAA-compliant workflow: "Improve the model for everyone" and Dictation Cloud Storage are no longer locked, and dictation data may be stored or used for model improvement depending on your settings. Revoking removes the lock but does not restore the values forced at signing — to resume model-training contribution or server-side transcript storage, turn both on in Settings → Data & Privacy.
Tip: Download the agreement for your records before you revoke.
Individual users (Mac and Windows)
Open Wispr Flow and go to Settings → Data & Privacy.
Click "Revoke BAA" next to the signed BAA.
Revocation is immediate, with no confirmation dialog; a success or error message confirms the result.
Business and Enterprise administrators (Mac and Windows)
Admins revoke in the admin portal; desktop settings has no inline "Revoke BAA" button for admins.
Open Wispr Flow and go to Settings → Data & Privacy.
Click "Manage in Portal" to open the admin portal organization settings.
Open the HIPAA BAA management view.
Select the revoke action and confirm.
Other desktop unlock paths: non-admin organization users get a "Request access" button that shows "Access requested" once tapped; users who turned Dictation Cloud Storage off themselves get a "Turn on Dictation Cloud Storage" button.
iOS
There is no in-app revoke on iOS. Once signed, the HIPAA screen becomes read-only and states "This action cannot be undone. Use of data to improve models and dictation cloud storage are turned off for your account." Contact support to unwind a BAA.
How to set model improvement and Dictation Cloud Storage
Note: The "Improve the model for everyone" toggle also appears during initial app setup, locked off for organization users under zero data retention enforcement. Onboarding lock notices include "Private Cloud Sync is locked off while HIPAA protections are active.", "Data Sharing is turned off by your HIPAA or organization privacy settings.", and "Your organization has disabled the use of your data for model improvement."
Mac and Windows
Open Wispr Flow and go to Settings → Data & Privacy.
Turn off "Improve the model for everyone" to stop your audio, transcripts, and edits from being used to evaluate and improve AI models. The toggle's description explains the server-side storage behavior it also controls.
iOS
Open Wispr Flow and go to Settings → Data & Privacy.
Turn off "Improve the model for everyone" to stop your audio, transcripts, and edits from being used to evaluate and improve AI models. Cloud-storage behavior is described in that toggle's description.
Android
Open Wispr Flow and go to Settings.
Turn off "Improve the model for everyone" in the Data & Privacy section to stop audio, transcripts, and edits from being used to evaluate and improve AI models.
Use the Dictation Cloud Storage option in the same section to change server-side storage.
Note: If your admin has locked data sharing, the toggle appears locked off with a generic reason such as "Dictation cloud storage is turned off because your organization has enforced it" or "...because a HIPAA BAA is signed" — your organization name is not shown. Org zero data retention forces model improvement and data sharing off regardless of the local toggle state.
FAQs
How does Wispr Flow handle subprocessors?
All subprocessors that may access PHI sign BAAs and maintain HIPAA-compliant security controls. For the current list, see the Subprocessors & Third-Party Security article.
What happens if there's a data breach?
Wispr Flow follows HIPAA-aligned breach notification procedures. Covered entities are notified without unreasonable delay and no later than 60 days after discovery, including the identities of affected individuals and details needed for covered entity notifications.
Does Wispr Flow support individual rights under HIPAA?
Yes. Wispr Flow supports covered entities in fulfilling individual rights, including access to PHI, amendment requests, an accounting of disclosures, and requests for restrictions.
How does Wispr Flow handle the minimum necessary standard?
Wispr Flow limits PHI use, disclosure, and access to the minimum necessary to accomplish the intended purpose, consistent with HIPAA requirements and BAA obligations.
What training do Wispr Flow employees receive?
All employees complete security and privacy training on hire, annual HIPAA refresher training, and role-specific training for personnel with PHI access.
Limitations and notes
BAA signing works on Mac, Windows, and iOS. Revocation works on Mac and Windows only — individual users in Data & Privacy settings, admins in the admin portal.
Downloading a signed individual BAA works on Mac and Windows only; on iOS the agreement can be reopened and read but not downloaded. Business and Enterprise admins download theirs from the admin portal.
The "Improve the model for everyone" toggle is available on Mac, Windows, iOS, and Android. Android has no BAA signing or in-app revocation, but its settings rows support locked states with two reasons — "locked, managed by your organization" and "locked, required by a signed compliance agreement" (e.g. HIPAA BAA).
Full HIPAA features (zero data retention enforcement, Local Data Policy, BAA management, SAML SSO) require a Business or Enterprise plan and are administered from the desktop app or the admin portal.
Organizations using SCIM directory sync manage users entirely through their identity provider.
On iOS, Wispr can re-enable note sync, the AI summary button, and Spotlight indexing together for individual users — contact support.
Still need help?
Contact your account representative for BAA or compliance questions — include your organization name and plan.
Request a countersigned copy of an individual BAA from support — include your account email and legal entity name.
Request HIPAA compliance documentation under NDA.
Review the Data Processing Addendum for data handling details.
Need a hand?
Reach the Flow team and we’ll help you get unblocked.