
Nabla
Nabla is an ambient clinical AI assistant that listens to patient encounters and drafts structured notes inside Epic and other major EHRs, adding dictation and E/M and ICD-10 coding suggestions across 55+ specialties and 36 languages.
What is Nabla?
Nabla is a clinical AI assistant built by Nabla Technologies, a French company headquartered in Paris with a second hub in New York. It presents itself as the Clinical AI Layer rather than a standalone tool: something that sits inside the systems clinicians already use and covers the documentation journey from the chart before the visit to the code submitted at the end of it.
Three modules make up the product. Ambient documentation listens to the clinician-patient conversation and generates a structured clinical note automatically. Dictation brings clinical-grade speech recognition to the cursor inside Epic and other major EHRs, with voice commands, shareable dot phrases and a custom dictionary for unusual terminology. Coding proposes E/M codes based on medical decision-making and AMA guidelines, alongside ICD-10, HCC and MCC codes, and shows the reasoning behind each one — Nabla reports better than 97% agreement with expert coders, validated against AAPC-certified reviewers, with every final decision left to the clinician.
The output goes back into the record rather than into a separate app. Notes are exported into EHR templates, while vital signs, diagnoses and patient instructions are pushed into charts, flowsheets and structured fields. Nabla also retrieves patient history and context from the EHR to inform the note, separates clinician and patient voices through diarization, and writes patient-friendly visit summaries.
Scale is a large part of the pitch. Nabla claims deployment across more than 130 health organisations, 85,000 clinicians and 20 million encounters a year, spanning 55+ specialties and 36 languages including bilingual consultations. Named customers include CVS Health, Children's Hospital Los Angeles, Carle Health, Denver Health and University of Iowa Health Care, and the efficiency figures are anchored in a NEJM Catalyst study and peer-reviewed research rather than in vendor claims alone.
For software teams there are two further doors. Nabla Connect embeds the assistant inside an EHR through an iFrame, and a documented public API covers note generation, natural-language editing, FHIR normalisation, real-time dictation and custom dictionaries. Security rests on SOC 2 Type II and ISO 27001 certifications, HIPAA and GDPR compliance claims, Google Cloud hosting in a customer-chosen region, and retention policies the organisation configures itself.
What it does
- Generate a structured clinical note automatically from the clinician-patient conversation
- Dictate straight at the cursor inside Epic and other EHRs, with voice commands and dot phrases
- Surface E/M, ICD-10, HCC and MCC coding suggestions grounded in the documentation
- Push notes, vital signs, diagnoses and patient instructions into EHR templates and structured fields
- Pull patient history and clinical context from the EHR before and during the visit
- Document bilingual encounters across 36 languages, with speaker diarization
- Call the API to generate, edit and normalise notes into FHIR-ready structured data
When to use Nabla / When not to
A quick filter to help you decide if Nabla is the right fit.
When to use Nabla
- Physicians in ambulatory, emergency, behavioural health and paediatric settings who lose evening hours to writing notes
- Nurses and nurse practitioners, whom Nabla is explicitly extending its assistant to cover
- Health systems and medical groups already running Epic, Oracle Health, athenahealth, NextGen or Greenway
- Clinical documentation specialists, medical coders and quality teams working on E/M, ICD-10, HCC and MCC accuracy
- EHR vendors and healthtech builders who would rather embed ambient AI through Nabla Connect or the API than build it
When not to use Nabla
- Buyers who need a published price: no rate appears anywhere on the site, and every quote goes through the sales team
- Individuals and organisations outside healthcare, whom the site redirects to a generic contact address
- Teams expecting automated billing: Nabla only suggests codes, and nothing is filed with a payer automatically
- Anyone looking for long-term storage, since patient data is kept for fourteen days by default
- People after a general-purpose meeting or interview transcriber, as the product is built solely around clinical documentation
How to use Nabla
A typical end-to-end flow, from setup to results.
- Start free from the Nabla onboarding page, or contact the team for an organisation-wide rollout
- For an organisation, Nabla creates the workspace and appoints an administrator
- Choose the Google Cloud region when the organisation is created, since it fixes where data will live
- Have the administrator add clinicians from the Admin Portal, using SSO, SAML or SCIM where needed
- Install the surface that fits the workflow: web app, iOS, Android, Chrome extension or an EHR-embedded view
- Open a new encounter and let Nabla listen — a session can run up to three hours
- Review the generated note and shape it with voice commands or dot phrases
- Check the E/M and ICD-10 suggestions and confirm the final code yourself
- Export the note and structured fields into the EHR; encounters stay accessible for fourteen days
- For EHR vendors, embed Nabla Connect in an iFrame or work API-first from the OpenAPI specs and sample app
Pros & Cons
Pros
- Outcomes rest on named, published evidence — a NEJM Catalyst study and peer-reviewed research from University of Iowa Health Care — not on vendor figures alone
- EHR coverage is genuinely broad: Epic, Oracle Health, Cerner, athenahealth, NextGen, Greenway, Arya and Altera, with Nabla Connect for the rest
- Certifications are obtained rather than aspired to: SOC 2 Type II, ISO 27001, HIPAA, and HDS-certified hosting through Google Ireland
- Legal documentation is unusually complete and public: terms, a full DPA with a named sub-processor annex, and a HIPAA business associate agreement
- 36 languages including bilingual encounters, which is rare in this segment
- A public, documented API with OpenAPI specs and a sample app, so the platform is not a closed box
- Retention is configurable by the organisation, and audio is not stored by default
Cons
- No pricing is published anywhere; the terms even point to a subscription package 'as published on NABLA website' that does not exist there
- The stance on model training is contradictory: product pages promise no training on your data while the US terms permit training on de-identified data
- Audio shared as feedback is kept indefinitely, even once anonymised
- Patient data is retained for fourteen days by default, which demands a disciplined export routine
- The security page dates from September 2023 and the privacy policy from May 2023, both older than the coding and agentic capabilities they ought to cover
- There is no documented way for a customer to opt out of model training
- The help centre and onboarding pages render only through JavaScript, which makes them awkward to consult or archive
Pricing & Plans
Nabla publishes no prices. The site advertises a free entry point, Try it for free, but documents no permanent free plan, and no rate card, tier or starting amount appears anywhere on it. The general terms state that the fee is a monthly subscription whose basis of calculation depends on the number of users, quoted in euros excluding VAT, with a one-month initial period renewing by tacit agreement and invoices payable within thirty days. Any actual figure has to be obtained from Nabla's team.
- Subscription Package — a monthly
- per-user contract whose scope is set by the modules it includes
- no tier is named or priced on the site
- Ambient AI documentation module
- Dictation module
- Coding module
- Nabla Connect
- the embeddable module for EHR vendors
- API access for teams building their own interface
Data, GDPR & hosting
A consolidated view of how Nabla handles your data.
GDPR overview
GDPR compliance is claimed explicitly and repeatedly: GDPR compliant on the dictation and Connect pages, HIPAA and GDPR Compliant on the EHR page, and a HIPAA / SOC 2 Type II / ISO 27001 / GDPR banner on the homepage. The implementation behind the claim is concrete. Nabla publishes a full Data Protection Agreement drafted under Article 28 GDPR and French law 78-17, names its sub-processors — Google Ireland Ltd for health data hosting, Microsoft Ireland Operations Ltd for speech and GPT models — and states that data is as a rule neither processed nor transferred outside the European Union, falling back on an adequacy decision or Standard Contractual Clauses when it is. Data subject rights are itemised with a one-month response target and a dedicated dpo@nabla.com address. As a French company Nabla needs no Article 27 representative. The policy is dated 16 May 2023.
Who owns the data?
Under Nabla's Data Protection Agreement the customer is the data controller and Nabla is only a processor within the meaning of Article 28 GDPR, so the healthcare organisation keeps ownership and control of patient and user data while Nabla acts on its instructions. The terms restate that the client retains full control over personal data; what Nabla keeps is full ownership of the software itself, its modules and any adaptations. Account-level data follows a different rule: Nabla Technologies SAS in France and Nabla Technologies Inc in Delaware are joint controllers for it. When the contract ends, Nabla returns the personal data or, by default, deletes it.
Reuse rights
The clinical output belongs to the customer. Notes, coding suggestions and patient instructions can be exported into the EHR and used freely, and nothing in the terms reserves rights over them for Nabla. Reuse in the other direction is much tighter: the terms forbid downloading, copying, redistributing or creating derivative works from the platform's content, code and design without written consent, and bar use beyond running your own business. Nabla's own reuse of customer material deserves attention. Its US terms let it process de-identified data generated through use of the service to train its internal AI model, and disclose that de-identified data, with patient audio excluded — while the product pages advertise no model training on your data. Audio is not stored by default, but audio a clinician chooses to share as feedback is anonymised at once and then kept indefinitely.
Data retention & training
Hosting summary
Nabla runs on Google Cloud Platform. Databases and storage buckets sit in the region the customer picks when the organisation is created, which makes hosting location a deployment decision rather than a fixed answer. The contracting host for the application is Google Ireland Ltd, certified HDS — the French standard for health data hosting — with a Paris office. The marketing site is separate, hosted by Netlify in San Francisco. Data is encrypted at rest with AES-256 through Google's key management service and in transit over TLS, and encrypted backups are held across several Google Cloud regions. The Data Protection Agreement states that data is as a rule neither processed nor transferred outside the European Union; where a transfer does occur, Nabla relies on a European Commission adequacy decision or on Standard Contractual Clauses. Account-management data follows a different path, with the privacy policy having customers consent to transfer to the United States. Two sub-processors are named: Google Ireland Ltd for hosting and Microsoft Ireland Operations Ltd for speech and GPT models.
Things to keep in mind
Risks and trade-offs to weigh before adopting Nabla.
- Automation complacency: a note that reads well is not necessarily a note that is right, and signing one unread moves an error straight into the patient's chart
- The training question is unsettled — the product promises no model training on your data while the US terms permit training on de-identified data, so read the contract you actually sign
- Audio shared as feedback is kept indefinitely; de-identification is done by Nabla, and a clinician sharing a clip is making a lasting decision on a patient's behalf
- The fourteen-day default retention is easy to forget: an encounter not exported in time is simply gone
- Coding suggestions carry billing and audit consequences; however confident the tool sounds, the clinician confirms every code and owns it
- Documentation skill can erode when the note is always drafted for you, which matters most for trainees still learning to write one
- Ambient listening changes the consultation room: patients need to know a microphone is on, and consent practice is the deploying organisation's responsibility, not the vendor's
Setup & Integrations
Technical difficulty
Low for clinicians, moderate for integrators. A clinician signs in on the web, iOS, Android or the Chrome extension and can open an encounter straight away; one customer describes the rollout as lightweight enough to start using immediately. An organisation needs Nabla to create the workspace, an administrator to manage users from the Admin Portal, and a decision on the Google Cloud region. EHR vendors embed Nabla Connect in an iFrame and are told to go live in days rather than months, while teams wanting full control work from the documented API, its OpenAPI specs and a sample app.
Deployment
Apps stores
Integrations
Supported languages
Behind Nabla
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
How much does Nabla cost?
Does Nabla submit codes to the payer for me?
How long does Nabla keep my data?
Is my audio recorded and stored?
Is my data used to train Nabla's models?
Which EHRs does Nabla work with?
How many languages does Nabla support?
Where is the data hosted?
Is there a free trial?
Does Nabla have mobile apps?
Should you pick Nabla?
Nabla is one of the better-documented tools in clinical AI, and that matters more than the marketing. The company is identifiable — a French SAS with its registration number, capital and VAT number on a proper legal notice page — and it publishes what a health system's procurement team actually asks for: full terms, a Data Protection Agreement naming its sub-processors, a HIPAA business associate agreement, obtained SOC 2 Type II and ISO 27001 certifications, a public trust portal and a documented API. The efficiency claims are backed by a NEJM Catalyst study and peer-reviewed research rather than by testimonials alone, and the customer list is named rather than anonymised.
The product itself is coherent. Ambient documentation, dictation and coding sit in one platform, output lands back in the EHR rather than in a separate window, and 36 languages with bilingual encounters is genuinely uncommon in this market.
Two things need checking before you commit. The first is cost: nothing is published, and the terms point at a subscription package on the website that is not there, so budgeting means a conversation with sales. The second is model training, where the product pages and the US terms do not say the same thing — no model training on your data on one side, permission to train on de-identified data on the other. Neither is a reason to walk away, but both are questions to settle in writing.
For a health system already on Epic or one of the other supported EHRs, and for EHR vendors who would rather embed ambient AI than build it, Nabla is a serious candidate. For an individual clinician wanting to know what it costs before talking to anyone, it is not built for you.
- Choosing a selection results in a full page refresh.
- Opens in a new window.