How to Revoke a HIPAA/BAA Agreement

Last updated: September 7, 2026

Available on: Mac, Windows. A BAA can be signed on iOS, but it can only be revoked from the desktop app.

Signed a HIPAA Business Associate Agreement (BAA) with Wispr Flow and no longer need it? Revoke it yourself from the desktop app in under a minute, and download a signed copy for your records first.


How to download your signed BAA

Available to individual (non-enterprise) users.

  1. Open the Wispr Flow desktop app on Mac or Windows.

  2. Go to Settings → Data and Privacy.

  3. Click Download signed BAA next to the HIPAA row. A PDF is saved to your device.


How to revoke your BAA

These steps apply to individual (personal) BAAs, including a personal BAA signed before joining an enterprise.

  1. Open the Wispr Flow desktop app on Mac or Windows.

  2. Go to Settings → Data and Privacy.

  3. Find the HIPAA Enabled setting and click Revoke BAA. You'll see "HIPAA BAA revoked."

Warning: Revoking takes effect immediately with no confirmation prompt and removes Privacy Mode enforcement. Sign a new BAA to resume HIPAA-compliant workflows.

What the BAA locks while active

Signing turns Cloud Sync and data sharing off automatically. "Improve the model for everyone" is forced off ("Your HIPAA agreement does not allow data to be used for model training."), and Cloud Sync is locked ("Cloud Sync is locked because HIPAA BAA is signed."). Revoking releases both locks.

How to sign again after revoking

The row reverts to Enable HIPAA → View and accept. The "HIPAA Business Associate Agreement" dialog has a "Click here to view" link that opens the full agreement in your browser and requires only your legal name. Enter your legal name and click I agree; the success message reads "HIPAA BAA signed." The dialog still says "This action cannot be undone", even though Revoke BAA remains available.

If you see "Error revoking HIPAA BAA"

The revoke did not go through. Click Revoke BAA again.


Enterprise accounts

  • Admins: Manage the org BAA from the Admin Portal, not the desktop app. If your org has signed, use "View signed BAA" to open the agreement externally; if not, use "Sign in to admin portal".

  • Non-admin members: Use the Open admin portal button; you cannot revoke the org BAA from the app.


FAQs

I signed my BAA on iOS. How do I revoke it?

BAA status is stored on your account, so revoke it from the Mac or Windows app.

Can I download my signed BAA right after signing?

Usually. The Download signed BAA button appears once a signer name is recorded on your account, which can take up to a minute.

What happens if the BAA download fails?

An error notification appears and no partial file is saved. Check your network connection and try again.

What happens to my data after I revoke?

The HIPAA locks are released (see "What the BAA locks while active"). Nothing is re-enabled automatically, so review your Data and Privacy settings afterward. Other settings can stay greyed out for org-policy reasons unrelated to HIPAA: local data storage may show "This setting is managed by your organization." or "Some options are restricted by your organization.", and transcript retention may show "Set by your admin."

Why is cloud storage still locked after I revoked?

If your organization signed an org-wide BAA, that lock remains after you revoke your personal BAA. Only an admin revoking the org-wide BAA lifts it.


Limitations and notes

  • Revoking is available on Mac and Windows only, and self-serve revoke applies to individual BAAs; enterprise org BAAs are managed by admins through the Admin Portal.

  • Downloading a signed copy is available to individual (non-enterprise) users on Mac and Windows; enterprise users should contact their admin or use the Admin Portal.

  • The HIPAA BAA interface is localized into 22 additional languages, so button labels appear in your app language (e.g. Danish "Tilbagekald BAA", Norwegian "Tilbakekall BAA").