Back to top
Healthcare Innovation

Is Otter.ai HIPAA Compliant?

Written By:
Robert Henehan
September 19, 2026
Is Otter.ai HIPAA Compliant?

Meeting transcription tools have quietly become some of the most widely used software in professional life. Otter.ai records calls, produces a searchable transcript, and writes a summary, and can join calendar meetings automatically and can join calendar meetings automatically.

Which is exactly how it ends up in a healthcare setting. A therapist who uses Otter for supervision calls wonders whether it could capture a session. A practice manager who relies on it for staff meetings considers it for intake calls. The tool is already installed, already familiar, and already producing the kind of transcript that would save real time on documentation.

Protected Health Information carries some of the strictest regulatory protections in the United States. Before anyone records a patient encounter with any tool, one question has to be answered first.

Is Otter.ai HIPAA compliant?

The short answer: yes it might be on Enterprise, no on every other plan

Otter.ai supports HIPAA compliance, but only on its Enterprise plan, only as an add-on, and only once a Business Associate Agreement has been signed. Otter's own Help Center states it plainly: "HIPAA compliance is only available for the Enterprise plan. Reach out to your account manager to start the Business Associate Agreement (BAA) process."

Otter's pricing page lists "HIPAA compliance (add-on)" as an Enterprise line item, with pricing available from Otter.

That produces a clean split:

  • Basic (free), Pro, and Business plans: no BAA is available, so these plans should not be used with PHI. Under the HIPAA Privacy Rule, disclosing PHI to a vendor acting as your business associate without a signed BAA is not a permitted disclosure.
  • Enterprise plan with the HIPAA add-on and an executed BAA: Otter's supported path for healthcare organizations handling PHI.

HIPAA business-associate status depends on the vendor’s role; the BAA documents the required obligations.

So the practical question for most people searching this is not whether Otter can ever be HIPAA compliant. It is whether the version of Otter they have is, and for a therapist in solo practice on Pro or a five-person clinic on Business, the answer is no.

This article covers what Otter's published policies actually say, what the Enterprise path requires, why a recent federal court ruling matters for anyone recording patient conversations, and what to use instead.

Otter is one case of a general framework. For the requirements any AI tool must meet before it touches patient data, including the BAA, technical safeguards, and data-use restrictions, see our guide to what makes an AI HIPAA compliant.

Otter.ai's Plans: Where the Compliance Line Falls

Otter offers four tiers. The capability differences between them are real, and so is the compliance difference.

Otter.ai plans
Plan Price (Sept 2026) Transcription Conversation history BAA available
Basic Free 300 min/user/month, 30 min per conversation 25 most recent No
Pro $16.99/user/month, or $8.33 billed annually 1,200 min/user/month, up to 90 min per meeting Unlimited No
Business $30/user/month, or $19.99 billed annually Unlimited meetings/in-app recordings, up to 4 hours; imports have separate limits Unlimited No
Enterprise Custom, demo required Unlimited meetings/in-app recordings, up to 4 hours; imports have separate limits Unlimited Yes, as an add-on

1. The BAA is available through Enterprise sales

A BAA is the specific contract HIPAA requires between a covered entity and a vendor that creates, receives, maintains, or transmits PHI on its behalf. It is not optional, and no amount of encryption substitutes for it.

Otter does offer one. Getting it means moving to Enterprise, adding the HIPAA add-on, and working through an account executive. Otter directs customers to sales for the BAA and pricing.

This review found no public Otter BAA template. A practice should request the agreement to review its terms, including indemnification, breach notification timelines, and subcontractor provisions. For an organization with counsel on retainer, that is a normal procurement step. For a smaller practice, it means evaluating a compliance decision while requesting the contract that governs it.

2. Enterprise security controls carry their own minimums

Otter's Enterprise tier includes SSO, SCIM provisioning, domain capture, activity logs, and custom data retention. Those are the controls Otter's own HIPAA guidance tells customers to configure.

