Healthcare AI & Medical Scribes

Heidi Health

Medium risk

AI medical scribe with a free tier, built by an Australian company and marketed to clinicians in the US, Canada, the UK, and Australia.

Verified 2026-08-31Heidi Health (Melbourne, Australia)www.heidihealth.com

Is Heidi Health safe for confidential data?

Heidi's published posture is solid — SOC 2 Type 2, a BAA made available to every US covered entity, US data hosted in the US, and Canadian data hosted in Canadian data centres (Quebec) with stated PHIPA, PIPA, and Quebec Law 25 compliance — but the practical risk is how it gets adopted. Heidi's free tier means individual clinicians routinely start recording patient visits with no BAA executed and no practice-level review, and the vendor is an Australian company operating across several jurisdictions, so a practice needs to confirm in writing which entity, which region, and which agreement actually covers its data.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Free
Not verified

A free scribe tier is the classic shadow-AI entry point: real patient audio processed before any BAA or organizational agreement exists. Do not treat free-tier use as covered use.

Pro / paid
Not verified

Paid individual and clinic plans. Heidi says it makes a BAA available to every covered entity it works with; execute it rather than assuming it applies automatically.

Enterprise / organization
Not verified

Organizational contracts with negotiated terms, admin controls, and the clearest path to documented residency and training commitments.

Data handling

Training on inputs

Heidi's compliance pages emphasize safeguards rather than a single prominent no-training statement; confirm the current model-training position for your tier in the agreement before rollout.

Retention

Heidi does not prominently publish a single audio-retention figure on its HIPAA compliance page; retention terms should be confirmed in the BAA or customer agreement.

Residency

Region-based hosting: US customer data is stored in the United States; Canadian customer data is stored in Canadian data centres (Quebec), which Heidi positions as meeting PHIPA, PIPA, and Quebec Law 25 requirements. The corporate parent remains Australian.

Compliance

  • SOC 2Yes
  • GDPR / DPANot verified
  • HIPAA BAAYes

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • BAA for US covered entities
  • Regional data hosting (US / Canada / Australia / UK)
  • Encryption in transit and at rest
  • Organization-level admin and account controls

Frequently asked questions

Is Heidi AI HIPAA compliant?

Heidi states it complies with HIPAA, is SOC 2 Type 2 certified, and makes a Business Associate Agreement available to every covered entity it works with. As with any self-serve scribe, the compliance question is really whether your use is covered: a clinician on the free tier with no executed BAA is not operating under those protections.

Where does Heidi store Canadian patient data?

Heidi states Canadian customer data is stored exclusively in Canadian data centres, hosted in Quebec, and that it complies with provincial requirements including PHIPA, PIPA, and Quebec Law 25. Because Heidi is an Australian company operating globally, Canadian clinics should still confirm the contracting entity and residency commitment in their own agreement rather than relying on marketing pages.

Our clinicians started using Heidi's free tier on their own — is that a problem?

Yes. Free-tier use means patient conversations are being recorded and processed by a third party with no BAA, no organizational agreement, and no review of consent workflows — the practice carries the privacy risk without any of the contractual protections. The fix is to move users onto a clinic or enterprise agreement with the BAA executed, and to set an explicit policy for tools adopted individually.

Policy changelog

  • Initial entry published from Heidi Health's published security documentation and cited coverage.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

Heidi Health is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles