Is Otter.ai HIPAA Compliant? Using Otter With Health Data
The plan you are on decides the answer, and most people are on the wrong one for PHI.
Otter.ai is HIPAA compliant only on its Enterprise plan, and only after you sign a Business Associate Agreement (BAA). The free, Pro, and Business plans are not HIPAA compliant.
Otter announced HIPAA compliance in July 2025. That was a real change, but it applies to a narrow slice of accounts.
If you record patient visits, therapy sessions, or any meeting with protected health information (PHI) on a consumer Otter plan, you are not covered. This guide explains the gap and how to close it.
The Short Answer
Otter.ai can be HIPAA compliant, but only on the Enterprise plan with a signed BAA in place first.
Otter is not a HIPAA-covered entity by default. It becomes a business associate only when your organization and Otter execute a BAA.
That BAA must be signed before any PHI touches the tool. Free, Pro, and standard Business accounts do not qualify.
So the answer depends entirely on your plan and your paperwork. Most individual users have neither.
Want the whole playbook, not just this page? The Complete Medical Practice AI Implementation Guide (2026) is the full step-by-step rollout for medical & dental practices.
Get the guide — $59 (reg. $89)How Otter Works With Your Data
Otter records or joins your meeting, sends the audio to its cloud, and transcribes it there. It then generates AI summaries and action items.
The audio and transcript live on Otter's servers, not only on your device. This is the core fact that matters for health data.
Otter's assistant can auto-join calendar meetings on Zoom, Google Meet, and Microsoft Teams. That means it can start recording without a person clicking record each time.
For a covered entity, every one of those steps counts as handling PHI in the cloud. HIPAA treats the vendor storing that data as a business associate.
- Capture: Otter records live or joins your video meetings.
- Cloud transcription: audio is processed and stored on Otter servers.
- AI features: summaries, action items, and search run on the stored transcript.
- Sharing: transcripts can be shared by link or to a workspace by default settings.
What HIPAA Actually Requires From a Tool
HIPAA requires a signed BAA before a covered entity lets any vendor create, receive, store, or transmit PHI. This is the non-negotiable gate.
A BAA is a contract. It binds the vendor to safeguard PHI, limit how it uses the data, and report breaches.
Marketing words like "secure," "encrypted," or even "HIPAA compliant" do not replace a signed BAA. The U.S. Department of Health and Human Services is clear that the agreement itself is required.
Encryption and SOC 2 Type II are good controls. They are not the same as a legal BAA that names your organization.
What Otter Enterprise Covers Now
Otter Enterprise can support HIPAA workloads once a BAA is executed with Otter. This is the only tier where that is offered.
Otter says it added stricter controls for this tier. These include encrypted storage and transmission, limited access to PHI, and restrictions on using customer data for AI model training.
Otter also holds SOC 2 Type II certification, which it says complements the HIPAA work. SOC 2 is an audited security standard, not a HIPAA sign-off.
To start, an organization contacts its Otter account manager or the Otter sales team to begin the BAA process. You cannot self-serve a BAA from inside a free account.
- Plan required: Enterprise only.
- Prerequisite: a signed BAA before any PHI is handled.
- Controls cited: encryption, access limits, and training restrictions on PHI.
- How to start: contact your Otter account manager or sales.
The Gaps on Free, Pro, and Business Plans
On free, Pro, and standard Business plans, Otter offers no BAA, so those tiers cannot lawfully hold PHI for a covered entity.
Consumer plans historically used account data to improve Otter's services. If your plan allows training on your content, that is a hard stop for PHI.
Retention is also a concern. Transcripts can sit in the cloud indefinitely unless you delete them, which multiplies your exposure over time.
Sharing defaults add risk too. A transcript shared to a workspace or by link can reach people who were never meant to see health details.
In our AI-compliance work with healthcare-adjacent and nonprofit clients, the failure mode we see most is staff pasting client data into consumer AI tools with no BAA. Otter on a personal plan is a textbook example.
The Otter Privacy Lawsuit Context
Otter faces a consolidated federal class action, In re Otter.AI Privacy Litigation, over how it records meetings. This is a live case, not a ruling.
