HIPAA and the AI Scribe: What Must Be True Before It Records

Practical guidance for healthcare teams and business associates

The phone sits on the counter between the doctor and the patient. It listens to the whole visit, and about ninety seconds after the patient leaves, a finished progress note is waiting in the EHR for a signature. For a physician who has spent evenings charting, this is the best thing software has done in a decade. For the person responsible for compliance, it is a new vendor holding the most sensitive recording the practice has ever made.

HIPAA does not prohibit ambient documentation. It also does not have a chapter about it. The tool is governed by the same business associate, risk analysis, access control, and minimum necessary provisions that govern every other system that touches P.H.I. (Protected Health Information). What follows is the sequence: what the vendor is under the regulation, what the contract has to say, what the practice has to do on its own side, and what to write down.

HIPAA AI Scribe Rules: Vendor, Contract, Practice, Paper

1. The Vendor Is a Business Associate, Full Stop

45 CFR 160.103 defines a business associate as a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter." An AI scribe receives audio of a clinical encounter, creates a draft note from it, maintains both for some period, and transmits the note into your chart. It hits every verb in the definition. A vendor whose terms of service call the product "a productivity tool" or "not a medical record" is still a business associate; the label in the contract does not change the function.

Under 45 CFR 164.502(e)(1), a covered entity may allow a business associate to create or receive P.H.I. on its behalf only "if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information," and (e)(2) requires those assurances to be "documented through a written contract." No B.A.A. (Business Associate Agreement), no recording. A consumer transcription app with no B.A.A. offered is in the same category as pasting a chart into a public chatbot, covered in the ChatGPT and HIPAA post.

2. Six Contract Terms That Decide Whether This Is Safe

45 CFR 164.504(e)(2) lists what a B.A.A. must contain. The clauses below are where AI scribes differ from an ordinary cloud vendor, so read them, and do not accept a vendor's standard agreement as the answer without reading it.

Question for the vendorRegulatory hookAcceptable answer
Will the vendor use the practice's audio or notes to train or improve its models?164.504(e)(2)(i): the contract must "establish the permitted and required uses and disclosures," and may not authorize a use the covered entity itself could not makeA written yes or no. If yes, only on data de-identified under 164.514(b), and only if the B.A.A. permits the business associate to de-identify (164.502(d)(1))
How long do you keep the audio, the transcript, and the draft?164.504(e)(2)(ii)(J): return or destroy P.H.I. at termination; 164.310(d)(2)(i) disposalStated retention periods per data type, a deletion setting the practice controls, and destruction on termination
Who else touches the data (speech vendor, model provider, cloud host)?164.504(e)(2)(ii)(D) and 164.502(e)(1)(ii): subcontractors must agree to the same restrictionsA subcontractor list and written confirmation that each is under a downstream agreement
What are the safeguards in transit and at rest?164.504(e)(2)(ii)(B): "use appropriate safeguards and comply, where applicable, with subpart C"; 164.312(e)(1) transmission securityEncryption in transit and at rest, stated plainly, with the practice able to verify settings
How fast do you report a security incident or breach?164.314(a)(2)(i)(C) and 164.504(e)(2)(ii)(C): report incidents and breaches "as required by § 164.410"A reporting window in days, not "promptly," plus a named contact
Can the vendor produce access logs and export a single patient's data on request?164.312(b) audit controls; 164.504(e)(2)(ii)(E): make P.H.I. available under 164.524Per-user logs the practice can export, and an export path for any patient's recordings if the practice retains them

The training question is the one most practices skip and most vendors bury. The practice cannot give a vendor a right it does not have itself. Training a commercial model is not treatment, payment, or health care operations for your practice, so the only lawful path is de-identified data, and de-identification has a specific meaning covered in the de-identification requirements guide. The common B.A.A. mistakes that let this slip through are listed in the BAA mistakes post.

3. The Practice Side: Four Things the Vendor Cannot Do for You

Risk analysis. 45 CFR 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities" to ePHI the practice holds. A new system that records every encounter is a material change. Add it: where the audio goes, who can hear it, what happens if a clinician's phone is lost with the app logged in, and what happens if the vendor is breached. The template for that entry is in the risk assessment template guide.

Access. 164.312(a)(2)(i) requires "a unique name and/or number for identifying and tracking user identity." Every clinician gets their own scribe login; a shared practice account makes the audit log meaningless. Set roles so the front desk cannot open recordings, per 164.514(d)(2), which requires identifying "those persons or classes of persons" who need access and limiting access accordingly. The daily version of that rule is in the minimum necessary post.

