ONESTEP SCRIBE

Is an AI scribe HIPAA compliant? The honest answer, and the questions that settle it

By Selam Koch, PMHNP-BC, founder of OneStep Scribe and practicing psychiatric nurse practitioner. Published August 2026.

Somewhere in the evaluation of every AI scribe, the same question surfaces: is this thing HIPAA compliant, and how would I even know? The question deserves a more honest answer than most vendor pages give it. Yes, a covered provider can use an AI scribe with protected health information, and many do. But the phrase "HIPAA compliant," stamped on a product, means less than the marketing wants you to think. Compliance under HIPAA is a legal relationship and an ongoing posture, maintained jointly by your practice and every vendor that touches your patients' data. It is not a feature that ships in software, and it is not something any product can hand you in a box. This guide covers what the law actually requires when a scribe vendor handles PHI, what a business associate agreement has to say, why a compliance certificate is a warning sign rather than a reassurance, and the specific questions that separate a vendor who has done the work from one who has done the marketing. It is written by a clinician, not a lawyer, and it is educational rather than legal advice. For decisions about your own practice, consult a privacy attorney or a compliance professional.

What HIPAA actually requires when a scribe vendor touches PHI

Start with what flows through an AI scribe. The audio of a clinical encounter is protected health information. So is the transcript generated from it, the draft note produced from the transcript, and any logs, backups, or cached copies of those artifacts. PHI is individually identifiable health information held or transmitted by a covered entity or its business associates, in any form, and a recorded conversation between a clinician and an identified patient qualifies many times over.

Under HIPAA, a vendor that creates, receives, maintains, or transmits PHI on behalf of a covered provider is a business associate. An AI scribe vendor fits this definition squarely. The audio arrives on their servers, their systems transcribe it, their systems generate the note. For a vendor serving a covered provider, it is very hard to read the rules any other way: under HHS's definition and published guidance, an AI scribe that receives and processes identifiable session audio sits inside the business associate category, and the narrow exceptions, such as the conduit exception for mere transmission services, do not plausibly apply.

That classification triggers a hard requirement: a signed business associate agreement must exist before PHI flows. This is not a formality to catch up on later. Disclosing PHI to a vendor without a BAA in place is itself a violation, regardless of whether the vendor handles the data responsibly and regardless of whether anything ever goes wrong. The sequencing matters. If a free trial starts ingesting session audio on day one and the paperwork arrives on day thirty, days one through twenty-nine are the problem.

There is no such thing as HIPAA certified

This is the single most useful fact in the entire vendor conversation. The federal government does not certify products, companies, or software as HIPAA compliant. The Office for Civil Rights, which enforces the HIPAA Privacy, Security, and Breach Notification Rules, offers no certification program, endorses no third-party seal, and recognizes no badge. Any vendor displaying a certificate that claims HIPAA certification is displaying something with no legal meaning, and the willingness to imply otherwise tells you something about how the rest of their claims are calibrated.

What legitimate vendors can show you instead is evidence of posture. A BAA they are ready to sign. A description of their safeguards: encryption in transit and at rest, access controls, audit logging, workforce training. Independent security audits, such as a SOC 2 examination, which attest to security controls but are not HIPAA certifications and should never be described as one. A straight answer about subcontractors. None of these is a certificate, because no certificate exists. Together they are what real diligence looks like.

The deeper point is that compliance is continuous. A vendor with excellent architecture and a signed BAA can fall out of compliance next quarter by adding an unvetted subcontractor or quietly changing a retention default. Your practice can fall out of compliance by never updating its risk analysis to mention the scribe at all. HIPAA describes obligations that persist for as long as the PHI does, which is why "is it compliant" is a weaker question than "what are you doing, on an ongoing basis, to stay within the rules."

What a BAA must cover, in plain terms

A business associate agreement is a contract with required contents. You do not need to be an attorney to check for the core provisions, and a vendor's standard BAA that is missing them is a finding in itself.

ProvisionWhat it means for your practice
Permitted uses and disclosuresThe vendor may use PHI only to provide the service and for the narrow purposes the agreement lists. Anything else, including product marketing and undisclosed model training, is off the table, and a BAA cannot authorize uses HIPAA itself prohibits, such as marketing uses of PHI without patient authorization.
SafeguardsThe vendor commits to appropriate administrative, physical, and technical safeguards for the PHI it holds, consistent with the Security Rule.
Breach and incident reportingThe vendor must report breaches of unsecured PHI and security incidents to you, so that your own notification obligations can be met on time.
Subcontractor flow-downAny subcontractor that touches PHI on the vendor's behalf must be bound by written agreements imposing the same restrictions. For an AI scribe, this covers the transcription vendor, the model provider, and the cloud host.
Access, amendment, and accountingThe vendor must support your obligations to give patients access to their records, accommodate amendments, and account for certain disclosures.
Return or destruction at terminationWhen the relationship ends, PHI is returned or destroyed where feasible, and protections continue for anything that must be retained.

