Ambient Scribes
N

Nabla

Ambient AI scribe generating structured clinical notes in real time from in person or telehealth encounters, reported across more than 85,000 clinicians at over 150 health organizations, weighted toward hospital systems, emergency departments, and multi provider groups. Two characteristics distinguish it. The first is EHR breadth: integrations span Epic, athenahealth, Oracle Health, NextGen, and Greenway, one of the widest footprints in the category and a practical fit for organizations running mixed EHR environments.

The second is language coverage across roughly 31 languages, with templates spanning more than 35 specialties customized through custom instructions and dot phrases. The vendor reports that about 55 percent of users save at least an hour a day on documentation with a 27 percent reduction in burnout, figures it attributes to a published NEJM study. Two disclosures matter for procurement and are covered in the capability records: the free tier reportedly does not include a Business Associate Agreement, and session data is used for model training by default. Founded 2018 in Paris.

AI Health Index verifiedJuly 6, 2026
Compare Nabla with other vendors
Founded
2018
Headquarters
Paris, France
Website
www.nabla.com
Categories
ambient-scribes
Indexed Products
Nabla Copilot
Buyer Segments
Large IDN, Community Health System, Medical Group, Independent Practice
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

Ambient speech to structured note generation is the product in full. There is no non AI version of it.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The oversight model is the category standard, but one detail is better than the category standard and reveals a design assumption. The company states that the 14 day data retention period exists to give physicians enough time to review, edit and export their note to the electronic health record.

The retention policy is sized around the clinician's review rather than around the vendor's convenience, which means the product is built on the expectation that a clinician will edit before export. Most vendors in this category assert clinician review as a disclaimer; here it is load bearing in the architecture. A structured feedback mechanism after each encounter gives clinicians a route to report problems back, which is a real if informal oversight channel.

Held below a higher grade on the absences that apply across this category. There is no published accuracy, hallucination or omission rate. Nothing states what the system does when audio quality is poor, when speakers overlap, or when a passage cannot be resolved. And no confidence indication is surfaced to the reviewing clinician showing which parts of a generated note are uncertain.

That last gap is sharper at 35 languages, where transcription confidence will vary far more than in a monolingual deployment, and a reviewer who is not told where the uncertainty sits is exposed to the automation bias that fluent drafts reliably produce.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

The training position is stated plainly and unconditionally: Nabla does not train its models on user data, and audio is not stored. That closes a question this index repeatedly fails to get answered elsewhere in this category, and it is closed alongside a genuinely honest carve out rather than in absolute terms. Clinicians may choose to share feedback after an encounter, and that feedback may include de identified audio.

Publishing the exception to your own privacy claim, rather than letting the headline stand unqualified, is the kind of detail a buyer would otherwise discover only in a contract. Infrastructure is named as Google Cloud Platform and Microsoft Azure. Held below a higher grade because the model itself is not characterised in any way.

There is no model class or version, no foundation model provider named, no architecture description, no update policy, no statement of what is proprietary versus wrapped, and no published accuracy, error or benchmark figure of any kind was located. Two capability figures are published and imply internal measurement that is not shared: support for more than 55 medical specialties and 35 languages. A vendor stating a language count that precisely holds per language performance data. No research, model card or technical documentation page was located in this review, and the company has a research presence, so this assessment could change.

BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an in house build, a cleared model that cannot be quietly swapped, or a deployment where the transfer does not occur at all. Naming only the hosting provider sits at the top of this band rather than in A.
Vendor Published

An unusual shape, and it is worth naming because it shows the two halves of this axis coming apart. The question has two parts, which third parties are in the chain, and whether customer content reaches them. Nabla answers the second part better than almost any vendor in the index and leaves the first part blank.

On the data boundary the commitments are explicit: models are not trained on user data, audio is not stored by default, and the company states it holds agreements to opt out of data retention with all services used to process the data, which forecloses accumulation at the sub processor layer rather than leaving it to a contract nobody reads.

