Steno for Healthcare

Clinical notes where PHI never leaves the device.

Consultations, care-team discussions, and clinical supervision involve protected health information that shouldn't be handed to a third party. Steno transcribes and summarizes entirely on-device, so PHI stays with you — supporting your HIPAA obligations instead of expanding them.

HIPAA-friendly by design Nothing leaves the device GDPR-aligned

Why cloud tools don't fit

  • Cloud transcription means PHI is transmitted to and stored by a vendor — a business-associate relationship you have to paper and trust.
  • Every additional processor is another entity in scope for a breach.
  • A bot in a patient consultation is a privacy problem before it's a product feature.

PHI stays on-device

Recordings, transcripts, and summaries never leave the machine. Because no PHI is transmitted to us, Steno isn't a business associate touching your patient data.

Supports HIPAA by design

The surest way to keep PHI out of third-party hands is to never send it anywhere. Steno's local-only pipeline does exactly that.

No bot in the consult

Audio is captured directly on the device — nothing joins the appointment.

Inspectable

Open source, so a compliance or security team can verify how PHI is handled rather than trust a badge.

On compliance

Steno runs entirely on your device. Your meeting recordings, transcripts, and summaries never reach our servers — there is no third-party processor handling your meeting data, which addresses a meaningful part of HIPAA, GDPR, and data-residency exposure. (Those frameworks also cover safeguards, agreements, and processes that remain your responsibility — no tool hands you compliance.) Steno itself isn't a certified cloud service, because there is no cloud service handling your meetings to certify — and that's the point: the vendor-breach risk that frameworks such as SOC 2 exist to assure against isn't in that path.

Questions

HIPAA compliance is a property of your overall environment, not a single app — so no tool can hand you compliance. What Steno does is keep PHI entirely on the device: nothing is transmitted to us, so there's no third-party processor and no business-associate exposure through Steno. That makes it a strong fit for a HIPAA-conscious workflow. We don't claim to be a certified service, because there's no cloud service to certify.

A BAA covers a vendor that handles your PHI. Steno never receives PHI — it all stays on your device — so there's no PHI-handling relationship for a BAA to govern. That absence is the privacy benefit, not a gap.

In local app storage on your device only. Nothing is synced to a server, which also means no cloud backup — export anything you need to retain.

Also built for: Government · Defense · Legal · Finance · Executive

Start keeping private notes.

Free. Open source. No account needed.

macOS 14.4+ (Apple Silicon) · Windows 10/11 (x64, alpha — unsigned) · ~4 GB for the default model