Is Nabla HIPAA Compliant?
A BAA you cannot avoid agreeing to, and one clause worth narrowing before you sign.
The Verdict
Nabla makes its BAA a mandatory appendix of its Terms of Service, you cannot use the service without agreeing to it. Audio is not stored by default and clinical notes retain for a configurable 14 days.
One clause to manage, the Terms of Service reserves Nabla's right to freely use fully de-identified patient information, so organizations wanting tighter terms should address it in contract.
| BAA | All plans, mandatory Terms of Service Appendix I |
| Trains on your data | No identifiable PHI; de-identified data use reserved in Terms of Service section 8.1 |
| Enterprise controls | Configurable retention, no audio storage by default, SOC 2 Type II, ISO 27001; SSO and audit logs UNVERIFIED |
| Sources | nabla.com/docs/terms-baa, trust.nabla.com, nabla.com/security, help.nabla.com |
The Catch
"Freely use, fully anonymized and de-identified" is broad language. Defensible under HIPAA, worth narrowing for a health system with data-governance standards.
If Your Staff Use It
Ambient scribes spread clinician-to-clinician faster than any category here. If one department has it, assume three do.
Related Resources
Continue across the compliance directory and the core governance hubs
AI Tool HIPAA Compliance Directory
Every "is X HIPAA compliant" verdict in one sourced, dated directory
Read article →HIPAA & AI Compliance
How HIPAA applies to AI tools and what OCR expects in 2026
Read article →Healthcare Shadow AI Use Cases
Where shadow AI shows up across clinical and administrative workflows
Read article →Best HIPAA Compliant AI Platforms
An independent comparison of governed AI platforms for healthcare
Read article →The Policy Question Comes Before The Rollout Question
Whether it is Nabla or another ambient scribe, the first control is a policy your staff can follow. Generate a healthcare-ready draft in minutes, then decide which tools earn a place in it.