HIPAA-compliant AI scribes: what actually matters (and what marketing gets wrong)
A practical breakdown of the HIPAA requirements every AI scribe should meet, the questions to ask a vendor before you sign, and the red flags that mean walk away.
Every AI scribe on the market claims HIPAA compliance. Most of the time that claim is accurate. Sometimes it is aspirational. The gap between "we say HIPAA-compliant" and "we can hand you a BAA today" is where practices get burned. This guide breaks down the six things HIPAA actually requires from a scribe, the questions to ask before you sign, and the red flags to watch for.
What HIPAA requires (in plain English)
HIPAA’s Security Rule is technical (safeguards for PHI); the Privacy Rule is procedural (who can see PHI and why); the Breach Notification Rule is operational (what happens when things go wrong). An AI scribe must address all three. In practice, that reduces to six deliverables:
- Encryption in transit and at rest. TLS 1.2 or higher for transit; AES-256 for at-rest. If the vendor uses the word "encryption" without specifying, ask.
- Access controls with audit logging. Role-based access, unique user identifiers, and a durable audit trail showing who accessed what and when. Auditors will ask to see the log.
- A signed Business Associate Agreement (BAA). The BAA is a contract making the vendor legally accountable for handling PHI on your behalf. Free, same-day BAA delivery is table stakes.
- Data retention limits with automatic deletion. HIPAA doesn’t mandate a specific retention window, but "minimum necessary" is a governing principle. 30-day automatic deletion is the current industry standard for ambient audio.
- Breach notification within 60 days. The vendor must have a documented breach-response plan that meets the 60-day HHS deadline.
- US-based data storage (or explicit cross-border consent). Practically all major scribes host US-only for HIPAA covered entities. Ask before you sign if data leaves the US.
What to ask a vendor before you sign
The following seven questions separate real compliance from a marketing bullet point. If a vendor can’t answer all seven within 24 hours, keep shopping.
- 1. Will you sign a BAA at no additional cost, and how fast can you send it? Anything longer than same-day suggests either legal thin-ice or a compliance department that’s not really staffed.
- 2. Where is patient data physically stored? AWS us-east-1? A Microsoft Azure US region? Your own data center in Missouri? Get the region name.
- 3. What’s the encryption standard for audio and transcripts, and how are keys managed? AES-256 with envelope encryption via KMS is the modern standard.
- 4. What’s the automatic data-deletion window? 30 days is the industry norm for audio; some vendors retain transcripts longer at the customer’s option. Confirm the default.
- 5. Who inside your organization can access PHI, and how is that logged? A serious vendor answers: engineering has no default access, support is role-gated, all access is audit-logged, and audit logs are retained six years.
- 6. Have you had a third-party HIPAA audit, and can you share the summary? SOC 2 Type II or HITRUST CSF is the gold standard. A vendor that hasn’t been audited isn’t automatically non-compliant, but they should be able to explain why.
- 7. What’s your breach notification SLA? The HHS deadline is 60 days. A good vendor commits to notifying you within 5-7 business days of discovery so you can meet the 60-day patient-notification window comfortably.
Red flags
- "HIPAA-compliant" but no BAA available on the pricing page. The BAA should be a click, not a sales call.
- BAA offered only at higher tiers. HIPAA compliance is not an upsell.
- Vague encryption language. "Enterprise-grade encryption" without a standard cited is a marketing phrase, not a technical claim.
- PHI shared with third parties for model training. Read the privacy policy before you sign. If patient data is used to train models without explicit customer opt-in, walk.
- No documented breach-response plan. If they can’t answer question 7 above with a specific SLA, they don’t have one.
The one HIPAA thing every practice forgets
The scribe is a Business Associate. Your practice is the Covered Entity. Under HIPAA, the Covered Entity is ultimately accountable for every disclosure of PHI, even ones made by the Business Associate. That means two things:
- Keep a copy of every signed BAA. If you ever face a compliance audit, the BAA is the first document requested.
- Do not use the scribe for anything the BAA doesn’t cover. If the vendor’s BAA covers transcription and clinical summarization, don’t start piping the transcripts into a general-purpose chat tool. That’s a new disclosure to a new business associate that isn’t covered.
Bottom line
HIPAA compliance is a checklist, not a philosophy. Six deliverables, seven questions, a handful of red flags. Any AI scribe that can’t hand you a BAA within 24 hours of the request is not compliant enough to serve your patients. Any scribe that names specific standards, hosts in the US, and audits itself against SOC 2 or HITRUST is doing the work.
If you want to skip the vendor-evaluation homework, start the ezScribe 14-day trial. BAA and privacy policy at the HIPAA page; download the BAA template at /api/legal/baa-template.pdf.
Try ezScribe on your next visit
HIPAA-compliant. BAA included. 14-day free trial. Cancel from your account in one click if we’re not the right fit.