Back to blog

Answer

Is an AI medical scribe HIPAA compliant?

Published July 15, 2026Updated July 15, 2026

Summary

The vendor can be. Your use of it is a separate question and it is yours to answer.

HIPAA compliance is not a badge a product carries. It is a set of obligations that land on your practice, and a vendor meets you part of the way by signing a business associate agreement.1 The rest is your risk analysis, your retention decisions and your consent workflow. And HIPAA is not the law most likely to catch you.5

A signed BAA before any encounter, and the consent attestation in the same record as the note.

Book a demo

The BAA is the floor

An ambient scribe creates, receives and maintains protected health information on your behalf. That makes the vendor a business associate under 45 CFR 160.103, and they have to sign a BAA before they touch a single encounter. If a vendor will not sign one, you cannot use them for patient care documentation. If their BAA reserves the right to use your patients' data for their own purposes, read that clause twice and then walk.

A BAA is where the answerable questions live. How long audio is retained. Whether your data trains their models. Where it is stored. What they owe you on breach notification. Ask for those in writing and not in a sales call.

You do not need a patient authorisation for it

HIPAA permits use and disclosure of PHI for treatment, payment and healthcare operations without a separate authorisation.2245 CFR 164.506. Recording a visit to produce your own clinical documentation sits inside that. You do not need a signed HIPAA authorisation form from each patient to run an ambient scribe.

That answer is narrow and it is often quoted as though it settles the matter. It does not. HIPAA sets a floor. State recording law sits on top of it, sixteen states require consent from every person in the room, and some of those statutes reach the clinician personally rather than the practice. We have set that out separately because it is the part that carries real exposure.

The part nobody does

The Security Rule requires a risk analysis covering all electronic PHI.33HIPAA Security Rule, 45 CFR Part 164 Subpart C. An ambient scribe creates four artefacts in a normal visit. A live audio stream, an interim transcript, a machine-generated draft, and metadata about the clinician, the patient and the visit. Every one of those is electronic PHI you are responsible for, including the copies on the vendor's servers.

Add the scribe to your asset and vendor inventory. Run the risk analysis against it. Most practices adopt one of these tools without doing either. An auditor finds that gap first, because it is documented nowhere.

The minimum-necessary standard applies too, and it sits awkwardly with a tool that records an entire visit including the small talk. Nobody has resolved that tension and we are not going to pretend we have.

Retention

Vendors differ here more than on anything else. Some delete audio within hours. Some keep recordings and transcripts to retrain models or to let you replay a visit. Nabla does not retain the encounter at all, which removes the question rather than answering it and is the strongest position anyone in this market has taken.44Nabla reports that audio, transcript and note remain in the clinician's browser and that patient information does not reach Nabla servers. Freed reports HIPAA, SOC 2 Type II and HITECH, with a BAA available. Confirm any vendor claim directly. For most practices the safest posture is to delete the raw recording once the note is signed and keep only the signed note in the record.

Ask us these four, in writing

We are a business associate and we sign a BAA before any encounter. Beyond that, we would rather give you the questions than a paragraph of assurance.

How long is the audio retained, and can you set it. Is your data used to train models, and can you refuse. Where is it stored, and under whose jurisdiction. And what are the breach notification terms. Ask us in writing, ask every vendor on your shortlist the same four, and compare the answers side by side.

A survey of 121 AI scribe products found data-protection statements on 73 percent of them and supporting evidence, meaning actual DPIAs and documented safeguards, on very few.99Kaczmarek K, et al. Trust Me, I Might be a Medical Device, The Problem with AI Scribes. Research Square, preprint, March 2026. Survey of 121 AI scribe products. Claims of being secure or HIPAA compliant were routinely made without enough detail to meet an assurance standard. A sentence on a website is not an answer. A signed BAA clause is.

What an auditor finds

Your asset inventory lists the tool. Your risk analysis covers the audio, the transcript, the draft and the metadata. The BAA is dated and signed. The retention window is set by you and evidenced. The consent attestation sits in the chart next to the note it authorised, not in a spreadsheet somebody keeps separately.

That last one is the part a scribe cannot give you. The consent and the note are the same record or they are two records, and an auditor asks for both.

What we are not claiming

No product makes you HIPAA compliant, including ours, and any vendor telling you otherwise is selling you something. Compliance is a programme you run. A vendor can sign a BAA, encrypt properly and give you retention controls. Your risk analysis, your consent workflow and your Notice of Privacy Practices are still yours.

This is general information rather than legal advice, and we are not lawyers.

Availability

WA\ Clinician runs a 14-day free trial. WA\ Admin runs as a 90-day pilot. Pricing is on one page.

Frequently asked questions

Is an AI medical scribe HIPAA compliant?

A vendor can be HIPAA compliant. Your practice is compliant or not compliant based on what you do, and no product changes that. The vendor obligation is straightforward. An ambient scribe creates, receives and maintains protected health information on your behalf, so it is a business associate under 45 CFR 160.103 and must sign a business associate agreement before touching a single encounter. If a vendor will not sign one, you cannot use it for patient care documentation. Your obligations are the Security Rule risk analysis, retention decisions, and patient consent, and the last of those is governed by state law rather than HIPAA.

Do I need a BAA with my AI scribe vendor?

Yes, and without exception. Any vendor that creates, receives, maintains or transmits protected health information on your behalf is a business associate under 45 CFR 160.103. An ambient scribe handles the audio, the transcript and the draft note, all of which are electronic PHI. If a vendor will not sign a BAA, or if their BAA reserves the right to use your patients data for their own purposes such as model training, that is a hard stop. The BAA should specify retention periods for audio and transcripts, whether your data trains their models, where data is stored, and breach notification obligations.

What does my HIPAA risk analysis need to cover for an AI scribe?

Every artefact the tool creates. A normal encounter produces a live audio stream, an interim transcript, a machine-generated draft note and metadata about the clinician, patient and visit. Under the Security Rule each is electronic PHI you are responsible for safeguarding, including the copies held on the vendor servers. Add the scribe to your asset and vendor inventory and run the analysis against it. Most practices adopt one of these tools without doing either. The minimum-necessary standard also applies and sits awkwardly with a tool that records an entire visit including small talk unrelated to care.

Ask us the retention questions first.

Start the trial and ask for the BAA before you record anything. We will send it the same day. If it works, the 90-day pilot reports revenue, hours saved and patients cared for from your clinic. If it does not, you have lost a fortnight.

About this article. Written and published by WA\, which sells an ambient documentation product and is a business associate to its customers. This is general information and not legal advice, and we are not lawyers. Regulations are cited in the margin and were current at the updated date above. Vendor retention and training positions change and should be confirmed directly with each vendor. Nabla, Freed and other named products are marks belonging to their owners. WA\ has no peer-reviewed clinical trials published to date and does not claim any. We have priced every competitor on this page from their own published material, including the tiers where they are a smaller subscription than us and the trial where Nabla beat us. We would rather you had the whole picture and chose someone else than had half of it and chose us.

Ask us the retention questions first.

Start the trial and ask for the BAA before you record anything. We will send it the same day. If it works, the 90-day pilot reports revenue, hours saved and patients cared for from your clinic. If it does not, you have lost a fortnight.

Book a demo