Sep 28, 2026

News

AI Scribes Went Mainstream in 2026 — Here's the HIPAA Checklist Before Your Practice Signs On

Nearly a third of physicians are now using an AI scribe to write their notes for them. If your practice hasn't been pitched one yet, it will be soon — and the sales demo is not going to walk you through the HIPAA questions you actually need answered first.

Where adoption stands now

According to Doximity's 2026 State of AI in Medicine report, 29% of physicians surveyed in January 2026 were using voice-based documentation tools — ambient listening apps and AI scribes — up from just 20% in April 2025. That's a 45% jump in nine months. Among physicians who've adopted the tools, usage isn't occasional: in family medicine, 88% of adopters use their AI scribe daily, and half of those use it multiple times a day.

The appeal is easy to understand. A separate analysis from the Texas Medical Liability Trust (TMLT) found that physicians spend roughly 5.8 hours out of every 8-hour patient day on documentation. Vendors claim their tools can cut that time by up to 70%. For a small practice where the physician is also often the one staying late to finish charts, that's not a marginal improvement — it's the difference between going home on time and not.

But an AI scribe isn't a note-taking app. It's a third party that listens to — and in most cases records — the actual conversation between a physician and a patient, processes that audio through an AI model, and generates language that becomes part of the permanent medical record. That's a materially different risk profile than a staff member typing a summary into ChatGPT, which is the AI/HIPAA question we covered in our last post. This one is about a vendor your practice formally selects, integrates with your EHR, and puts in the room with every patient.

Why it matters

TMLT's risk management guidance flags several places this goes wrong for practices that skip the diligence step. Several states now require explicit patient consent before recording a healthcare encounter with AI — not a blanket notice in the waiting room, but a documented conversation that covers what's being recorded, how the AI will use it, and that the patient can opt out. Practices that treat this as implied consent because "everyone does it now" are building a compliance gap into every single visit.

Then there's the vendor relationship itself. Not every AI scribe is built into your EHR by the EHR vendor you already have a BAA with. Many are separate companies that plug into your workflow — which means a separate Business Associate Agreement, a separate security review, and a separate set of questions about where the audio and transcripts are stored, for how long, and whether they're used to train the vendor's models on your patients' data.

And accuracy is its own liability question. TMLT specifically warns about AI "hallucination" — the tendency of these systems to generate plausible-sounding clinical detail to fill gaps rather than leave them blank — plus the risk of AI systems reproducing bias in how they characterize patients. Regardless of how the note was generated, the physician who signs it is fully responsible for what's in the chart. A scribe that saves five minutes per visit isn't worth much if it also means notes get signed without being read closely.

What this means if you're a South Florida practice

None of this is a reason to avoid AI scribes — the time savings are real, and adoption is clearly not slowing down. It's a reason to treat the purchase like the vendor decision it is, not a productivity app you install and forget. Before any AI scribe touches a patient conversation in your Palm Beach, Broward, or Miami-Dade practice, you should have a signed BAA in hand, a documented consent workflow your front desk and clinical staff actually follow, and a written policy on physician review before notes are finalized. We're seeing the same question come up as we extend our HIPAA-focused work into Martin and St. Lucie counties: practices growing along the Treasure Coast are evaluating these tools at the same pace as everyone else in South Florida, often without a chance to slow down and vet the vendor first.

Practical takeaways

  • Before signing with any AI scribe vendor, confirm whether it's covered under your existing EHR's BAA or requires its own — and get it in writing before the tool touches a single patient encounter.

  • Build a real consent workflow: patients need to be told an AI is recording and processing the conversation, and given a documented way to opt out, not just a sign on the wall.

  • Set a practice-wide policy that no AI-generated note gets signed without the physician actually reading it — hallucinated detail in a chart is a liability problem, not just an inconvenience.

  • Ask the vendor directly where audio and transcripts are stored, how long they're retained, and whether patient data is ever used to train their models.

  • If your IT partner hasn't reviewed your AI scribe vendor's security posture and BAA terms, that review should happen before rollout, not after an incident.


Get expert clarity

Frequently asked questions

Can my staff use the free version of ChatGPT or Claude at work?

Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.

What is a BAA and why does it matter for AI tools?

A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.

Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?

No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.

What should our practice do before letting staff use AI with patient information?

Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.

How does UpsiteGroup help with this?

We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

Build smarter systems and grow with confidence

Build smarter systems and grow with confidence