HIPAA Compliant. Every Paid Plan Includes a Signed BAA.
Clinical documentation means handling protected health information on every visit. Notiro's policies, hosting, and Business Associate Agreement are built around that reality from day one, not adapted to it after the fact.
How Notiro Protects PHI
The Practices Behind the Claim
A HIPAA compliance claim is only as good as what's actually behind it. Here's what that looks like for Notiro, plainly stated.
HIPAA Compliant
Notiro's policies and data handling practices are designed to protect PHI in line with HIPAA requirements.
Business Associate Agreement
A signed BAA is included on every paid Notiro plan: Starter, Professional, and Enterprise. Most requests are reviewed and signed within 48 hours.
US-Based Hosting
Notiro's patient data is hosted on Microsoft Azure, in the United States. Audio and clinical documentation are not stored or processed outside the US.
No PHI Used for AI Training
Protected health information from patient encounters is never used to train Notiro's underlying AI models.
Provider-Controlled Data Retention
Audio is retained for up to seven years by default. Any provider can request immediate deletion at any time, and Notiro processes that request right away.
Annual HIPAA Training
Every Notiro employee completes HIPAA training annually as part of the company's internal compliance program.
SOC 2 Type II (In Progress)
Notiro is currently pursuing SOC 2 Type II certification. Contact our compliance team for current status and available documentation.
The Business Associate Agreement
What a BAA Is, and Why
It Can't Be an Afterthought
Under HIPAA, any vendor that creates, receives, stores, or transmits protected health information on behalf of a healthcare provider is acting as a business associate. That relationship has to be governed by a signed BAA before any real patient data touches the platform, not arranged retroactively once a practice is already using the tool.
Request
Email [email protected], or ask your account contact, once you're on a paid plan.
[email protected]
Review
Notiro's compliance team reviews the agreement and prepares it for signature.
Signed
Most BAAs are reviewed and returned within 48 hours of the original request, ready before your first recorded patient visit.
~48 hours
In plain terms: if you record a real patient visit with an AI scribe and no BAA is in place, the practice carries that compliance risk regardless of how secure the underlying technology is. A signed BAA is what makes the relationship enforceable.
Audio Retention & Deletion
You Control How Long
Your Data Actually Stays
Notiro retains audio for up to seven years by default. That default is never the only option.
Day 0
Visit recorded
Audio is captured and stored on
US-based Azure infrastructure.
Year 7
Standard retention ends
Default deletion point if no earlier
request has been made.
Or, at any point

Request deletion whenever you need to
Any provider can ask Notiro to delete their audio at any time, for any reason. The request is processed immediately, not queued behind the seven-year default.
A Note on Patient Consent
Telling Patients You're Using an AI Scribe
Many clinicians choose to let patients know that a tool like Notiro is helping with documentation during the visit. Exact consent requirements vary by state and specialty, so this is worth confirming with your own compliance officer or legal counsel rather than treating any general guidance as a final answer. If it would help to talk through how other practices have built this into their workflow, reach out to [email protected].
Frequently asked questions
Find quick answers to the most common questions about Notiro — how it works, what it documents, and how it fits into your clinical workflow.
Yes. Notiro's policies and data handling practices are designed to protect PHI in line with HIPAA requirements.
Yes. A BAA is included on every paid Notiro plan, Starter, Professional, and Enterprise. It is not an enterprise-only add-on or something that requires a custom quote to access.
Most requests are reviewed and signed within 48 hours of being submitted to [email protected]. There's no sales call required before the request can be made.
All data is hosted in the United States on Microsoft Azure. Notiro does not store or process patient data outside the US.
No. Protected health information from patient encounters is never used to train Notiro's underlying AI models.
Audio is retained for up to seven years by default. Any provider can request immediate deletion at any time, and that request is processed right away rather than waiting for the default retention window to end.
Yes. Every Notiro employee completes HIPAA training annually as part of the company's internal compliance program.
Notiro is in the process of completing SOC 2 Type II certification. Contact [email protected] for the current status and to request available documentation.
Email [email protected]. Our compliance team handles BAA requests, security questionnaires, and any other compliance-related questions directly, without routing through sales.