By Elena Pak, Credentialing Department, WCH
The AI Scribe Is No Longer Just a Documentation Tool
The physician finishes the visit, signs the note, and moves on. But the encounter itself may have already traveled through several systems the physician never sees.
A typical path looks something like this: patient → microphone → transcription engine → AI model → vendor infrastructure → EHR → final clinical note. Somewhere along that chain, a conversation that started as two people talking in an exam room becomes data sitting on servers, subject to rules the clinician in the room may never have read.
Which raises the question every compliance officer should be asking before the next AI scribe contract gets signed: who actually controls the data at each step?
The Risk Isn’t Just That AI Gets the Note Wrong
Most of the public conversation about AI scribes focuses on one question: what if the model hallucinates? That’s a fair concern, but it’s not the whole picture. A security briefing has to ask a broader question: what happens to the information before, during, and after the AI generates the note?
Break it into three stages.
- Before. Patient notice and any required consent, how the recording is captured, what device does the capturing, and how the workflow is designed around it.
- During. How the audio is transmitted, where the vendor processes it, what cloud environment it lands in, which subcontractors touch it, and who has access along the way.
- After. What happens to the transcript, the audio file, and the generated note once they reach the EHR — retention periods, deletion practices, and any secondary use of the data.
Each of those stages carries its own risk profile, and organizations may have a clear answer for the EHR while having less visibility into what happens to raw audio, transcripts, or other intermediate data held by the vendor.
The New PHI Pipeline
This is really the heart of the issue. An AI scribe doesn’t produce a single record of the encounter — it produces several, and each version can live in a different place with different rules attached.
The chain typically runs: audio recording → transcript → AI-generated draft → edited clinical note → EHR record.
Every link in that chain can come with its own retention schedule, its own access permissions, its own audit logging, its own deletion policy, and — often — its own vendor. A hospital might have a solid retention policy for the EHR and no clear answer for how long the vendor keeps the raw audio, or whether the transcript is treated as a separate record entirely. That gap is where a lot of the actual risk lives.
What’s Happening Inside the Vendor’s Environment?
Before any AI scribe goes live, the security and compliance team needs answers to a specific set of questions — not because HIPAA spells out every one of them in exact terms, but because a Business Associate Agreement alone won’t surface the details that matter operationally. Some of this is about what the law requires; some of it is about what a careful organization should require contractually, even where the law is silent.
| Worth asking directly: Where is patient data actually processed, geographically and technically? Is the audio retained after the note is generated? For how long? Is the transcript retained separately from the note? Is any of this data used to train or improve the vendor’s models? Are subcontractors involved in processing, and where are they located? Can the organization audit the vendor’s practices, or only take their word for it? What happens to the data when the contract ends? How, exactly, is data deleted — and what about backups? Who inside the vendor’s organization can access recordings and transcripts? |
Deleting the audio also does not necessarily mean the encounter has disappeared from the vendor’s environment. A transcript, metadata, logs, cached copies, or the downstream clinical record may still exist elsewhere in the workflow. Whether that’s actually the case for a given vendor is a question to verify, not an assumption to make either way — but it’s exactly the kind of gap a “we deleted the audio” answer can paper over.
None of these are exotic questions. Vendors should be able to provide clear, specific answers to these questions. If they cannot, that uncertainty should be treated as part of the organization’s vendor-risk assessment.
A BAA Is Not the Whole Security Program
It’s tempting for an organization to treat a signed Business Associate Agreement as the finish line: “we have a BAA with the vendor, so we’re covered.” Where the AI vendor is acting as a business associate — creating, receiving, maintaining, or transmitting PHI on behalf of a covered entity, much as an independent medical transcriptionist would — a BAA is required. But it doesn’t automatically solve for inappropriate access, weak authentication, overly broad permissions, insecure integrations with the EHR, unclear retention timelines, model-training questions, subcontractor visibility, incident response planning, or clinical documentation governance more broadly.
In other words: a BAA is a legal baseline, not a risk management program. Treating it as one leaves real gaps unaddressed.
What If the AI Creates a False Clinical Record?
This is where the documentation-integrity problem becomes a patient-safety problem, and it’s worth framing it that way rather than jumping straight to malpractice.
AI-generated notes can omit a medication, get a dosage wrong, miss a documented allergy, invent a symptom that was never mentioned, misinterpret something the patient said, or drop the context behind a clinical decision. A 2026 article in JCO Oncology Practice cited a case in which an AI transcription tool was criticized for inventing several sentences of text, including details about a patient’s medical treatment, race, and medication — the kind of error that’s easy to miss on a quick read-through.
The broader evidence on note quality backs this up. A study led by researchers at the University of Washington and the Veterans Health Administration, published in the Annals of Internal Medicine in April 2026, had 18 human clinicians generate notes from the same five standardized primary care encounters, then had 30 blinded raters score every note using a validated 10-domain instrument. Human-generated notes scored higher than AI-generated notes across every one of the five clinical cases. The finding is notable because it wasn’t based on a single vendor: the evaluation included 11 commercial AI scribe tools and found lower scores for AI-generated notes across all 10 assessed quality domains, with the biggest gaps in thoroughness, organization, and overall usefulness.
