Healthcare AI & Medical Scribes

Microsoft Dragon Copilot (Nuance DAX Copilot)

Medium risk

Microsoft's enterprise ambient clinical AI (successor to Nuance DAX Copilot) that records patient encounters and drafts documentation inside major EHRs.

Is Microsoft Dragon Copilot (Nuance DAX Copilot) safe for confidential data?

Dragon Copilot is about as contractually well-covered as ambient clinical AI gets: enterprise-only licensing under Microsoft's healthcare cloud commitments, BAA-covered HIPAA-compliant handling, audit logging, and published retention (DAX Copilot for Epic guidance describes audio, transcript, and note summary deleted after 30 days). The open questions are deployment-level rather than vendor-level: hospitals publish their own patient-privacy FAQs precisely because ambient recording needs explicit consent workflows, some deployments state that recordings are used to help train and improve the system, and Canadian hospitals adopting it (Sunnybrook's Toronto emergency department began in July 2025) must reconcile Azure hosting regions and any US processing with PHIPA custodianship and provincial residency expectations.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Enterprise (only tier)
Conditional

Sold only through enterprise health-system contracts with a Microsoft BAA; no self-serve or free tier. Some published deployment FAQs state recordings are used to improve the system — verify and negotiate this per contract.

Data handling

Training on inputs

Varies by deployment agreement. Public hospital FAQs for DAX Copilot deployments (e.g. Sunnybrook) state recorded conversations help train and improve the system, managed under applicable health privacy law — so training rights are a contract term to verify, not assume away.

Retention

Published guidance for DAX Copilot for Epic describes recorded audio, transcript, and note summary retained for 30 days and then deleted; the finalized note lives in the EHR. Confirm the retention schedule for your specific deployment.

Residency

Runs on Microsoft Azure with regional data residency options (US, EU, UK, select APAC). Canadian deployments should confirm in-contract which Azure region processes audio and whether any processing leaves Canada, a live PHIPA and provincial-policy question.

Compliance

  • SOC 2Yes
  • GDPR / DPAYes
  • HIPAA BAAYes

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • Enterprise contract with Microsoft BAA
  • Azure regional data residency options
  • Audit logging
  • EHR-embedded access control (Epic and others)
  • Published retention schedule (30-day audio deletion in Epic guidance)

Frequently asked questions

Is DAX Copilot (Dragon Copilot) HIPAA compliant?

Yes — Dragon Copilot is delivered under Microsoft's healthcare cloud commitments with a BAA and HIPAA-compliant data handling, and it is the most institutionally vetted product in the category. HIPAA compliance does not settle recording consent, though: hospitals deploying it still publish patient FAQs and consent processes because state and provincial law, not HIPAA, governs whether a visit may be recorded.

Do patients have to consent to DAX Copilot recording their visit?

In practice yes. Published hospital FAQs (Sunnybrook in Toronto, UVA Health and others) describe telling patients the visit will be recorded and letting them decline, and clinicians can stop recording at any time. In all-party-consent states and under Canadian provincial health privacy law, a documented consent workflow is a requirement of deployment, not a courtesy.

Does an enterprise tool like Dragon Copilot end our AI privacy exposure?

No. It covers ambient documentation for licensed clinicians in covered workflows — meanwhile staff without licenses, or working outside the EHR, still reach for free consumer chatbots for drafting and summarizing, with no BAA behind them. The governance work is pairing the sanctioned tool with a clear policy and monitoring for the unsanctioned ones.

Policy changelog

  • Initial entry published from Microsoft's published documentation and cited hospital deployment FAQs.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

Microsoft Dragon Copilot (Nuance DAX Copilot) is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles