Nobody Issues a HIPAA Certificate

Start with the thing that makes this search term hard to answer honestly.

There is no such thing as HIPAA certification. The Office for Civil Rights, the division of Health and Human Services that enforces HIPAA, does not certify, endorse or approve any product as HIPAA compliant, and nothing in the rule provides for it. When a vendor writes "HIPAA compliant" on a pricing page, including us, that is a self-assessment. It is not a credential anyone else issued and there is no registry you can check it against.

That is not an accusation aimed at anybody. It is a structural fact about the label, and it has a consequence worth sitting with: compliance is a property of a deployment, not of a piece of software. The same app can be used compliantly by one practice and not by another, depending on who has access, what the contract says, and how the notes are handled once they exist.

So "which dictation app is HIPAA compliant" is close to unanswerable as asked, because almost all of them can be. The answerable question underneath it is what each vendor actually does with the recording of your patient, and there the answers diverge much more than the shared label suggests. One tool sends the audio of every encounter to a research environment where human annotators may review it. Another never lets the audio leave the phone. Both describe themselves with the same two words.

Six questions separate them. This post sets them out, answers them for the seven tools an independent practice actually shortlists, and then says which one wins on which question, including the several where the answer is not us.

What a Business Associate Agreement Actually Covers

The BAA is the one thing in this area that is genuinely required, so it is worth being exact about what it does.

Under the Privacy Rule at 45 CFR 164.504(e), a covered entity may hand protected health information to a vendor only with satisfactory assurance, set out in a written contract, that the vendor will safeguard it. That contract has to establish what the vendor is permitted to do with the data, require appropriate safeguards, bind subcontractors to the same terms, require the vendor to report any use or disclosure the contract does not permit, and deal with returning or destroying the data when the relationship ends.

That is real protection. It moves legal obligation onto the vendor and gives you a contractual claim if they mishandle your patients' data. You should not use any clinical tool that will not sign one, and every product in this post will sign one.

Here is what it does not do. A BAA does not tell you where the audio is processed, which cloud it lands in, how long the recording is kept, whether a human ever listens to it, or whether it is used to improve the vendor's models. All of those are permitted under a signed BAA when the contract permits them, and vendors differ enormously on all five while every one of them is entitled to the same label.

AWS states this about its own service more plainly than most vendors state it about theirs: a service being HIPAA eligible means AWS supports using it with PHI under a BAA, and does not by itself make your workload compliant. Every product on this page sits in exactly that position, ours included.

A BAA is a contract, not a description of the architecture. It tells you somebody is on the hook. It does not tell you what they are doing. Two vendors with identical BAAs can have completely different answers to "where is the recording right now," and that difference is the entire subject of this post.

The Six Questions

These are the questions that actually separate the field. None of them is answered by the phrase on the pricing page, and all of them are answerable from published documentation if the vendor publishes it.

  1. 1
    Will they sign a BAA, and can you get one without an enterprise contract
    Every vendor here will sign. The real variable is the friction. Two of the seven cannot be bought at all without a sales process, which means the BAA arrives with a negotiated agreement rather than at signup.
  2. 2
    Where is the audio processed
    On the device, or streamed to a cloud. If a cloud, which one, and does the vendor name it. A vendor that will not name its infrastructure is asking you to accept a description you cannot check.
  3. 3
    What happens to the recording once the note exists
    Deleted immediately, deleted on a timer, or retained. The timer lengths in this category range from never uploaded at all to ninety days, and the difference is not a detail.
  4. 4
    What happens to the note and the transcript
    The note is the clinical record and generally persists. The question is whether it persists in the vendor's system, for how long, and whether you can delete it on your own schedule.
  5. 5
    Do they train on your data, in any form
    The sharpest question of the six, because the common answer is neither yes nor no. It is "only on de-identified data," which is a different thing from no and is usually written to read like no.
  6. 6
    Can you get at the audit log
    The Security Rule requires audit controls. Almost no consumer scribe tells you whether the resulting record exists for your practice to inspect, which matters the day someone asks you to produce one.

Where the Audio Goes, and How Long It Stays

This is question two and three together, because the answers interlock. If audio never leaves the device, retention policy is close to moot. If it streams to a cloud, retention policy is the whole safeguard.

ToolWhere audio is processedHow long the recording is kept
HIPAA DictateOn the iPhone, via WhisperKitNever uploaded, so no vendor-side retention
FreedMicrosoft Azure, stored in the United StatesAutomatically deleted on successful note generation, which the vendor puts within 60 seconds of the encounter ending
TwofoldMicrosoft Azure and Google CloudStates no recording is ever written to disk, and that audio is deleted immediately after the transcript and note are generated
SukiGoogle CloudOriginal audio permanently deleted after 30 days, transcript after 30 days
SunohA private cloud on Microsoft AzureRecording and summary deleted after seven days
Dragon CopilotMicrosoft Azure, at rest in the customer's own geographySelect customer data, audio included, goes to a research environment and is anonymized within 90 days
Dragon Medical OneCloud, operated by Nuance and MicrosoftNot separately published

Taken from each vendor's own published documentation and checked on 5 September 2026. Where a vendor does not publish an answer, this table says so rather than inferring one.

Three things are worth pulling out of that table.

The range is ninety days to never. Those are not variations on a theme. Dragon Copilot's ninety-day window is disclosed clearly in Microsoft's own privacy white paper and is a considered design decision by the largest vendor in the category, not a lapse. It is also two orders of magnitude away from the policies of the smaller vendors on the same list, and roughly infinitely far from a tool that never transmits the audio at all.

Naming the cloud is a real differentiator. Freed, Twofold, Suki, Sunoh and Microsoft all name their infrastructure. That deserves credit, because a vendor who names a subprocessor has given you something you can verify and can be held to. When we compared HIPAA Dictate to Twofold we asserted that Twofold ran on Azure, could not substantiate it, and removed the claim. Twofold's security page now names both Azure and Google Cloud, which resolves the question in their favour.

Deleting the audio is a genuine mitigation and it is not the same as never sending it. Freed's sixty-second window and Twofold's never-written-to-disk claim are both meaningfully strong. What remains is that the audio existed somewhere other than your building for some period, handled by systems you are trusting a third party to describe accurately. For most primary care that distinction is academic. For workers' compensation, occupational medicine, or anything that might end up as an exhibit, it is a shorter chain of custody versus a longer one.

The Training Question, Which Is Where Vendors Diverge

Question five produces the widest gap in the whole comparison, and the gap is mostly hidden by careful wording.

Ask "do you train on my patients' data" and you get three distinct answers that sound like two.

ToolWhat the vendor's documentation saysCategory of answer
TwofoldDoes not use your data to train AI models, theirs or anyone else'sFlat no
SunohPatient data is not used to train SunohFlat no
HIPAA DictateTranscript goes to AWS Bedrock, where AWS states content is not used to improve base models and is not shared with model providers. We do not retain the note or transcript server-sideFlat no
FreedAI is only trained on de-identified notes, stripped of patient identifiers. PHI is not used for trainingDe-identified training
SukiData used for ML training is de-identified. Audio is broken into chunks so the original cannot be reconstructed, transcripts have PII removedDe-identified training
Dragon CopilotModels are trained solely on anonymized data. Customer data, including audio, is anonymized within 90 days in a research environmentDe-identified training
Dragon Medical OneNot separately publishedNot disclosed

The de-identified answers are not dishonest. HIPAA de-identification is a defined standard with real requirements, Microsoft documents its anonymization process at some length, and Suki's audio chunking is a serious technical measure rather than a gesture. All three vendors are telling you what they do, in public, which is more than several tools in this category manage.

The point is that de-identified training is still training, and it means your patients' encounters became raw material for a product improvement programme. Whether that bothers you is a judgement call and it is yours to make. What is not reasonable is making it by accident because a page said "HIPAA compliant" and you assumed that answered the question. It does not. Training on de-identified data is entirely permissible under HIPAA and under a standard BAA.

One further detail from Microsoft's privacy white paper deserves surfacing, because it is the kind of thing that is disclosed properly and read by almost nobody. Dragon Copilot's documentation states that in strictly limited scenarios customer data may be subject to human review by selected Microsoft employees and subprocessors, including human annotators assisting with the creation of anonymized data sets. That is a defensible practice, it is controlled, and it is written down. It also means the honest answer to "could a person other than my staff ever hear this encounter" is yes for that product, and the practice buying it should know that before the first visit rather than after.

What this looks like in a product

The architecture argument is easier to judge against a finished note than against a table. Ours is the only tool here that never transmits the audio, which constrains what the rest of the product can do and is the whole reason the trade exists.

See how on-device dictation works →

Audit Logging, the Requirement Nobody Advertises

The Security Rule's technical safeguards at 45 CFR 164.312 require audit controls: mechanisms that record and examine activity in systems holding electronic PHI. Unlike most of the rule, that standard carries no implementation specification softening it. You need the mechanism.

Almost no dictation vendor markets this, which makes it the easiest question to forget to ask and an awkward one the day a payer, an attorney or your own compliance review wants to know who accessed what. Twofold states that all system access is logged and auditable. Suki, Freed, Sunoh and Microsoft all operate audit infrastructure as a matter of course, but none of them makes a clear published statement about what a small practice can retrieve on its own. HIPAA Dictate writes every AI interaction and every data export to a seven year audit trail in AWS CloudWatch, and that record holds metadata rather than content: which visit type, how long the transcript was, how long processing took, whether it succeeded. It records that the event happened without recording what was said.

If audit access matters to your practice, ask for it specifically and in writing, from any vendor here. It is a fair question and none of them should struggle with it.

Encryption Is Weaker Evidence Than It Sounds

Every vendor in this post advertises encryption in transit and at rest, and every one of them means it. It is also the least discriminating fact on the list, for a reason most buyers do not know.

Under the current Security Rule, encryption is an addressable implementation specification rather than a required one, both for data at rest under 164.312(a)(2)(iv) and in transit under 164.312(e)(2)(ii). Addressable does not mean optional in practice, but it does mean the rule asks you to assess and document rather than simply mandating the control. A vendor advertising encryption is advertising the industry default.

The proposed Security Rule update published in late 2024 would change this, moving encryption from addressable to required in both states along with mandatory multi-factor authentication and other controls. As of this writing it remains a proposal with no final rule issued, and the target for final action has slipped into 2027. It is worth tracking and it is not yet law, which is exactly how it should be described until it is.

The Field, and Where Each One Wins

Prices first, because access to the product and access to the BAA are the same question for two of these.

ToolPublished priceHow you buy it
HIPAA Dictate$49 a month, everything includedApp Store, 7 day trial, no sales call
Freed$39 Starter capped at 40 notes, $79 Core unlimited, $119 Premier or $104 on annual billingSelf-serve, 7 day trial, no card
Twofold$69 a month billed monthly, $49 a month on annual billingSelf-serve, 7 day trial, no card
Sunoh$149 per user a month, published as a limited-time rate reduced from $199Demo and sales process
SukiNot publishedDemo and sales process, enterprise contract
Dragon CopilotNot publishedReseller or Microsoft agreement
Dragon Medical OneNot published as a self-serve list priceReseller

Suki does not publish pricing. Third-party listings put it in the region of $299 to $399 per provider per month, which we could not confirm against Suki's own documentation and are therefore not stating as fact. Dragon pricing moves through resellers and is broken down separately in our Dragon cost analysis.

Freed is the strongest all-round product on this list for a practice that wants ambient capture and a mature platform. It is the only vendor here whose own security page states a completed SOC 2 Type 2, which we do not have and cannot claim. Its audio deletion is the fastest published in the category. Its weakness is the tiering: ICD-10 and CPT coding and the EHR push both sit at Premier, so the tier that compares to a tool with coding included is $119 a month or $104 annually, not the $39 headline. Choose Freed if you chart in a browser-based EHR and want the Chrome extension, or if your compliance team requires a SOC 2 report. We went through the tiering in detail in HIPAA Dictate versus Freed.

Twofold comes out of this analysis better than any other cloud product, and we should say so given it is our closest competitor. It names both of its cloud providers, states that no recording is ever written to disk, and gives as flat a no on training as anyone here. It is undergoing SOC 2 Type II certification, which is honest phrasing for in progress. It also remains the broader product on every breadth axis, as we said the last time: more platforms, more than fifty languages, more note formats, more specialties, ambient capture, and handwritten OCR that we do not have. At $49 on annual billing it is the same price as us. If breadth matters to you, that comparison is not close, and it does not become close because this post is on our site.

