Skip to main content
The Practice
Practice growthJuly 29, 2026

What to Ask Before an AI Scribe Hears a Session

A vendor due-diligence checklist for bringing an AI scribe into a therapy practice: what the business associate agreement must cover, how to question training-data and de-identification claims, retention and breach terms, consent, and who is accountable for the signed note.

Callie Editorial 18 min read
The due-diligence issue
Sign off
Session note
S

Relevant report

Caregiver reports carryover at home

O

Observable change

78% accuracy · minimal verbal cue

A

Clinical meaning

Self-monitoring is emerging

P

Next decision

Progress to conversational retell

At a glance

What you’ll leave with

  • An AI scribe vendor that receives session audio is a business associate under HIPAA, so a signed business associate agreement must exist before any real session is recorded — and its required provisions are your negotiating leverage, not boilerplate.
  • Three contract questions separate vendors quickly: whether your data trains their models, how long audio and transcripts are retained and how deletion actually works, and which subcontractors also touch the recording.
  • Whoever drafts the note, the signing clinician owns it. Medicare review looks for the treating clinician’s signature, and both ASHA and APTA treat AI output as something a clinician verifies, not something that verifies itself.

The pitch for an AI scribe is easy to like: the software listens to the session, and a draft note is waiting before the next client walks in. For a therapist who documents at nine at night, that is not a gimmick — it is hours. But strip away the interface and what you are actually deciding is this: a company you found last month will receive a recording of everything said in your treatment room, by you, by your patients, and by their families, session after session. That makes the decision a vendor due-diligence problem before it is a productivity one. The good news is that the diligence is finite. A handful of questions — most of them answerable from the contract and the business associate agreement — separate vendors who have built for healthcare from vendors who have built a demo. This article walks through those questions and ends with the checklist to run before any real session is recorded.

The product

What an AI scribe actually is: a data flow, not a feature

Under every AI scribe is the same pipeline: audio is captured in the room or on the telehealth call, shipped to servers, transcribed, and run through a model that drafts a note, which then syncs to your documentation system. Each stage is a place where protected health information exists in a new copy — the raw audio, the transcript, the draft, and whatever logs the vendor keeps around them. Vetting the product means vetting that pipeline: who operates each stage, where the copies live, how long each copy survives, and who can listen. A vendor who can walk you through their own pipeline in those terms, unprompted, is telling you something as useful as any feature list.

Notice what this framing does to the sales conversation. Questions like “is it accurate?” and “does it integrate?” matter, but they are the questions every buyer asks and every demo is built to answer. The questions in the rest of this article are the ones the pipeline forces — and they are the ones where vendors genuinely differ.

The entry ticket

The BAA is required before the first recording — and it is leverage

HIPAA’s rules on this are not subtle. A vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity is a business associate, and the Privacy Rule requires a written business associate agreement before that PHI flows. An AI scribe that receives session audio is squarely inside that definition. There is no trial exception, no “we only keep it briefly” exception, and no exception because the vendor markets itself as HIPAA compliant. If a real patient’s voice reaches the vendor’s servers before a BAA covering your account is signed, the practice — not just the vendor — has a problem.

The BAA is also more useful than most buyers treat it. The regulation at 45 CFR 164.504(e) dictates what the contract must contain, and each required provision maps to a question you would want answered anyway: the agreement must establish the permitted and required uses and disclosures of your PHI (so read what the vendor has permitted itself); it must require appropriate safeguards, including Security Rule compliance for electronic PHI; it must obligate the vendor to report non-permitted uses and disclosures, including breaches of unsecured PHI; it must ensure any subcontractor that touches your PHI agrees to the same restrictions; and at termination it must require the vendor to return or destroy the PHI where feasible. A vendor’s standard BAA, read against that list, is the fastest honest signal you will get about how seriously they take the obligation.

Two provisions deserve a slower read than the rest. The permitted-uses clause is where broad language hides: “to provide and improve the services” can mean routine quality assurance, or it can mean your sessions become training material — the next section takes that apart. And the subcontractor clause matters because an AI scribe is rarely one company: cloud hosting, a speech-to-text provider, and a model provider may each touch the audio or the transcript. You are entitled to know that chain exists and that every link in it is bound to the same restrictions the vendor accepted. Ask for the list of subcontractors that process your data, in writing.

