Try Symbal free for 7 days. No credit card required.
    Symbal basics

    Is Symbal HIPAA compliant? What we do with your audio

    Spencer Tolleson · CEO at Symbal · September 17, 2026 · 7 min read

    Key takeaways

    • Yes. We sign a Business Associate Agreement at signup, encrypt in transit and at rest, and host on AWS in the US.

    • Audio goes to Deepgram for transcription and to OpenAI for note writing. Both have signed BAAs with us.

    • Audio is kept 30 days by default, then hard-deleted. Your practice can change that window.

    • You can flag any patient as do-not-record, and you can ask us to delete data within 72 hours.

    • We do not train AI models on patient data.

    Your practice manager asked the question every practice manager should ask: "Where does the recording go?" It's a fair question. You shouldn't need a 30-minute demo to get a straight answer.

    Here is the exact path your audio takes. Every step, from the moment you tap record to the day the file gets wiped. We wrote it in plain English so you can send it to whoever handles IT or compliance for your practice. Nothing is hidden in fine print.

    What does HIPAA compliant mean for a med spa scribe?

    HIPAA compliance means a software vendor legally binds itself to protect your patient data and encrypts that data everywhere it goes. It starts with a Business Associate Agreement, or BAA. A BAA is a legal contract. It says if we touch your patient data, we have to guard it the way federal law requires. If we drop the ball, we take on the legal liability. Symbal signs a BAA with your practice the second you create an account, and we hold signed BAAs with every vendor that handles your files.

    Here is the part most people get wrong: there is no such thing as HIPAA certification. The federal government does not inspect software companies and hand out certificates. So if a vendor tells you their product is "HIPAA certified," they are describing something that does not exist. Treat it as a warning sign.

    What happens to your audio when you record a visit?

    1. A provider taps record

    You hit record on your phone, your tablet, or our Chrome extension. Your patient should already know you're recording. If you flagged that patient as do-not-record, the session will not record.

    2. The audio is encrypted and uploaded

    Audio travels to our servers using TLS 1.2 or higher. The moment it lands, we encrypt it with AES-256. Our servers live on AWS in Oregon. Patient data never leaves the United States.

    3. Deepgram turns the speech into text

    We send the audio file over to Deepgram. They run speech-to-text. We have a signed BAA with them, so they follow the same rules we do.

    4. OpenAI turns the transcript into a structured note

    Next, the transcript goes to OpenAI under our signed BAA. It comes back as a structured SOAP note. Our agreement covers protected health information, and patient data is not used to train models.

    5. The note waits for the provider

    The draft note sits inside Symbal. You read it. You edit it. You approve it. Only then does our Chrome extension push the text into your chart. Nothing touches Boulevard, Aesthetic Record, or PatientNow until you sign off.

    6. The audio is deleted

    We keep audio for 30 days by default. Then we hard-delete it. Hard-deleted means wiped, not sitting in a recycle bin. Your practice can shorten or lengthen that window in settings.

    Who touches your patient data?

    Three companies, and that's the whole list.

    VendorWhat it doesBAA signed
    SymbalRecords, stores, shows the note, fills the EMRYes, with your practice at signup
    DeepgramSpeech to textYes, with Symbal
    OpenAITranscript to structured noteYes, with Symbal

    Hosting runs on AWS in the US, Oregon region. No ad network. No analytics vendor with access to your audio. No offshore processing.

    What controls does your practice have over audio data?

    You control how audio and notes are stored or wiped in your account. You don't have to open a support ticket or call sales to manage your files.

    • Do-not-record flag, per patient. Tag a patient once and that patient is never recorded.

    • Custom retention window. Thirty days is the default. You can make it shorter or longer.

    • Deletion on request. Ask, and we delete within 72 hours.

    • Audit log. Ask, and we provide one.

    What happens if there is a security breach?

    If we discover a breach involving your patient data, we notify you within 5 business days. That commitment is written into our BAA, not just this post.

    We're also careful about what we don't claim. We never say our system is "end-to-end encrypted." Any tool that transcribes audio on a server has to decrypt the file to read it, so that phrase doesn't describe what's actually happening. We say encrypted in transit and at rest, because that's what it is.

    HIPAA controls how you store data. State law controls whether you can record in the treatment room at all. California is an all-party consent state under Penal Code 632, which means every person in the room has to agree before you hit record.

    Other states commonly listed as all-party consent include Florida, Washington, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, Connecticut, Michigan for third parties, Nevada for phone calls, and Oregon for in-person conversations. Confirm the rule for your state, and verify with a healthcare attorney. A line on your intake form plus a verbal heads-up usually covers it. Something like: "I'm going to record this so I can focus on you instead of a screen, is that okay?"

    Frequently asked questions

    Who can see my recordings?

    The users in your practice's Symbal account, according to the access you give them. Deepgram and OpenAI process the audio and transcript under BAA to do their one job, and nothing else. If you want to see who accessed what, ask us for the audit log.

    Can I turn it off for one patient?

    Yes. Flag that patient as do-not-record and the session will not record. You can still write the note by hand in your EMR the way you do today.

    What if I cancel my account?

    Ask us to delete your data and we delete it within 72 hours. Your audio was already on its way out under the 30-day default. If you want an export of your notes first, ask before you cancel.

    Do you train AI models on my data?

    No. Symbal does not train AI models on patient data, and our BAA with OpenAI covers this as well. Your patients' visits are not anyone's training set.

    If this answers your IT person's questions, the next step is to see the note it produces. Try Symbal free for 7 days, no credit card required.

    Tags

    med spa hipaa complianceai scribe securitypatient audio privacydeepgram baaopenai baaaesthetic record hipaaboulevard chart securitypatientnow compliance

    Try Symbal free for 7 days

    No credit card. $65 per provider per month after that.

    Try for free