Granola is not HIPAA compliant, cannot sign a BAA, and must not process PHI or capture patient or therapy sessions. Consent alone does not change that limit. Its security FAQs, transcription documentation, and security overview describe cloud transcription and AI processing, not local-only operation. Consider only an explicitly approved non-clinical meeting with no PHI.
Keep IEP meetings, student health assessments, therapy planning, counseling, and confidential student support records out of Granola. Use a district-approved system for those records. Do not assume consent or a missing bot makes sensitive student conversations suitable.
Public curriculum and department planning
A department may evaluate Granola for an explicitly approved discussion of public curriculum resources, classroom equipment, or a public event schedule. Keep individual student records and PHI out. If that boundary cannot hold, use manual notes.
Before capture, obtain the required participant consent and review cloud processing, sharing, and retention settings with your organization. Review generated decisions and action items before circulating notes; summaries can omit or misattribute details.
For that limited non-clinical workflow only, evaluate administrative meeting notes. New Granola users get their first three months free through my link. This is an affiliate link; I may earn a commission.


Discussion
Giscus