Healthcare provider using a HIPAA compliant AI scribe integrated with an electronic health record system

Introduction: AI Scribes Can Help Providers, But HIPAA Comes First

An AI scribe can be HIPAA compliant — but only if the vendor signs a Business Associate Agreement (BAA), encrypts PHI, limits data retention, and does not use patient data to train AI models. The tool itself carries no certification. Compliance depends entirely on how the vendor handles protected health information and whether your practice has the right agreements and workflows in place.

AI scribes, ambient note tools, and automated clinical documentation are among the most requested technologies in healthcare right now. AI scribe adoption has accelerated rapidly, and major EHR platforms including Epic and athenahealth now offer ambient documentation as a built-in feature — reflecting a broad industry shift toward AI-assisted clinical workflows.

The reason adoption is accelerating is straightforward: providers are overwhelmed by documentation. A landmark study of 263 physicians found that ambient AI scribes reduced clinician burnout from 51.9% to 38.8% in just 30 days, with cumulative time savings exceeding 15,700 hours across participants over one year.

But before a medical practice uses any AI tool with patient information, there is a critical compliance question that must be answered first: Is the AI scribe HIPAA compliant?

The answer depends on the vendor, the workflow, the BAA, data storage location, whether the AI trains on patient data, and whether patients have been properly notified. AI can be a valuable tool in healthcare, but it must be implemented carefully. Medical practices should not treat AI documentation like a simple add-on app — it touches clinical workflow, patient privacy, consent, compliance, and the legal medical record.

At Medi-EHR, our position is straightforward: AI should reduce documentation burden without creating unnecessary privacy risk.

Is an AI Scribe HIPAA Compliant?

An AI scribe can be used in a HIPAA-compliant manner, but only if the vendor and workflow meet healthcare privacy requirements. A HIPAA-ready AI scribe should include:

  • A signed Business Associate Agreement (BAA)
  • Secure handling of protected health information (PHI)
  • Encryption in transit and at rest, plus access controls
  • Defined data retention and deletion policies
  • Clear rules on whether patient data is used for AI training
  • Audit-friendly workflows
  • Provider review before the note becomes final
  • Integration with the clinical documentation process
The most important point: AI is not automatically HIPAA compliant just because it is used in healthcare. A consumer AI tool, general chatbot, generic transcription app, or standalone note generator should not be used with PHI unless the practice has confirmed that the vendor supports HIPAA-compliant use and has signed the required agreements.

Can ChatGPT Be Used With PHI?

Medical practices should be extremely careful before entering patient information into ChatGPT or any other general AI platform. PHI can include:

  • Patient names, dates of birth, addresses, and phone numbers
  • Medical record numbers, diagnoses, and medications
  • Lab results, visit details, and insurance information
  • Any information that can identify a patient in connection with care

A provider should not paste PHI into a general AI tool unless the practice has confirmed that:

  • The vendor will sign a HIPAA-compliant BAA
  • The tool is configured for healthcare use
  • PHI is not used to train public AI models
  • Data is stored, retained, and deleted according to the practice’s policies
  • The workflow has been approved by the practice’s compliance program

A provider may think they are only asking AI to “clean up a note” or “summarize a visit,” but if the text includes patient information, it may constitute PHI. The safer approach is to use AI tools that are part of an approved healthcare workflow — not allow staff to use random AI tools outside the EHR.

Do AI Note Tools Sign a BAA?

Any AI note tool that creates, receives, maintains, or transmits PHI on behalf of a medical practice generally needs to sign a Business Associate Agreement. Under HHS guidance, a business associate is any person or entity that performs functions involving the use or disclosure of PHI on behalf of a covered entity. A BAA is one of the first things a practice should ask about when evaluating an AI scribe vendor.

Before using an AI documentation tool, ask:

  • Will the AI vendor sign a BAA?
  • Are subcontractors involved, and are they also covered under the BAA?
  • Does the BAA cover the specific AI service being used?
  • Where is patient data processed and stored?
  • How long are recordings and transcripts retained?
  • Is PHI used to train AI models?
  • Can patient data be deleted on request?
  • What happens if there is a security incident?
If the vendor will not sign a BAA, the practice should not use that tool with PHI. A vendor homepage that says “HIPAA compliant” without providing a signed BAA and documented security practices does not satisfy HIPAA obligations. HHS provides sample Business Associate Agreement provisions that covered entities can use as a reference when reviewing vendor contracts.

Where Is Patient Data Stored?

Patient data storage is one of the most important questions when evaluating AI scribes. Some AI tools process audio, transcripts, or draft notes through cloud systems. Some retain recordings temporarily. Some store transcripts for quality review. Some involve third-party AI infrastructure or subcontractors.

