Short answer: "HIPAA compliant" is not a badge a platform earns and displays. It is a signed Business Associate Agreement (BAA) plus a specific set of administrative, technical, and physical safeguards under the HIPAA Security Rule, each of which is either documented and current or it is not. A vendor's marketing page saying "HIPAA compliant" tells you nothing until you have checked the artifacts behind the claim.
This draws on Oasys's ongoing conversations with practice owners evaluating exactly this question, plus Oasys's own seat at the infrastructure layer of real practices, where session audio, consent, and documentation actually move through a system every day. The pattern that recurs: therapists trust the phrase "HIPAA compliant" less the more software they have evaluated, because nearly every vendor uses it and few explain what specifically backs it up.
That is the real distinction worth drawing: not whether a platform claims compliance, but whether it can name, specifically, what a practice is allowed to verify before signing. Below is what "HIPAA compliant" actually requires, what to check for session audio and AI documentation specifically, and the questions worth asking before a demo turns into a contract.
What "HIPAA compliant" actually requires
Two things, concretely. First, a signed Business Associate Agreement (BAA) naming every vendor in the chain that touches protected health information, not just the primary platform. Second, documented Security Rule safeguards across three categories: administrative (who can access what, and why), technical (encryption in transit and at rest, audit logging, automatic logoff), and physical (where data physically lives and who can reach it).
Oasys's position is that a BAA is table stakes, not a feature to sell, and that a practice should be able to ask any vendor, Oasys included, to name every business associate touching a session before signing anything. A platform that treats its BAA as a differentiator is telling a practice something about how low the bar was to begin with.
Session audio and AI documentation specifically
This is where compliance claims get vague fastest, because "we're HIPAA compliant" says nothing about what happens to the actual recording of a session.
Other platforms may be built differently. Oasys does not store session audio: it transcribes during the session, and the audio itself is gone when the session ends. That single fact determines whether an audio artifact of a client's session exists anywhere that could later be reached by a data request or a subpoena, and it is the first question worth asking any AI-documentation vendor.
Consent is the second piece, and it should be per-client, not a practice-wide toggle. Oasys allows clients to opt in or out of AI note-taking individually, rather than switching the whole practice on or off at once, so a clinician working with a client who declines is not stuck choosing between the tool and that client's preference.
The transcript itself needs a defined lifecycle. Oasys removes the transcript from the record once the note is signed and locked, so what remains in the chart is the finished clinical note, not a verbatim log of everything said in the room. A persisted transcript is a second, more detailed record of a session that can be reached separately from the note itself, which is exactly the exposure a defined deletion lifecycle is meant to close.
Access controls and audit logging
The technical safeguards that matter most in practice are role-based access (a biller should not see full clinical notes; a supervisor should see only their supervisees) and an audit trail of who viewed or changed what, when. These are Security Rule requirements, not optional extras, and a practice should be able to review how a platform documents them rather than take the claim on faith.
Oasys documents its access-control and audit-logging safeguards for a practice to review directly, the same standard it expects any vendor touching client data to meet.
Common compliance evaluation mistakes
Treating "HIPAA compliant" as a fixed claim rather than a set of checkable artifacts. The phrase means nothing without the BAA and the safeguards behind it.
Assuming a signed BAA with the primary platform covers every vendor in the chain. AI transcription, storage, and analytics providers may each be separate business associates requiring their own agreement.
Not asking about audio retention specifically. A platform can be broadly HIPAA compliant and still retain session audio far longer than a practice assumes, simply because nobody asked.
Treating consent as a practice-wide setting. A single on/off switch for AI note-taking is a design limitation a practice inherits, not a requirement HIPAA imposes.
What to ask before you commit to a platform
Can you name every business associate, not just the primary vendor, that touches session audio or notes?
Is session audio stored, and if so, for how long, and can that answer be found in the contract rather than a sales call?
Is consent for AI documentation per-client or practice-wide?
What is the deletion lifecycle for a transcript once a note is signed?
Are access controls and audit logging documented in a way a practice can actually review, not just asserted?
How Oasys handles it
Oasys treats every vendor that touches session audio or a drafted note as a HIPAA business associate by default. Audio is not stored: transcription happens during the session and the audio is gone once the session ends. Consent is per-client, not a practice-wide toggle. The transcript is removed once a note is signed and locked, leaving the finished clinical note as the record. Access controls and audit logging are documented for a practice to review before signing, not asserted without evidence.
FAQ
What does "HIPAA compliant" actually mean for a therapy platform? It means a signed Business Associate Agreement covering every vendor that touches protected health information, plus documented administrative, technical, and physical safeguards under the HIPAA Security Rule. The phrase alone, without those artifacts, is a marketing claim.
Does a HIPAA compliant platform store session audio? It depends on the platform, and this is one of the most important questions to ask directly. Oasys does not store audio: it transcribes live and the audio is gone when the session ends. Other platforms may retain audio for longer, which a practice should confirm in the contract, not assume.
Can a client opt out of AI note-taking without the whole practice losing the feature? On Oasys, yes, consent is tracked per client rather than as a single practice-wide switch. Other platforms may only offer an all-or-nothing toggle, which forces a practice to choose between the tool and an individual client's preference.
Do I need a separate BAA for an AI transcription vendor if my EHR already has one? Often yes, if the transcription provider is a distinct business associate from the primary platform. A practice should ask any vendor to name every party in the chain rather than assume one BAA covers all of them.
What happens to the session transcript after a note is signed? On Oasys, the transcript is removed from the record once the note is signed and locked, leaving the finished note as the chart entry. Other platforms may retain the full transcript indefinitely, which is worth confirming since a persisted transcript is a more detailed, separately discoverable record of the session.
"HIPAA compliant" is a claim a vendor makes about itself. The safeguards behind it are the only part a practice can actually verify, and verifying them before signing is cheaper than discovering the gap after a breach.
Mariam Shaker··


