Ambient AI documentation is moving into clinics faster than almost any technology before it. In the American Medical Association's 2026 Physician Survey on Augmented Intelligence, 81% of nearly 1,700 physicians reported awareness or use of AI in practice, more than double the 2023 rate. Thirty percent use it for discharge instructions, care plans, or progress notes, and 28% for billing codes, charts, or visit notes. MGMA found in August 2025 that 71% of medical group leaders already have AI somewhere in the patient visit.
Most of those rollouts skipped a step. The tool listening in your exam room is a HIPAA business associate, and a lot of practices cannot produce the agreement, the data map, or the retention answer that proves they treated it like one.
For a specialty clinic in New York City, the gap runs in two directions. HIPAA governs the PHI. New York governs the safeguards, the notification clock, and, in one case, the microphone itself.
The Rule Is Not Ambiguous, But Your Contract Might Be
45 CFR 160.103 defines a business associate as a person or entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. An ambient scribe does all four. It receives the audio, creates the draft note, transmits both somewhere, and maintains them for a retention window you may never have asked about.
Two vendor answers come up in these conversations. Neither survives contact with the regulation.
The first is the conduit argument, meaning we only pass the data along. HHS closed that door in its cloud computing guidance, which limits the conduit exception to transmission-only services where access to PHI is "only transient in nature." A vendor holding visit audio for 14 days is not transient. It is a landlord.
The second is the encryption argument. HHS is unusually direct here: "Lacking an encryption key for the encrypted data it receives and maintains does not exempt a CSP from business associate status," and an entity that maintains ePHI on your behalf is a business associate "even if the entity cannot actually view the ePHI." Encryption is a safeguard. It is not a legal disguise.
The serious vendors already agree, which makes this an easy screen. Suki states that it signs Business Associate Agreements. Nabla publishes its BAA as an appendix to its public terms. Ambience Healthcare says it is classified as a business associate under HIPAA. Abridge says it acts as a business associate processing data solely on the provider's instruction. If a vendor cannot produce a countersigned BAA before go-live, you have learned something useful about the rest of its compliance program.
So Where Does the Audio Go?
A BAA is the floor. 45 CFR 164.504(e) requires it to cover permitted uses, safeguards, breach reporting, subcontractor obligations, individual access, availability of records to HHS, and return or destruction of PHI at termination. Three things get skipped in practice, and they are the three that matter most for an ambient scribe.
Retention. Ask for a number, in writing, for audio and for transcripts separately. Suki publishes 30 days for both. Nabla's trust center says it does not store audio by default. Vendors that will not commit to a number in the contract are telling you the number is subject to change.
Model training. Public statements diverge sharply here. Microsoft's Dragon Copilot privacy documentation says its models are "trained solely on anonymized data," with customer audio, transcriptions, and clinician corrections anonymized within 90 days. Freed says its models train only on de-identified notes and never on PHI. Others say less. When a vendor says de-identified, ask which method: the Safe Harbor at 164.514(b)(2) or an Expert Determination. It matters, because voice prints are one of the 18 enumerated Safe Harbor identifiers. Raw clinical audio is a poor Safe Harbor candidate, so any claim of de-identified audio is running on an expert determination that someone should be able to hand you.
Subcontractors. Your scribe vendor is probably not building its own speech recognition, its own language model, and its own data center. HHS is explicit that a subcontractor which creates, receives, maintains, or transmits PHI is itself a business associate, and that your vendor "must establish a BAA with its subcontractor before disclosing PHI." Ask for the chain. Business associates are directly liable to OCR for Security Rule failures and for failing to paper their own subcontractors, so a competent vendor will have the answer ready.
When the Vendor Gets Breached, You Get the Call Late
In March 2026, OCR settled with MMG Fusion, a business associate whose breach exposed the PHI of roughly 15 million people, for $10,000 and a three-year corrective action plan. OCR's findings included failure to conduct an accurate and thorough risk analysis and, more instructive for you, "failing to notify covered entities affected by the incident of the breach." The incident occurred in December 2020. OCR opened its investigation in March 2023, after the data surfaced on the dark web.
Read that timeline again as a covered entity. Your 60-day individual notification clock starts at discovery, and discovery depends on your vendor picking up the phone. The regulation gives a business associate up to 60 days of its own to tell you. Your BAA should cut that down hard. The proposed HIPAA Security Rule would require notice to covered entities within 24 hours of a business associate activating its contingency plans, alongside mandatory multifactor authentication and an asset inventory mapping how ePHI moves. That rule is still proposed and the current Security Rule remains in effect, so a 24-hour clause today is a negotiation, not a citation.
The exposure is not theoretical. The 2025 Verizon Data Breach Investigations Report found the share of breaches involving a third party doubled to 30%. IBM's 2025 Cost of a Data Breach Report put healthcare's average breach cost at $7.42 million, the most expensive of any industry studied, and found one in five breached organizations traced an incident to unsanctioned AI use, adding roughly $670,000. We covered the broader version of this in BAAs and Vendor Risk.
New York Adds Another Complication That HIPAA Does Not
Three state requirements change the calculus for a clinic operating in the five boroughs.
Vendor diligence is state law, not just good practice. The SHIELD Act, General Business Law 899-bb, requires reasonable safeguards for the private information of any New York resident, and the administrative safeguards it names include "selecting service providers capable of maintaining appropriate safeguards, and requiring those safeguards by contract." A HIPAA-compliant entity is deemed compliant with 899-bb, but the Attorney General enforces the underlying expectation directly. In October 2024, the AG secured a $500,000 penalty and $2.25 million in required security investment from Albany ENT & Allergy Services, with findings that expressly included inadequate monitoring of third-party cybersecurity vendors.
Your notification clock is shorter than the federal one. New York amended GBL 899-aa in December 2024 to require individual notice within 30 days of discovery, and separately added medical information and health insurance information to the definition of private information effective March 21, 2025. Medical information is now a standalone trigger, so it does not need to be paired with a Social Security number for notice to be owed. A leaked visit transcript qualifies on its own. HIPAA-covered entities also owe the Attorney General notice within five business days of notifying HHS. Our breakdown of how these clocks interact is in NY SHIELD Act for Healthcare and Breach Notification Timelines.
The microphone has its own statute. New York is a one-party consent state, and a clinician recording a visit they are part of is not eavesdropping under Penal Law 250.00 for two independent reasons: a party consented, and the "mechanical overhearing" definition only reaches someone "not present thereat." The exposure is the always-on device in a room with no staff member in it, capturing a patient talking to a family member. That is a class E felony, and the exam room microphone has no idea the visit ended. Push-to-record beats always-on. And if you run telehealth, a patient sitting in California brings Penal Code 632 and its all-party consent rule with them.
Two things that come up and do not apply: NY DFS Part 500 is keyed to financial and insurance licensure, and the hospital cybersecurity rule at 10 NYCRR 405.46 covers general hospitals only. If you contract with a hospital system, expect 405.46's vendor terms to arrive by contract anyway.
The Draft Note Is Not the Record Until Someone Signs It
Ambient scribes are good. They are not finished. A UC Davis Health study published in JMIR Medical Informatics in April 2026 formally reviewed 356 of 7,545 AI-generated notes. It found 94.7% free of significant errors, which sounds excellent until you read the rest: 18% contained accidental omissions, 11.5% contained hallucinations, and 5.3% contained errors rated as posing serious or imminent risk. Roughly 15% of notes were left entirely unedited. Research on general-purpose speech-to-text has found about 1% of transcriptions containing phrases that appear nowhere in the audio, with 38% of those hallucinations carrying explicit harms such as fabricated associations and false authority.
Three governance decisions belong in policy before the first clinician logs in. Who attests to the note, and whether the attestation states that a human reviewed AI-generated content. Whether raw audio is part of the designated record set, which determines what you must produce under Public Health Law 18's 10-day inspection window. And what happens when the scribe is unavailable, which is the same discipline as your EHR downtime procedure.