A medical practice should understand the full data flow:

  1. The provider-patient conversation is captured or transcribed.
  2. Audio or text is processed by the AI system.
  3. A draft note is generated.
  4. The provider reviews and edits the draft.
  5. The final note is saved into the EHR.
  6. Temporary data is retained or deleted based on policy.

Practices should confirm:

  • Whether audio and transcripts are stored, and for how long
  • Whether the practice can delete the data
  • Whether data is stored in the United States
  • Whether third-party processors or subcontractors are involved
  • Who can access the data, and under what conditions
“Where is the data stored?” is not just a technical question. It is a HIPAA, privacy, and patient trust question.

Does AI Train on Patient Data?

This is one of the biggest concerns with AI medical documentation. A healthcare AI vendor should clearly state whether patient data is used to train, improve, or fine-tune AI models. Medical practices should be especially cautious about any tool that may use identifiable patient information to train a public, shared, or general-purpose model.

A stronger AI privacy position from a vendor should include:

  • PHI is not used to train public AI models
  • Patient data is used only for permitted healthcare purposes
  • Any model improvement use is clearly disclosed in the BAA
  • De-identified data, if used, follows HIPAA de-identification standards
  • The practice retains control over its patient data
  • The vendor can explain retention and deletion policies in plain language
The question should not only be, “Does the AI work?” The better question is: Can this AI improve documentation without creating unnecessary risk for my patients or my practice?

Do Patients Need to Consent to an AI Scribe?

In many cases, HIPAA allows PHI to be used for treatment, payment, and healthcare operations without a separate authorization. However, AI scribes create additional practical and legal concerns because they may involve listening to, recording, or transcribing a patient-provider conversation.

Patient notice or consent may be especially important when:

  • The visit is being recorded
  • Ambient listening technology is used
  • A third-party AI vendor is processing the audio
  • Audio leaves the exam room
  • State recording laws require all-party consent
  • The patient may not expect AI to be involved
  • The visit involves sensitive services such as behavioral health, reproductive health, substance use, or infectious disease care
Sample patient-facing notice:
“Our practice uses secure AI documentation technology to help prepare a draft note from your visit. Your provider reviews and approves the note before it becomes part of your medical record. You may ask questions at any time or request that AI not be used during your visit.”

Is Recording a Patient Visit Legal?

Recording laws vary by state — and they operate on a separate legal track from HIPAA. HIPAA governs how protected health information is handled after it is captured. State wiretapping and eavesdropping statutes govern whether the recording itself was lawfully obtained in the first place. A recording that violates state law is not fixed by having a signed BAA.

One-Party vs. All-Party Consent

In one-party consent states, a recording is lawful if at least one person in the conversation consents — typically the provider. In all-party (two-party) consent states, every person in the conversation must agree to be recorded. A significant number of U.S. states have all-party consent requirements, including California, Pennsylvania, Florida, Illinois, and Washington, among others. However, the exact list varies depending on whether the conversation is in-person or by phone, how courts have interpreted local statutes, and specific exceptions that may apply in healthcare settings.

Important: State recording laws are complex, carry criminal and civil penalties, and should not be interpreted from a general list alone. Practices should consult legal counsel to determine their specific obligations before enabling AI scribe recording in any state.
Legal exposure in all-party consent states can be significant and may extend beyond HIPAA. As Thompson Coburn LLP notes in its AI scribe compliance guidance, HIPAA and state wiretapping statutes “operate on parallel but distinct tracks” — a valid BAA does not resolve a state recording law violation. Penalties under state law can include civil liability and, in some states, criminal exposure. Practices operating across state lines or using telehealth should consult legal counsel to verify obligations in each relevant state.

The 2026 AI Scribe Landscape: What Has Changed

The AI scribe market changed significantly in 2026. In February 2026, athenahealth began offering its ambient AI scribe tool free to all customers — removing cost as a barrier for hundreds of thousands of providers. Epic has made ambient AI charting broadly available across its client base, with nearly two-thirds of Epic-affiliated hospitals now using the feature.

Alongside expanded adoption, legal risk has grown. In April 2026, a class-action lawsuit was filed against Sutter Health and Memorial Healthcare Services, alleging that an AI platform recorded patient-clinician conversations and transmitted audio externally without adequate patient consent. Additional lawsuits have raised wiretapping claims, consent violations, and concerns about AI-generated consent language. These cases signal that practices need more than a BAA — they need documented, encounter-level consent workflows and clear patient-facing disclosures.

For medical practices evaluating AI documentation tools, the stakes of getting it wrong are higher than they were even a year ago. The question is no longer whether to use AI scribes — it is whether your specific vendor, workflow, and consent process can withstand legal and regulatory scrutiny.

Standalone AI Tools vs. EHR-Integrated AI

One of the most important decisions for a practice is whether to use a standalone AI scribe or an AI tool connected to the EHR workflow. Standalone tools may be fast to adopt, but they can create workflow and privacy concerns if providers have to copy and paste notes, manage separate logins, move PHI between systems, or manually track consent.