The consequence chain is straightforward: a wrong note becomes part of the permanent EHR record, which shapes a downstream clinical decision, which can lead to patient harm and, eventually, liability. Framed that way, documentation quality isn’t a side issue — it’s the mechanism through which most of the other risks materialize.
The Physician Still Owns the Final Note
It would be an overstatement to say a clinician is legally liable for everything an AI tool does. That’s too broad a claim to hold up. A more accurate way to put it: AI assistance doesn’t eliminate the clinician’s responsibility to review the accuracy of the record before signing it.
Reporting from Healthcare Dive on this exact issue notes that clinicians remain ultimately on the hook for documentation mistakes regardless of whether AI was used to generate the notes, and that there are no public malpractice cases tied to AI scribes yet — though experts caution that doesn’t mean none exist. The legal literature more broadly tends to treat liability as something that could be distributed across clinicians, organizations, and vendors depending on the specific facts of a case — not a question with one clean answer.
The Risk Most Organizations Miss: Trust
This might be the most underappreciated angle in the whole discussion, and it isn’t about AI making mistakes — it’s about people stopping noticing when it does.
Call it what it is: an accuracy problem that becomes a human-oversight problem. When clinicians wrote their own notes, they had a built-in check — they’d remember, mid-review, “wait, the patient mentioned something about that medication.” When an AI produces something that looks clean, structured, and complete, the temptation is just to sign it.
Healthcare Dive’s reporting on this is direct: as providers lean more heavily on AI scribes, they may spend less time and effort actually reviewing the notes, rubber-stamping documentation, assuming everything important was captured, or skipping the critical thinking about what got recorded. That’s a behavioral shift driven by the tool’s polish, not its accuracy — and it’s exactly the kind of second-order effect a security review tends to miss if it’s only looking at data flows and access controls.
What Healthcare Organizations Should Put in Place
Before deployment: centralized approval rather than letting individual clinicians pick their own tools, a proper security and privacy assessment, real vendor due diligence, a signed BAA, a full data-flow map, a review of retention terms, and a look at who the vendor’s subcontractors actually are.
During deployment: least-privilege access controls, strong authentication, role-based permissions, controls around how the tool integrates with the EHR, and audit logging with active monitoring — not logging that just sits unused.
For clinicians: treat every AI-generated note as a draft, not a finished product. Build in mandatory review, specifically verify medications and allergies, have a clear correction process, and set up an escalation path for recurring AI errors rather than letting each clinician handle them ad hoc.
Ongoing: periodic audits, accuracy testing against real outcomes where possible, monitoring for model drift, staying current on vendor and model updates, an incident response plan that actually accounts for this tool, and re-evaluation whenever the vendor pushes a major software change.
The Security Briefing Checklist
Before your organization approves an AI scribe, get answers to these:
Data — What’s actually collected: audio, transcript, metadata, or all three?
Vendor — Who processes the data, who are the subcontractors, and is there a signed BAA?
Model — Is PHI used to train or improve the model, and how are model updates governed?
Retention — How long is data stored, and how is it deleted when the time comes?
Access — Who can access recordings and transcripts, and are those access events logged?
Clinical — Who reviews the generated note, and what’s the process when the AI gets something wrong?
Governance — Who owns this risk internally, who approved the vendor, and who is monitoring performance after go-live?
***
The question isn’t whether AI is dangerous, and it isn’t whether AI can transform healthcare documentation — both framings are too simple to be useful. The security question is no longer whether AI has entered the exam room. It’s whether the organization knows where patient information goes once it gets there — who can access it, how long it remains there, how it becomes part of the medical record, and what happens when something goes wrong.
Sources
- Reddy, A., et al. “Rapid Evaluation of Artificial Intelligence Technology Used for Ambient Dictation in Primary Care: Comparing the Quality of Documentation of Artificial Intelligence–Generated and Human-Produced Clinical Notes.” Annals of Internal Medicine (2026). DOI: 10.7326/ANNALS-25-02772
- “ACP: Lower Quality Scores Seen for AI- Versus Human-Generated Visit Notes.” Ophthalmology Advisor / Rheumatology Advisor / Hematology Advisor / The Cardiology Advisor (HealthDay News), April 2026.
- “AI scribe tools produce lower quality medical notes compared to human clinicians.” UW Department of Medicine News, April 17, 2026.
- “Why AI scribes are a malpractice risk, according to experts.” Healthcare Dive, 2026.
- “Liability Risks of Ambient Clinical Workflows With Artificial Intelligence for Clinicians, Hospitals, and Manufacturers.” JCO Oncology Practice, ASCO Publications.
- “AI Scribes Pose Liability Risks.” MICA Insurance, August 2025.
- “AI Scribe Gaps Create New Physician Liability Exposure.” PhysEmp.
Discover more from Doctor Trusted
Subscribe to get the latest posts sent to your email.
