Are AI Scribe Tools HIPAA Compliant? What Healthcare Practitioners Need to Know
Updated July 2026
Yes, HIPAA-compliant AI scribes exist. Whether a tool is fully compliant depends on both the safeguards the vendor has in place and how it’s used in your practice. Your AI scribe vendor should be willing to sign a Business Associate Agreement, use encryption in transit and at rest, and clearly explain how your data is handled.
Your practice has a role to play, too. That includes following your licensing board’s guidance and your state’s consent requirements for recording sessions, reviewing notes before they’re saved, and keeping devices and accounts secure.
💡For Canadian practices, here’s what PIPEDA requires when using an AI scribe.
In this article:
- What does HIPAA compliance actually mean?
- Are AI scribe tools HIPAA compliant?
- AI scribe HIPAA compliance checklist: must-haves vs. red flags
- What are my responsibilities using an AI scribe as the treating practitioner?
- What do licensing and professional boards say about AI scribes?
- FAQs
What does HIPAA compliance actually mean?
HIPAA protects health information through three rules.
- the Privacy Rule
- the Security Rule
- and the Breach Notification Rule
Together, they provide a framework for how protected health information (PHI) is used and safeguarded, including what to do if an incident occurs. HIPAA compliance isn’t a single certification a tool can earn. It’s more of a shared, ongoing responsibility between your practice and the vendors that handle PHI on your behalf.
Are AI scribe tools HIPAA compliant?
Yes, there are HIPAA-compliant AI scribes, but compliance isn't automatic. It depends on what the vendor has built and what you do on your end as the practitioner. The moment an AI scribe records, transcribes, or stores anything from a client session, all three HIPAA rules above apply to it. Depending where you practice, your state may have additional privacy requirements to follow.
The first thing to check is whether the vendor will sign a Business Associate Agreement (BAA). A BAA is a legal contract that documents the vendor's role as a "business associate" under HIPAA.
It holds them to HIPAA's security and privacy standards and makes them directly liable if they mishandle client data. If a vendor declines to sign one, their tool isn’t the right one to use with client information under HIPAA, even if no incident ever occurs.
A signed BAA is a major part of a HIPAA-compliant AI scribe, but here are a few other important things to check for.
AI scribe HIPAA compliance checklist: must-haves vs. red flags
💚 Must-haves
- Strong encryption practices (AES-256 or equivalent). AES-256 is a widely trusted encryption standard used by many organizations, including the U.S. government. In simple terms, it turns recordings and transcripts into unreadable code, so only someone with the right access can open and read them. It’s a pretty standard level of protection for tools that work with sensitive healthcare data.
- A signed BAA. Really a non-negotiable for US practitioners. Make sure to get your BAA in writing before you try out an AI scribe in session.
- A clear, written data-use policy. It should explain how your data is stored, shared, and used, including whether or not it's used to train or improve the vendor’s AI model.
- SOC 2 Type II certification (or equivalent). This type of certification means an independent auditor has verified the vendor's security controls. It's third-party confirmation that their systems actually do what they say they do.
- Permanent deletion on request. You should be able to fully delete recordings and transcripts, not just archive them.
🛑 Red flags
- Won't sign a BAA. Without one, the tool won’t meet HIPAA requirements for handling protected health information.
- Can't tell you where your data is stored. A compliant vendor should be able to walk you through the details of their data storage and retention policy.
- Can't give you a clear timeline for when the recordings will be deleted. This makes it difficult to know how long sensitive information is being stored.
- Uses your data to train their AI model. This means information from client sessions may be used for purposes beyond creating your notes.
- Completely free with no clear business model. Building secure AI systems takes real investment. If a tool is free, it may be monetizing your data in ways that aren't transparent.
What are my responsibilities using an AI scribe as the treating practitioner?
Even the best vendor out there can't do it alone. Privacy is a shared responsibility between your vendor's infrastructure and the habits you build in your own practice.
