All engagements conducted under NDA·Evidence preserved to technical chain-of-custody standards·Engagements limited to qualified organizations

Free scanThe studyForensic TriageForensic AuditAI VendorsResearch
Free scan · no install

Does Otter.ai have a HIPAA BAA, and does it train on your recordings?

Basic, Pro & Business: No BAA, HIPAA is Enterprise-only · Trains on de-identified recordings and transcriptions, with no plan-based exception published · Retention not stated

Enterprise: BAA on request · Whether a BAA changes the training posture is not stated · Customer-defined retention

Basic, Pro & BusinessEnterprise
HIPAA BAANo"HIPAA compliance is only available for the Enterprise plan"; Business at $30/user/month is not coveredYeson request - contact your account manager to start the BAA process. Otter is not a covered entity by default; it becomes a Business Associate only once a BAA is signed
Trains on your dataYesOtter trains "on de-identified audio recordings and on transcriptions"; the privacy policy states no plan-based exception. Imported documents (e.g. from Google Workspace) are excluded from trainingNot publicly clarified for this tierthe privacy policy states training on de-identified recordings and transcriptions with no plan-based carve-out, and no document states whether an executed BAA changes that posture
Survives deletionNot publicly statedthe privacy policy gives no retention timeline, only that deletion renders data "irrecoverable or irreproducible"; customer-defined retention is an Enterprise controlCustomer-defined retention policies; Otter deletes data on contract termination at customer request. No default retention period stated
Deployer / admin log accessNot publicly stated for these tiersadmin controls are documented for EnterpriseYesEnterprise admin controls are documented
Third-party attestationSOC 2 Type 2 stated on Otter's Privacy & Security page. ISO 27001/2 is described as the framework their policies are "created based on," not a certification. Scope by plan not statedSOC 2 Type 2 stated; ISO 27001/2 described as a framework basis, not a certification
Commonly mistaken for — Basic, Pro & Business

Otter Enterprise, the only plan with a BAA - paying $30/user/month for Business does not get HIPAA coverage; also Otter's ISO 27001/2 wording, which describes a framework basis rather than a certification

Commonly mistaken for — Enterprise

The Business plan, which has no BAA; also the assumption that signing a BAA turns training off, which Otter's published policy does not state

Source: https://help.otter.ai/hc/en-us/articles/33975072019991-HIPAA-Otter-aiDocument: Otter.ai Help Center - HIPAAVerified: September 2, 2026Verified by: Adil — Shadow AI Forensics

Vendor terms change without notice. This page reflects what Otter.ai published as of September 2, 2026. Re-verified quarterly.

This page states what the vendor published. It does not score them.

If you need a scored Go / Conditional Go / No-Go verdict for a vendor decision — including a vendor not listed here — that's an AI Vendor Risk Assessment: three binary industry gates, nine scored criteria, four provenance fields on every finding. $997, delivered in 48 hours.

See how AVRA works →

Want all 13 tools in one file?

AI Vendor Compliance Quick-Reference

Covers 22 tiers across 13 tools — same sourcing, side by side, printable for a vendor file.