Skip to content
SessionSoundthe sound of care, handled with care

The dated record

Audio tools and BAAs: what vendors publish

This page does one job, narrowly and on purpose. It records what four companies publish about business associate agreements and HIPAA, in their words, with the date we read them — so that when you sit down with the person who actually advises you on compliance, the conversation starts from quotations rather than from marketing impressions. That is the entire contribution. We are a technology desk, and the determination you need is not one a technology desk can make.

Read this before anything else on the page. SessionSound does not certify any vendor as HIPAA-compliant, and we would be wrong to — there is no such certification to hold, and compliance is a property of your practice's whole arrangement, not of a product you installed. Everything below is a vendor's own published claim, quoted and dated. Nothing here is medical, legal, or compliance advice. Verify all of it with your compliance counsel before you rely on any of it, and treat a page last updated in September 2026 as a starting point rather than a current state.

The one structural fact worth internalizing

Before the vendor-by-vendor record, the pattern that explains most of the confusion in this category: a BAA is something executed, not something included. Buying a qualifying plan does not put an agreement in place. Somebody has to request it, somebody has to sign it, and it has to exist as a document before the arrangement it describes means anything. Practices get caught out by this repeatedly — they upgraded to the right tier two years ago, assumed the paperwork came with it, and have never had a signed agreement.

A BAA is something executed, not something included
  1. Buying a qualifying plandoes not put an agreement in place
  2. Somebody has to request it
  3. Somebody has to sign it
  4. It has to exist as a documentbefore the arrangement means anything

The page’s structural fact, drawn as steps. Which vendor, plan or practice needs one is a question for your compliance counsel — not a determination this page makes.

The second-most-useful pattern: vendors are far more precise about BAAs in their security and trust documentation than on their marketing pages. A homepage badge reading "HIPAA-compliant" tells you a company's positioning. A sentence in the trust centre naming which tier can sign a BAA tells you something you can act on. Where the two disagree, believe the boring document.

Two kinds of vendor page
  • A homepage badgetells you a company’s positioning
  • A sentence in the trust centrenaming which tier can sign a BAA tells you something you can act on

Where the two disagree, believe the boring document.

Krisp — specific, and worth reading closely

Krisp is the tool we recommend most on this site, which is exactly why its compliance record gets the most careful treatment. Read 2026-09-20, Krisp's security page for the AI Meeting Assistant states:

"Signing a Business Associate Agreement (BAA) is available to subscribers of the Business tier of Krisp AI Meeting Assistant only." — Krisp security documentation, read 2026-09-20. Customers are directed to contact Krisp to request a copy.

A discrepancy we are obliged to flag: on the same date, krisp.ai/pricing listed its Meeting AI tiers as Core, Advanced, and Enterprise. There is no tier named "Business" on the pricing page. We do not know whether this is a legacy plan name, a renaming that the security documentation has not caught up with, or a distinct enterprise arrangement. We are not going to guess on your behalf — if a BAA matters to your practice, make Krisp name the specific plan in writing.

The plan-name discrepancy, as read on 2026-09-20

Krisp security documentation

“…the Business tier of Krisp AI Meeting Assistant only.”

krisp.ai/pricing, same date

CoreAdvancedEnterprise

No tier named “Business” on the pricing page. We do not guess the mapping — ask Krisp to name the plan in writing.

Krisp's HIPAA Notice adds a posture that repays a slow read: "Krisp does not knowingly collect, access, retain, process, or disclose any ePHI," noting that it does not inspect content for ePHI and applies the same security standards to all user content regardless. Read carefully, that is a vendor describing itself as not looking at your content — which is reassuring about intent and is not the same thing as a contractual undertaking about your specific use. The Notice also states that where a BAA is in place with a corporate customer, Krisp acts in accordance with its terms, and it names a Privacy Officer contact.

On assurance, Krisp publishes a SOC 2 Type II report through its Trust Center. Worth knowing what that is: an auditor's attestation that described controls operated effectively over a period. It is a genuine signal and it is not a HIPAA certification, because no such thing exists.

Our reading for a solo or small practice, offered as reasoning rather than advice: the suppression-only configuration — assistant features off, processing local — is the one that raises the fewest questions, because it is the configuration in which the tool is not handling session content at all. The moment you switch on transcription and summarization, you are in a different conversation, and the details in where your session audio goes are the ones to bring to it.

Doxy.me — the badges, quoted

Doxy.me's homepage, read 2026-09-20, carries the claims "HIPAA-compliant," "Free BAA," "SOC 2-certified," "End-to-end encrypted," "GDPR-compliant," and "CPRA-compliant," alongside "No downloads." A free tier for individual providers is offered.