Two of them carry a license minimum. Otter's pricing comparison lists a "minimum 100-user license required" for both Single Sign-On and SCIM user provisioning. This is a license minimum for SSO and SCIM; 2FA is available across plans, and HIPAA does not specifically require SSO or SCIM.

3. Data retention is not configurable below Enterprise

Custom data retention appears only in the Enterprise column of Otter's plan comparison. Below it, scheduled retention is unavailable: Basic provides access to the 25 most recent conversations and archives older ones, and Pro and Business list conversation history as unlimited, likely meaning recordings and transcripts persist until someone deletes them by hand.

Neither shape is a retention policy. A free-tier cap that limits access to older conversations is not a data lifecycle rule, and an unlimited archive that only shrinks when a staff member remembers to clear it is the opposite problem. HIPAA-conscious organizations need a retention policy they can implement and document.

Otter's HIPAA guidance asks healthcare customers to "configure transcript and recording retention in accordance with their HIPAA-compliant data lifecycle policies," and points them to an account executive to set it up. That control is part of the Enterprise package.

4. Compliance work sits with the customer

Otter's HIPAA article is unusually candid about how much configuration falls on the healthcare organization. It asks customers to control when the Notetaker joins meetings, review calendar integrations and auto-join settings, disable public and link-based transcript sharing, enforce 2FA and SSO, remove access for departing staff promptly, ideally within 24 hours, review usage logs and dashboards, and set retention policies.

That is a real compliance program, not a checkbox. A signed BAA is the entry requirement, not the finish line, and an organization that signs one and changes nothing about its configuration has not done the work.

5. The tool is built for meetings, not encounters

Otter is a general-purpose meeting assistant. It offers summaries and custom templates that can request formats such as SOAP, DAP, or BIRP.

Even on a fully compliant Enterprise deployment, customized output still requires review against clinical documentation requirements.

6. Accidental exposure is the realistic failure mode

The risk here is rarely a deliberate decision. It is a provider who already uses Otter for internal calls leaving it running for a telehealth session, or the Notetaker joining a video visit because it joins every calendar event.

Otter names this risk itself, telling customers they are "responsible for controlling when and how PHI is introduced into the Otter environment," including managing the Notetaker's auto-join behavior. A tool designed to be always on requires deliberate work to keep it off.

7. Sensitive clinical content needs careful handling

Clinical encounters can involve trauma, abuse, substance use, self-harm, and anatomical detail. Healthcare teams should evaluate whether an AI tool preserves clinically relevant details and produces usable documentation when these topics arise.

What Otter Does Publish About Security

Giving Otter credit where it is due matters, because anyone evaluating this needs the real picture rather than a sales pitch.

Otter maintains a public Trust Center at trust.otter.ai listing HIPAA, SOC 2, GDPR, CCPA, and VPAT, with a HIPAA report, SOC 2 report, penetration test report, architecture diagram, HECVAT self-assessment, and information security policy available on request. Otter is SOC 2 Type II certified. Its plan comparison lists TLS encryption and AES-256 encryption for real-time content across tiers, with two-factor authentication available on every plan.

Those are legitimate security credentials. They are also a separate question from the one this article is about.

Why "Secure" Does Not Mean "HIPAA Compliant"

This distinction causes more confusion than any other in this category, so it is worth stating plainly.

A vendor can encrypt data in transit and at rest, restrict employee access, hold a SOC 2 Type II attestation, publish a trust center, and describe its platform as secure and private, and still not be usable with PHI on the plan you happen to be on. Security certifications describe how a company protects data. A BAA is a contract that assigns legal responsibility for PHI and obligates the vendor to specific safeguards, breach reporting, and subcontractor terms.

Both safeguards and the required BAA matter under HIPAA. With Otter, the BAA is tied to a specific plan tier and a specific add-on.

The Data Training Question

Otter's privacy policy describes using customer content to "improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions." The policy notes that transcriptions may contain Personal Information.