The consolidated complaint was filed on December 5, 2025. It brings claims under the federal Electronic Communications Privacy Act (ECPA) and the California Invasion of Privacy Act (CIPA).
Plaintiffs allege Otter recorded conversations without all-party consent and used content to train its models. Otter disputes the claims, and a motion-to-dismiss hearing was set for May 2026.
No court has ruled that Otter's practices are illegal. Still, the case is a clear signal to treat recording consent and data training as real compliance risks. Our full breakdown is linked below.
- Case: In re Otter.AI Privacy Litigation (consolidated).
- Filed: December 5, 2025.
- Claims: federal wiretap (ECPA) and California CIPA.
- Status: pending, no finding of liability.
You Still Need Consent to Record
HIPAA is not the only rule in play. Recording a conversation can trigger state wiretap and two-party consent laws.
In all-party consent states, every person on the call must agree before you record. An AI notetaker that joins quietly does not satisfy that on its own.
For health data, you often need consent for both recording and for processing the PHI. These are separate obligations.
Build consent into your workflow, not an afterthought. Our consent guide, linked below, walks through the practical steps.
Safe Ways to Use Otter, and When to Switch
You can safely use consumer Otter for meetings that contain no PHI, such as internal ops syncs or general marketing calls.
If a meeting will include patient names, diagnoses, or any health detail, you need Otter Enterprise with a signed BAA or a different HIPAA-ready tool.
Do not rely on redacting later. PHI that reaches an uncovered cloud is already a disclosure, even if you delete it after.
If Otter Enterprise is not an option, choose a scribe or notetaker that will sign a BAA for your plan. Our roundup of HIPAA-compliant AI note-takers, linked below, compares the realistic choices.
- Safe: non-PHI meetings on any Otter plan.
- Not safe: PHI on free, Pro, or Business plans.
- Compliant path: Otter Enterprise plus a signed BAA.
- Alternative: a note-taker that signs a BAA on your tier.
The Verdict
Otter.ai is HIPAA compliant only on Enterprise with a signed BAA, and not on any consumer plan. Match your plan to your data before you record.
If you handle PHI and cannot confirm both the Enterprise tier and an executed BAA, stop using Otter for that data today.
Plans and terms change, so verify your exact status directly with Otter and with your own compliance counsel.
The goal is simple. No PHI should ever sit in a tool that has not signed to protect it.
Frequently Asked Questions
- Only on the Enterprise plan with a signed BAA. Otter announced HIPAA compliance in July 2025, but the free, Pro, and standard Business plans are not covered and cannot lawfully hold PHI.
- Yes, but only for Enterprise customers. You must contact your Otter account manager or sales team, and the BAA has to be executed before any PHI is handled in the tool.
- No. Those plans do not include a BAA, so putting PHI in them would violate HIPAA. Use Otter Enterprise with a BAA or a different HIPAA-ready note-taker instead.
- On its Enterprise HIPAA tier, Otter says it restricts using customer data for AI model training. Consumer plans have historically used account data to improve the service, which is a problem for PHI.
- A consolidated federal class action, In re Otter.AI Privacy Litigation, alleges Otter recorded meetings without all-party consent and used content to train its models. The case is pending, and no court has found Otter liable.
- Often yes. Many states require all parties to consent before a call is recorded, and an AI notetaker joining does not satisfy that by itself. For health data you may also need consent to process the PHI.
- Look for AI scribes and note-takers that will sign a BAA for your specific plan. Our roundup of HIPAA-compliant AI note-takers compares realistic options for clinical and health-adjacent teams.
- No. SOC 2 Type II is an audited security standard, and Otter holds it, but it does not replace a signed BAA. HIPAA compliance for a vendor still requires that contract.
The complete AI playbook for medical & dental practices
The Complete Medical Practice AI Implementation Guide (2026): HIPAA-compliant vendor selection, scribes, voice agents, scheduling and intake, front-desk automation, dental-specific plays, and the specialty cuts — for the owner rolling AI into a real practice in 2026.
Get the guide — $59 (reg. $89)