Is Nabla HIPAA Compliant?
A BAA you cannot avoid agreeing to, and one clause worth narrowing before you sign.
The Verdict: Is Nabla HIPAA Compliant?
Is Nabla HIPAA compliant? Yes. The BAA is a mandatory appendix to Nabla's Terms of Service, so it covers every plan and no customer can decline it.
Section 8.1 is the one clause to manage: it reserves Nabla's right to freely use fully de-identified patient information. Narrow it in contract.
Verified against Nabla's Terms of Service BAA appendix, 2026-07-12.
| BAA | All plans, mandatory Terms of Service Appendix I |
| Trains on your data | No identifiable PHI; de-identified data use reserved in Terms of Service section 8.1 |
| Enterprise controls | Configurable retention, no audio storage by default, SOC 2 Type II, ISO 27001; SSO and audit logs UNVERIFIED |
| Sources | nabla.com/docs/terms-baa, trust.nabla.com, nabla.com/security, help.nabla.com |
This is not legal advice, and your counsel makes the call for your organization.
The Catch
"Freely use, fully anonymized and de-identified" is broad language. Defensible under HIPAA, worth narrowing for a health system with data-governance standards.
If Your Staff Use It
Ambient scribes spread clinician-to-clinician faster than any category here. If one department has it, assume three do.
Clinician-to-clinician is the entire distribution model. One physician shows another what it did to her charting time, and three departments are running it before anyone files a request. AI adopted by recommendation instead of procurement is what that produces, and a mandatory BAA appendix settles the contract while telling you nothing about the footprint.
Nabla and HIPAA: Common Questions
Does Nabla sign a BAA?
Yes. Nabla's BAA is a mandatory appendix to its Terms of Service, so it applies on all plans and there is no request process. Section 8.1 reserves broad rights over fully de-identified data, which is worth narrowing in contract.
Is this legal advice?
No. This is not legal advice, and your counsel makes the call for your organization.
Related Resources
Continue across the compliance directory and the core governance hubs
AI Tool HIPAA Compliance Directory
Every "is X HIPAA compliant" verdict in one sourced, dated directory
Read article →HIPAA & AI Compliance
How HIPAA applies to AI tools and what OCR expects in 2026
Read article →Healthcare Shadow AI Use Cases
Where shadow AI shows up across clinical and administrative workflows
Read article →Best HIPAA Compliant AI Platforms
An independent comparison of governed AI platforms for healthcare
Read article →The Policy Question Comes Before The Rollout Question
Whether it is Nabla or another ambient scribe, the first control is a policy your staff can follow. Generate a healthcare-ready draft in minutes, then decide which tools earn a place in it.