When searching for an interview transcription service, researchers shouldn't have to choose between staying within budget, getting the words right, and protecting participants' privacy and confidentiality.
Staying within a research budget matters, especially when you're working under a grant. But low price can become expensive if it doesn’t deliver what you need.
For confidential research, that means the transcription must meet two requirements:
- Accurately reflect what participants said
- Maintain confidentiality throughout the process
The goal isn't just to find a low price. It is to find a competitive price that delivers the accuracy, confidentiality, and control the research requires.
Price Is Not Easy to Compare
General transcription services list their rates right on their website. These companies often use AI and/or freelance workers outside the US. As you might imagine, the prices vary widely.
But price alone doesn’t tell you how the work will be done. You still need to know:
- Who is transcribing the recording?
- Is AI involved?
- Where is the work being performed?
- Who has access to the files?
- How are they protected?
- How long are they kept?
- And has anyone independently verified the company's security and confidentiality practices?
Priority #1: The Words Must Be Right
In our first article, AI Transcription: The Price Is Right. Are the Words? we looked at the relationship between price and accuracy.
A 2025 systematic review found word-error rates under 10% in some controlled settings but above 50% in some conversational and multi-speaker recordings. It also found recurring problems with specialized terminology and accented speech. [1]
That doesn't mean automated transcription is always the wrong choice. It means researchers need to define the accuracy level required to meet their objectives.
When the transcription becomes part of the research data, accuracy is non-negotiable.
Once the required accuracy level is established, the researcher must clarify how their confidential data will be protected.
Who Has Access to Your Research?
A company can say on its website that it is secure and takes confidentiality seriously.
But can it prove it?
A human subject research interview may contain a person's health history, which could include discussions of PTSD, substance use, homelessness, military sexual trauma, finances, family problems, and other deeply personal subjects.
The participants will never know who transcribed their interview. They trust the researcher to protect their personal information. It is the researcher’s duty to know who has access to it.
Before sending confidential recordings to a transcription service, the researchers must know:
- Where will the recordings be transcribed?
- Is AI used anywhere in the process?
- Where - and how - will they be stored?
- Who can access them?
- Is the data encrypted in transit and at rest (on the server)?
- How long are recordings and transcriptions retained?
- How are they deleted?
- Has an independent third party verified the company's security controls?
- What credentials support the company's claims of security and confidentiality?
- Does the transcription company provide a Business Associate Agreement (BAA)?
Veterans Affairs (VA) Researchers Have Even More to Consider
VA researchers have an additional layer of responsibility because the methods used to transfer, process, and store sensitive research data must meet applicable VA and study requirements. The VA's Research IT and Data Governance program specifically addresses secure access, storage, and use of sensitive research information. [2]
This is particularly important if the researcher is considering using AI. VA guidance says sensitive data, including PHI and PII, may only be entered into AI tools with a VA Authority to Operate (ATO) covering that use. Just because an AI tool is available on the VA network does not mean it is approved for sensitive VA data. [3]
For researchers, this raises the question:
Where is my research interview going?
If a transcription service uses AI, researchers should know what system processes the recording and whether that use is permitted for the data involved.
HIPAA Compliance Is Important. But There Is More.
The U.S. Department of Health and Human Services specifically identifies independent medical transcriptionists and transcription-app vendors as examples of business associates. [4]
Under HIPAA, business associates must safeguard the protected health information (PHI) they access. These obligations are covered by a signed Business Associate Agreement (BAA). [4]
But a BAA doesn't tell a researcher how the work is actually being performed.
Without documented confidentiality practices, HIPAA training, access controls, and independent security verification, how does a researcher know who is handling the recording - and under what conditions?
Could the work be performed in a crowd-shared workspace? On an unsecured network? In an internet café thousands of miles away?
The issue isn't whether work is performed overseas. The issue is whether the researcher knows where and how the data is being handled, and what safeguards are in place to protect it.
A transcription company must provide more than a "we take security seriously" statement on their website.
SOC-2 is an independent examination of a service organization's controls related to areas such as security and confidentiality. [5] Instead of relying only on a company's claims, researchers can ask what independent evidence supports them.
The Value of a SOC-2 Report
A SOC-2 report, like other independent audit reports, provides documented, independently examined evidence of the security and confidentiality controls in place. For example, Research Transcriptions' SOC-2 report covers over 112 documented and verified controls. Clients may review it under a signed NDA.
Is U.S.-Based Transcription Safer?
Yes. But location alone doesn't create security.
Researchers should look for layers of protection, including:
- U.S.-based personnel
- Identity verification and background screening
- Confidentiality agreements
- Privacy and security training (including HIPAA)
- Encryption in transit and at rest
- Role-based access controls
- Audit logging
- Documented retention and deletion procedures
- Independent security verification
- Business Associate Agreement (BAA)
No single safeguard is enough. Together, these controls provide a clearer picture of how confidential research information is handled.
Can You Have All Three?
Low Price. Accuracy. Confidentiality.
Yes. But the lowest price only has value when the service delivers the accuracy the research requires and protects confidential information throughout the process.
The goal should be to obtain a competitive price without compromising either.
For a competitive price from Research Transcriptions, contact us.
References
[1] Ng JJW, Wang E, Zhou X, et al. Evaluating the performance of artificial intelligence-based speech recognition for clinical documentation: a systematic review. BMC Medical Informatics and Decision Making. 2025;25:236. doi:10.1186/s12911-025-03061-0. https://pmc.ncbi.nlm.nih.gov/articles/PMC12220090/
[2] U.S. Department of Veterans Affairs, Office of Research & Development. Research IT and Data Governance. https://www.research.va.gov/programs/itdg/
[3] U.S. Department of Veterans Affairs. Guidance for Generative AI Use at VA. Updated July 22, 2026. https://department.va.gov/ai/guidance-for-generative-ai-use-at-va/
[4] U.S. Department of Health and Human Services. Business Associates. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/
[5] American Institute of Certified Public Accountants (AICPA). SOC 2 - SOC for Service Organizations: Trust Services Criteria. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2/
Submit a comment