Devices. The scribe usually runs on a phone. That phone is now a workstation that captures ePHI, and 164.310(b) and (c) apply to it: who may use it, screen lock, encryption, and a lost-device procedure with a deadline measured in hours.

Training. 164.530(b) requires training on the practice's policies. Two sentences in the annual session are not enough here. Clinicians need to know when to pause the recording (a family member steps in to discuss someone else's care), how to correct a draft, and that the AI draft is not the record until a licensed person reviews and signs it.

4. Telling the Patient, and the State Law Question

Using P.H.I. to document the visit is treatment, and 45 CFR 164.506 permits it without authorization. HIPAA therefore does not require a signed consent to use a scribe for a treatment note. Whether the patient must consent to being recorded is a different question, answered by state recording and wiretap law, and it varies. Some states require every party to agree to a recording. Check yours with counsel before the first visit is captured; this post does not state any state's rule.

Even where consent is not legally required, tell the patient anyway. A one-line script ("The doctor uses a recording tool to write your note; it is fine to say no") and an opt-out that works without an argument is cheap, and it removes the complaint that starts most OCR investigations: a patient who feels something was done to their information without their knowledge.

5. The Audio Is Now a Record. Decide What Kind.

45 CFR 164.501 defines a designated record set to include "the medical records and billing records about individuals maintained by or for a covered health care provider" and any records "used, in whole or in part, by or for the covered entity to make decisions about individuals." If the practice keeps the audio, or the vendor keeps it on the practice's behalf, and clinicians go back to it when a note is questioned, it is arguably part of that set, which means it is subject to the patient's right of access under 164.524 and must be producible within 30 days. The cleanest policy for a small practice is to have the audio deleted once the note is signed, and to say so in writing. A practice that chooses to retain audio should decide, with counsel, whether it is part of the designated record set and how it will be produced and retained.

6. What to Write Into Policy

  • The approved product, by name, and a statement that no other recording or transcription app may be used for patient encounters.
  • The B.A.A. date, the data-use (training) answer, retention periods, and the subcontractor list, filed with the vendor register described in vendor management.
  • Per-user accounts, role restrictions, and the device rules for any phone or tablet running the app.
  • The patient notice script, the opt-out, and where the choice is recorded.
  • When to pause, how drafts are reviewed and signed, and a rule that an unsigned AI draft is never released or billed from.
  • Audio retention: deleted at signature, or retained under a stated period and access process.
  • The lost-device and vendor-incident steps, with the reporting window from the contract.
  • The risk analysis entry date and the annual review date.

None of this is exotic. It is the business associate rule, the risk analysis rule, and the access control rule, applied to a microphone. Practices that do the paperwork before the first recording get the evenings back without adding a vendor they cannot explain to an investigator.

---

FAQ

Is using an AI scribe a HIPAA violation?

No. Documenting a visit is a treatment use permitted under 45 CFR 164.506. The violation risk comes from a vendor without a business associate agreement, an undisclosed model-training clause, shared logins, and no risk analysis entry.

Does the AI scribe vendor need to sign a BAA?

Yes. It creates, receives, maintains, and transmits P.H.I. on the practice's behalf, which is the 45 CFR 160.103 definition of a business associate, and 164.502(e) requires the written agreement before any P.H.I. flows.

Can the vendor train its AI on our patient recordings?

Only if the agreement expressly permits it and only on data de-identified under 45 CFR 164.514(b). Training on identifiable recordings is not a use the practice could make itself, and 164.504(e)(2)(i) bars a business associate agreement from authorizing it.

Do patients have to consent to being recorded by an AI scribe?

HIPAA does not require an authorization for a treatment use. State recording law may require consent, and it varies by state; check with counsel. Tell patients regardless and honor an opt-out.

Is the AI scribe audio part of the medical record?

It depends on whether it is retained and used to make decisions about the patient, which is the 45 CFR 164.501 designated record set test. Deleting audio at signature avoids the question; retained audio needs a written retention and access decision.

Conclusion

An AI scribe is a vendor review, a risk analysis entry, and a one-page policy, all of which fit in a week if someone owns them. One Guy Consulting's Full-Scope plan includes the vendor and B.A.A. review, the risk analysis update, and the policy template for new technology. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading