A HIPAA Label Is Not Enough for an AI Medical Scribe
Before an AI scribe records a visit, pin down who handles the data, whether it trains models, when recordings disappear, and how corrections reach the chart.
August 9, 2026 · 8 min read

Picture one ordinary appointment. A tablet on the exam-room counter captures the conversation, sends audio to a cloud service, produces a transcript and turns that transcript into a draft note. The clinician edits the draft, signs it and sends the final note into the electronic health record, or EHR.
That chain is the unit to evaluate. “HIPAA compliant” does not tell a buyer whether the vendor keeps the original recording, lets employees inspect difficult passages, uses transcripts to improve a model, preserves the clinician’s edits or can retrieve data when a patient requests a copy. Each handoff needs an owner and a rule.
This is a procurement checklist, not legal or medical advice. Health systems should apply their own counsel, privacy program, clinical governance and state recording rules to the final decision.
Start with the business-associate relationship
A business associate is an organization that handles protected health information, or PHI, on behalf of a HIPAA-covered entity. For the exam-room workflow, the first useful exercise is to draw every place where the audio, transcript, generated note and usage logs travel, including cloud infrastructure and subcontractors that the scribe vendor uses behind the product.
The HIPAA Privacy Rule’s requirement is more specific than a badge on a sales page: “A covered entity may disclose protected health information to a business associate and may allow a business associate to create, receive, maintain, or transmit protected health information on the covered entity’s behalf, if the covered entity obtains satisfactory assurances that the business associate will appropriately safeguard the information.” Those assurances are documented through a business associate agreement, or BAA, under the rule’s contract provisions.
Ask the vendor to identify the legal entity signing the BAA and the services the agreement covers. A BAA attached to one enterprise product may not cover a browser extension, mobile recorder, support tool or optional analytics service sold under a different set of terms. The product order, BAA and technical architecture should describe the same workflow.
Then trace subcontractors. The contract should require equivalent restrictions for services that create, receive, maintain or transmit PHI, while the vendor documentation should show which subprocessors host recordings, run transcription, provide model inference or handle customer support. A generic right to change subprocessors leaves the buyer with little operational control unless it includes notice, a review path and a way to stop sending new data when a material change is unacceptable.
The fallback is straightforward. If the vendor will not sign an applicable BAA, cannot map the data path or excludes a required feature from its covered service, do not put identifiable patient conversations into that feature.
Separate care delivery from model improvement
Return to the tablet. The clinician expects the recording to produce today’s note. The vendor may also want to use the encounter to tune speech recognition, evaluate summaries, diagnose product failures or train a later model. Those purposes are not interchangeable merely because they happen inside one platform.
Read the BAA beside the vendor’s privacy notice, product terms, data-processing addendum and any AI-specific terms. Public vendor documentation often distributes relevant commitments across these documents, and a statement such as “customer data is not used to train models” may cover a foundation model while leaving room for quality review, feature development, evaluation datasets or improvement of another component.
The contract should name the data covered by the restriction. Audio, transcripts, generated notes, clinician edits, prompts, metadata and support tickets can expose different parts of an encounter. It should also state whether the restriction covers the vendor, affiliates, subprocessors and third-party model providers, and whether any use depends on an administrator’s opt-in rather than a default setting that individual clinicians can change.
De-identification needs its own line. HIPAA permits information that has been de-identified under its standards to fall outside the rule’s PHI protections, but that does not answer the commercial question of whether a buyer wants its encounters turned into a reusable training asset. Procurement can contract for tighter limits than the regulatory floor, including a prohibition on deriving training data from customer content even after de-identification.
If model improvement is valuable, make the exchange explicit. Specify the dataset, purpose, review period and deletion or withdrawal mechanics rather than accepting an open-ended license to “improve services.” A lower product price may not justify broad reuse of sensitive conversations when the buyer cannot inspect the resulting dataset or remove its contribution later.
Give every artifact a deletion rule
After the clinician signs the note, the final record may need to remain in the EHR under the provider’s record-retention policy. That does not mean the vendor needs to keep the exam-room audio for the same period.
Set a retention schedule by artifact and state when the clock starts. Raw audio might disappear after transcription or after a short correction window; draft notes may remain until export is confirmed; security and audit logs may require a longer period because they show access and administrative activity. The appropriate periods depend on the organization’s workflow, but “for as long as necessary” is not an operational schedule.
Do not accept the common shorthand that HIPAA requires all medical data to be held for six years. HIPAA contains six-year retention requirements for specified compliance documentation, but it does not create one universal six-year period for medical records or temporary scribe audio. Other federal requirements, state law, payer rules and organizational policy may govern the record itself.
Deletion also needs mechanics. Ask whether data leaves active systems, backups, caches and disaster-recovery copies on the same timetable; whether legal holds suspend deletion; whether administrators can delete one encounter; and what evidence the vendor supplies after contract termination. The contract should state what happens when return or destruction is infeasible, rather than allowing backups to remain usable for product development.
Test the control before rollout. Record a synthetic visit with no real patient information, delete it through the normal administrator interface, and ask the vendor to show what remains in the portal, support systems and audit trail. That rehearsal exposes a frequent gap: a deletion button may remove the visible transcript while a recording remains under a separate retention setting.
Put clinician correction inside the controlled workflow
An AI scribe produces a draft, not an independently verified clinical record. Speech recognition can confuse medication names, negation, speakers or numbers, while summarization can omit a qualification that appeared in the conversation. The control is not a disclaimer buried in the terms. It is a review step that the software and clinic cannot bypass quietly.
For the tablet workflow, define the status changes from recording to transcript, draft, clinician-reviewed note and signed EHR entry. The product should make an unsigned draft visibly different from a completed note, prevent automatic filing unless the organization has approved that configuration, and preserve enough history to show who changed or approved material content.
Procurement should run correction tests using synthetic encounters. Change a medication, restore a missing negation and reassign a statement to the correct speaker. Confirm that edits appear in the exported note, that a stale draft cannot overwrite the correction, and that the audit log records the relevant user and time without exposing more PHI than auditors need.
The contract should also divide responsibility for failures. A service-level commitment about uptime does not guarantee clinical accuracy, and a vendor’s model-quality statement does not replace clinician review. Buyers need an escalation route for recurring transcription errors, a method to identify affected notes after a model or configuration change, and a fallback that lets clinicians document directly in the EHR when the scribe is unavailable.
That fallback costs time. It is still necessary. A clinic that cannot complete a visit when the scribe or network fails has treated an optional drafting tool as critical infrastructure without buying the controls critical infrastructure requires.
Decide what enters the patient-access process
HIPAA generally gives an individual a right of access to PHI about that person in a designated record set, a defined collection that includes medical and billing records maintained by or for a covered entity. The signed EHR note will usually sit inside the provider’s established access process. The status of audio, transcripts and discarded drafts depends on how the organization maintains and uses them, not on what the scribe vendor calls them.
Before launch, the health system should decide which artifacts become part of its designated record set and document who answers access, amendment, restriction and accounting requests where applicable. The BAA must support the covered entity’s obligations; it should not leave the vendor free to decide whether a transcript can be found or exported after a patient request arrives.
Run one more synthetic test. Search for the sample encounter using the identifiers available to privacy staff, export the material in a usable format and verify that deletion settings have not created a mismatch between the clinic’s policy and the vendor’s ability to respond. Also establish how a patient-reported correction moves from the access team to the clinician and into the EHR, because changing a vendor transcript alone may not amend the signed record.
Patient notice and recording consent remain separate controls. HIPAA business-associate status does not settle state consent requirements or determine what patients should be told about ambient recording, human review and data reuse. The intake script, room signage and product interface should match the approved workflow rather than promising that “nothing is stored” while the contract permits retention.
Make the contract testable
The best procurement record for the exam-room tablet is a control matrix tied to evidence. For each artifact and handoff, record the permitted purpose, system of record, retention period, deletion method, authorized roles, subprocessor path and audit evidence. Attach the relevant contract clause or vendor-documentation page, then assign an internal owner who can test the control after launch.
Repeat the synthetic encounter after material product changes. A new transcription provider, automatic EHR filing option, analytics dashboard or model-improvement setting can alter the data path without changing the clinic’s intended policy. Contractual notice helps, but a test shows whether the implemented controls still match the promise.
Questions people ask
Does a
HIPAA-compliant AI scribe still need a BAA?
If the vendor creates, receives, maintains or transmits PHI on behalf of a covered entity, the relationship generally requires a BAA that applies to the purchased service. A marketing claim or security certification does not replace the agreement, and buyers should confirm that mobile recording, support and optional AI features fall within its scope.
Can a medical scribe vendor train its model on patient visits?
The answer depends on the governing agreements, configuration and proposed use. Buyers should require explicit terms for audio, transcripts, drafts and clinician edits, including whether de-identified material can support training, evaluation or human review. A narrow statement about foundation-model training may not cover every form of product improvement.
How long should an AI scribe keep encounter audio?
HIPAA does not impose one universal retention period for temporary audio. Set a period based on the correction workflow, applicable record rules and operational need, then verify deletion across active storage and backups. Keeping the signed note in the EHR does not require keeping the source recording indefinitely.
Can a patient request the AI transcript or recording?
Potentially, depending on whether the provider maintains the artifact in a designated record set and how applicable access rules apply. The provider should decide that status before deployment, while the BAA and product controls must let privacy staff locate, export, amend or delete material according to the organization’s approved process.
One story a day
The story of the day, in your inbox
One real story about AI each morning — no hype, no alarm, just company for the road.