The hard question

Does your caseload train their model?

This is the question that most cleanly separates vendors, and the one sales calls are least eager to answer plainly. Ask it in three parts, and require the answers in the contract rather than in an email: Is audio, transcript, or note content from our practice used to train, fine-tune, or improve your models or your subcontractors’ models? If yes, is that use something we can decline, and where is the opt-out recorded? And if the answer leans on the word “de-identified,” which de-identification standard do you apply, and where is that stated?

The de-identification follow-up matters because the word has a specific regulatory meaning that marketing copy borrows loosely. Under the Privacy Rule, health information is de-identified only by one of two methods: Safe Harbor, which removes eighteen categories of identifiers and requires that the entity has no actual knowledge the remaining data could identify someone, or Expert Determination, in which a qualified expert applies accepted statistical principles and documents that the re-identification risk is very small. A session transcript is dense with names, places, schools, employers, and family details, so genuinely de-identifying one is real work, not a checkbox. A vendor that says “we only train on de-identified data” should be able to say which method, applied by whom — and should be willing to write the claim into the agreement. If they will not, price the promise accordingly.

The clock

Retention, deletion, and what happens on a bad day

Every copy in the pipeline has a lifetime, and you want each one stated: how long raw audio survives after the note is drafted, how long transcripts and drafts are kept, what deletion on request actually removes (including backups, on whatever delay), and what happens to all of it at termination — which the BAA must already address through the return-or-destroy provision. Shorter retention is not automatically better for you; some practices want transcripts retained through an audit window. The point is that the number should be a decision you made, not a default you discovered later.

Then plan for the bad day while you are still choosing. Under the Breach Notification Rule, a business associate that discovers a breach of unsecured PHI must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery, and the practice must in turn notify affected individuals without unreasonable delay and no later than 60 days after the breach is treated as discovered. The trap is in the word “discovered.” If the vendor operates as your agent under the federal common law of agency, the rule imputes the vendor’s discovery to your practice — your notification clock can be running before any report reaches you, and a vendor report that lands on day 45 may leave you 15 days, not a fresh 60. Whether an AI scribe vendor is an agent or an independent contractor is a legal determination about the relationship, worth making with counsel before the pilot rather than during an incident. It is also why a short contractual reporting window — days, not weeks — is worth negotiating: it cannot move the statutory clock, but it gets you the facts while there is still time to act on them. While you are in that clause, check what the vendor commits to include in the report: whose information, what data types, and what they have done about it.

HIPAA governs what the vendor may do with the information; it does not settle whether you may record the conversation in the first place. That is state law, and it varies in a way that cannot be waved at: some states allow recording with one party’s consent, others require the consent of everyone being recorded, and a therapy session routinely includes voices beyond the patient — a parent in the room, a sibling in the background, a caregiver on a telehealth call. Verify your own state’s recording-consent law before the pilot, and if you treat across state lines by telehealth, verify for where the patient sits too. Your professional liability carrier and your state association are both reasonable places to start; the sales rep is not.

Beyond legality, there is the plainer standard: the people in the room should know what is happening. Pediatric caseloads add the questions that generic consent forms skip — who consents for a minor, how a teenager’s own assent is handled, what happens when the consenting parent is not the one who attends, and how a family revokes consent without it feeling like a confrontation. Get the revocation path into your workflow before anyone needs it: the schedule should show, before the session starts, that this client is not recorded. Consent language for recording is its own topic and deserves its own article; for vendor due diligence, the test is simpler — the vendor’s suggested consent language, if they offer any, should describe what their pipeline actually does, and nothing in their product should make honoring a “no” difficult.

Accountability

The signature owns the note, no matter what drafted it

CMS answered the accountability question for human scribes years ago, and the logic transfers cleanly. In its 2017 Program Integrity Manual update on scribe services, CMS said reviewers are only required to look for the signature of the treating clinician — the scribe need not sign — because the treating clinician’s signature affirms that the note adequately documents the care provided. Medicare’s general signature rule points the same way: services must be authenticated by the author, by handwritten or electronic signature. Swap the human scribe for a model and nothing about the responsibility moves. The AI drafted it; you authored it the moment you signed it.