Otter's enterprise marketing page says: "Keep your organization's data out of AI model training. Contact your account manager to get started."

Otter's Enterprise admin guide says workspaces are excluded from training by default; opting in requires an account manager. For anyone on Basic, Pro, or Business, the reasonable reading is that eligible recorded content may be used to improve Otter's models; Otter says imported customer data, such as Google Workspace documents, is excluded.

A Federal Court Ruling Worth Knowing About

On August 13, 2026, Judge Eumi K. Lee of the U.S. District Court for the Northern District of California ruled on Otter.ai's motion to dismiss in In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL. The court granted the motion in part and denied it in part.

Claims under the federal Electronic Communications Privacy Act, California's Invasion of Privacy Act, Illinois' Biometric Information Privacy Act, plus unjust enrichment and California's Unfair Competition Law, were allowed to proceed. Claims under the CFAA, CDAFA, and the Washington Privacy Act were dismissed with leave to amend, as were several plaintiffs' privacy claims.

Three parts of the reasoning matter for healthcare specifically.

The court's analysis turned on what the vendor does with the recording. Otter argued its Notetaker is an invited participant acting as the host's own recording tool. The court held that Otter is plausibly a third-party eavesdropper under CIPA Section 631 based on allegations that it independently collects, retains, and uses conversations for its own commercial purposes, including model training. A vendor that hands the transcript back and keeps nothing is in a different position than one that retains and reuses the content.

One medical-call allegation survived the pleading stage. One plaintiff's confidential-communication claim survived specifically because the plaintiff alleged a call with a medical professional involving deeply personal medical information. Other plaintiffs who described their calls only as "private" or "sensitive" had those claims dismissed as too vague. The ruling turned on the specificity and sensitivity of the alleged medical communication.

The biometric-collection allegations survived the pleading stage. The court found that Otter's speaker-tagging and speaker-identification features plausibly involve capturing voiceprints, which are biometric identifiers under Illinois' BIPA.

Two caveats matter, and they are not small ones. This was a ruling on a motion to dismiss, which tests whether allegations are plausible enough to proceed, not whether they are true. Otter contested the claims. This order made no determination of liability.

Court order last verified: September 17, 2026. This summary reflects the August 13, 2026 ruling.

Still, the practical takeaway for a covered entity is clear enough. Recording consent is a live legal question in this category right now, and the question worth asking any vendor is whether it retains and reuses your conversation content to train its own models.

Practical Challenges of Using Otter.ai in Healthcare

Consent obligations sit on top of everything else

Recording a patient encounter raises consent requirements independent of HIPAA. All-party consent states, including California, Illinois, Pennsylvania, Florida, Massachusetts, Washington, and Maryland, require all-party consent for specified private or confidential communications, with scope and exceptions varying by state. Check applicable state rules for the intended behavioral-health workflow.

Practitioners retain their consent obligations; vendors may also have obligations. A signed BAA does not satisfy a state recording statute, and every tool, including a purpose-built healthcare one, requires a lawful recording workflow. Obtaining and documenting consent in every state is a recommended practice.

Meeting bots behave in ways healthcare settings cannot absorb

Assistants that auto-join calendar events may join a telehealth appointment the same way they join a team standup. A visible bot in a therapy session changes the session. Otter provides workspace controls to disable Notetaker and manage auto-join, but they have to be configured deliberately, and Enterprise administrators can lock auto-join settings across the workspace. Otter also offers botless recording through its desktop app.

Output requires rework

A meeting summary is not a progress note. Custom templates can request clinical fields, including SOAP structure, session time, risk documentation, and treatment plan linkage; each output needs review against applicable requirements. The transcription saves keystrokes and leaves the documentation work in place.

Accuracy still requires review

Any AI-generated healthcare content requires review by a qualified professional before it enters the record. That is true of every tool in this category, including purpose-built ones.

