If you handle protected health information (PHI), the riskiest moment in most AI transcription tools is the one you cannot see: the upload. The audio of a client leaves your machine, lands on a vendor’s servers, and is processed by a model you do not run on infrastructure you do not control. That single step is what pulls a transcription tool into your HIPAA scope — and it is exactly the step Kajo does not take.
What “on-device” actually means here
Kajo Voice transcribes audio locally. Translation, summaries, and the chat assistant all run against the same on-device Gemma 4 model on your own Mac, Windows, or Linux machine. There is no “process in the cloud” mode to leave switched on by accident, because the product has no cloud-processing path at all. The audio, the transcript, and the summary — which carries a review-required line — all stay in an encrypted library on the device in front of you.
That is a meaningful distinction for a covered entity or business associate. HIPAA’s Security Rule is about safeguarding PHI as it is created, stored, and transmitted. When PHI is never transmitted to a third party for transcription, you remove an entire category of exposure: there is no transcription vendor that would need a Business Associate Agreement for that step, no data-residency region to configure, and no breach-notification surface tied to a processor you onboarded.
What Kajo is — and what it is not
Kajo is a tool, not a compliance program, and it is not marketed as a certified medical device or a turnkey way to “be HIPAA compliant.” Compliance is a property of your whole practice — your devices, your access controls, your training, your agreements — not of any one app. What Kajo gives you is a transcription workflow whose easiest path is also the private one, so the technology stops working against your obligations.
Concretely, that means:
- Audio stays put. No session recording is uploaded. The copy of what a client shared in confidence lives only on the hardware you already secure.
- Encryption at rest. The local library is encrypted, with the key wrapped by your operating system’s keychain.
- On-device processing only. Transcription, translation, summaries, and chat all run locally — there is no cloud-processing path to leave switched on by accident.
- No sides taken. Kajo will not flag risk or diagnose — summaries carry a review line, and chat answers only from that client’s folder unless you explicitly choose the whole library.
Where you still own the work
On-device processing narrows your risk; it does not erase your responsibilities. You still need client consent to record, device-level safeguards (disk encryption, screen locks, access control), and a clear retention and deletion policy. If you export a summary or transcript into an EHR or a cloud drive, that destination is in scope even though Kajo’s transcription step was not. And as always, the authoritative read on your specific situation comes from your own privacy officer or compliance advisor — this article is general information, not legal advice.
The point is simpler than the regulation: the fewer places PHI travels, the smaller your compliance problem. Keeping transcription on the device is the most direct way to keep a client’s words where they belong.
Related reading
- Kajo for therapists — private, on-device session transcription
- Security overview — how Kajo protects data on the device