Private Medical and Legal Dictation on Mac and iPhone
Why clinicians and lawyers need a private medical dictation app or legal dictation software that keeps audio on the device, and what to check with compliance.
If you dictate clinical notes or client memos, the question is not whether dictation software works; most of it does. The question is where your voice goes after you stop talking, and who can hear it on the way. This article explains why on-device processing changes the confidentiality picture for clinicians and lawyers, walks through realistic workflows on a Mac and an iPhone, lists what to check with your own compliance advisor, and is honest about what on-device processing does not solve.
Why dictation is different in a clinic or a law firm
A dictated note is not an ordinary document. A clinical note contains a patient's name, history, medication, and diagnosis. A file note in a law practice contains a client's identity, the facts of a matter, and privileged advice. Both are the most sensitive class of information the organisation holds, and both are subject to obligations that predate any software: confidentiality to the patient or client, professional rules, and, depending on where you practise, health-privacy and data-protection law.
Many voice typing tools send audio to a server, transcribe it there, and send the text back. For a shopping list that is fine. For a note that names a patient, it means a third party has processed protected information, and that has consequences.
What "vendor processing" means and why compliance teams ask about it
When audio leaves the device to be transcribed, the company running the server is processing your data on your behalf. In most regimes that makes them a processor, a business associate, or an equivalent term, and it triggers a set of questions your compliance officer will ask before approving the tool:
- Is there a contract that binds the vendor to confidentiality and to specific security measures?
- Where are the servers, and does the data cross a border?
- Is the audio retained, and for how long? Is it used to train models?
- Who at the vendor can access it, and how is that logged?
- What happens after a breach, and how quickly are you told?
- Can the vendor delete everything on request, and can they prove it?
None of these questions are unreasonable, and good cloud vendors have answers. But each answer is a document to review, a contract to sign, and a dependency to monitor. For a small practice, the review alone can take longer than the tool saves in a year.
The on-device answer
There is a simpler way to satisfy those questions: make sure the audio never leaves the device. If speech recognition runs on the Mac or iPhone itself, there is no server, no processor, no border crossing, and no retention policy to review, because there is no second party. The vendor-processing questions do not get easier answers; they stop applying.
Apple's own hardware makes this practical. Apple Silicon Macs and recent iPhones have a Neural Engine that can run modern speech models at conversational speed, so an on-device transcript is no longer a slower, worse version of the cloud one. The trade-off is that the model has to be downloaded once during setup, and the device needs enough memory to hold it.
Two points to be precise about, because they come up in reviews:
- On-device processing removes the vendor-processing question. It does not by itself make you compliant with anything. Compliance is a property of your whole practice: device encryption, access control, backups, retention, staff training. The dictation tool is one line in that picture. Confirm requirements with your own compliance advisor.
- "On-device" should mean all of it: speech recognition, any AI cleanup or summarisation, and any speaker recognition. A tool that transcribes locally but sends the transcript to a cloud model for a summary has reintroduced the same question one step later. Ask.
The general comparison of local and cloud transcription, including the honest cases where cloud is the better choice, is in On-device vs cloud transcription.
Workflow examples
The workflows below are written for ThinkScribe because it is the tool we can describe accurately, but the shape applies to any software that keeps audio local.
Clinical notes after a patient visit
- Open the patient record in your EHR or practice software on the Mac, and put the cursor in the note field.
- Press the global voice-typing hotkey (Option-Space by default) and dictate the note: history, examination, assessment, plan.
- Press it again to stop. The transcribed text is on the clipboard; paste it with Command-V. If you have enabled ThinkScribe under System Settings > Privacy & Security > Accessibility, the text is typed straight at the cursor instead, hands-free. Accessibility is optional and never required.
- Read the note before you sign it. On-device does not mean error-free; drug names and dosages deserve a second look in any dictation system.
For longer dictations, or a consultation you want to keep as a recording with the patient's consent, record in the app itself and export the transcript afterwards as TXT, DOCX or PDF, or send a summary to Apple Notes. Set your default transcription language once in Settings > Transcription so the record bar follows it.
Client memos and file notes
- After a client call, open a new document in whatever your firm uses: a Word document, an email draft, a note in your practice-management system.
- Dictate the file note with the hotkey. Names, dates, and the advice given.
