Almost every AI medical scribe vendor's homepage says "HIPAA compliant" somewhere above the fold. That phrase, on its own, doesn't mean much - HIPAA compliance isn't a certification a product earns once and displays like a badge. It's a set of specific, verifiable practices around how a vendor handles protected health information, and it depends as much on your practice's agreements with the vendor as it does on the product itself. This is a practical checklist for confirming compliance is real, not just marketing language, before you sign a contract.
Start With the Business Associate Agreement
Any vendor that records, transcribes, or processes patient conversation audio is a business associate under HIPAA, and is legally required to sign a Business Associate Agreement (BAA) with your practice before you use their tool with real patient data. This isn't a formality - it's the contract that makes the vendor legally accountable for how they handle PHI, and without one, using the tool for actual patient encounters isn't authorized under HIPAA regardless of what the marketing page claims.
A few things to look for specifically in the BAA itself, not just its existence:
- Does it explicitly cover the AI processing pipeline - transcription, note generation, and any model involved - not just data storage?
- What are the breach notification terms, and do they meet HIPAA's required timeline?
- What encryption standard is specified for data at rest and in transit?
If a vendor says they're "HIPAA compliant" but won't sign a BAA, that's a firm stop, not a negotiating point.
Ask About Subcontractors, Not Just the Vendor
This is the step practices most often skip. Many AI scribe platforms don't build their own speech recognition or language models from scratch - they route audio through third-party APIs or cloud infrastructure. If your vendor sends patient audio to a subcontractor, that subcontractor also needs its own BAA in place. Major cloud providers can offer HIPAA - compliant infrastructure, but only if the vendor has actually activated those protections - it's not automatic. Ask directly: does any patient audio or transcription pass through a third-party service, and does that service have its own signed BAA? A vendor that can't answer this clearly is a red flag, not a minor detail.
Understand the Audio Retention Policy
This is where vendors vary the most, and it's worth asking about explicitly rather than assuming:
- How long is raw audio kept after a note is generated? Some vendors delete it within minutes to hours; others retain it for weeks for quality review; a few retain it indefinitely unless you opt out.
- Is there a difference between the audio recording and the generated note? HIPAA's documentation retention requirements (generally a minimum of six years for compliance records) apply to the clinical note itself, but there's rarely a clinical reason to retain the raw audio once an approved note exists. Zero or short-term audio retention is increasingly treated as the safer default for that reason.
- Can your practice manually delete recordings or set an auto-deletion policy? Configurable retention, rather than a fixed vendor-wide policy, gives you more control.
Confirm Whether Your Data Trains Their AI Model
This is a question worth asking in plain language, because it's often buried in a privacy policy rather than stated upfront: does the vendor use patient audio or notes - identifiable or de-identified - to train or improve their AI model? Some vendors explicitly state they only train on de-identified data, or don't use patient data for training at all. Others are less clear, and a BAA alone doesn't guarantee an opt-out from model training unless it says so explicitly. If this matters to your practice's risk tolerance, get the answer in writing, not just from a sales conversation.
Check State-Level Recording Consent Laws
HIPAA compliance and state recording consent law are two separate requirements, and both apply. A number of states require all-party consent before recording any conversation, which affects how a scribe should be introduced and consented to at the start of a visit - this isn't something the AI vendor handles for you; it's a practice-level workflow you need to have in place regardless of which tool you choose.
Verify the Human Review Layer, If There Is One
Some AI scribe platforms use human reviewers or quality-assurance staff to check transcripts, particularly early in an implementation or for complex encounters. If a human ever reviews a transcript containing PHI, that reviewer needs to be covered under the BAA and trained on HIPAA requirements. The same as any staff member with access to patient records. Ask whether any human review happens, and if so, under what agreement.
A Practical Verification Checklist
Before signing with any AI scribe vendor, get clear, written answers to:
- Will you sign a BAA that explicitly covers the AI processing pipeline, not just storage?
- Do any third-party subcontractors process patient audio, and do they have their own BAAs?
- What is the default audio retention period, and can our practice configure or shorten it?
- Is patient data used to train your AI models, and can we opt out?
- What encryption standard is used for data at rest and in transit?
- What are the breach notification terms and timeline?
- Does any human ever review transcripts, and under what agreement?
A vendor that answers all of these clearly and in writing, without deflecting to a general "we take security seriously" statement, is the one worth taking seriously in return.
Bottom Line
"HIPAA compliant" on a landing page is a marketing claim until it's backed by a signed BAA covering the full processing pipeline, a clear retention and deletion policy, and honest answers about subcontractors and AI training. None of these questions require legal expertise to ask - they just require asking them before you sign, not after an incident forces the conversation.
Compare AI scribes and documentation tools in our Clinical Documentation category on Doxiverse.
FAQ
Is an AI scribe automatically HIPAA compliant if the vendor says so on their website? No. Compliance depends on a signed BAA covering the full AI processing pipeline, documented retention and deletion policies, and subcontractor agreements — not a marketing claim.
Do AI scribe vendors need a BAA for third-party services they use? Yes. If a vendor routes patient audio through a third-party speech recognition or cloud service, that subcontractor must also have its own BAA in place.
Can an AI scribe vendor use patient data to train their AI model? It depends on the vendor's specific policy. Some train only on de-identified data or exclude patient data entirely; others are less explicit. Get this answer in writing before signing.

Top comments (0)
Please login or create an account to leave a comment.