Is Fireflies HIPAA Compliant? Private Storage, Data Security, and Compliance Explained

Fireflies is HIPAA, SOC 2 Type II, FERPA, and GDPR compliant. Learn how Private Storage keeps your meeting data secure, where it's stored, and how to set it up.
On this page
- What is HIPAA Compliant Meeting Transcription?
- Fireflies Compliance Certifications at a Glance
- Where Is Your Fireflies Data Stored?
- Will Fireflies share your data with third parties?
- Does Fireflies train AI on your meeting data?
- What Is Fireflies Private Storage?
- Fireflies Managed Private Storage
- Bring Your Own Storage (BYOS)
- What Is the Difference Between Private Storage and Private Cloud?
- Who Needs HIPAA Compliant Meeting Transcription?
- How to Set Up Private Storage in Fireflies
- Storage Options Compared
- Frequently Asked Questions About Fireflies Data Security
- Is it HIPAA compliant to use Fireflies with Zoom?
- Is it HIPAA compliant to use Fireflies with Google Meet?
- Does Fireflies have a BAA?
- Can Fireflies store data outside the U.S. for GDPR compliance?
- What data is stored in Private Storage?
- Is Private Storage HIPAA compliant by default, or is setup required?
- Is it HIPAA compliant to use an AI notetaker for patient meetings?
- Conclusion
Fireflies is a HIPAA compliant AI Notetaker, and this compliance standard matters if your team handles patient records, privileged client communications, or regulated financial conversations. In Fireflies, HIPAA compliance is available on the Enterprise plan alongside private storage and a signed Business Associate Agreement. In addition to these standards, Fireflies is FERPA, SOC 2 Type II, and GDPR compliant, and appears on the EU-US Data Privacy Framework list.
To help you navigate these security features, this article will cover where Fireflies stores your data by default, which cloud providers you can use to supply your own bucket, and what your video platform's own BAA covers when an AI Notetaker joins the call.
What is HIPAA Compliant Meeting Transcription?
HIPAA compliant meeting transcription is transcription of conversations containing Protected Health Information, carried out under a signed Business Associate Agreement, with the transcript stored separately from public cloud storage.
HIPAA compliant meeting transcription matters most in healthcare, legal, finance, and defense and government work. HHS treats any cloud service that stores or processes protected health information as a business associate, so a covered entity that runs an AI Notetaker on a patient call without a signed BAA is in violation itself, regardless of how secure the vendor is.
Most tools in this category work from uploaded audio files. A HIPAA compliant AI Notetaker joins the call itself, transcribes it live, and writes the transcript into dedicated storage under a signed BAA, which means the compliance question covers the meeting itself and not just the file afterward.
Fireflies Compliance Certifications at a Glance
Fireflies holds SOC 2 Type II certification, complies with HIPAA, FERPA, and GDPR, and is listed in the EU-US Data Privacy Framework. Each one covers a different requirement and applies to a different set of plans:
- SOC 2 Type II: An independent audit of how Fireflies handles security, availability, and confidentiality. It applies to every plan including Free, and Enterprise customers can access the full report after signing an NDA.
- GDPR: European standards for handling personal data. It also applies to every plan including Free.
- EU-US Data Privacy Framework: A transfer mechanism for personal data moving from the EU to the United States. Fireflies is listed on it.
- HIPAA compliance (Enterprise): U.S. protection for Protected Health Information. It is established through a signed Business Associate Agreement and Private Storage on the workspace, both required together.
- FERPA (Enterprise): Covers student education records at educational institutions. It requires a signed Data Sharing Agreement, which is a separate document from the BAA.
Where Is Your Fireflies Data Stored?
By default, Fireflies stores and processes your data in U.S. cloud infrastructure running on AWS. Enterprise organizations can move storage elsewhere with Private Storage, either to a region Fireflies manages or to their own AWS S3 or Google Cloud Storage bucket.
That default environment is encrypted with 256 bit AES at rest and 56-bit SSL/TLS encryption in transit, and it meets SOC 2 Type II and GDPR standards.
You own your data either way. The Fireflies Terms of Service states it directly, and ownership does not shift based on which storage option you use.
Jurisdiction is the harder question. Data sitting in U.S. infrastructure falls under U.S. law regardless of which company owns it, and choosing a storage location changes only where the data rests. Processing still happens on Fireflies servers in the United States, whichever region holds the bucket.
Private Storage resolves the storage side of that, though a plan upgrade alone does not deliver it. The default setup puts meeting data in shared infrastructure, which clears SOC 2 Type II and GDPR, though it falls short for Protected Health Information. HIPAA requires that data live in dedicated, private infrastructure, and Private Storage is what moves it there.
Will Fireflies share your data with third parties?
Fireflies does not sell or share customer data with third parties. Meeting content is processed by AI and speech recognition subprocessors under signed BAAs and a Zero Data Retention policy. Fireflies has signed BAAs with vendors including OpenAI, and the privacy policy prohibits them contractually from storing customer data or using it to train their own models.