Standalone AI — Risks

  • PHI copied into outside systems
  • Notes stored outside the EHR
  • Limited or no audit trail
  • Separate vendor access
  • Confusing retention policies
  • Extra steps for providers
  • Higher shadow IT risk

EHR-Integrated AI — Benefits

  • Documentation stays in clinical workflow
  • No copy-paste PHI exposure
  • Provider review before signing
  • Audit-friendly by design
  • Connects AI to the patient chart
  • Easier provider adoption

AI Medical Documentation Privacy Risks

AI documentation tools can be useful, but practices should understand the compliance risks. Common risks include:

  • Using AI without a signed BAA
  • Entering PHI into a consumer AI tool
  • Recording visits without proper notice or consent
  • Retaining audio longer than necessary
  • Allowing AI-generated errors into the clinical record
  • Using patient data to train AI models without proper controls
  • Failing to review subcontractors involved in AI processing
  • Not training staff on approved AI use policies
  • Allowing providers to choose their own AI tools without compliance review
  • Copying and pasting PHI between systems
AI should not become a “shadow IT” problem where each provider uses a different app without oversight. The practice should approve the AI workflow, train staff, document consent procedures, and maintain control over patient information.

Human Review Is Still Required

AI scribes should create draft notes — not final clinical judgment. The provider remains responsible for reviewing, editing, and approving documentation before it becomes part of the medical record.

This matters because AI tools can:

  • Misunderstand clinical context
  • Miss important details from the visit
  • Include incorrect or incomplete information
  • Over-document or under-document the encounter
  • Create billing or compliance concerns if not reviewed

A safe AI documentation workflow should include: draft generation → provider review → provider edits → final approval → audit trail → signed documentation inside the EHR.

How Medi-EHR Helps Practices Use AI More Safely

Medi-EHR, an ONC-Certified EHR platform based in New Jersey, builds AI documentation into the provider workflow — so audio, transcript, and note review happen inside the patient chart rather than in a separate app. AI documentation is not a disconnected gadget at Medi-EHR; it fits into the way providers already work: intake, consent, documentation, review, signing, billing, and patient communication.

AI-assisted documentation workflows
AI dictation and note creation support
EHR-connected clinical documentation
Patient intake and consent tools
Secure patient portal access
Audit-friendly documentation workflows
Customizable templates by specialty
Provider review before note completion
Workflow automation for clinical teams
Front desk and intake automation

See AI Documentation Inside Medi-EHR

Request a demo to see how Medi-EHR helps your practice use AI-assisted documentation while keeping privacy, consent, and clinical workflow at the center.

Frequently Asked Questions: AI Scribes and HIPAA Compliance

No. An AI scribe is not automatically HIPAA compliant simply because it is marketed for healthcare use. Compliance depends on whether the vendor signs a Business Associate Agreement (BAA), encrypts PHI, has defined data retention and deletion policies, and does not use patient data to train AI models. The practice must verify each of these requirements before clinical use.

Yes. Under HIPAA, any vendor that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity is a business associate and must sign a BAA. If an AI scribe vendor will not sign a BAA, the practice should not use that tool with patient data.

Not without verified compliance measures. A practice should not paste PHI into ChatGPT or any general AI platform unless the vendor has signed a HIPAA-compliant BAA, the tool is configured for healthcare use, and PHI is confirmed not to be used for AI training. Consumer AI tools do not meet this standard by default.

HIPAA allows PHI to be used for treatment without separate authorization — but AI scribes may involve recording a conversation, which triggers state wiretapping laws. A significant number of states have all-party consent requirements, including California, Pennsylvania, Florida, Illinois, and Washington, among others. Requirements vary by state and context. Best practice is to obtain and document patient consent before AI scribe use in every state, and to offer a clear opt-out. Consult legal counsel to confirm your state’s specific requirements.

Yes. Practices should have a documented workflow for patients who decline AI scribe use. Refusing AI documentation should not affect the quality of care the patient receives. Staff should be trained on how to handle and document a patient declination.

EHR-integrated AI documentation generally carries lower compliance risk. When providers copy and paste notes from a standalone app into the EHR, PHI moves between systems without audit trail visibility. EHR-integrated workflows keep recording, transcription, review, and signing inside the clinical record — reducing copy-paste risk and improving auditability.

This varies by vendor. Practices must confirm in writing whether PHI is used to train, fine-tune, or improve AI models — including by subcontractors. PHI should not be used to train public or shared AI models. Any data use for model improvement should be clearly disclosed in the BAA and the vendor’s privacy policy.

Previous Post
Behavioral Health AI in 2026: 10 Technologies Transforming Mental Health Care