Start Free Trial
← All posts
The compliance checklist

HIPAA-compliant live captioning: what medical interpreters need to know

Yes, you can use AI captioning on medical calls — if the tool was built for it. Five questions decide whether one belongs near a patient. Ask them of any vendor, including us.

5 questions 8 min read Published August 2026

Medical interpreters discovered live AI captioning for the same reason everyone else did: it works now. A live transcript under your ear catches the drug name read at speed and the dosage you half-heard. But a captioning tool on a patient encounter is, by definition, processing protected health information — and most captioning tools were built for meeting notes, not medicine. The test is not the word "secure" on a marketing page. It is what happens to the audio. This guide is practical orientation, not legal advice.

What HIPAA actually covers here

HIPAA protects PHI — protected health information: health information that can be tied to a person. A live medical conversation is full of it — names, conditions, medications, dates, identifiers. Three things follow for captioning:

  • The audio of a patient encounter is PHI. A tool that hears the call is handling PHI, full stop. It does not matter that the tool is "just captioning."
  • Obligations sit with covered entities and their business associates — providers, health plans, and vendors that process PHI for them. Hospitals and agencies typically formalise vendor relationships with a business associate agreement (BAA). If you work through an agency or health system, their compliance office decides what tooling is approved — ask before you bring anything into a session.
  • "HIPAA compliant" is a posture, not a certificate. There is no government-issued HIPAA badge. What a serious vendor offers is specific, verifiable practices — encryption, no retention, access controls, audits (this is where SOC 2 comes in) — and a willingness to state all of it in writing.

The five questions that actually decide it

Ask these of any captioning or translation tool — including ours — before it touches a medical call.

Is the session encrypted end to end?

Audio and text should be encrypted in transit. A good answer names the practice plainly. A bad answer talks about "bank-level security" and names nothing.

Is audio stored?

The single most important question. Stored audio of patient encounters is a breach waiting for a mechanism. The best answer is the simplest: audio is never stored — it is processed live and discarded. That is Unicaption's answer.

What happens to transcripts when the session ends?

Retention is where meeting-notes tools fail medicine: their whole product is keeping transcripts forever. For medical work you want the opposite default — transcripts deleted when the session ends, nothing sitting in a searchable archive.

Is your data used to train models?

Many free and consumer tiers pay for themselves with your data. Patient conversations must never be training material. Look for an explicit statement that session content is not used for training.

Will the vendor put it in writing?

Any vendor serious about healthcare states its compliance posture (HIPAA, SOC 2, GDPR) publicly and answers a compliance officer's questions directly — including about formal agreements. Evasiveness here is itself an answer. For Unicaption enterprise and agency questions: hello@unicaption.com.

Red flags, in the order they actually appear

The privacy policy never mentions PHI or HIPAA. The tool was not built for this. Consumer captioning apps and built-in meeting captions generally fall here.
Recordings are on by default. If the product's mental model is "record now, read later," it is the wrong shape for patient encounters.
A free tier funded by data. Check what the free plan's privacy terms allow. "We may use content to improve our services" means training.
"We anonymise the data." Anonymising conversational health data reliably is genuinely hard; treat the claim as marketing unless it is explained.
Compliance answered only by a chatbot. If no human will answer a compliance question before the sale, nobody will answer one after.

Where responsibility still sits with you

A compliant tool does not make a session compliant by itself. The parts that stay yours:

  • Follow your engagement's rules. If you work through an agency or health system, use what their compliance office has approved. Bringing unapproved tooling into a clinical encounter is a professional risk even when the tool itself is sound.
  • Consent and transparency norms vary by state, setting, and employer. Know the ones that apply to your sessions.
  • Your own device hygiene — screen privacy in shared spaces, locked devices, no screenshots of session content.

None of this is legal advice; for a specific engagement, the answer comes from the covered entity's compliance office, not from a blog post — ours included.

Frequently asked

Is it HIPAA compliant to use AI transcription during medical appointments?

It can be, if the tool is built for PHI: encrypted sessions, no audio storage, no transcript retention, no training on your data, and a vendor that states its compliance posture in writing. Unicaption meets these conditions — it is HIPAA, SOC 2, and GDPR compliant, never stores audio, and deletes transcripts at session end. Consumer captioning tools and default meeting-notes apps generally do not meet them.

Do built-in Zoom or Teams captions count as HIPAA compliant?

Platform captions inherit the platform's agreement with the host organisation — that is between the hospital or agency and the vendor, and depends on the specific plan and settings. As an interpreter you usually cannot verify it from your seat. A dedicated tool with a public compliance posture, like Unicaption, gives you an answer you can actually check.

Does Unicaption store recordings of my medical calls?

No. Audio is never stored — it is processed live and discarded — and transcripts are deleted when the session ends. Sessions are end-to-end encrypted.

What should I ask a captioning vendor before using it with patients?

Five things: encryption of sessions, whether audio is stored, what happens to transcripts, whether your data trains models, and whether they will put their compliance posture in writing. Any hesitation on the first four is disqualifying.

Built for the calls where accuracy is not optional

HIPAA, SOC 2, and GDPR compliant, with built-in medical terminology. First 30 minutes free — no credit card.

Start Free Trial →