The BAA sets three conditions, and Fireflies groups them under what it calls the Zero Data Retention policy:
- Storage: Vendors hold no copy of your data after processing completes.
- Access: Vendors lose access to it once the service is delivered.
- Training: Your data is never used to train AI models, internally or externally.
None of this is gated behind Enterprise. The Zero Data Retention terms apply to every plan and every user, including Free.
Does Fireflies train AI on your meeting data?
Fireflies.ai does not use customer data to train any AI models. Your personal data is never used to train AI models. Users own their data.
What Is Fireflies Private Storage?
Private Storage is a dedicated storage bucket that holds only your organization's data, isolated from other Fireflies customers, in a location you choose. It is available on the Enterprise plan in two forms, Managed Private Storage and Bring Your Own Storage.
Transcripts, video recordings, and audio recordings live in the bucket. You pick the storage region during setup, and support can move it later if your requirements change.
The difference between Managed Private Storage and Bring Your Own Storage is who carries the operational responsibility. With Managed Private Storage, Fireflies handles encryption, retention, availability, and disaster recovery. With Bring Your Own Storage, those become a shared responsibility between Fireflies and your organization, which is why implementation takes more coordination on your side.
Fireflies Managed Private Storage
With Managed Private Storage, Fireflies provisions the bucket in the location you specify and stays accountable for confidentiality, integrity, encryption, and disaster recovery.
You still set the policies that govern the data, including permission control, privacy, and retention. It suits teams that need the compliance position without adding cloud administration to their workload.
Bring Your Own Storage (BYOS)
Bring Your Own Storage puts the bucket on your own cloud account. You give Fireflies credentials to a Google Cloud Storage bucket or an AWS S3 bucket, and your data is written there.
Those two providers are the only ones supported. Azure Blob Storage is not on the list.
The tradeoff is confidentiality, integrity, encryption, retention, availability, and disaster recovery all become shared between Fireflies and your organization. You keep full control of the bucket and carry part of the operational burden, and implementation takes coordination between both teams.
What Is the Difference Between Private Storage and Private Cloud?
Private Storage provides dedicated storage infrastructure. A private cloud provides a complete computing environment, covering storage, networking, and compute together. Fireflies offers Private Storage and does not offer Private Cloud.
The practical consequence sits in where processing happens. With Private Storage, your meeting data rests in a bucket you control while transcription, summarization, and every other operation run on Fireflies servers in the United States. If your requirement covers processing location as well as storage location, Private Storage addresses the storage half and processing stays with Fireflies.
Who Needs HIPAA Compliant Meeting Transcription?
HIPAA compliant meeting transcription matters most in healthcare, legal, finance, and defense and government work. HHS treats any cloud service that stores or processes protected health information as a business associate, so a covered entity that runs an AI Notetaker on a patient call without a signed BAA is in violation itself, regardless of how secure the vendor is. Encryption does not change that, because HHS has said a provider holding only encrypted PHI, without even the decryption key, is still a business associate.
The need for compliant transcription plays out differently across those four sectors:
- Healthcare
Telemedicine appointments, patient consultations, and clinical documentation all generate Protected Health Information the moment they are transcribed. HIPAA requires that any transcript containing health information stay separate from public cloud storage, which is the specific problem a HIPAA compliant AI Notetaker has to solve, and what Private Storage fixes. - Legal
Client calls, deposition prep, and case strategy sessions run on attorney client privilege, which makes who else holds a copy of the recording a live question. Firms doing healthcare work carry a second obligation, since a firm handling PHI for a covered entity is a business associate under HIPAA in its own right. Private Storage keeps the transcript in a bucket the firm controls, with retention rules the firm sets. - Finance
Client advisory calls, trade discussions, and compliance recordings fall under retention and supervision rules that vary by regulator and by jurisdiction. Firms that administer health plans sit under HIPAA directly, because a health plan is a covered entity in its own right. Private Storage adds control over where those records sit and how long they are kept. - Defense and government
Contractor programs and agency work often carry data residency terms written directly into the contract, specifying which country the data sits in and who can reach it. Private Storage lets you place the bucket accordingly, and BYOS keeps it inside infrastructure your own team administers.
How to Set Up Private Storage in Fireflies
Private Storage requires an Enterprise plan. If you are already on one, setup runs from your dashboard.
On Enterprise, the Security Checklist in Team Settings shows your compliance status and tracks the two items HIPAA depends on. To enable Private Storage, open Settings, go to the Account tab, scroll to the Private Storage block, and switch the toggle on. New meetings are then written to dedicated storage; the location is set during initial setup and Fireflies support can change it later. Next, review and sign the Business Associate Agreement at fireflies.ai/baa.
Once both are complete, HIPAA Compliance shows as enabled in the checklist and the controls go active across your team. FERPA follows the same pattern, with a Data Sharing Agreement in place of the BAA.
If your team is not on Enterprise yet, start with the enterprise contact form and the team will scope the plan, the storage, and the agreements together.
Storage Options Compared
Fireflies offers three storage configurations, and the differences come down to where the data sits and who administers the bucket.
This table breaks down how the three setups compare:
| Feature | Fireflies Cloud (Public) | Private Storage | Bring Your Own Storage |
|---|---|---|---|
| Available on | Free, Pro, Business | Enterprise | Enterprise |
| Data ownership | You own it | You own it | You own it |
| Bucket administered by | Fireflies | Fireflies | You |
| Storage location | U.S., on AWS and Google Cloud | Region you choose | Your own AWS S3 or Google Cloud Storage bucket |
| Processing location | U.S. | U.S. | U.S. |
| Operational responsibility for encryption, availability, and disaster recovery | Fireflies | Fireflies | Shared between Fireflies and your organization |
| Implementation effort | None | Low, enabled from Team Settings | High, requires coordination with Fireflies |
| SOC 2 Type II and GDPR | Yes | Yes | Yes |
| Zero Data Retention with AI vendors | Yes | Yes | Yes |
| HIPAA compliance | Not available | Available with a signed BAA | Available with a signed BAA |
| FERPA compliance | Not available | Available with a signed DSA | Available with a signed DSA |
| Custom retention policy | Not available | Yes | Yes |
Frequently Asked Questions About Fireflies Data Security
Is it HIPAA compliant to use Fireflies with Zoom?
Using Fireflies with Zoom is HIPAA compliant when both vendors are covered by their own Business Associate Agreement. Zoom supports HIPAA compliance through Zoom for Healthcare, which requires executing a BAA with Zoom on a paid plan. A BAA covers the party that signs it, so Zoom's agreement covers Zoom. Fireflies needs its own, which comes with the Enterprise plan and Private Storage enabled. That holds for medical appointments and any other meeting type, and it works the same way on any platform Fireflies joins.
Is it HIPAA compliant to use Fireflies with Google Meet?
Using Fireflies with Google Meet is HIPAA compliant when both Google Workspace and Fireflies are covered by their own Business Associate Agreement, and Google states that boundary explicitly. Google Meet sits on the HIPAA Included Functionality list under a Google Workspace BAA, which an administrator has to accept before any PHI moves through it. Google also publishes that third party applications and add ons are not covered by that BAA, and that deciding whether you need a separate agreement with the third party is the customer's responsibility. For Fireflies, that separate agreement is the Enterprise BAA, with Private Storage holding the transcript.
Does Fireflies have a BAA?
Fireflies offers a Business Associate Agreement on the Enterprise plan, and it also holds BAAs with vendors including OpenAI and its ASR providers. The BAA is the legal instrument that establishes each party's responsibility for Protected Health Information. Both layers do different work. The first makes Fireflies accountable to you, and the second binds the vendors behind it.
Can Fireflies store data outside the U.S. for GDPR compliance?
Fireflies can store data outside the U.S. through Private Storage, which lets you choose the storage region so EU organizations keep meeting data on EU infrastructure under EU jurisdiction. HHS permits ePHI storage outside the United States when a BAA is in place, while noting that the risk profile changes with geography. One caveat is worth surfacing early in a procurement review. Storage location and processing location are separate questions, and Fireflies processes data on U.S. servers whichever region holds the bucket.
What data is stored in Private Storage?
Private Storage holds meeting transcripts, video recordings, and audio recordings. On Enterprise you also control how much of that is kept at all, since recording modes can delete the audio after transcription, or delete both the audio and the transcript once the summary is generated.
Is Private Storage HIPAA compliant by default, or is setup required?
Private Storage requires setup before it is HIPAA compliant. Compliance depends on an Enterprise plan, Private Storage enabled on the workspace, and a signed BAA, all three at once. It stays live only while all three hold. Plan downgrades or storage changes immediately disable it, and the Security Checklist monitors this automatically and shows current status. Worth checking before a renewal cycle changes your plan tier.
Is it HIPAA compliant to use an AI notetaker for patient meetings?
Using an AI Notetaker for patient meetings is HIPAA compliant when the vendor signs a BAA and stores the data in isolated infrastructure. HIPAA governs how Protected Health Information is stored and who can reach it, and recording or transcribing a patient meeting is permitted under those rules. Without a BAA in place, HHS treats the covered entity as the party in violation. Fireflies provides the BAA and Private Storage together on the Enterprise plan.
Conclusion
Fireflies is a HIPAA compliant AI Notetaker on the Enterprise plan, with Private Storage enabled and a signed BAA in place. FERPA runs on the same Enterprise footing through a Data Sharing Agreement. SOC 2 Type II, GDPR, and the Zero Data Retention terms apply on every plan including Free, so the security baseline exists before you upgrade.
For healthcare, legal, finance, and government teams, Private Storage is what turns that baseline into something a security review will sign off on. You own the data, you choose where it sits, and you set how long it stays.
Talk to the Fireflies team through the enterprise contact form to scope storage, region, and the agreements together.