Sunoh is the value option for practices already on eClinicalWorks, where the integration is the point. Seven day deletion of recording and summary is clearly published, the flat no on training is clear, and $149 a month is plainly stated even if the limited-time framing means it may not hold. There is no self-serve path, and Sunoh's own documentation does not state a SOC 2 or HITRUST attestation, so ask for the security packet during procurement.

Suki is built for organisations with EHR write-back requirements and the contracting capacity to negotiate. Its published security detail is genuinely good: named cloud, specific encryption standards, specific thirty day retention for both audio and transcript, and an unusually candid description of how audio de-identification works. Third-party listings describe Suki as SOC 2 Type II certified and its own security documentation does not say so, which is the kind of gap worth closing with the vendor rather than with a search engine. It is not a product an independent practice buys on a Tuesday afternoon, and there is no published price.

Dragon Copilot is the enterprise answer and Microsoft documents its data handling more thoroughly than anyone else here, which is a credit to them even though the substance of what is documented is the most expansive use of customer data on this page. Ninety day anonymization windows, a research environment and human annotators are the trade for an ambient product backed by the largest vendor in healthcare AI. For a health system with a Microsoft agreement, it is a rational choice. For a solo practice, it is not purchasable on any sensible terms.

Dragon Medical One remains the best direct-to-cursor dictation into arbitrary Windows applications, and that is a real capability nothing else here replicates. It is also a mature product in a long transition toward Dragon Copilot, with the PowerMic hardware line discontinued. We covered what happened to Dragon separately.

HIPAA Dictate is ours, so read the next section instead of this paragraph.

Where HIPAA Dictate Is Not the Answer

A roundup written by a vendor in the roundup is worth nothing unless it is specific about where the vendor loses. These are the real ones.

We have no SOC 2 Type II. Freed does. Twofold is undergoing it. If your compliance officer or your hospital affiliation requires an independent attestation, we cannot produce one and no argument about architecture substitutes for it.

We do not do ambient capture, by design. HIPAA Dictate is active dictation: you speak the note after the encounter rather than having the visit listened to. That follows directly from the first decision. Ambient capture means recording the patient's voice and streaming it somewhere, which is the exact thing on-device transcription exists to avoid, and the two cannot both be true in one product. The JAMA findings on ambient scribes are worth reading before treating ambient as automatically the better mode. If it is the mode you want, every other product here offers it.

iPhone only, English only. No Android, no desktop, no web, no iPad. Twofold runs on four platforms and speaks more than fifty languages. If you need either of those, the comparison ends there.

No EHR write-back. Copy and paste into any EHR, which works everywhere and is worse than Freed's Chrome extension for browser-based systems and worse than Suki's integrations for enterprise ones.

What we do have is one answer nobody else on this list can give: the audio never leaves the phone. WhisperKit runs the speech model on the iPhone's neural engine, so questions three and four collapse for the recording, because there is no vendor-side recording to retain, delete or anonymize. Only the resulting text goes to AWS Bedrock under a signed BAA, we do not store the note or the transcript, and the audit log holds metadata rather than content.

That is one criterion out of six, and it is the one that cannot be added later by a policy change or a contract term, because it is a property of where the software runs. It matters most for occupational medicine, workers' compensation and medico-legal documentation, which is the practice type we built for and the reason the product is shaped this way. For a therapy practice that wants DAP and BIRP formats, a multilingual clinic, or a clinician who wants ambient capture, one of the other products here fits better.

How to Actually Choose

Ignore the label. Ask the six questions in writing, of every vendor on your shortlist, and keep the answers.

  1. Ask 1
    Send me your BAA before I sign up
    If the BAA only appears after a negotiated contract, that is a fact about the vendor's business model and it may be fine. It should not be a surprise discovered in week three.
  2. Ask 2
    Name your cloud provider and any subprocessors handling audio
    Every vendor in this post except one names theirs. A vendor that will not is asking for trust it has not evidenced.
  3. Ask 3
    How long is the recording retained, measured from what
    The answers in this category run from never uploaded to ninety days. Get the number and get what the clock starts from.
  4. Ask 4
    Can I delete a note on demand, and does deletion propagate to backups
    Retention of the note is usually configurable. Deletion semantics rarely are, and rarely get asked about.
  5. Ask 5
    Do you train any model on my data, including de-identified or anonymized data
    Ask it with those words. "We do not train on PHI" and "we do not train on your data" are different sentences and both get used.
  6. Ask 6
    What audit record exists, and can my practice retrieve it
    You need to answer this the day somebody asks who accessed a record, and that is a bad day to find out.