Reported as published. Two observations that are ours rather than Doxy.me's: "Free BAA" is an unusually low-friction position in this market and a genuine point in the platform's favour for solo practitioners — but per the structural fact above, free still means executed, so find the document and sign it rather than assuming the badge covers you. And "end-to-end encrypted" is a phrase with real technical meaning that varies with call configuration; if that specific property is load-bearing for your compliance posture, it is worth asking Doxy.me to describe precisely which sessions it applies to.

SimplePractice — inside the suite

Read 2026-09-20, SimplePractice's telehealth feature page presents itself as "HIPAA-Compliant Telehealth," displays HIPAA, HITRUST, and PCI badges, and links to a dedicated BAA page. Telehealth is a built-in feature of the practice-management suite rather than a separately evaluated product.

The structural consequence for audio, which is our actual lane: when telehealth is one feature of a suite, the compliance arrangement covers the suite, and the audio path is not independently configurable to any meaningful degree. What remains in your control is everything in the core guide — connection, microphone distance, machine hygiene — plus, if you add one, a local suppression layer that sits outside the platform entirely.

Zoom — precise about the mechanism, silent on the tiers

Zoom's HIPAA compliance page, read 2026-09-20, states: "Zoom helps customers enable HIPAA compliant programs by executing a Business Associate Agreement (BAA) and safeguarding protected health information (PHI)." The page states that Zoom "aligns its controls to the Healthcare Industry Trust Alliance Common Security Framework (HITRUST CSF)" and offers a SOC 2 + HITRUST report to healthcare customers seeking assurance.

What that page does not do is list which subscription plans are eligible to execute a BAA. We checked, because we wanted to publish the list. It is not there. Third-party guides state the eligible tiers confidently and do not agree with one another, which is the clearest possible signal that this is a question to put to Zoom directly rather than to a comparison article — ours included. What survives is the structural point: the BAA is executed as a separate step, and an account without one in place is outside the arrangement regardless of what it cost.

The record, side by side

Vendor-published positions as read on 2026-09-20. Quotations are the vendors'; the "our note" column is ours. This is a record for your counsel, not a compliance determination by SessionSound.
VendorPublished BAA positionPublished assuranceOur note
KrispBAA "available to subscribers of the Business tier of Krisp AI Meeting Assistant only"SOC 2 Type II report via Trust Center; HIPAA Notice; named Privacy Officer"Business tier" is not a plan name on the current pricing page — get the mapping in writing
Doxy.me"Free BAA" stated on homepage"SOC 2-certified," "HIPAA-compliant," "GDPR-compliant," "CPRA-compliant" badgesLow friction, genuinely helpful for solo practice — still has to be executed
SimplePracticeDedicated BAA page linked from telehealth feature pageHIPAA, HITRUST, and PCI badgesSuite-level arrangement; audio path not independently configurable
ZoomStates it enables HIPAA programs "by executing a Business Associate Agreement (BAA)"; eligible plans not enumerated on that pageHITRUST CSF alignment; SOC 2 + HITRUST reportAsk Zoom which plan qualifies — the public sources conflict

What we will not tell you

A short list, because being explicit about the boundary is more useful than gesturing at it. We will not tell you whether your practice needs a BAA with an audio-tool vendor. We will not tell you whether a given tool is safe for your caseload, your jurisdiction, or your professional body's requirements. We will not tell you whether noise suppression touches PHI in a way that matters legally — that is a genuinely contested question and the people arguing it have credentials we do not. And we will never put the words "HIPAA-compliant" next to a product on our own authority, no matter how many badges its homepage carries.

What we will keep doing is this: read the documentation, quote it exactly, date it, flag the places where a vendor's own pages contradict each other, and hand you something concrete enough to be worth a professional's time. A discrepancy like the Krisp plan-name mismatch above is precisely the kind of thing that is invisible from a marketing page and obvious from a trust centre — and finding those is a job a technology desk can honestly do.

The configuration that raises the fewest questions

If you want a suppression layer without adding a party to the session, Krisp run as suppression-only — assistant features off, processing local per its security documentation — is the setup we describe throughout this site. Checked 2026-09-20: 7-day free trial, then Core at $8/month billed annually or $16 monthly.

Try the 7-day free trial

A referral link, said plainly: if a Krisp subscription starts from this button, Krisp may pay SessionSound, and what you pay stays the same. It has not softened a word above — the plan-name discrepancy we flagged is about the vendor we earn from. The recommendation on this page that pays us nothing: Doxy.me's free tier with its free BAA, which for a solo practice starting out is a genuinely strong answer.