Set expectations on the business case, too. The Peterson Health Technology Institute's review of eight health systems found ambient scribes cut documentation time and burnout, while the financial impact "is unclear." Buy it to keep your physicians, not to raise throughput.
The Shadow IT Problem Is Really a Procurement Problem
Several ambient scribes are sold directly to individual clinicians. Freed advertises a seven-day trial with no credit card and individual plans from $39 per month, with the organization-wide BAA sitting on its group tier rather than the individual one. Commure's self-serve scribe has a free tier, also with no credit card. That is not a knock on either product. It describes how a well-meaning physician acquires your clinic's newest vendor relationship in four minutes, without procurement, security review, or a BAA anyone in the building has read.
IBM found that 63% of breached organizations either have no AI governance policy or are still writing one. In a multi-specialty clinic where each service line brings its own software preferences, an approved-tools list is cheaper than the alternative. Our 90-day AI governance plan is a workable starting template.
The Pre-Rollout Checklist
Ten things to have on paper before the first patient is recorded.
A countersigned BAA covering all 164.504(e) provisions, executed before any pilot.
Written retention periods for audio and for transcripts, stated separately, with a deletion mechanism.
A model training answer in the contract, and if the vendor claims de-identification, the method and who determined it.
The subcontractor chain, naming the speech recognition, model, and hosting providers, with BAAs flowing down.
Breach notification in hours, with a named contact and an escalation path.
Data residency, plus a return or destruction commitment at termination that specifies format and timeline.
The SOC 2 Type II report and the most recent penetration test summary, reviewed rather than filed.
An attestation policy stating who signs the note and what the clinician is certifying.
A recording consent workflow, push-to-record by default, with a rule for telehealth patients in all-party consent states.
An updated risk analysis reflecting the new data flow. This is the most cited failure in OCR's Risk Analysis Initiative.
An ambient scribe is a good investment for a busy integrated clinic. Vet it the way you vetted your EHR, and the rollout is a project. Skip that, and it becomes an incident with a 30-day clock attached.
Techvera provides Managed AI, Compliance Readiness, and vCIO Services to integrated health clinics in New York City, Dallas-Fort Worth, and Tulsa. If you are evaluating an ambient documentation vendor, we will run the vendor assessment and the updated risk analysis with you. Schedule a strategy session.
Frequently Asked Questions
Is an AI scribe a HIPAA business associate?
Yes, in nearly every deployment. Under 45 CFR 160.103, a business associate is any entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity, and an ambient scribe does all four when it records a visit, generates a draft note, and stores the audio or transcript. HHS has stated that neither transmission-only claims nor lack of an encryption key exempts a vendor from business associate status. A signed Business Associate Agreement meeting the requirements of 45 CFR 164.504(e) must be in place before the vendor receives any PHI, including during a pilot.
Do you need patient consent to record a visit with an AI scribe in New York?
New York is a one-party consent state under Penal Law 250.00 and 250.05, so a clinician recording a visit they are participating in is not eavesdropping. HIPAA does not require separate recording consent either. Two caveats matter operationally. An always-on device that captures a conversation when no staff member is present, such as a patient speaking with a family member in an empty exam room, can fall outside the one-party protection. And a telehealth patient physically located in an all-party consent state such as California brings that state's rule, California Penal Code 632, into the encounter. Most clinics still disclose recording to patients as a matter of trust, which is a separate and defensible decision from the legal minimum.
How long should an AI scribe vendor keep visit audio?
There is no HIPAA-specified retention period for vendor-held audio, which is exactly why the number belongs in the contract rather than in the vendor's product documentation where it can change. Published practices vary: Suki states that audio and transcripts are deleted after 30 days, and Nabla states that it does not store audio by default. The clinic-side decision that drives the answer is whether raw audio is part of the designated record set. If it is, retention has to align with your state medical records retention obligations and your ability to produce records under New York Public Health Law 18. If it is not, the shortest workable retention window is the right one, and it should be written down.
About the Author
Team Techvera
Techvera Team
Articles written collaboratively by the Techvera team, combining expertise across cybersecurity, managed services, and digital transformation.
