The Privacy Rule of HIPAA permits a covered entity to use or disclose protected health information for treatment, payment, or healthcare operations without a patient’s separate authorization. The usage is typical for an AI scribe that captures a visit, turns it into a clinical note, and stores it as part of the record.

So long as the vendor is acting as a business associate under a properly executed business associate agreement (BAA), and its use of PHI remains within the agreement’s permitted purposes, HIPAA does not itself require the patient to sign a separate authorization before the microphone turns on. But as researchers writing in NPJ Digital Medicine explain, “While consent for recording clinical conversations is essential, legal requirements vary across jurisdictions.”

The answer to whether an AI scribe needs to disclose that it is recording is not because of HIPAA. In some cases, it must disclose if it is recording due to state laws, many of which are evolving because of increased AI usage and privacy concerns. Compliance programs that map an AI-scribe rollout only to the HIPAA Security Rule and a signed BAA are addressing only part of the legal exposure.

 

The legislative standard

Every state has some form of recording-consent law, which can be grouped into two categories. It is a fact that is made evident by the Reporters Committee for Freedom of the Press Recording Guide, which summarizes each state’s laws regarding phone calls and in-person conversations.

In one-party-consent states, a clinician participating in the conversation may generally provide the consent required by the recording statute. The clinician is consenting as a participant, not on behalf of the patient. All-party or two-party consent states require everyone being recorded to consent before the recording starts. California, Illinois, Pennsylvania, Florida, Massachusetts, Washington, and Maryland require all-party consent. Recording a confidential patient encounter without the consent required under applicable state law may create liability under wiretapping or eavesdropping statutes, regardless of whether the HIPAA documentation is otherwise complete.

The Sutter and MemorialCare case is based on that theory, and it is a distinction that covered entities cannot get out of with a BAA alone.

 

Why adoption has moved faster than legal safeguards

According to the NPJ Digital Medicine study, roughly 30% of physician practices now use AI scribes, with increasing adoption across major health systems, and documentation time can drop 20% to 30% with these tools in place. A quality improvement study published in JAMA Network Open, spanning six health systems and 263 clinicians, found that after 30 days on an ambient AI scribe, burnout in ambulatory settings dropped from 51.9% to 38.8%, with parallel gains in after-hours charting time and attention available for patients. Numbers like that generate their own momentum, and momentum is not the same thing as governance.

The clinical literature is candid about the tradeoffs that come with that speed. The same npj study points out that modern large-language-model-based scribes report lower transcription error rates than earlier dictation tools, roughly 1% to 3% versus 7% to 11%, but that they introduce distinct failure modes. Hallucinated content, omissions, and misattributed statements create new types of safety risk. An editorial in JMIR Medical Informatics in 2025 states that although the evidence suggests that ambient AI scribes are associated with reduced burnout and meaningful time savings, these benefits are offset by ongoing concerns about the accuracy, consistency, and style of AI-generated notes, and diligent clinician oversight is still needed.

 

What this means operationally

The practical checklist for covered entities piloting or scaling an ambient scribe looks different when you stop treating HIPAA and recording-consent law as the same requirement.

  1. The scribe vendor is a business associate that manages electronic protected health information (ePHI), so the tool is part of your HIPAA Security Risk Analysis.
  2. A line buried in a long new-patient packet signed weeks ago is a poor substitute for a clear statement at the start of the encounter, especially in all-party consent states where the legal bar is that every participant agreed before recording began.
  3. Know your state because a multistate health system should not assume that the minimum legally sufficient workflow in one state will work everywhere. It may either tailor its procedures by jurisdiction or adopt a national workflow that satisfies the strictest applicable requirements.
  4. Consent for documentation and secondary use is separate. If recordings, transcripts, or deidentified derivatives could ever be used to train or fine-tune a model, that would require its disclosure.
  5. Be careful about claims of 'no audio stored' since some vendors market that they discard audio after transcription.

 

The pattern is not unique to scribes.

Paubox research on shadow AI in healthcare found that 95% of organizations say staff is already using AI tools in email, 62% say staff have tried tools like ChatGPT even if not approved, and 16% say compliance was never involved before AI email tools were turned on. In a panel discussion on the very same research, a participant talked about this specific form of the problem happening with note-taking tools, saying, “You'll join a meeting, and somebody signed up for some free AI note-taking tool…you have no visibility into what they're doing with your data.”

It is the same governance failure described in the Sutter lawsuit, just moved from the exam room to the inbox and the conference call. We use a tool because it saves time. Nobody in the immediate team is watching it, recording, storing, or transmitting anything sensitive. Compliance, if it learns at all, learns after the fact.

After a visit is transcribed, the note, the after-visit summary, or a portal message referencing what the AI captured is often emailed to the patient. A signed BAA and encryption on the scribe side do not automatically translate to what happens when that output leaves the EHR via a messaging system that was not built with a BAA in place.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

Can a patient withdraw consent after recording begins?

A patient can tell the clinician to stop recording. The provider should have a procedure for immediately disabling the tool and documenting the withdrawal.

 

Does consent from the patient cover everyone else in the room?

In an all-party-consent jurisdiction, consent may be needed from every recorded participant, including relatives, interpreters, caregivers, students, and other clinicians.

 

Can patients ask whether the recording is stored?

Patients can ask whether the system retains the original audio or only produces a transcript or clinical note; where the data is processed; how long it remains available; who may access it; and whether it is used to train or improve AI models.