AI documentation tools are moving into home health fast. For agency administrators evaluating these tools, HIPAA compliance can't be an afterthought; it has to be the first question.
The challenge is that "HIPAA compliant" has become marketing language. Nearly every vendor says it. What varies enormously is what's actually in place, how patient data is handled, and what happens when something goes wrong.
This guide walks through the questions your agency should ask before signing with any AI documentation vendor.
Important: This article is for informational purposes only and does not constitute legal advice. We recommend consulting your legal counsel before making compliance decisions for your agency.
Why HIPAA compliance is more complex with AI
Traditional documentation software stores and displays patient data. The HIPAA requirements are well-understood: secure storage, access controls, audit logs, BAA with the vendor.
AI documentation tools introduce a layer that didn't exist before: audio capture of patient conversations. That audio contains protected health information (PHI), not just structured data fields, but the actual words a patient says about their symptoms, medications, living situation, and clinical history.
How that audio is processed, where it's stored, how long it's retained, and who can access it are all HIPAA questions that need clear answers from any vendor you're considering.
Not all AI tools handle patient data the same way. The BAA is where the details live.
The Business Associate Agreement: what to look for
Any AI documentation vendor that handles PHI on behalf of your agency is a Business Associate under HIPAA. You need a signed BAA before any patient data flows through their system. This is non-negotiable.
But a signed BAA doesn't tell you much on its own. What matters is what's in it. Key things to review:
- Permitted uses of PHI: The BAA should clearly limit how the vendor can use patient data. Look specifically for language prohibiting use of your patient data for AI model training or improvement.
- Subcontractors: If the vendor uses third-party services (cloud infrastructure, AI model providers), those subcontractors should also be covered under BAA requirements. Ask who they are.
- Breach notification timelines: HIPAA requires notification within 60 days of discovering a breach. A strong BAA will specify shorter timelines; 10 business days is reasonable.
- Data return and destruction: What happens to your patient data when you end the contract? The BAA should require return or certified destruction.
Questions to ask about audio data specifically
Because ambient AI tools capture audio of patient visits, you need to understand exactly how that audio is handled. These are the questions to ask:
Is audio stored, and for how long? Some vendors store raw audio. Others process it and discard it. If audio is retained, understand where it's stored, who can access it, and how it's secured.
Is audio used to train AI models? This is critical. Your patient conversations should never be used to improve a vendor's AI model without explicit consent. Reputable vendors will state this explicitly and put it in the BAA.
Where is data processed? If audio or transcription is processed by a third-party AI provider (such as a large language model API), understand what data that provider receives and what their data handling practices are.
Is data processed in the United States? For HIPAA purposes, data handling in US-based infrastructure is generally preferred and easier to audit.
Patient consent and disclosure
Using AI to capture a patient visit raises consent questions that vary by state. In most states, one-party consent applies, meaning the clinician's presence is sufficient. However, some states require all-party consent for audio recording.
Regardless of the legal requirement in your state, best practice is to inform patients that a documentation tool is in use during the visit. This can be as simple as the clinician saying they're using an AI note-taker before starting. Most patients respond positively; it signals that their clinician is investing in accuracy.
Ask any vendor whether their product includes a patient disclosure prompt or workflow. Purpose-built tools should.
Security practices to verify
Beyond the BAA, there are security practices you should verify through the vendor's documentation or security overview:
- End-to-end encryption for data in transit and at rest
- Role-based access controls (not all staff should have access to all patient data)
- Audit logging: who accessed what, when
- Multi-factor authentication for clinician and admin accounts
- Incident response plan: what happens if there's a breach
Red flags to watch for
Some warning signs that a vendor may not have their compliance house in order:
Vague answers about data storage. If a vendor can't clearly explain where patient data is stored and who can access it, that's a problem.
BAA takes weeks to produce. A mature vendor should have a standard BAA ready to review immediately. Delays suggest the compliance infrastructure isn't built out.
No clear answer on AI training. If the vendor can't confirm that your patient data won't be used for model training, assume it will be.
No mention of subprocessors. Almost all cloud-based AI tools use third-party infrastructure. A transparent vendor will disclose who those subprocessors are.
What Scribble's approach looks like
We include a signed BAA with every agency before any data flows. Patient data is never used to train or improve our AI models; we put this in writing. Audio processing happens within HIPAA-compliant infrastructure, and we disclose our subprocessors on request.
Our clinician app includes a disclosure workflow before each visit so patients know a documentation tool is in use. We believe transparency with patients is both the right thing to do and a practical best practice.
If you're evaluating Scribble or any other AI documentation tool, we're happy to walk through our security and compliance documentation in detail. Ask us.
The bottom line
HIPAA compliance in AI documentation isn't just about having a signed BAA. It's about understanding how patient data, including audio, is handled at every step. The questions in this guide will help you separate vendors who've built compliance into their product from those who've bolted on a compliance label.
Your patients trust you with their most sensitive health information. The vendors you bring into your agency need to earn that same level of trust.
AO')">