📝 Get client consent and document it
A good place to cover consent is your intake form or a dedicated AI scribe consent form. You can explain when AI may be used for note-taking, what information is collected, and how that information is retained and protected. Your licensing board may have additional disclosure requirements, too.
Here’s one way to explain it:
"I use a fully encrypted, HIPAA-compliant AI tool to help with my clinical notes. It helps me stay fully present during our sessions instead of typing notes. I review everything before it's added to your chart. Are you comfortable with that? Do you have any questions?"
If a client would prefer that you don't use it, switch to another note-taking method for their sessions. Our guide to getting client consent for an AI scribe has more scripts and tips for handling that conversation.
👀 Review every note before it goes into the chart record
AI can mishear words, miss important context, or introduce small inaccuracies. You're still responsible for the overall documentation and accuracy of the clinical record, so always review and edit before saving an entry.
🔒 Keep your setup secure
Your own habits matter here too. On your device, use a strong password, turn on two-factor authentication when it’s available, and avoid sharing login details. It also helps to be mindful of where you review notes, especially on public Wi-Fi or in shared spaces.
These are likely the same everyday privacy practices you already use with patient records, now just extended to your use of an AI scribe.
What do licensing boards say about AI scribes?
Guidance is still developing across many disciplines. Mental health associations have published the most detailed resources so far, with some guidance also available for physical and occupational therapists.
🧠 Mental health practitioners
- The APA has published a step-by-step guide for evaluating AI-enabled clinical tools, along with ethical guidance for AI in professional practice.
- The NBCC published ethical principles for AI in counseling, including guidance on confidentiality and encryption.
💪 Physical therapists
- APTA published a Practice Advisory on AI-Enabled Ambient Scribe Technology. It covers documentation responsibilities, informed consent, and legal and regulatory considerations.
🏡 Occupational therapists
- AOTA's 2025 Code of Ethics requires advance disclosure, informed consent, and transparency about data storage when AI is used for transcription or documentation.
- AOTA also adopted a standalone AI ethics policy.
If your discipline isn’t listed here, your existing technology and confidentiality requirements are a helpful place to start. More discipline-specific guidance will likely follow as licensing bodies continue to consider how AI fits into practice, so it’s also a good idea to check with your regulator for the latest advice.
FAQs
How do I know if my AI scribe is HIPAA compliant?
A helpful place to start is with two questions: will the vendor sign a BAA, and can they provide a current SOC 2 Type II report or an equivalent? Both give you something nice and concrete to review. A HIPAA-compliant AI scribe will have both. If a vendor can’t or won’t sign a BAA, the tool isn’t suitable for use with protected health information in a US-based practice.
Can I use a free AI scribe and still be HIPAA compliant?
Probably not. Most free tools don't sign BAAs for US practitioners, lack strong security measures, and may use your data to train their models. True HIPAA compliance requires serious security infrastructure, which costs real resources to build and maintain.
How long should AI scribe recordings be kept?
Only as long as it takes you to generate the note. Many compliant AI scribes automatically delete the audio recording once the note is created. Transcripts and notes may be retained longer, though, depending on the vendor’s settings and your BAA. Ask your AI scribe vendor for their exact deletion timeline in writing before your first session.
💡 If a transcript becomes part of the clinical record, state retention laws usually decide how long it needs to be kept. This is often 6 to 10 years (may be longer for minors) and is separate from your vendor’s deletion settings.
Do I still need to worry about compliance if my vendor says they're HIPAA-compliant?
Yes. The vendor is responsible for safeguards like encryption, retention, storage, and incident notification. Your role is to use the tool carefully by getting consent, reviewing notes, keeping your devices secure, and confirming a BAA is in place. HIPAA compliance relies on both sides doing their part.
This article offers general information and isn’t intended as legal or regulatory advice. Requirements can look different depending on your practice, discipline, and state. For guidance on your specific responsibilities, speak with a legal or regulatory professional who understands your practice.
Jane's AI Scribe helps you write detailed chart notes in less time, and it's fully HIPAA-compliant. See what Jane's AI Scribe can do.