Radiological.ai
All posts
Guides

HIPAA Compliant Transcription Software for Radiology Groups

Transcription and dictation are sold as one purchase and carry different HIPAA exposure. A human typist introduces a subcontractor chain, and that chain is where medical transcription actually goes wrong. What a BAA has to cover, why offshore routing is a visibility problem rather than a legality problem, and why encryption is still Addressable rather than Required in the rule as it stands.

By the Radiological.ai team

September 2026 · 7 min read

The Reading Station

Worklist

SERIES 1 · AX
SLICE 24/64
SAMPLE STUDY
NOT FOR DIAGNOSTIC USE
W 80 · L 40
ILLUSTRATIVE SAMPLE

Structured report

Draft

Run the assistant to draft this report for review.

You review & sign

Illustrative sample · not a real patient study, not a diagnosis

Drafted in · you review & sign Worklist re-prioritized

Decision support for qualified clinicians. Radiological.ai does not provide a diagnosis and is not a substitute for professional judgment.

The short answer: HIPAA compliant transcription software is transcription that runs under a signed business associate agreement, applies the Security Rule safeguards at 45 CFR 164.308, 164.312 and 164.314, and flows those same obligations down to every subcontractor who can hear the recording. No product is federally certified as HIPAA compliant, because no such certification exists. The question that separates transcription from ordinary dictation is who or what is listening: a human typist introduces a subcontractor chain, and that chain, not the encryption slide in the vendor deck, is where medical transcription actually goes wrong.

Last updated September 2026.

Radiology groups keep buying transcription and dictation as if they were one product. They are not, and the HIPAA exposure is different enough that the security review should be different too. This is about the back end: recordings that leave your building and come back as text somebody typed. If you are choosing the front end instead, the tool a radiologist speaks into, that decision is on our page for HIPAA compliant dictation software, which maps every technical safeguard onto the questions a reviewer will ask.

What is HIPAA compliant transcription software?

It is software for turning recorded clinical speech into text where the vendor has agreed in writing to protect the protected health information it handles. The agreement is the part with teeth. Under 45 CFR 164.314 a covered entity may not hand PHI to a business associate without a contract that binds them to safeguard it, and on our reading of that section in the current regulation both of its implementation specifications are Required rather than Addressable. Everything else in a vendor's compliance page is context around that contract.

What the phrase does not mean is that a government body inspected the product. There is no HIPAA certification scheme. When a transcription vendor advertises itself as HIPAA certified, it is describing an audit it commissioned and paid for. That can be genuinely useful evidence, and a SOC 2 Type II report with a healthcare scope is worth more than a logo, but it is not federal approval and it does not transfer your obligations to them.

What is the difference between medical transcription and speech recognition?

Transcription historically means a person listens to a recording and types the report, usually billed per line or per minute of audio. Speech recognition means software converts speech to text in real time, and the clinician does the correcting. The distinction matters commercially, because per-line pricing scales with how much you dictate while a subscription does not, and it matters for HIPAA, because only one of them puts a human being in the loop who can hear a patient's name.

Most US radiology groups moved to front-end speech recognition years ago and kept a small transcription service for the hard cases: heavily accented dictation, complex interventional reports, a locum who never trained a voice profile. That residual service is easy to forget in a security review precisely because it is small. It is also the piece most likely to be subcontracted.

What you are buyingWho hears the audioThe HIPAA question that matters mostHow it is usually priced
Back-end transcription serviceA human typist, possibly employed by a subcontractorWho is in the subcontractor chain, and where are theyPer line or per minute of audio
Transcription software you run yourselfNobody outside your organizationYour own safeguards, since there may be no business associate at allLicense or subscription
Front-end speech recognitionA recognition engine, in your network or a vendor cloudIs the voice channel encrypted, and is audio retained or used for trainingPer user subscription
General purpose AI transcription toolsA vendor model, often with no healthcare scopeWill they sign a BAA at all, and on which plan tierPer user subscription

Do transcription services need a business associate agreement?

Yes. A transcription vendor creates, receives, maintains and transmits PHI on your behalf, which is the definition of a business associate. You need the BAA in place before the first recording moves, not after the pilot. Ask for the vendor's template early, because the clause that takes longest to settle is almost never encryption. It is breach notification timing, where vendors like to write "without unreasonable delay" and buyers want a number of days they can actually plan an investigation around.

The onboarding paperwork usually arrives as a set: the BAA, the security questionnaire, the most recent audit report and a current certificate of insurance showing the cyber liability cover is still active, which is the one that silently expires between annual reviews and nobody notices until a claim. Whoever owns vendor risk at your group should be collecting all four for every business associate, transcription included.

Is offshore medical transcription legal under HIPAA?

