In October 2025, Paubox published an article discussing how collaboration apps can become attack surfaces when integrations, external sharing, and loose settings grant improper access to company data. The article covers how generative AI chatbots can create meeting transcripts, summaries, and action items that will then need to be correctly classified, retained, and protected.

When discussing healthcare data in meetings, these tools have access to protected health information (PHI), which can be included in the meeting transcript, summary, calendar entry, email, or attached app. Healthcare organizations should assess these privacy and security risks before allowing an AI assistant to join a meeting in which confidential information may be discussed.

 

What is an AI meeting assistant?

An AI meeting assistant listens to the meeting and leverages technologies like automatic speech recognition and generative AI to create a transcript, summary, speaker labels, action items, or follow-up messages. Some assistants will join virtual meetings by appearing as a bot on screen that others can see. Other assistants run quietly within the meeting platform or on a user’s device.

An ambient AI scribe automatically drafts documentation of what was said during the clinical conversation. While some virtual assistants may offer ambient scribing, they likely do not have the controls needed to handle healthcare privacy rules, clinical vocabulary, patient-consent workflows, or electronic health record (EHR) integrations.

 

AI meeting assistants can reduce documentation work

A systematic review analyzed eight AI scribe studies. It found evidence of reduced documentation time, better clinician workflow, and provider buy-in. However, it cited variability by product and setting. The researchers concluded, “AI scribes show promise in improving documentation efficiency and clinician workflow, although the evidence remains limited and heterogeneous.”

For that reason, health systems should approach AI efficiency claims as a hypothesis to be tested rather than a promise to deliver. Providers can begin with low-risk pilots and measure total time saved, time editing notes, missed information, incorrect attributions, and satisfaction. Then, with HIPAA compliant email, the pilot team can forward approved summaries and PHI to other reviewers.

 

HIPAA compliance depends on the complete data flow

The HHS Office for Civil Rights lists an independent medical transcriptionist or app vendor providing transcription services to a physician as an example of a business associate. Broadly speaking, a vendor typically qualifies as a business associate when it creates, receives, maintains, or transmits PHI under the direction of a covered entity or another business associate.

HIPAA regulated healthcare organizations should enter into an appropriate business associate agreement (BAA) before the vendor accesses electronic PHI on their behalf. Healthcare organizations should review the executed BAA to confirm that it covers the product, applicable service tier, optional AI features, and intended use. For example, a platform’s agreement may not extend to cover all optional assistants and third-party integrations.

Note that using encryption does not negate the need for this review process. According to HHS cloud-computing guidance, a cloud provider that maintains PHI that has been encrypted by a customer may qualify as a business associate of the customer, even if the cloud provider does not have access to the decryption key.

Before approval, healthcare organizations should determine:

  • Does the vendor use customer audio, transcripts, or summaries to train or improve its models?
  • Where are audio recordings, transcripts, summaries, and backups stored?
  • Who has access to customer data, including employees, model providers, and subcontractors?
  • Can administrators control and audit access, retention, deletion, sharing, and downloads?
  • Does the assistant have the security features necessary to support strong authentication, audit logs, incident reporting, and immediate termination of access for former employees and contractors?

Patients and meeting participants need clear information

HIPAA does not provide a universal consent standard that applies to all recordings. In addition to HIPAA, healthcare organizations should be aware of applicable federal and state recording laws, professional requirements, patient expectations, and their own internal policies when crafting their recording approach. When in doubt, speak to legal counsel on whether your organization is required to provide notice, give verbal consent, or acquire written consent.

One group performed a quality improvement study on informed consent for ambient documentation with clinicians and patients. In total, they spoke with 18 clinicians and 103 patients. 77 patients (74.8%) stated they were comfortable or very comfortable with their physicians using ambient documentation. Letting the clinician use the technology did not imply patients consented to all downstream uses of their data. Results from their thematic analysis showed participants desired a flexible consent model that included digital touchpoints and education, support from nonclinical staff, and easy opt-out capabilities.

 

AI-generated transcripts should always be reviewed by humans

AI-generated text may also look correct at face value but fail to include a qualification, attribute a statement to the wrong speaker, or substitute another medication, dose, diagnosis, or follow-up instruction. While these mistakes may be harmless, they become necessary if people rely on the summary for patient care, billing, or task ownership.

One BMC research summary pulled data from 29 clinical speech-recognition studies and found that reported WERs ranged from 8.7% when transcribing controlled dictation to greater than 50% for conversational or multi-speaker speech. WER was also affected by specialty-specific terminology and accented speech. Researchers found that recent LLM-based approaches offered automated summarization features, yet often required human review to ensure clinical safety.

The meeting owner, responsible licensed clinician, or translator (if needed) should review the output, compare it against the original conversation, make edits as needed, remove any unnecessary PHI, and approve the summary. The summary should not be automatically appended to the medical record, sent to the patient, or used to generate orders/task ownership if it has not been reviewed. Once approved, the organization can decide who receives the summary through HIPPA compliant email for the purpose of caring for that patient.

 

Governance must address shadow AI

According to the report, 62% of surveyed organizations had observed staff experimenting with ChatGPT or similar unauthorized tools, while 75% believed employees assumed that products such as Microsoft Copilot were automatically HIPAA compliant.

Organizations can reduce shadow AI by maintaining lists of approved tools and prohibited uses, providing a simple process for requesting approval, and explaining how staff should report unintended disclosures. HIPAA compliant email puts compliance teams in a position to share those rules and narrowly tailored updates if a vendor adjusts its privacy terms, adds subprocessors, changes retention settings, or toggles AI features.

In general, organizations should start with a small pilot, watch for privacy and accuracy problems, and re-run the security check any time the tool or its data practices change. A safer deployment keeps the assistant in a supporting role and prevents its output from automatically becoming part of a record, disclosure, or clinical decision.

 

FAQs

Does removing patient names make an unapproved AI-generated transcript safe to process?

No, diagnoses, appointments, locations, relationships, and other information can identify the patient when combined.

 

Does obtaining a vendor’s signed BAA make prior, unauthorized employee use acceptable?

No, a signed BAA cannot retroactively make previous disclosures acceptable, nor does it eliminate the organization’s responsibility to conduct a risk analysis, approve the service, and implement security controls.

 

How can healthcare organizations discover shadow use of AI meeting assistants?

Security teams can inspect calendar integrations, OAuth scopes, bots in meetings, network traffic, application logs, and transcripts leaving company networks for evidence of unauthorized services.

 

What should employees do if they discover an unrecognized AI bot in a meeting where they will be discussing PHI?

Meeting organizers should suspend the meeting and have the bot removed if its owner, approval status, BAA coverage, and notice to participants cannot be confirmed.