The professional associations have landed in the same place. ASHA’s guidance on AI for communication sciences and disorders professionals treats generative AI as a support tool that is not a substitute for clinical reasoning, used in a way that safeguards client privacy. APTA published a practice advisory in 2025 specifically on AI-enabled ambient scribe technology, covering documentation responsibilities and the legal and regulatory considerations that come with it. For due diligence, this cashes out as a workflow requirement, not a slogan: the product must make the clinician review pass natural — drafts clearly marked as drafts, edits easy, sign-off deliberate rather than bulk — and your documentation policy should say in writing that the signing clinician verifies objective data, skilled-service language, and anything the model could have plausibly invented. What that review pass looks for is its own article; what matters when choosing a vendor is that the product assumes the review happens, rather than quietly encouraging you to skip it.

The centerpiece

The due-diligence checklist, run before the first real session

Every line below is written as a statement you can only make truthfully after doing the work — reading the clause, sending the question, or testing the behavior yourself. Run it per vendor, keep the answers in writing, and treat a line the vendor cannot satisfy as information, not as a negotiation failure. Most practices will finish this in a week of emails and one careful reading of the contract, which is cheap against what it protects.

Field checklist

15 items

The AI scribe vendor due-diligence checklist

  • BAA: the vendor produced its standard business associate agreement on request, and it was signed covering our account before any real patient audio was captured, trials included.
  • BAA: the permitted-uses clause is specific enough that I can restate it to a parent in one honest sentence, and nothing in it surprised me on a second read.
  • BAA: at termination, return or destruction of our PHI is in writing, with a format and a timeline.
  • Training data: the contract states whether our audio, transcripts, or notes are used to train or improve any model, including subcontractors’ models, and records our opt-out if we declined.
  • De-identification: any “we only use de-identified data” claim names its method — Safe Harbor or Expert Determination — in the agreement, not just in marketing.
  • Subcontractors: we have the written list of every third party that touches audio or transcripts (hosting, speech-to-text, model providers), and the BAA binds them to the same restrictions.
  • Retention: the lifetime of each copy — raw audio, transcript, draft note, backups — is stated in writing, and we chose those numbers rather than discovered them.
  • Deletion: we tested deletion on pilot data and the vendor confirmed in writing what it removed and on what delay, backups included.
  • Breach: the contractual reporting window to us is explicit and shorter than the regulatory 60-day maximum, and the clause says what the report will contain.
  • Breach: counsel has told us whether this vendor is our agent or an independent contractor under the federal common law of agency, since agency means the vendor’s breach discovery starts our own notification clock.
  • Access: we know who at the vendor can listen to session audio and under what circumstances — support, quality assurance, debugging — and how that access is logged.
  • Consent: we verified our state’s recording-consent law (and the patient’s state, for telehealth), and our consent process covers guardians, minor assent, and revocation.
  • Consent workflow: the schedule shows before the session starts that a client has declined recording, and honoring the “no” requires no workaround.
  • Review workflow: drafts are unmistakably drafts until a clinician edits and signs, and there is no bulk sign-off path that skips the review.
  • Policy: our documentation policy now states in writing that the signing clinician verifies AI-drafted content before signing, and every clinician in the pilot has read it.

The rollout

Pilot small, measure the note, then decide

Once the checklist passes, resist the caseload-wide switch. Run a bounded pilot: two or three clinicians, a defined set of consenting clients, a few weeks. Measure the thing the product promised — total time from session end to signed note, including the review pass, not just the drafting the demo showed. Some clinicians find the review of a machine draft slower than writing their own note for complex sessions and faster for routine ones; that split, mapped to your actual caseload, is the real ROI calculation. The pilot is also where the workflow questions on the checklist stop being hypothetical: you will find out quickly whether the revocation path works and whether sign-off is genuinely deliberate. A vendor confident in the product will welcome the structure; a vendor pushing for the annual all-seats contract before a pilot has told you their forecast of your second month.

Is an AI scribe HIPAA compliant for a therapy practice?

No product is HIPAA compliant on its own — compliance describes the arrangement, not the software. The vendor must operate as a business associate under a signed BAA, and your practice must use the tool inside its own safeguards: consent, access controls, and a documentation policy that covers the clinician review. A vendor can make compliance achievable or impossible, which is what the due-diligence checklist tests, but the label “HIPAA compliant” on a website is a marketing claim, not a certification — HHS certifies no such thing.

Do I need a BAA for a free trial of an AI scribe?

If any real patient information reaches the vendor during the trial — audio, transcripts, or notes — yes, before it does. The business associate rules turn on whether the vendor receives PHI on your behalf, not on whether money changed hands. The clean approach is to trial with role-played sessions and fictional clients until the BAA covering your account is signed, then pilot with real, consenting clients afterward.

Do patients have to consent to an AI scribe recording the session?

Treat it as two questions. Recording law is state law: some states require consent from one party to the conversation, others from all parties, and telehealth can put the patient in a different state than you. Verify your situation specifically. Separately, telling patients clearly what is being recorded and what happens to it — and honoring a no without friction — is basic trust in a therapeutic relationship, whatever the statutory minimum. For minors, plan for guardian consent, the child’s assent where appropriate, and revocation.

Can an AI scribe vendor use our sessions to train its models?

Only if your agreement permits it, which is exactly why the permitted-uses clause deserves a slow read. Ask directly whether audio, transcripts, or notes train or improve any model, including subcontractors’; whether you can decline; and, if the vendor says it trains only on de-identified data, which regulatory method — Safe Harbor or Expert Determination — it applies. Vendors differ genuinely here, and a claim the vendor will not put in the contract should be treated as absent.

Who is responsible if an AI-generated note contains an error?

The clinician who signed it. CMS made the equivalent point about human scribes: reviewers look for the treating clinician’s signature, which affirms the note adequately documents the care provided. ASHA and APTA guidance treats AI output the same way — a draft the clinician verifies, not a substitute for clinical judgment. Practically, that means the review pass before signing is where invented objective data or softened skilled-service language gets caught, and your documentation policy should require it explicitly.

What happens if the AI scribe vendor has a data breach?

Under the Breach Notification Rule, a business associate must notify the covered entity without unreasonable delay, and no later than 60 calendar days after discovering a breach of unsecured PHI. Your practice then owes notifications to affected individuals — but do not assume your own 60-day clock starts when the vendor’s report arrives. If the vendor acts as your agent under the federal common law of agency, the rule imputes the vendor’s discovery to your practice, so your deadline can already be running. Negotiate a shorter contractual reporting window up front, confirm what the report will include, and ask counsel whether the relationship is agency or independent contractor before you need the answer.

Primary sources

Bibliography / 10
  1. 01Business Associates (HIPAA guidance)U.S. Department of Health and Human Services
  2. 02Business Associate Contracts: Sample ProvisionsU.S. Department of Health and Human Services
  3. 0345 CFR § 164.504 — Uses and Disclosures: Organizational RequirementsElectronic Code of Federal Regulations
  4. 0445 CFR § 164.410 — Notification by a Business AssociateElectronic Code of Federal Regulations
  5. 0545 CFR § 164.404 — Notification to Individuals (discovery and agency imputation)Electronic Code of Federal Regulations
  6. 06Guidance Regarding Methods for De-identification of Protected Health InformationU.S. Department of Health and Human Services
  7. 07Medicare Program Integrity Manual Transmittal 713: Scribe Services Signature RequirementsCenters for Medicare & Medicaid Services
  8. 08Complying with Medicare Signature Requirements (MLN905364)Centers for Medicare & Medicaid Services
  9. 09Artificial Intelligence (AI): Considerations for CSD ProfessionalsAmerican Speech-Language-Hearing Association
  10. 10APTA Practice Advisory on AI-Enabled Ambient Scribe TechnologyAmerican Physical Therapy Association

Written by Callie Editorial

Published July 29, 2026

Educational content, not legal, billing, or patient-specific clinical advice.