AI medical scribes listen to a patient visit, transcribe it, and drop a draft note into the EHR before the clinician even leaves the room. Adoption has moved fast because the tools genuinely work: less typing, less burnout, more eye contact with patients. Vendors like Abridge, Nuance DAX, Suki, and Nabla all market themselves as HIPAA compliant, and most will sign a Business Associate Agreement without hesitation.
But a HIPAA compliant vendor is not the same thing as a compliant deployment. In April 2026, three California patients filed a federal class action against Sutter Health and MemorialCare over exactly this gap, and it is worth understanding before your practice turns an ambient scribe on.
$5,000: statutory damages per unauthorized recording under California’s wiretap law (CIPA). 20-31%: of ambient AI notes contain at least one hallucination in blinded studies. 11 states: require all-party consent before a conversation can be recorded at all.
1. Treating “HIPAA Compliant” Marketing as the Whole Answer
All 15+ major ambient scribe tools on the market claim HIPAA compliance, but the quality of the actual Business Associate Agreement varies enormously. Attorneys reviewing real vendor contracts have found missing BAA terms, vague indemnity language, and provisions that let the vendor use your patients’ recordings to train its models.
What’s at risk: A signed BAA that does not actually protect you, plus patient audio being used to train a vendor’s AI without your knowledge or consent.
The fix: Read the actual BAA line by line before anyone signs it, not just the marketing page. Confirm retention terms, whether data can be used for model training, where audio is stored, and breach-notification obligations. If a vendor will not sign a BAA, or reserves the right to use PHI for its own purposes, that is a hard stop.
2. Recording Patients Without a Documented Consent Process
This is the heart of the Sutter Health case. The lawsuit does not allege a HIPAA violation. It alleges that recording physician-patient conversations without informed consent violates California’s wiretap and medical-confidentiality laws, and the Federal Wiretap Act, regardless of whether the vendor signed a BAA. The legal theory is that the violation happens at the moment of interception, not later when the data is stored or used, so a BAA cannot undo it.
What’s at risk: Statutory damages that start at $5,000 per unauthorized recording under California law alone, multiplied across every affected patient encounter. Eleven states currently require all-party consent to record a conversation.
The fix: Build a scripted, documented consent workflow: verbal disclosure and a clear opt-out before the microphone activates, not template language buried in the finalized note. Update your Notice of Privacy Practices to describe the AI tool, what it captures, and the patient’s right to decline.
3. Leaving the Scribe Out of Your Security Risk Analysis
An ambient scribe generates far more than the note that lands in the chart: a live audio stream, an interim transcript, a machine-generated draft, and metadata about the clinician, patient, and visit. Every one of those artifacts is electronic PHI you are responsible for safeguarding, even the copies sitting on the vendor’s servers. OCR investigators look specifically for exactly this kind of ungoverned data flow.
What’s at risk: An audit finding that your required Security Risk Analysis never accounted for the scribe. Under the 2026 penalty structure, unintentional violations run up to nearly $64,000 each, with willful neglect reaching over $2.1 million per violation.
The fix: Add every ambient scribe to your technology asset and vendor inventories. Map exactly how audio and transcripts flow from the exam room to the vendor’s cloud and back into the EHR, and document encryption, access controls, audit logging, and retention at each hop.
4. Letting AI Drafts Auto-File Without Clinician Review
Ambient scribes draft notes; they do not practice medicine. Peer-reviewed evaluations have found that 20 to 31 percent of AI-generated notes contain at least one hallucination. In medicine, a hallucinated medication or misattributed history that reaches the chart is both a documentation error and a potential HIPAA breach.
What’s at risk: Incorrect medications, allergies, or history entering the legal medical record, creating both breach exposure and malpractice risk.
The fix: Require a clinician to read and correct every AI-generated draft before it is signed. No note should auto-file into the record without human review, no matter how accurate the vendor claims its model is.
5. No Retention or Deletion Policy for Audio and Transcripts
Some vendors delete raw audio within hours of a visit. Others retain recordings and transcripts indefinitely to retrain models or let a clinician replay an encounter later. Every extra day that audio sits on a vendor’s servers is another day it can be subpoenaed, breached, or used in ways your practice never agreed to.
What’s at risk: An expanding, unmonitored footprint of patient audio outside your practice’s control, and a harder, messier breach response if that vendor is ever compromised.
The fix: Decide how long raw audio and interim transcripts should live, typically no longer than it takes the clinician to review and sign the note, then confirm the vendor actually enforces that window in the BAA. Verify it in your audits rather than taking the vendor’s word for it.
Quick Self-Audit: How Many Apply to Your Practice?
- We adopted an ambient scribe based on the vendor’s marketing, not a line-by-line BAA review
- Patients aren’t given clear notice or an opt-out before the microphone activates
- Our Security Risk Analysis was never updated to include the scribe
- AI-drafted notes can be signed without a clinician reviewing every line
- We don’t know how long the vendor retains audio or whether it’s used to train models
If you checked even one box, it’s worth reviewing your AI documentation setup before it becomes the subject of a complaint instead of a compliment.
Rolling Out an AI Scribe? Get a Second Set of Eyes First
Our free 30-minute IT & HIPAA Security Assessment reviews your AI tools, vendor BAAs, and Security Risk Analysis. No obligation, no jargon, just a clear picture of where your practice stands before you turn a new tool on.