Then run the same visit through two of them. Every self-serve product here has a free trial that takes minutes to start. Compare what comes out against your own documentation requirements, and compare the six answers against what your practice actually needs to defend. That settles it faster than any comparison page, this one included.

Common questions

Is there such a thing as a HIPAA certified dictation app?

No. Health and Human Services and its Office for Civil Rights do not certify or endorse any product as HIPAA compliant, and no provision of the rule creates a certification. Any badge or claim to that effect is either a vendor's own assessment or a third-party program that HHS neither recognises nor endorses. What is real is a signed Business Associate Agreement, a documented architecture, and independent attestations like SOC 2 Type II, which is an audit of controls rather than a HIPAA certificate.

Does a signed BAA mean my patient data is safe with the vendor?

It means the vendor is contractually bound to safeguard it, to limit what it does with it, to bind its subcontractors to the same terms, to report improper use or disclosure, and to deal with the data at termination. It does not constrain where the audio is processed, how long it is retained, whether humans review it, or whether it trains models. Those are separate questions the BAA is not designed to answer, and vendors with identical BAAs answer them very differently.

Is on-device transcription meaningfully safer than cloud transcription?

It is a shorter chain of custody, which is a real difference and a narrow one. If audio never leaves the phone, there is no vendor-side recording to retain, to breach, or to anonymize into a training set. Cloud vendors with fast deletion policies mitigate most of that risk, and Freed's deletion on note generation and Twofold's no-disk-write claim are both strong. The residual difference matters most where documentation may become legal evidence, and matters least in routine primary care.

What does it mean when a vendor says they only train on de-identified data?

It means your patients' encounters are used to improve the product after identifiers are removed. It is permitted under HIPAA and under a standard BAA, the de-identification standards are real, and the vendors doing it document it publicly. It is also categorically different from not training on your data at all, and the wording is frequently constructed so the two read alike. If it matters to you, ask specifically whether de-identified or anonymized data is used, because "we do not train on PHI" is true of both answers.

Which of these is cheapest for a solo provider who wants coding included?

HIPAA Dictate and Twofold are level at $49 a month with ICD-10 and CPT coding included, Twofold on annual billing. Freed's equivalent is Premier at $119 monthly or $104 annually, because coding sits behind that tier. Sunoh is $149 at its current published rate. Suki and both Dragon products do not publish pricing and are not sold self-serve.

Do I still need a BAA if the audio never leaves my phone?

Yes, from anyone who processes any part of the encounter. In our case the transcript text goes to AWS Bedrock for structuring, which is covered by a signed Business Associate Agreement with AWS. On-device transcription shrinks what is transmitted, it does not eliminate a business associate relationship, and any vendor telling you otherwise is describing a product that does nothing in the cloud at all.

How often do these answers change?

Often enough that a comparison a year old should not be trusted. Freed restructured its tiers during 2026, Sunoh's current price is published as limited-time, Microsoft consolidated the Dragon line and changed its pricing model in May 2026, and Twofold's SOC 2 status is in progress rather than settled. Every figure here was checked against vendor documentation on the date stamped below, and we have corrected this site twice already when a competitor claim turned out to be wrong.

Sources

Vendor documentation consulted on 5 September 2026: Freed pricing, Freed security and its HIPAA compliance FAQ; Twofold pricing and security; Suki security and compliance; Sunoh pricing and its security statement; Microsoft's Dragon Copilot privacy white paper; and the Amazon Bedrock FAQ for the infrastructure behind HIPAA Dictate. Regulatory text is at 45 CFR 164.504 for business associate contracts and 45 CFR 164.312 for technical safeguards.

Try HIPAA Dictate free for 7 days

On-device transcription, the real-time checklist, and coding included from day one. Seven day trial, no hardware, no contract.

Download on the App Store →
On a desktop?

Running a practice, not just documenting in one? The assessment looks at everything your staff does by hand, not only the notes.

Book a practice assessment →