Radiological.ai

Reporting & worklist · HIPAA compliant dictation

HIPAA compliant dictation software and app for radiology reporting

The short answer

HIPAA compliant dictation software is speech and reporting software whose vendor will sign a business associate agreement and whose controls satisfy the HIPAA Security Rule safeguards at 45 CFR 164.308, 164.312 and 164.314. There is no government certification for this, so no product is officially "HIPAA certified" and any vendor claiming to be is describing its own audit, not a federal approval. What actually exists is a checklist you apply yourself. Of the seven implementation specifications in the technical safeguards at 45 CFR 164.312, exactly two are Required, unique user identification and an emergency access procedure, and the other five, including encryption of stored records and encryption in transit, are Addressable, meaning you must either implement them or document in writing why an equivalent measure is reasonable. Radiological.ai drafts the structured report before you dictate, and the questions on this page are the ones to put to us and to every vendor you shortlist.

Buying dictation software for a radiology group is two purchases wearing one coat. The radiologists judge recognition quality and macros. Then the contract stops for weeks in a security review run by people who never touch the microphone, and the questions there are about where the audio goes, who can replay it, and whether the vendor will sign a business associate agreement without redlining the breach clause into meaninglessness.

Most vendor pages answer the first purchase and wave at the second with a HIPAA badge. This page does the opposite. It maps the dictation decision onto the safeguards a security reviewer actually cites, taken from the regulation as it stands today rather than from a compliance blog, and it is honest about which of them the rule requires and which it merely asks you to consider and document.

Last updated September 2026

The Reading Station

Worklist

SERIES 1 · AX
SLICE 24/64
SAMPLE STUDY
NOT FOR DIAGNOSTIC USE
W 80 · L 40
ILLUSTRATIVE SAMPLE

Structured report

Draft

Run the assistant to draft this report for review.

You review & sign

Illustrative sample · not a real patient study, not a diagnosis

Drafted in · you review & sign Worklist re-prioritized

Decision support for qualified clinicians. Radiological.ai does not provide a diagnosis and is not a substitute for professional judgment.

Run the assistant

Flag · prioritize · draft · you review and sign

X-RAY CT MRI BUILT WITH RADIOLOGISTS

Decision support not a diagnosis

You review & sign

This page is about passing the security review. If you are still choosing the product itself, radiology dictation software covers recognition, macros and the difference between dictating into a blank template and editing a draft, and the best medical dictation software for radiology practices compares the field on federal contract records rather than vendor claims.

One question decides more of this than any control: is recognition running on your own servers or in a vendor cloud. On premises keeps voice inside your network and puts the whole burden on your team. Cloud moves the burden to a business associate and makes the BAA the load bearing document. Groups leaving PowerScribe 360 are making exactly that move right now, since renewals and maintenance ended on August 31, 2026 and full support ends August 31, 2027, which is laid out in PowerScribe One vs 360 and the migration checklist.

Be careful with the compliance timeline a vendor quotes you. A proposed overhaul of the Security Rule would make encryption and multi-factor authentication mandatory rather than Addressable, and it is real, but it is still a proposal. Checked against the Federal Register API on September 9, 2026, regulation identifier 0945-AA22 has exactly one published document: the proposed rule of January 6, 2025. No final rule has been issued. Buy for the rule that exists and ask how the vendor would handle the one that might.

Transcription is a separate exposure with a separate answer, because a person somewhere is listening to the recording rather than a model transcribing it. HIPAA compliant transcription software covers the subcontractor chain and why offshore routing is the question that matters there. If the wider platform is what your reviewer is assessing, radiology reporting software is the surrounding system.

Side by side

The technical safeguards a dictation vendor is measured against, and which ones the rule actually requires

Every implementation specification in the HIPAA technical safeguards, with its status exactly as the regulation words it. Reviewers quote these paragraph numbers, so it is worth knowing which two are non-negotiable before a vendor tells you all seven are.