The published carve out is what makes the claim credible, since clinicians may choose to share post encounter feedback which may include de identified audio, and publishing the exception to your own privacy statement is rare. Infrastructure is named, across Google Cloud Platform and Microsoft Azure. What is missing is enumeration.

The parties covered by those retention opt outs are not listed, no sub processor page was located, and the model layer is not characterised at all, with no provider, class, version or statement of what is proprietary against what is wrapped. So a buyer knows a boundary is asserted around content without knowing who sits on the other side of it. Ask for the sub processor list, and ask specifically whether any foundation model provider is among the services covered by the retention opt outs.

AA on Clinical and Operational EvidencePeer reviewed or independently evaluated performance, prospective and multi site where the claim requires it, with the method available to read.
Third Party Estimated

Upgraded from B on 23 July 2026 once the underlying study was retrieved directly. The evidence is now the strongest efficiency result in this category, and it is independent rather than vendor generated. In Lukac et al, NEJM AI, published 26 November 2025 (NCT06792890), 238 outpatient physicians across 14 specialties at UCLA Health were randomized 1:1:1 to Nabla, Microsoft DAX Copilot or usual care over two months across roughly 72,000 encounters.

Nabla reduced time in note by 9.5 percent against control and was the only arm to meet the primary endpoint; the DAX arm reached 1.7 percent and was not statistically significant. Both arms improved secondary burnout measures by roughly 7 percent. The trial was funded by UCLA, not by either vendor, and the protocol is registered and published.

Two honest caveats the study itself records: utilization was low, with Nabla used at 6,981 of 23,653 eligible visits, and physicians were instructed to use the scribe only at English language visits because translation capability had not been internally validated. Graded on the existence, venue, independence and documented design of the evidence; this index does not re verify the underlying study.

AA on AI Safety and PHI StewardshipRetention windows, training use and de identification are stated specifically enough to be contradicted, alongside the safety engineering: guardrails, hallucination mitigation, and how a safety event is handled.
Vendor Published

Nabla publishes a complete data deletion lifecycle, including backup expiry, which nothing else in this index does. Audio is not stored by default. Medical data is retained for a configurable 14 days, a window the company explicitly sizes to give physicians time to review, edit and export their note. On expiry, data is immediately removed from the application and remains only in backups, and seven days later the backups also expire and patient data is entirely gone from their systems.

That last step is what makes it a genuine deletion claim: a commitment that stops at the application layer leaves the question of backups unanswered, and most vendors never address it. Two further commitments support it. Stored transcripts and notes carry two layers of encryption, system and application. And the company states it holds agreements to opt out of data retention for all services used to process the data, which closes the subprocessor gap most vendors leave open.

Retention is additionally customisable per organisation. The company also states it does not train its models on user data, alongside one carefully published exception: clinicians may choose to share post encounter feedback, which may include de identified audio. Publishing the exception to a privacy claim rather than letting the headline stand unqualified is unusual and worth crediting. Confirming the training position and retention configuration contractually remains sensible practice.

Regulatory and Compliance
CC on HIPAA and BAA PostureCompliance is claimed without the underlying document, or the published privacy notice covers the website rather than the service that handles patients.
Third Party Estimated

HIPAA and GDPR compliance are stated, but the free tier reportedly does not include a Business Associate Agreement. That makes the free tier unusable in production for any US organization handling protected health information regardless of how well the scribe performs, the same structural constraint identified for Heidi. Evaluate on the tier you would actually contract.

AA on Security Certifications and Trust CenterCertifications named with their type and version and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
Vendor Published

A public trust centre runs at trust.nabla.com, hosted on Secureframe, and the operational detail behind it is among the strongest in this index. Certifications are named with their types: SOC 2 Type II and ISO 27001, with the company stating that its information security programme follows both frameworks and has obtained the associated certifications, and that it undergoes independent third party assessments to test security and compliance controls.