Example. A group practice uses Otter Business for weekly staff meetings, which is a reasonable use with no PHI involved. A newly hired therapist, seeing the tool in the shared workspace, enables it during a telehealth intake to save time on the note. Business does not carry a BAA. The recording, the transcript, and the summary now sit with a vendor the practice has no HIPAA agreement with, and the practice has a potential breach to assess.

BastionGPT: A Healthcare-First Alternative

For healthcare professionals who want the time savings a transcription tool promises without a plan-tier gate in front of the compliance paperwork, BastionGPT is built for healthcare from the ground up. It is used by 10,000+ health organizations and is a Microsoft Partner with Qualys-secured infrastructure.

A BAA is included with all plans. Every subscription includes a HIPAA Business Associate Agreement in the terms of use, including the free trial. There is no sales review, no add-on to purchase, and no seat minimum. A solo practitioner on the $20 per month Professional plan receives the included BAA, and signed copies are available via DocuSign on request.

Customer Data is not used to train, fine-tune, evaluate, enhance, or improve any AI model. The current Terms state this as a contractual commitment. Transcript retention is configurable, with a 30-day default. Chats remain until deletion or 30 days of account inactivity; users can delete sooner.

An AI Scribe built for patient encounters. Unlimited transcription on all plans, subject to fair use, with multi-speaker recognition for up to 10 speakers and recordings up to 240 minutes. Record live or upload audio from in-person visits, telehealth, or phone consults. It works with Zoom, Microsoft Teams, and Google Meet without placing a visible bot in the room, and it supports ambient listening or dictation.

Output in the formats documentation actually requires. Available outputs include Transcription, Summary, SOAP Note, Detailed SOAP Note, DAP Note, and Custom Note tabs. The scribe also generates BIRP, H&P, and progress notes, plus custom templates that match your own formatting.

Healthcare-appropriate content handling. BastionGPT is designed to support legitimate clinical discussion of sensitive topics, including trauma, abuse, substance use, and anatomical details.

More than a scribe. Beyond transcription, BastionGPT drafts referral letters, discharge summaries, and intake reports, analyzes uploaded documents and clinical images, and supports prior authorizations and insurance appeals. It runs multiple leading AI models in one interface, configured for healthcare use, and the model lineup is kept current as new versions are released.

Works with what you already use. BastionGPT works alongside 50+ EMR and EHR systems, including Epic, Cerner, athenahealth, eClinicalWorks, SimplePractice, and TherapyNotes, through a copy or upload workflow with nothing for IT to install.

Security built for regulated data. Cloud infrastructure including Microsoft Azure, with provider-level ISO 27001 certifications, AES-256 encryption at rest and TLS 1.2 or higher in transit, and third-party penetration testing.

Alexis Arceo, CEO, Expedited Reports: "The HIPAA compliance is a huge time saver because I do not have to take out identifying information."

Catherine Maxted, RN, Nurse Coordinator: "People compliment the quality and clarity of my documentation all the time now. I can't imagine working without Bastion!"

