An Azure service that integrates speech processing into apps and services.
Hello @Adrian Dumitrescu
It is worth asking these questions before using MAI-Transcribe with clinical data, especially since the feature is still in public preview.
According to Microsoft's current documentation, separate the features explicitly documented for the Speech service/Fast Transcription data path from those that still require confirmation from Microsoft, specifically for MAI-Transcribe preview.
1. DPA coverage
The Product Terms of Microsoft state that the Microsoft Products and Services Data Protection Addendum (DPA) is the document that regulates the processing and security of Customer Data and Personal Data with regard to Online Services; there are specific exceptions listed in the current Product Terms where the DPA does not apply, and MAI-Transcribe is not currently included in those exceptions.
However, MAI-Transcribe-1.5/2 is specifically designated as a public preview and is being provided without any service level agreement, and is not recommended for use in production environments.
Do not consider the lack of a DPA exception enough to confirm by contract that each GA Speech compliance commitment automatically applies unaltered to this preview. For a clinical workload, I would ask Microsoft to confirm the applicable Preview Supplemental Terms, along with your DPA, before handling production PHI.
2. Regional processing, EU Data Boundary
The current regional documentation for Microsoft Speech states that Azure Speech neither stores nor processes any customer data outside the region in which the Speech resource was created; data is stored or processed only in the region where the resource was created.
Hence, in the usual documented speech processing procedure, a North Europe speech resource offers regional processing in North Europe.
The EU Data Boundary involves a broader contractual obligation for eligible Microsoft enterprise online services, with documented exceptions and restricted transfers.
No publicly available statement specific to MAI-Transcribe-2 confirms that all enhancedMode processing components, including any transient processing, are treated the same way under the EU Data Boundary commitment when in preview mode. Since your situation involves clinical use, ask Microsoft to confirm that point explicitly rather than infer it.
3. Audio retention
Fast Transcription now has a quite clear record of this section. As Microsoft's documentation on speech privacy states:
For real-time speech-to-text, fast transcription, pronunciation assessment, and speech translation, Microsoft does not keep or store data supplied by its customers.
That is, Fast Transcription is not listed as having a configurable retention period because it does not retain or store the data submitted after processing; Batch Transcription, by contrast, does have configurable storage and retention settings.
There is no separately documented 'zero-retention' setting for Fast Transcription since the stated behavior involves no retention of the customer data submitted.
Even if you're using enhancedMode just in order to access MAI-Transcribe-2, still ask Microsoft in writing to confirm that the Fast Transcription no-retention statement applies without change to that preview model.
4. Training/improvement
The documentation on speech privacy states that customer audio is processed in order to carry out the requested speech operation and includes details regarding the retention policy mentioned above; for instance, even if diarization is enabled, the speaker characteristics that are extracted are kept temporarily only for the purpose of carrying out speaker separation and are then discarded once the processing is complete.
Refrain from making the general contractual statement that the preview inputs and transcripts of MAI-Transcribe-1.5/2 are never used for model improvement unless Microsoft highlights a provision that specifically applies to these preview models. This point matters when conducting a clinical-data governance review.
5. ISO/SOC/HIPAA
Be especially careful here.
For its ISO, SOC, HIPAA BAA, and other compliance programs, Microsoft provides an audit scope on a service-by-service basis and advises customers to use the Azure compliance scope documentation and relevant audit reports to determine which cloud services are included.
It would be wrong of me to say that MAI-Transcribe-2 has inherited the ISO 27001, ISO 27701, SOC 2 or HIPAA BAA eligibility simply because Azure Speech has those attestations; preview features may have a different compliance scope.
Regarding PHI, I would ask Microsoft to confirm whether MAI-Transcribe-1.5 and MAI-Transcribe-2 using Fast Transcription enhanced mode are currently included in the HIPAA BAA, rather than relying on the general Azure/Speech compliance listing.
6. Preview → GA
The current documentation for Microsoft's MAI-Transcribe still has the feature marked as being in public preview, does not include an SLA, and is not recommended for use in production environments. I also do not see a published general availability date in the current documentation.
Review the MAI-Transcribe documentation and the Azure Updates rather than trying to work out a timeline; each GA announcement should include updated service documentation outlining the supported production characteristics.
Since the document is meant for clinical use, I recommend you not proceed with transferring production PHI through MAI-Transcribe-2 based solely on community guidance. Instead, you should open a Microsoft support or compliance request and request written confirmation of each of these four points:
The applicability of DPA goes to the EU Data Boundary and then to the applicability of Fast Transcription zero-retention to enhancedMode, which in turn relates to the HIPAA BAA/compliance scope for MAI-Transcribe-2 preview.
Microsoft should confirm those contractual/compliance questions for the specific preview version.
References:
MAI-Transcribe in Azure Speech (preview)
Speech-to-text data, privacy and security
Supported regions for Azure Speech
Microsoft Products and Services DPA
Microsoft Product Terms - Privacy & Security
Azure services in compliance audit scope
=============================================================================
Help make this community better for everyone: If the answer helped or resolved your issue, please accept it or upvote it. This helps others in the community find similar solutions.