- Use the on-device rewrite to make it shorter or more formal before you file it. The rewrite runs on the device too, so the draft does not go anywhere either.
- For a long dictation, such as a first draft of a letter of advice, record it as a transcript in the app and use the one-tap Clean Transcript action, then export to DOCX.
Dictating on an iPhone between appointments
On an iPhone, the ThinkScribe Voice keyboard lets you dictate into any app. Enable it in Settings > General > Keyboard > Keyboards > Add New Keyboard > ThinkScribe Voice, then tap it and enable Allow Full Access; that permission is needed so the keyboard can talk to the app. iOS does not allow any keyboard extension to use the microphone, so the dictation is routed through the ThinkScribe app with push-to-talk, a Live Activity on the Lock Screen shows it is listening, and the text lands where you were typing. It works offline, which matters in a hospital basement or a courthouse with no signal. The full setup is in Offline dictation on iPhone.
For the Mac side, Voice typing on a Mac explains clipboard mode versus the hands-free Accessibility mode.
The same constraint turns up outside clinics and firms, and research interview transcription sits under an ethics approval that usually names where participant data may be stored, and the answer is easier when the audio never leaves the machine.
What to check with your compliance advisor
A short list to take into the conversation. None of this is legal advice; it is the set of things that usually decides whether an on-device tool passes review.
- Where the transcripts are stored. In ThinkScribe they stay in the app's library on the device. iCloud sync of transcripts is optional and off by default, and audio never syncs unless you turn it on. If you enable sync, your iCloud configuration becomes part of the review.
- Device encryption and screen lock. A private transcript on an unlocked, unencrypted laptop is not private. FileVault on the Mac and a passcode on the iPhone are the baseline.
- Retention. Decide how long recordings and transcripts stay on the device, and delete what you do not need. A dictation tool should make deletion easy and complete.
- Network use. ThinkScribe's only network use is the one-time download of open-source model weights during setup, and optional anonymous crash and performance reports, which can be turned off in Settings. Your advisor may want the reports off; that is a one-toggle decision.
- No account. There is no ThinkScribe account, so there is no vendor-side user record tied to your dictations.
- Consent. Recording a consultation or a client call, as opposed to dictating your own notes afterwards, may need the other person's consent depending on where you are. That is a rule about recording, not about software, but it belongs in the same policy.
What on-device does not solve
- It does not fix a bad microphone or a noisy corridor. Accuracy depends on the audio.
- It does not replace proofreading. Read every note before it becomes part of a record.
- It does not protect a device that is lost while unlocked, or a transcript pasted into a system that then sends it somewhere. Once text is in your EHR or email, that system's rules apply.
- It does not cover what a cloud vendor might offer that a local tool cannot: shared team dictation queues, human review, or integrations into a specific hospital system. If you need those, the vendor-processing review is the price, and it is a reasonable one.
ThinkScribe for clinicians and lawyers
Frequently asked questions
Is there a HIPAA compliant dictation app?
"HIPAA compliant" describes a covered entity's whole program of safeguards, not a label a piece of software can carry on its own, and you should be cautious of any product that claims it outright. What a dictation app can do is remove the vendor-processing question by keeping audio and text on the device, which takes the business-associate discussion off the table for that tool. Whether your overall practice meets its obligations is a question for your compliance advisor.
Can I use my iPhone for medical dictation offline?
Yes, if the dictation runs on the device. Apple's keyboard dictation handles some languages on-device and others on Apple's servers; check Apple's documentation for the current list. A dictation keyboard that routes audio through an on-device app works with no connection at all, which is useful in buildings with poor signal and removes the question of where the audio went.
Is Apple Dictation private enough for legal work?
Apple processes dictation on-device for a number of languages and on its servers for others, and its documentation describes the current behaviour; check it for the languages you use. If your firm's policy requires that no third party processes client audio, you need to be sure your language and device combination stays on-device, or use a tool that processes everything locally regardless of language.
Does dictation software need a business associate agreement?
If the software sends audio or text containing protected health information to the vendor's servers, the vendor is handling that information on your behalf and an agreement is normally required; your compliance advisor will confirm the specifics for your jurisdiction. If the software processes everything on the device and the vendor never receives the data, there is nothing for such an agreement to cover, which is the practical reason clinicians choose on-device tools.