Also listed are HIPAA, GDPR, CCPA, NIST Cybersecurity and TX-RAMP. Three operational disclosures go beyond the badge list and are what distinguish this record. An independent third party penetration test is performed at least annually, stated plainly rather than implied. The policy set is quantified at 25 information security policies, all updated at minimum annually, which is a more falsifiable claim than describing a programme in the abstract.

And there is a named vendor management programme: all vendors are logged, ranked by criticality using standard risk methodologies, and critical and high vendors are audited annually. A dedicated information security and privacy team is stated to own internal audits and to work with external auditors. Encryption is described as two layers, system and application, on stored transcripts and notes, with infrastructure named as Google Cloud Platform and Microsoft Azure.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

No FDA clearance, none claimed and none required for ambient documentation. The clinician reviews, edits and exports the note, and the 14 day retention window is explicitly sized around that review. The noteworthy fact here is an absence, and it makes this record the exception in its own category in a way that is entirely to its credit on this axis.

Every other ambient scribe assessed in this index has expanded past documentation into functions that change its regulatory object: coding at the evaluation and management, HCC and ICD-10 levels, real time clinical insights, clinical reasoning and chart question answering, ambient order staging, point of care HCC capture, patient facing receptionist products, and revenue cycle work.

Nabla is reported to have no coding capability at all, with the vendor saying it is in development, and nothing located shows a decision support, patient facing or reimbursement function. It has stayed a scribe. That keeps its regulatory position the simplest and cleanest in the category, and it is the clearest evidence available that the scope expansion elsewhere in this segment is a commercial choice rather than an inevitability. The assessment reflects that no clearance exists and none is needed, not that anything is deficient. If coding ships, the regulatory object changes and this should be reassessed.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

No AI specific governance artefact was located: no responsible AI statement, no bias or fairness position, no demographic, language or speaker group performance analysis, no error taxonomy, no model monitoring description and no published evaluation output. What does exist is strong security and data governance, which is easily mistaken for AI governance if read quickly, and the distinction is worth holding.

A dedicated information security and privacy team, 25 annually updated policies, an audited vendor management programme, NIST Cybersecurity alignment and a clear commitment not to train on user data are all real, but they govern how data moves rather than how the model behaves. The absence is most conspicuous on language, and more so here than for most competitors.

This vendor is European in origin, operates across 35 languages, and sells into GDPR jurisdictions where the EU AI Act treats clinical AI as high risk and contemplates exactly this kind of disclosure. Speech recognition accuracy varies measurably across accent, dialect, speech rate and vocal characteristics, and a multilingual ambient product has both the strongest reason and the best underlying data to publish performance by language.

At least one competitor in this category now holds an independently audited AI management system certification, which is the credential this record lacks and the one most likely to change the assessment.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

The commitments Nabla publishes are real, falsifiable and specific, and they are all about data rather than about output. A complete deletion lifecycle is published including backup expiry, medical data is retained for a configurable fourteen days, and the company states the window is sized deliberately to give a physician time to review, edit and export the note before it goes.

That last detail is the part that touches this axis, because a retention window designed around clinician review is a designed correction window: the period during which an error introduced by the system can still be found and fixed by the person who signs. Encryption specifics and per organisation configurability sit alongside it. What is absent is any commitment standing behind the note itself.

No accuracy, error or benchmark figure of any kind was located, no performance guarantee, no remediation obligation and no indemnity toward the customer. Two capability figures are published, more than 55 specialties and 35 languages, and a vendor stating a language count that precisely holds per language performance data it has chosen not to publish.

That matters here rather than only on transparency, because uneven performance across languages is a liability question for whoever deploys it in a multilingual population. The patient has no route, as everywhere in this category. Ask for per language accuracy and for what the vendor commits to when a note is wrong.

Integration and Deployment
AA on EHR and Interoperability DepthNamed bidirectional integrations with major record systems, verifiable in marketplace listings or integration documentation, with evidence the connection runs in production.
Vendor Published

The widest EHR footprint in this category: Epic, athenahealth, Oracle Health, NextGen, and Greenway. For an organization running different systems across hospital and clinic settings, that breadth means one scribe contract instead of several, which is a materially different procurement position from vendors integrated deeply with a single EHR.