Comparison: BastionGPT vs. Otter.ai

FeatureBastionGPTOtter.ai
BAA availability Included with all plans, including the free trial. No seat minimum, no add-on purchase, no sales review. Signed copies via DocuSign on request. Available on the Enterprise plan as an add-on, executed through an account executive. Not available on Basic, Pro, or Business. This review found no public agreement.
Healthcare specialization Purpose-built for healthcare documentation, with note formats and workflows designed for clinical work. General-purpose meeting assistant. Custom templates can request healthcare note formats.
Data and AI training Customer Data is excluded from AI-model training, fine-tuning, evaluation, enhancement, and improvement. Privacy policy describes training Otter's proprietary AI on de-identified recordings and transcriptions that may contain personal information. Enterprise workspaces are excluded by default. Otter says imported customer data, such as Google Workspace documents, is excluded from training.
Data retention control Configurable transcript retention, with a 30-day default; chats remain until deletion or 30 days of account inactivity. Users can delete sooner. Custom data retention listed as an Enterprise feature, configured through an account executive. Basic provides access to the 25 most recent conversations and archives older ones; Pro and Business are unlimited with manual deletion.
Identity controls SSO available on Ultra. 2FA across plans. SSO and SCIM listed with a minimum 100-user license required. 2FA across plans.
Recording length Up to 240 minutes per recording, unlimited transcription on all plans, subject to fair use. Up to 4 hours per meeting on Business and Enterprise; 90 minutes on Pro and 30 minutes on Basic. 300 monthly minutes on Basic, 1,200 on Pro, unlimited meetings/in-app recordings above; imports have separate limits.
Transcription output Transcription, Summary, SOAP, Detailed SOAP, DAP, and Custom Note output options. Up to 10 speakers. Meeting transcript, summary, action items, and custom templates.
Meeting platform behavior Works with Zoom, Microsoft Teams, and Google Meet without placing a visible bot in the room. Otter Notetaker joins Zoom, Microsoft Teams, and Google Meet as a participant; auto-join is admin-configurable. Otter also offers botless desktop recording.
Pricing and accessibility From $20 per user per month with the BAA included. 7-day free trial, 45-day refund policy, subject to published terms. Free to $30 per user per month for self-serve tiers. Enterprise pricing is quote-based and HIPAA add-on pricing is available from Otter.
Security infrastructure Microsoft Azure and Google cloud services, provider-level ISO 27001 certifications, AES-256 at rest, TLS 1.2 or higher in transit, third-party penetration testing. SOC 2 Type II certified, AWS infrastructure, TLS and AES-256 encryption, public trust center with HIPAA, SOC 2, and pentest reports on request.

Conclusion

Otter.ai is a capable meeting transcription tool with real security credentials, and it does offer a path to HIPAA compliance. That path runs through the Enterprise plan, a HIPAA add-on, a signed Business Associate Agreement obtained through sales, and a configuration checklist that Otter hands back to the customer.

For a health system with a procurement process and an IT team, that is a workable path worth evaluating on its merits.

For the therapist in solo practice, the four-person group, or the practice manager who already has Otter open in another tab, it requires an Enterprise arrangement. On Basic, Pro, and Business there is no BAA, which means those plans should not touch a patient encounter.

The gap BastionGPT is built to close is exactly that one. A BAA is included with all plans, including the free trial, and healthcare note formats come standard.

Most users can sign up and start using BastionGPT through self-service signup. There are no setup costs, a 7-day free trial, and no fixed commitments. Whether you need secure transcription, help drafting SOAP or DAP notes, or support with prior authorizations and insurance appeals, BastionGPT is designed to support HIPAA-compliant workflows.

Begin with a 7-day free trial of BastionGPT.

BastionGPT is designed to assist healthcare professionals with documentation and clinical workflows. It does not replace professional judgment, clinical expertise, or human oversight. All AI-generated output should be reviewed by qualified professionals before use in clinical settings.

If you have questions or want to connect:

Email: [email protected] Phone: +1 (214) 619-8696 Schedule a Chat: Book a Meeting

Frequently Asked Questions (FAQ)

Is Otter.ai HIPAA compliant?

Otter.ai supports HIPAA compliance on its Enterprise plan only, as an add-on, and only after a Business Associate Agreement is signed. Otter's Help Center states that "HIPAA compliance is only available for the Enterprise plan." The Basic, Pro, and Business plans do not carry a BAA, so they should not be used to record, transcribe, or summarize patient encounters.

Does Otter.ai sign a BAA?

Yes, for Enterprise customers. Otter's Help Center directs customers to contact their account executive to start the BAA process. This review found no public BAA template or self-serve signature flow. Otter publishes no BAA offering for the free, Pro, or Business tiers.

How much does Otter.ai HIPAA compliance cost?

Otter does not publish a price. HIPAA compliance is listed on the pricing page as an Enterprise add-on, and Enterprise itself is quote-based and requires scheduling a demo. Expect a sales conversation rather than a checkout page.

Can therapists use Otter.ai for session notes?