Read the model training language twice. Some agreements permit the vendor to use de-identified data for product improvement, which can be acceptable when the de-identification standard is stated and real. Some are silent, which is worse. Ask directly, and get the answer in the agreement rather than in an email.

Where the PHI actually lives in a scribe pipeline

A useful mental model for diligence is to follow the data. Audio is captured on a device, transmitted to the vendor, and transcribed, often by a specialized speech recognition subcontractor. The transcript is sent to a language model, sometimes hosted by yet another company, which drafts the note. The draft comes back to you for editing and signature. At each hop there is a copy, and each copy has a location, a retention period, and a set of people who could conceivably access it.

In psychiatry the stakes of those copies are unusually high. A finished psychiatric note concentrates sensitive material by design: the sections a structured note engine produces, such as the interval history, the substance use review, the mental status examination, and the risk assessment, together capture suicidal ideation, substance use, trauma history, and third-party information about family members. The raw transcript is more sensitive still, because it contains everything the patient said in their own words, including what you deliberately chose to leave out of the note. Records involving substance use disorder treatment can carry additional federal confidentiality protections beyond HIPAA in some settings, and psychotherapy notes kept separate from the record have their own special status. If your work touches either category, that is a specific question for your attorney, not a detail to assume away. To see how much clinical material a structured note actually holds, look at the annotated progress note example with this lens: every section of it is PHI, and so is the transcript behind it.

The questions to ask any AI scribe vendor

These are the questions that matter, roughly in the order they disqualify vendors.

  1. Will you sign a BAA, and does it take effect before any PHI flows? A vendor that will not sign, or that wants PHI flowing during a trial before the agreement exists, has answered the entire evaluation. This includes free tiers: the law does not have a hobby exemption.
  2. Where are audio and transcripts stored, and for how long? You want named infrastructure, a stated region, and a stated retention period, not a gesture at "the cloud." Ask specifically whether audio is deleted after transcription and whether transcripts persist after the note is generated.
  3. Is my patients' data used to train models, and can I opt out? Ask what the default is, whether opting out is possible at the account level, and how training use squares with the permitted-uses clause of the BAA. If the answer involves de-identification, ask which method and who verified it.
  4. Who are your subcontractors, and do they sign BAAs downstream? The speech recognition vendor, the language model provider, and the cloud host each hold your patients' data at some point. HIPAA requires the flow-down agreements to exist. A vendor who cannot name these parties has not mapped their own pipeline.
  5. What is retained after the note is generated, and can I control it? The best answers give the practice a retention setting rather than a promise. If your policy is that audio disappears immediately and transcripts persist for thirty days, the platform should be able to enforce that, not merely agree with it.
  6. What happens when something goes wrong? Ask for the breach notification commitment in days, what forensic detail they provide, and whether they assist with your notification obligations to patients and regulators. Ask whether they have had reportable incidents and how they were handled.
  7. Who inside your company can access my patients' data, and is that access logged? Support engineers debugging a transcription problem are a real access path. You want role-based access, a need-to-know policy, and an audit trail that records reads as well as writes.

Notice what is absent from this list: any question answerable with a badge. Every one of these requires the vendor to describe how their system actually works, which is precisely why they are useful.

Free consumer tools are not an option for PHI

The tempting shortcut is real and worth naming. General-purpose consumer chatbots draft plausible clinical notes, and the free tier is free. But a consumer tool that has not signed a BAA with your practice is, under HIPAA, simply an unauthorized recipient. Pasting a session transcript into one is a disclosure to an entity with no legal obligation to protect it, and consumer terms of service frequently permit the company to retain inputs and use them for training. The convenience does not change the analysis, and neither does good intent.

The common defense, "I remove the name first," misunderstands the de-identification standard. HIPAA recognizes two paths: removal of a long list of identifier categories, including all elements of dates other than the year and most geographic detail, plus no actual knowledge that the remaining information could identify the person, or a formal determination by a qualified expert that re-identification risk is very small. A psychotherapy transcript with the name stripped still contains ages, dates, workplaces, family structures, and life events specific enough to identify a person, and it will almost always fail the standard. If a tool will not sign a BAA, nothing derived from a patient encounter belongs in it. This applies to prescribers and therapists alike; the same reasoning is covered from each angle in the guides on AI scribes for psychiatrists and AI scribes for therapists.

Your side of the equation

A signed BAA does not complete the project, because HIPAA assigns your practice obligations no vendor can absorb. The Security Rule requires a risk analysis, and adopting an AI scribe changes yours: a new data flow leaves the building, a new vendor holds recordings, a new failure mode exists. The analysis should say so, along with the safeguards you rely on and the reasoning behind the vendor choice. Your written policies should cover who in the practice may use the scribe, how patients are informed, how consent is captured and documented, and what staff do if something looks wrong. If you cannot point to where the scribe appears in your risk analysis and policies, that is the gap to close, and a compliance professional can help you close it efficiently.

Two adjacent issues deserve explicit attention. First, recording consent is governed by federal and state recording laws, separate from HIPAA; federal law generally requires the consent of at least one party, and some states require the consent of every party. Disclose the scribe and document the patient's consent in every case; one-party recording statutes set a legal floor, not a clinical standard. Second, telehealth adds its own layer, since the session already runs through a platform with its own BAA and its own recording questions; the telehealth documentation guide covers that terrain. State privacy laws can also be stricter than HIPAA generally, so the federal floor is exactly that, a floor.

The most common failure is sequencing, not security. PHI starts flowing during a trial before any BAA exists, or a clinician pastes a transcript into a consumer chatbot to save an evening. Neither requires a breach or a bad actor to be a violation. The rule is simple to state and simple to follow: no PHI moves to any vendor until the agreement covering it is signed.

Frequently asked questions

Is there an official HIPAA certification for AI scribes?

No. The federal government does not certify any product as HIPAA compliant, and no official HIPAA certification exists for software. Vendors can show meaningful evidence of a strong security posture, such as a willingness to sign a business associate agreement, documented safeguards, and independent security audits like SOC 2 reports, but a certificate or seal claiming HIPAA certification is a marketing artifact, not a legal status. Treat any vendor waving one as a reason to ask more questions, not fewer.

Does signing a BAA make my practice HIPAA compliant?

No. A business associate agreement is necessary before a vendor touches PHI, but it is one piece of a larger program. Your practice still needs its own risk analysis, written policies, workforce training, and safeguards, and the vendor still needs to actually operate the way the agreement describes. Compliance is an ongoing posture maintained by both parties, not a document either one can sign once and forget. A privacy attorney or compliance professional can help you assess your specific obligations.

Can I use a free consumer chatbot for notes if I remove the patient's name?

This is far riskier than it feels. Removing a name does not de-identify health information under HIPAA. The regulation recognizes two de-identification methods, one requiring removal of a long list of identifier categories, including dates and geographic detail, and the other requiring formal expert determination. A session transcript almost always retains identifying detail, and pasting it into a consumer tool that has not signed a BAA is a disclosure to an entity with no obligation to protect it. Use tools that will sign a BAA for anything derived from patient encounters.

Do patients need to consent to an AI scribe recording their visit?

HIPAA itself permits uses and disclosures of PHI for treatment and health care operations, but recording consent is governed separately by federal and state recording laws; federal law generally requires the consent of at least one party, and some states require the consent of all parties to record a conversation. Regardless of your state's recording law, patients should always be told an AI scribe is in use, and their verbal or written consent should be obtained and documented in the note before any recording begins. Check your state's recording statutes and your malpractice carrier's guidance, and consult a qualified attorney if you are unsure.

Do the vendor's subcontractors need BAAs too?

Yes. HIPAA requires business associates to obtain satisfactory assurances, in the form of a written agreement, from subcontractors that create, receive, maintain, or transmit PHI on their behalf. For an AI scribe, that typically includes the speech recognition vendor, the language model provider, and the cloud host. A vendor who cannot tell you who those parties are, or whether downstream agreements exist, has not finished the work the law requires of them.

What happens if my AI scribe vendor has a breach?

HIPAA itself requires the vendor to notify your practice of breaches of unsecured PHI, and a proper BAA sets the timeline and detail of that notification; the breach notification rules then govern notification to affected patients, regulators, and in larger breaches the media, generally driven by the covered entity. Before signing, ask the vendor how quickly they commit to notifying you, what information they will provide, and whether they will assist with your notification obligations. The time to learn a vendor's incident process is before an incident, not during one.

Related guides

OneStep Scribe signs a BAA with every practice.

OneStep Scribe is an AI scribe built for psychiatric clinicians, founded by a practicing psychiatric nurse practitioner. It signs business associate agreements, checks every account against the NPI registry at signup, gives practices control over data retention, and keeps an append-only audit trail of note activity. The BAA is executed at signup, before any audio is recorded, including during the free trial. It drafts the note for your review and signature; your compliance program remains your own, as it does with any vendor.

Start a 14-day free trial

This article is educational and reflects one clinician's understanding of federal privacy requirements at the time of writing. It is not legal advice, and it is not billing, payer-specific, or medical advice; consult a qualified attorney or compliance professional about your practice's specific obligations. No product, including ours, makes a practice HIPAA compliant by itself. Privacy laws, enforcement practices, and state requirements vary and change; always verify current requirements with your own counsel and compliance advisors. CPT is a registered trademark of the American Medical Association.