BB on Deployment Model and Data ResidencyOptions and residency are stated with isolation or the processing path left open.
Vendor Published

Hosting is named specifically as Google Cloud Platform and Microsoft Azure, with processing stated to run in compliance with both HIPAA and GDPR, so the vendor operates across United States and European regulatory regimes rather than one. The electronic health record footprint is the broadest in this category, with more than 15 platforms named including Epic, Oracle Cerner, athenahealth, NextGen Healthcare, Greenway Health and Altera Health.

A second deployment surface is distinctive and is the reason this record is not simply a scribe. Nabla Connect is a plug and play module that lets any electronic health record vendor embed the ambient AI inside their own platform, with integration stated to complete in around three days via an authentication setup, an encounter context call, an embedded session and a note export.

That makes Nabla infrastructure other software vendors resell, which is a real interoperability position and also a governance question, since a clinician may be using the product under another vendor's brand without knowing it. One governance feature is genuinely unusual and worth crediting: the data retention policy is customisable per organisation to meet each customer's own governance requirements, rather than being fixed by the vendor.

Scale is reported at more than 65,000 clinicians across 100 plus health organisations. Held below a higher grade because no explicit data residency commitment was located: GDPR compliance and dual cloud hosting are stated, but no region is named and no in country storage guarantee is offered.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Third Party Estimated

Pricing moved in the wrong direction for buyers during 2026. The company historically published tiers, including a free plan of about 30 consultations a month and a Pro plan reported near $119 per month, and reporting indicates it has since moved off public per month pricing toward a demo and contract sales motion, with aggregator listings now conflicting on tier names and rates. Graded on the current state, which requires a sales conversation, with the prior published position noted because the direction of travel is itself informative.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Vendor Published

Broad and specifically stated: roughly 31 languages and templates across more than 35 specialties, spanning in person and telehealth encounters on mobile, desktop, and browser, with a customer base weighted toward hospital systems and emergency departments.

Tracked Since Listing

What Changed

Material product, regulatory, evidence and commercial changes at Nabla, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.

Aug 25, 2026Product / capability

Nabla released version 2026-08-25 of its Core API. An optional specialty field was added to user management and note generation on the Server API, and an encounter date field was added to note generation on both the User and Server APIs, so a caller can now tell Nabla what kind of encounter it is transcribing instead of leaving the model to infer it. The release also introduces an audio chunk acknowledgement protocol and enforces strict endpoint path prefixes, which is a breaking change for anyone relying on loose paths.

Bears on: EHR and Interoperability DepthSource
Jul 6, 2026Pricing / packagingPartially verified

Nabla appears to have withdrawn public per month pricing in favor of a demo and contract sales motion, particularly for organizations. The company historically published a free tier of roughly 30 consultations a month and a Pro plan reported near $119 per month. Third party listings now conflict on tier names and rates. Recorded as Partially Verified: the shift is consistently reported by third parties but was not confirmed in vendor published materials, and the date reflects the verification pass rather than an announcement.

Bears on: Commercial TransparencySource
Our read on these changes →Tracked since Jul 2026
Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor (previously published tiers, withdrawn)
Previously per user per month with a free tier; now demo and contract sales Free tier reportedly does not include a Business Associate Agreement Third Party Estimated

ESTIMATED and in flux. The company historically published a free tier of roughly 30 consultations a month and a Pro plan reported near $119 per month. Reporting through 2026 indicates a move off public per month pricing toward demo and contract sales, particularly for organizations, and third party listings now conflict on tier names and rates. Neither the historical figures nor the current structure is confirmed by the vendor.

Two procurement constraints carry more weight than the price: the free tier reportedly lacks a Business Associate Agreement, and session data is used for model training by default. Confirm both, and whether training can be disabled contractually, before deployment.