AI Compliance for Medical Practices: Using Scribes and Chatbots Without Breaking HIPAA
Ambient AI scribes have swept through medical practices faster than almost any technology in recent memory. They listen to the visit, draft the note, and hand physicians back hours of their day. Patient-facing chatbots are close behind, handling scheduling and questions around the clock. The productivity case is obvious. The compliance case is where practices get into trouble — because the moment protected health information (PHI) flows into an AI tool, HIPAA applies in full. AI compliance for medical practices isn’t about avoiding these tools. It’s about adopting them without turning a time-saver into a reportable breach or a lawsuit.
The gap between “this is amazing” and “this is a violation” is narrower than most practice owners realize, and it usually comes down to a few specifics no vendor demo highlights.
Medical AI Scribes
Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate — and an ambient AI scribe does all four. It listens to the encounter, processes the conversation, and generates documentation. That makes a signed Business Associate Agreement (BAA) non-negotiable before the tool touches a single patient visit.
This is not a technicality. If PHI reaches a vendor without a BAA in place, both you and the vendor are in violation the instant data is sent — even if nothing is ever breached. The HHS Office for Civil Rights has settled cases for millions of dollars where the only failure was a missing agreement. The HHS guidance on business associates and HIPAA spells out the obligation clearly. Before you enable any AI tool, the first question is simple: will they sign a BAA, and what does it actually commit them to?
Beyond the Chart Notes
Here’s what practices routinely underestimate. A single ambient-scribe encounter doesn’t just produce the note that lands in the EHR. It typically generates a live audio recording of the conversation, an interim transcript, a machine-drafted note, and metadata about the clinician, patient, and visit. Under the HIPAA Security Rule, every one of those artifacts is electronic PHI you are responsible for safeguarding — including the copies sitting on the vendor’s servers.
That reality drives the questions your BAA and your vendor review need to answer:
Does the vendor encrypt PHI in transit and at rest? How long is data retained, and can you require deletion? Critically, does the vendor use patient data to train or fine-tune its AI models — and does your agreement explicitly prohibit it? Are sub-processors disclosed? A tool can absolutely be HIPAA-compliant, but only when the vendor signs a BAA, encrypts PHI, limits retention, and keeps your patients’ data out of its training pipeline. If a vendor won’t answer these plainly, that’s your answer.
Beyond HIPAA Compliance
This is the trap catching practices in 2026. Meeting HIPAA does not immunize you from state and federal wiretap laws, which can require patient consent to record a conversation. A high-profile class action against Sutter Health and MemorialCare alleges they used an ambient AI scribe to record patient-clinician conversations without informed consent — raising claims under California’s Invasion of Privacy Act, the Confidentiality of Medical Information Act, and the federal Wiretap Act. Reporting on the Sutter/MemorialCare case shows how a HIPAA-compliant tool can still create serious legal exposure if patients aren’t properly informed.
The practical fix is straightforward: build patient consent and clear notice into your workflow before you record anything. Tell patients an AI tool is being used, document their agreement, and know your state’s recording-consent rules.
Security Rule Requirements
Some practice owners assume this level of scrutiny is for big hospital systems. It isn’t. As we’ve written about how compliance now reaches businesses of every size, a two-provider clinic carries the same core HIPAA obligations as a health system — with far fewer resources to absorb a penalty. And these AI obligations sit on top of the broader Security Rule requirements we covered in what HIPAA compliance now requires of healthcare organizations. Getting the underlying environment right — access controls, encryption, and backup and data protection — is what makes safe AI adoption possible in the first place.
Working with an Eclipse AI Expert
AI compliance for medical practices comes down to a short checklist you can run before turning on any AI scribe or chatbot: Get a signed BAA that prohibits model training on your data. Confirm encryption, retention limits, and disclosed sub-processors. Build patient consent and notice into the workflow to satisfy wiretap laws, not just HIPAA. And make sure the environment underneath — access controls, encryption, backups — is actually sound. Do those four things and you get the productivity without the liability. Skip them and a tool meant to save time becomes the most expensive mistake in the practice.
Eclipse Networks helps medical practices across Georgia and Florida adopt AI safely — vetting vendors and BAAs, securing PHI across every system that touches it, and building the cybersecurity and data protection foundation HIPAA requires. If you’re evaluating an AI scribe or chatbot and want to be sure you’re covered, schedule a consultation before the tool goes live — not after.