Not on Basic, Pro, or Business, because no BAA is available on those plans. A practice on Enterprise with the HIPAA add-on and a signed BAA can, provided it also completes Otter's configuration requirements and obtains patient consent for recording. Custom templates can request SOAP, DAP, or BIRP structure; professional review remains necessary.

Is Otter.ai secure even where it is not HIPAA compliant?

Those are different questions. Otter is SOC 2 Type II certified, publishes a trust center, and encrypts data in transit and at rest. Security describes how a vendor protects data. HIPAA compliance requires a specific contract, the BAA, that assigns legal responsibility for PHI. A tool can be well secured and still be unusable with patient information on the plan you are on.

How long does Otter.ai keep my recordings?

It depends on the plan. Scheduled retention is an Enterprise feature. Basic provides access to the 25 most recent conversations and archives older ones. Pro and Business list conversation history as unlimited, so recordings and transcripts persist until someone deletes them manually. Custom data retention is an Enterprise feature configured through an account executive, which is also where Otter's HIPAA guidance points healthcare customers.

What happens if I already recorded a patient session with Otter.ai?

If a BAA was required and the account had none in place, disclosing PHI to that vendor was not a permitted disclosure. The appropriate next steps are to stop the practice, determine what was recorded and where it is stored, preserve the incident facts and coordinate mitigation with your compliance officer, apply HIPAA’s breach presumption, exceptions, and documented risk assessment to determine notification obligations, and consult counsel or your compliance officer.

Does Otter.ai use my recordings to train AI models?

Otter's privacy policy describes training its proprietary AI technology on de-identified audio recordings and transcriptions that may contain personal information. Its enterprise marketing page says: "Keep your organization's data out of AI model training. Contact your account manager to get started." The Enterprise admin guide states that exclusion is the default; opting in requires an account manager. Otter says imported customer data, such as Google Workspace documents, is excluded from training.

What is the Otter.ai lawsuit about, and does it affect healthcare users?

In In re Otter.AI Privacy Litigation (N.D. Cal., No. 25-cv-06911-EKL), plaintiffs allege Otter's Notetaker recorded meetings without all participants' consent and that Otter retained the recordings to train its models. On August 13, 2026, the court allowed ECPA, CIPA, and BIPA claims to proceed while dismissing others. One plaintiff's claim survived based on sufficiently specific allegations about a confidential medical call. Otter contested the claims; this order made no determination of liability. The practical lesson is to ask any vendor whether it retains and reuses conversation content for model training.

Is there a HIPAA-compliant alternative to Otter.ai for healthcare professionals?

BastionGPT includes a BAA with all plans, including the free trial, with no seat minimum and no add-on to purchase. It provides unlimited HIPAA-compliant transcription, subject to fair use, with multi-speaker recognition for up to 10 speakers and recordings up to 240 minutes. Available outputs include Transcription, Summary, SOAP, Detailed SOAP, DAP, and Custom Note outputs. Plans start at $20 per user per month.

Do I need patient consent to record a session, even with a compliant tool?

Recording consent requirements are separate from HIPAA. Practitioners retain their obligations; vendors may also have obligations. All-party consent states, including California, Illinois, Pennsylvania, Florida, Massachusetts, Washington, and Maryland, require all-party consent for specified private or confidential communications, with scope and exceptions varying by state. Check applicable state rules for the intended behavioral-health workflow. As a recommended practice, obtain and document consent in every state.

Disclaimer: This article provides general information about HIPAA compliance and AI tools based on publicly available information as of September 2026. It does not constitute legal advice. Healthcare organizations should consult qualified legal counsel and compliance experts to confirm their specific use of any technology meets HIPAA requirements and other applicable regulations. AI provider policies and features are subject to change.

Sources

Try BastionGPT free for 7 days

Draft progress notes, letters, and treatment plans in a HIPAA-compliant AI assistant. A signed BAA is included on every plan, and pricing starts at $20 a month.

Start your free trial