Yes, HIPAA does not prohibit sending PHI outside the United States, and a large share of medical transcription has been performed offshore for two decades. What HIPAA does require is that the obligations flow down. Your vendor must bind its own subcontractors to the same protections it owes you, so a chain that runs from your group to a US transcription company to an overseas partner to an individual typist is permissible only if each link is contractually covered.

The practical risk is not legality, it is enforceability and visibility. If a typist four links down keeps a recording on a personal device, your remedy is a contract claim against a company in another jurisdiction, and your breach notification duty in the United States is unaffected by how hard that claim is to bring. Some states and some hospital systems also impose their own data residency terms by contract even though HIPAA does not. So the question to ask is not "do you use offshore staff", which invites a defensive answer, but "list every entity and country that can access our audio, and show me the flow-down clause in each contract".

Can we use general transcription tools for medical records?

Only if the vendor will sign a BAA covering the plan you are actually on, and many will not, or will only on an enterprise tier that costs considerably more than the consumer plan somebody already expensed. This is the most common accidental HIPAA failure in radiology groups today. A convenient AI notetaker gets used for a tumor board or a dictated addendum, nobody checks the terms, and PHI ends up with a vendor that never agreed to protect it and may be training on the input.

Before anything touches a patient recording, confirm three things in writing: the vendor signs a BAA on your subscription tier, your audio and transcripts are excluded from model training, and you can delete both on request with confirmation. If any of the three is missing, the tool is fine for an internal meeting and not fine for clinical content.

How long is dictation audio kept, and does it matter?

It matters more than most questionnaires suggest. The recording is individually identifiable health information in electronic form, so it is ePHI with exactly the same standing as the report text, and it tends to live in places nobody inventoried: a queue on the vendor side, a local cache on the workstation, a backup of both. Ask for the retention period in days, who inside the vendor can replay audio and under what approval, whether recordings are used to improve speech models, and what the documented deletion process is. A vendor that answers those four crisply has thought about it. A vendor that answers with a link to a trust page has not.

How much does HIPAA compliant transcription cost?

Transcription is normally billed per 65-character line or per minute of audio, which is why its cost tracks dictation volume rather than headcount and why groups that grow reads quickly get an unpleasant surprise in year two. Front-end speech recognition converts that into a per-radiologist subscription, which is predictable but does not fall when volume falls. Nobody in this category publishes list pricing, so the only reliable comparison is your own volume run through both models over three years, including the renewal escalator. Our comparison of the best medical dictation software for radiology practices works through the field using federal contract records rather than vendor claims, which is the closest thing to public pricing this market has.

Does HIPAA require encryption for transcription software?

Not in the blunt way vendors imply. In the technical safeguards at 45 CFR 164.312, encryption of stored ePHI and encryption in transmission are both Addressable rather than Required, which means you assess whether the safeguard is reasonable for your environment, implement it if it is, and document your reasoning if you implement an equivalent instead. Addressable is not optional and it is not a loophole. It is a written decision an investigator can ask to see. In practice, unencrypted transmission of clinical audio over the internet in 2026 would be extremely difficult to defend as reasonable, so treat it as mandatory in your own requirements even though the regulation words it more softly.

There is a proposal to remove that softness and make encryption and multi-factor authentication flatly required. It was published on January 6, 2025 under regulation identifier 0945-AA22. Checked against the Federal Register on September 9, 2026, that proposal is still the only document filed under the identifier and no final rule has been issued. It is a fair thing to ask vendors about, and a poor thing to be sold on as a current legal obligation.

What should we do about it this quarter?

Inventory first. List every route by which clinical speech leaves a radiologist's mouth and becomes text, including the small residual service and the tool somebody expensed. For each one, confirm a signed BAA exists, get the subcontractor and country list, get the audio retention period, and get the training exclusion in writing. That exercise usually finds one route nobody had documented, and finding it is the whole point.

Then decide whether you are solving the right problem. Transcription exists because the report starts empty and someone has to fill it. Cutting the typing is one answer; starting the report further along is another. Radiology dictation software covers dictating over a draft instead of into a blank template, and structured radiology reporting covers the templates the words land in. Radiological.ai drafts the structured report from the study before you speak, which is decision support rather than diagnosis, and the responsible radiologist reviews, edits and signs every report.

See Radiological.ai read a study

The assistant flags suspected findings for review, prioritizes the worklist so urgent studies surface first, and drafts the structured report into your template. You review, edit and sign every study.

Bring the assistant to your reading workflow

Radiological.ai flags suspected findings, prioritizes the worklist and drafts the structured report across X-ray, CT and MRI, in one calm pane. The responsible radiologist reviews, edits and signs every study.

X-ray, CT & MRI · Flag, triage, draft · You review & sign

Radiological.ai is a workflow and decision-support tool for qualified clinicians. It does not provide a diagnosis and is not a substitute for professional medical judgment.