Implementation specification Citation Status in the rule today What to ask a dictation vendor
Unique user identification 164.312(a)(2)(i) Required Does every radiologist get their own login, or does the reading room share one account because it is faster at shift change?
Emergency access procedure 164.312(a)(2)(ii) Required If the vendor cloud is unreachable mid shift, how do you still get to reports already dictated? Ask for the documented procedure, not a reassurance.
Automatic logoff 164.312(a)(2)(iii) Addressable Is the timeout configurable per site? A workstation timeout tuned for an office is unusable in a dark reading room and gets disabled locally.
Encryption and decryption of stored ePHI 164.312(a)(2)(iv) Addressable Are report text and dictation audio both encrypted at rest, or only the text? The audio is the part vendors forget to mention.
Mechanism to authenticate ePHI 164.312(c)(2) Addressable How would you detect that a signed report was altered after signature, and is that evidence available to you or only to the vendor?
Integrity controls in transmission 164.312(e)(2)(i) Addressable What protects the report on the hop back into the RIS or EHR, which is usually a different interface owned by a different vendor?
Encryption in transmission 164.312(e)(2)(ii) Addressable Is voice streamed to a cloud recognition engine, and is that channel encrypted end to end? For cloud dictation this is the whole ballgame.
Audit controls 164.312(b) Standard, no separate specification Can you export access logs yourself for your own audit, or must you file a support ticket and wait?

Retrieved from the Electronic Code of Federal Regulations on September 9, 2026, for 45 CFR 164.312 as in force September 1, 2026. The section's own source note reads 68 FR 8376, Feb. 20, 2003, as amended at 78 FR 5694, Jan. 25, 2013, so these technical safeguards have not been amended since January 2013. Counts across the neighboring sections on the same retrieval: 164.308 has 10 Required and 11 Addressable specifications, and 164.314 has 2 Required and none Addressable.

Why it works

What your group gets with HIPAA compliant dictation

A BAA, not a badge

No federal body certifies software as HIPAA compliant. What is enforceable is the business associate contract required by 45 CFR 164.314, so ask for the BAA itself early rather than a logo on a marketing page.

Know Required from Addressable

Five of the seven technical implementation specifications are Addressable, including encryption. That is not permission to skip them. It means you implement or you document an equivalent, and reviewers ask to see which one you chose.

Dictation adds voice to the problem

A reporting platform holds report text. A dictation platform also holds audio of a clinician speaking patient details aloud, which is PHI with its own retention, replay and access questions that most security questionnaires forget to ask.

What it handles

Flagged, prioritized and drafted for your review

The assistant pre-reads each study, surfaces a region of interest for review, re-prioritizes the worklist, and drafts the structured report in your template. You confirm, edit and sign.

  • Drafts the structured report before you dictate
  • Vendor signs a business associate agreement
  • Unique user identification per radiologist
  • Access and audit trails over report activity
  • Encryption of records in transit and at rest
  • Radiologist reviews, edits and signs every report
HIPAA COMPLIANT DICTATION STAT

Region of interest flagged for review

A focal region is surfaced on the sample study for the radiologist to review. The assistant does not characterize it as a diagnosis.

Draft impression

Suspected finding flagged for radiologist review. Correlate clinically and confirm. Draft for review and sign-off.

Illustrative sample · not for diagnostic use You review & sign

Why Radiological.ai

One assistant across the whole read

Not three vendors stitched together. Flag, prioritize and draft in one calm pane, on X-ray, CT and MRI, with the radiologist signing every study.

Flags suspected findings

A second set of eyes surfaces regions of interest for review on every study, so a suspected finding is less likely to slip past late in a shift.

Prioritizes the worklist

Suspected-critical studies move to the top, so urgent reads surface ahead of routine follow-ups across your sites and shifts.

Drafts the report

A structured draft arrives in your template, ready to edit and sign. The draft saves the typing and the measuring, never the judgment.

Good questions

Questions about HIPAA compliant dictation

No dictation product is HIPAA compliant on its own, because compliance describes how your organization uses a tool, not a property the tool ships with. The vendor has to be willing to sign a business associate agreement and to support the safeguards in the Security Rule. You then have to configure and operate it correctly. A product with excellent controls that your group runs on a shared login is not compliant.
Three things together. A signed business associate agreement, since 45 CFR 164.314 requires that contract before a vendor may handle your PHI. Technical safeguards that meet 45 CFR 164.312, where unique user identification and an emergency access procedure are Required and the other five specifications, including encryption, are Addressable. And your own administrative safeguards under 164.308, which the vendor cannot supply for you.
No. There is no federal HIPAA certification program and no government body certifies software as compliant. Vendors advertising HIPAA certification are describing a voluntary third party audit they paid for, which may still be useful evidence but is not an approval. Ask what standard the audit covered and read the report rather than trusting the badge on the pricing page.
Not outright, which surprises most buyers. Encryption of stored ePHI at 45 CFR 164.312(a)(2)(iv) and encryption in transmission at 164.312(e)(2)(ii) are both Addressable, not Required. Addressable means you assess whether the safeguard is reasonable and appropriate, implement it if it is, and document your reasoning if you implement an equivalent instead. In practice a modern cloud dictation deployment that is not encrypted in transit would be very hard to defend.
Required specifications must be implemented as written. Addressable ones must be assessed: you implement the safeguard, or you implement a reasonable equivalent and document why, or you document why neither is reasonable for your environment. Addressable is not optional. The paperwork trail is what an investigator asks for, so the practical difference is that Addressable items generate a written decision and Required items do not need one.
Yes, if the vendor creates, receives, maintains or transmits PHI on your behalf, which any hosted dictation or reporting platform does. The contract requirements sit at 45 CFR 164.314, and on the retrieval behind the table above both of that section's implementation specifications are Required rather than Addressable. Get the vendor's BAA template before contract negotiation, not after, because its breach notification timing is usually the clause that takes longest to settle.
Yes. A recording of a radiologist speaking a patient's findings is individually identifiable health information in electronic form, so it is ePHI and the same safeguards apply to it as to the report text. This is the gap worth probing, because security questionnaires are usually written around documents. Ask how long audio is retained, who inside the vendor can replay it, whether it is used to train speech models, and how you get it deleted.
Not inherently, and for many groups it is more secure in practice, because a vendor operating one platform patches and monitors it more consistently than a small imaging group patches a server in a closet. What changes is who is accountable and how you prove it. On premises you hold the whole burden and the evidence. In the cloud you transfer part of the burden to a business associate and your evidence becomes the BAA, the audit reports and the logs the vendor lets you export.
Start with the four that most often go unanswered. Will you sign our BAA rather than only your own, and what is your breach notification window in days. Where is dictation audio stored, for how long, and is it used for model training. Can we export our own access and audit logs without a support ticket. And which subcontractors touch PHI, since their obligations flow down to you through the vendor.
No. The proposal to strengthen the Security Rule, which would make encryption and multi-factor authentication mandatory rather than Addressable, was published on January 6, 2025. Checked against the Federal Register on September 9, 2026, regulation identifier 0945-AA22 still shows exactly one document, that proposed rule, and no final rule. Treat it as a strong signal of direction and a fair question to ask vendors about roadmaps, but not as a current obligation.
It adds a system that reads studies and writes report text, so it is another business associate handling ePHI and it belongs in the same review as dictation. The questions are the same ones: BAA, encryption, audit trails, retention, and whether your data trains anyone's model. Radiological.ai drafts a structured report for the radiologist to review, edit and sign. It is decision support, it makes no diagnosis, and the responsible radiologist signs every report.

Explore more

More ways teams read with Radiological.ai

From the blog: best AI radiology software in 2026, how much radiology AI costs, how to implement AI in a radiology workflow, and AI radiology companies.

Read more studies, with the assistant alongside you

Flag suspected findings, prioritize the worklist, and draft the structured report. You review and sign every study.

See pricing

Radiological.ai is a workflow and decision-support tool for qualified clinicians. It does not provide a diagnosis and is not a substitute for professional medical judgment.