Healthcare AI & Medical Scribes

Nabla

High risk

Ambient AI assistant that transcribes clinician-patient encounters and drafts notes, used by dozens of health organizations and strong in telehealth settings.

Verified 2026-08-31Nabla Technologieswww.nabla.com

Is Nabla safe for confidential data?

Nabla's privacy design is genuinely aggressive in the right direction — audio is processed in chunks and never stored, nothing is used for training, and transcripts and notes expire after a short configurable window (14 days by default, backups gone about a week later) — but its documented incident cuts the other way. An October 2024 Associated Press report described research showing that Whisper, the speech model underpinning Nabla's transcription at the time, fabricated text in a meaningful share of transcriptions, including invented treatments and statements no one made; because Nabla deletes the source audio, clinicians could not check a suspect transcript against what was actually said. The tool had transcribed an estimated seven million visits at that point. The lesson for buyers: the privacy-protective deletion that reduces breach exposure also removes the audit trail, so clinician review of every note before it enters the chart is a hard requirement, not a best practice.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Free / individual trial
No training

Nabla has offered free individual access, which lets clinicians adopt it ahead of any BAA or organizational review — the standard shadow-adoption path even with good vendor defaults.

Pro / organization
No training

Paid and enterprise deployments with BAA, EHR integrations (including Epic), and configurable retention.

Data handling

Training on inputs

Nabla states patient audio is never stored or used for model training; audio chunks are processed and immediately discarded.

Retention

No audio retention at all. Transcripts and notes are stored temporarily for a configurable period (14 days by default), then removed; backups expire roughly 7 days after that.

Residency

US customer data is processed in HIPAA-aligned US infrastructure; Nabla also operates under GDPR in Europe. No published Canadian residency commitment — confirm before PHIPA-governed use.

Compliance

  • SOC 2Yes
  • GDPR / DPAYes
  • HIPAA BAAYes

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • BAA for covered entities
  • SOC 2 Type 2 and ISO 27001 certifications
  • Configurable transcript/note retention
  • EHR integrations with organizational admin
  • No audio storage by design

Frequently asked questions

Is Nabla HIPAA compliant?

Yes — Nabla signs BAAs, is SOC 2 Type 2 and ISO 27001 certified, and its data handling is unusually conservative: audio is never stored, nothing trains on patient data, and transcripts expire after a short window. On paper it is one of the cleaner privacy postures in the category.

What happened with Nabla and Whisper hallucinations?

An Associated Press report in October 2024 covered researchers finding that OpenAI's Whisper model — which powered Nabla's transcription — invented text that was never said, including fabricated medical content, in a meaningful fraction of transcriptions. Because Nabla deletes the original audio for data-safety reasons, there was no way to verify a questionable transcript afterward. Nabla acknowledged the issue and pointed to clinician review of notes; the company has iterated on its models since, but the structural point stands: deletion trades auditability for privacy.

If the audio is deleted, is using Nabla without approval harmless?

No. Even with no stored audio, patient conversations are still processed by a third party, and transcripts and notes exist for days — without a BAA or organizational agreement, that processing has no contractual cover, and the practice owns the risk. Individual free-tier adoption should be converted to an organizational agreement, and every AI-drafted note must be reviewed before signing, since transcription errors cannot be checked against a recording later.

Policy changelog

  • Initial entry published from Nabla's published security documentation and cited coverage.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

Nabla is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles