Back to blog

Medical Dictation on Mac in 2026: What a General Dictation Tool Can and Cannot Do

If you search for medical dictation on a Mac, you get two kinds of answers. One kind is a marketing page that tells you a dictation app understands medical vocabulary and will save you an hour a day. The other kind is a quote request from a clinical software vendor who wants to talk about your practice size before mentioning a price.

The gap between those two answers is the whole subject of this article, and it is not a gap in accuracy. Modern transcription handles clinical vocabulary well. The gap is certification: who is contractually and legally permitted to hold patient data, and who is not.

We publish a general dictation app, so this article starts with a disqualification rather than a pitch. Dikto is not a medical dictation product, and it should not be used to dictate identified patient records. What follows explains why, which category does serve that need, and what remains — which turns out to be a large share of what clinicians actually write.

This is not legal advice. Your data protection officer, your professional body, and your own counsel decide what your practice may use.

The short version

  • Content that identifies a patient and is created for their care — clinical notes, consultation reports, referral letters, discharge summaries, anything destined for the record — belongs in a certified clinical dictation product or an ambient scribe integrated with your record system.
  • Content that contains no person — protocols, teaching material, journal prose, grant text, guideline summaries, departmental admin, blank templates — is ordinary professional writing, and a general dictation tool is a reasonable choice for it.
  • The boundary is not “how sensitive does this feel.” It is whether an individual is identifiable, directly or indirectly, from what you dictate.

Why medical dictation is a separate product category

Three distinct rules stack on top of each other, and vendors tend to answer only the one they satisfy.

Health data is a special category under the GDPR. Article 9(1) of Regulation (EU) 2016/679 prohibits the processing of data concerning health by default, with the exceptions in Article 9(2) — for care, typically 9(2)(h) read with 9(3) and its professional-secrecy condition. What matters in practice is that health data starts from a prohibition rather than from a balancing test, so “we are GDPR compliant” is not by itself an answer to whether a tool may process it.

Professional secrecy binds you, not your software. In France, medical confidentiality is set out in Article L.1110-4 of the public health code and enforced through Article 226-13 of the penal code. In Germany it is §203 StGB. These duties attach to the clinician. Choosing a tool that routes a consultation report through a third party with no health-data arrangement in place – no certification scope, no Article 28 terms covering it, no BAA – is your decision and your exposure, regardless of how the vendor markets itself.

Hosting health data is separately regulated. In France, a third party that hosts personal health data collected in the course of prevention, diagnosis, care, or medico-social follow-up must hold HDS certification (Hébergeur de Données de Santé), under Article L.1111-8 of the public health code. Whether a given cloud processing step counts as hosting is a question for your counsel, not for a blog post. The practical consequence is simpler than the legal analysis: if a vendor cannot give you a certification scope in writing, you do not have the assurance.

In the United States, the relevant instrument is a contract. Under 45 CFR 160.103, a vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity is a business associate, and 45 CFR 164.502(e) requires a business associate agreement before that happens. A vendor that does not offer a BAA has not decided it is exempt; it has declined the arrangement.

European jurisdiction does not substitute for a BAA, and a BAA does not substitute for HDS. They are different instruments answering different regulators.

Where Dikto actually stands

These are product facts, not positioning. They are all in our privacy policy, and we would rather you read them here than discover them later.

  • Dikto is cloud-only. There is no offline mode. Raw audio leaves your Mac.
  • Audio goes to Dikto’s backend, hosted by Scaleway in France, and then to Mistral AI for transcription with Voxtral. Transcribed text, prompts, saved context, and dictionary terms may also be sent to Mistral for cleanup, translation, and text actions.
  • We do not intentionally write raw recordings or full transcripts to Dikto’s application database, and we do not train our own models on them. Provider-side retention and training controls depend on the Mistral plan and settings applied to our account.
  • Saved dictionary terms and context do persist in Dikto’s database until you change them or delete your account.
  • Mistral states that some features or subprocessors may involve temporary processing outside the European Union.
  • Our published policy and terms make no claim of HDS certification, and we do not offer a business associate agreement. In the absence of a certificate and a signed contract, the correct reading is that identified patient data must not be dictated into Dikto.

That is the whole disclosure, and it rules Dikto out of one category while leaving it perfectly usable in another.

The four categories on a Mac, and what each is for

1. macOS built-in dictation. Free, included, and for many languages it runs on the device. It produces raw transcription: no punctuation inference, no cleanup, no medical vocabulary tuning. Being on-device removes the third-party question for the transcription step, which is a genuine advantage — but it says nothing about where the resulting text ends up, and Apple does not certify it for clinical use. Fine for a quick note to yourself. Not a documentation system.

2. General AI dictation apps. Dikto, Superwhisper, Wispr Flow, Typeless, MacWhisper and the rest of the category. They transcribe and then clean the text with a language model, which is why the output is usable immediately. Their privacy postures differ sharply — some run small models locally, some are cloud-only, some are hybrid — and a few of them do advertise healthcare-specific arrangements. Verify each vendor individually rather than assuming the category has one answer. Ask for the certificate or the contract, not the marketing page.

3. Clinical dictation products. Dragon Medical One, from Microsoft following its acquisition of Nuance, is the historical product in this category. What makes a product belong here is the certification and the contract it can show you, not the category label – put it through question 1 below and ask for the scope in writing. It is sold through Microsoft and its resellers rather than self-serve, and there is no public list price, so budget by quote. It is a Windows application; clinicians working on a Mac generally reach it through a virtual desktop or a managed session rather than a native Mac app, and you should confirm the current arrangement with the vendor for your own setup. Note that Dragon for Mac, the consumer product, was discontinued in 2018 and Dragon Anywhere ended sale on 1 July 2026 — any roundup still listing either as a purchasable Mac option is out of date.

4. Ambient AI scribes. Nabla, Abridge, and Microsoft’s ambient product — now marketed as Dragon Copilot, previously DAX Copilot; check the current naming, it has changed more than once. These do a different job: they listen to the consultation itself and draft the note into your record system, rather than transcribing what you dictate afterwards. This is the category that actually targets the documentation burden that Sinsky and colleagues quantified in Annals of Internal Medicine in 2016, when they observed US ambulatory physicians spending nearly two additional hours on electronic health record and desk work for every hour of direct clinical face time. That was 57 physicians in four specialties, in the United States, ten years ago — quote it for what it is, not as a current European figure, and not as something a dictation app fixes.

If your problem is the note, categories 3 and 4 are where your shortlist comes from. Categories 1 and 2 are not competing for that work.

What never goes into a general dictation tool

Write this list down once and stop re-deciding it consultation by consultation.

Never dictate: a patient’s name or initials; a medical record number, IPP, NHS number, or social security number; a date of birth, admission, discharge, or death; an address, postcode, or workplace; a phone number or email; a photograph description or any device identifier; the audio of a consultation itself; or a combination that identifies someone even without a name — a rare diagnosis plus a small hospital plus a month is an identifier.

Two traps are worth naming explicitly.

Pseudonymisation is not anonymisation. Replacing a name with a code leaves personal data, under Article 4(5) and Recital 26 of the GDPR, if anyone can reverse it. “Mrs M., 74” is still patient data.

HIPAA de-identification is a formal test, not a judgement call. It is either the Safe Harbor removal of eighteen enumerated identifier types, or a documented expert determination. Improvising a personal standard and calling the result de-identified does not meet it.

The working rule that survives a busy clinic: if you have to ask whether something is de-identified enough, it is not. Anything you would not be comfortable publishing on a public blog does not go into a general dictation tool.

What is left — and it is not a small pile

Strip out everything that names a person and look at what a clinician still writes in a week:

  • Protocols, SOPs, and care pathways — the document, not its application to anyone.
  • Teaching material: lecture notes, slide text, exam questions, registrar feedback that discusses technique rather than a case.
  • Research and academic prose: introductions and discussions, grant aims, protocol text with no participant in it, conference abstracts, peer review reports.
  • Patient-facing material written for everyone rather than for someone: generic information leaflets, standard advice sheets that name no one and describe no individual case, practice website copy.
  • Departmental and administrative writing: rota policy, equipment cases, supplier correspondence, audit methodology, meeting minutes with no patient in them.
  • Blank templates: the structure of a referral letter with every field left empty.

That is real volume, it is genuinely slow to type, and none of it is identified patient data, which is the line this article is about.

There is one more case, and it is the one we built for. A clinician whose working language is not English still has to write in English — for a journal, for an international colleague, for a conference. Dictating in your own language and having the English come out is a meaningfully different experience from writing English at forty words a minute, and it applies to exactly the non-patient text above. We are not alone in offering it: Typeless, Spokenly, and TypeWhisper all ship some form of speak-one-language-write-another, and it is worth trying more than one.

Medical vocabulary in practice

Drug names, eponyms, anatomical terms, and specialty abbreviations are where general transcription engines fail, and the fix is the same in every tool that offers one: a custom vocabulary. Declare the twenty or thirty terms you actually use — the drugs on your ward’s formulary, the scoring systems in your specialty, your department’s abbreviations — and most of the errors disappear at once.

Two cautions. Never put a patient identifier in a custom dictionary; in Dikto those terms are stored on the server and sent to Mistral for processing, which is the opposite of transient. And sound-alike drug names remain a known source of transcription error across every engine, which is one more reason that text capable of informing a clinical decision does not belong in a general dictation tool at all.

The questions to ask any vendor

Send these verbatim. The quality of the answer tells you more than the answer itself.

  1. Are you HDS-certified? For which entity and which scope, and can you send the certificate?
  2. Will you sign a business associate agreement? Will you sign an Article 28 data processing agreement with a named subprocessor list?
  3. Where is my audio processed, by which subprocessors, and under which jurisdiction — including any temporary processing outside the EU?
  4. Is my audio retained? Is my transcript retained? For how long, and by whom in your chain?
  5. Is any of it used to train models — yours or a provider’s — and is the opt-out contractual or a settings toggle?
  6. Can I have all of that in writing rather than on a marketing page?

A vendor that answers with adjectives instead of a certificate number and a contract is answering no. That includes us, on questions 1 and 2.

Frequently asked questions

Can I use Dikto for medical dictation? Not for identified patient records. Use it for the clinical writing that contains no person — protocols, teaching, research prose, admin, templates — and use a certified product or an ambient scribe for the record.

Is Apple’s dictation safe for clinical notes? On-device processing removes the third-party transcription question, which is a real advantage, but it does not make the workflow compliant, and Apple does not certify it for clinical use. Your record system, your storage, and your professional duties are all still in scope.

What about a local, offline dictation app? A tool that never sends audio anywhere is a materially different risk profile, and several good ones exist for macOS. It is still your responsibility to establish that the rest of the workflow — where the text lands, how it is stored, who can read it — meets your obligations.

Is cross-language dictation useful in healthcare? Yes, for writing that has no patient in it: journal submissions, correspondence with international colleagues, conference material. Not as a way to route patient content around a certification question.

Why doesn’t Dikto get certified? It is a fair question, and the honest answer is that HDS certification and a BAA programme are commitments a general-purpose dictation product has to make deliberately, not retrofit. Until we do, we would rather say so on this page than let a search result imply otherwise.

In summary

Medical dictation on a Mac is not a single market. It is one market that requires certification and one that does not, and the tools in each are barely comparable.

If you need the note, shortlist certified clinical dictation and ambient scribes, and put every vendor through the six questions above. If what you need is to stop typing the protocols, the teaching material, the grant text, and the English-language correspondence, a general AI dictation tool does that work well, and you can try Dikto free without a credit card — for exactly that half of the job, and not the other one.

Start using Dikto for free

AI-powered voice dictation for macOS.

Start using Dikto for free