A psychiatric practice is ready to test an AI scribe. The vendor offers a business associate agreement. The demo turns a conversation into a polished note. The plan sounds simple: invite the clinicians, connect the electronic health record, and begin.
Then the unresolved questions appear. Does the tool retain encounter audio? Is the transcript stored separately from the draft note? Can vendor personnel review content for support? Are subprocessors involved? What happens when a patient declines recording? Who catches a reversed negation, a medication error, or a sentence attributed to the wrong speaker?
This fictional composite is not a report about a patient, practice, or product. It illustrates the central governance problem:
Before an AI documentation tool enters a psychiatric encounter, the practice should be able to map what the tool receives, creates, stores, shares, returns, and deletes—and who is responsible at every step.
Federal sources below were reviewed August 14, 2026. They are a U.S. federal baseline, not a state-law conclusion, vendor approval, or clinical standard.
Start with the data path, not the product label
“AI scribe” is a product description. It does not determine the vendor’s legal role or the workflow’s operational risk.
For a HIPAA-covered practice, a non-workforce vendor may be a business associate when it creates, receives, maintains, or transmits protected health information on the practice’s behalf. Subcontractors that handle that information for a business associate can fall within the same federal definition. The answer depends on the actual relationship and data flow, not the product label.
Map each artifact separately:
live audio or video
stored encounter audio
transcript
prompts, instructions, and contextual data
generated draft note
corrections and final signed note
metadata and user analytics
support copies and quality-review samples
audit and incident logs
cached data and backups
derived data used for analytics, model evaluation, or product improvement
For each artifact, identify who creates it, where it goes, who can access it, how long it remains, and whether it can be returned or deleted. “The vendor does not store the note” is not an answer about audio, transcripts, logs, backups, or derived data.
A business associate agreement answers only part of the launch question
When a vendor is a business associate, HIPAA requires a written contract or other arrangement that meets the applicable requirements, including permitted and required uses and disclosures, safeguards, reporting, subcontractors, and return or destruction of protected health information at termination where feasible.
That is a necessary baseline when the rule applies. It is not a federal certification, a technical audit, an accuracy assessment, or approval to deploy.
The practice still needs clear answers to:
May encounter content be used for model training, product improvement, benchmarking, or human review?
Which subprocessors receive which data, and can the practice obtain a current list and notice of material changes?
What are the retention periods for audio, transcripts, drafts, logs, backups, and derived data?
What does “deletion” exclude, and how is deletion verified?
Which personnel can obtain privileged access, and is that access logged?
Can the practice export its data and retrieve it if service ends?
What must the vendor report as a security incident or breach, to whom, and how quickly?
What happens during an outage or failed integration?
The current federal breach rule generally requires a business associate to notify the covered entity of a breach of unsecured protected health information without unreasonable delay and no later than 60 calendar days after discovery, subject to the rule’s qualifications. A shorter operational-notice period is a negotiated control, not the federal outer limit.
Put the tool inside the practice’s risk analysis
The current HIPAA Security Rule requires an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information, plus reasonable risk management, activity review, access and audit controls, authentication, incident procedures, and related documentation.
HHS identifies technologies that electronically record or transcribe a telehealth session as creating Security Rule obligations when electronic protected health information is involved. Current guidance directs covered entities to consider risks to recordings and transcripts, including unauthorized access, encryption, authentication, and storage.
Match the analysis to the real system: device and microphone, vendor environment, electronic-health-record integrations, support access, subprocessors, data movement, backups, user provisioning, audit evidence, and the fallback when the tool is unavailable or the draft is unusable. A “HIPAA compliant,” encrypted, locally processed, SOC 2, or HITRUST claim may be relevant evidence. It does not replace that analysis.
The 2024 Security Rule proposal remains proposed; HHS states the current rule remains in effect.
HIPAA is not a nationwide recording-consent answer
HIPAA governs uses, disclosures, safeguards, and rights within its scope. It does not, by itself, answer whether or how an encounter may be recorded. State recording, health-information, board, minor-consent, and related rules can change the analysis. Relevant locations may include the clinician’s state, the patient’s state, and another participant’s state.
Before launch, obtain a jurisdiction-specific answer to:
Is notice, consent, or all-party consent required for this recording or transcription workflow?
Must the notice use particular language or be documented in a particular way?
What should happen when a patient declines?
How do the rules apply to minors, guardians, interpreters, family members, or other participants?
Does the practice’s notice of privacy practices, telehealth consent, or other patient-facing material need revision?
A plain-language explanation and a no-recording alternative are operational controls, not a substitute for state-specific legal review.
Decide what becomes part of the record
An AI documentation workflow can create more than one record-like object. Decide, with qualified review, how the practice will treat the transcript, draft, corrections, final note, and any retained audio or supporting data.
HIPAA access and amendment rights apply to protected health information in a designated record set, subject to the rules’ limits. They do not automatically place every temporary AI artifact in that set. Classify each artifact by how it is maintained and used.
Avoid a common retention mistake: the six-year Security Rule retention provision applies to required security documentation—policies, procedures, and required documented actions or assessments. It is not a federal instruction to keep encounter audio, transcripts, prompts, drafts, or model logs for six years.
Define a justified period for each data class—final clinical record, audio, transcripts, drafts, prompts, logs, backups, and derived data—document the authority and purpose, and verify that the system can carry it out. State law, professional rules, contracts, litigation holds, and payer requirements may add obligations.
Treat human review as a workflow control—not an AI-specific HIPAA quotation
Treat the output as a draft until the practice’s authorized clinician-review process is complete. The federal sources reviewed here do not contain an AI-scribe-specific sentence requiring a clinician to verify every generated note. Human review is a record-integrity and clinical-workflow control, not a HIPAA quotation or a nationwide standard of care.
In psychiatric documentation, review for high-consequence errors that can hide inside fluent prose:
a negation reversed or omitted
a statement attributed to the patient when it came from someone else
the wrong medication, dose, timing, or response
uncertainty rewritten as certainty
historical information presented as current
a safety statement omitted, overstated, or assigned to the wrong speaker
sensitive relationship or trauma detail copied into the wrong section
text inserted into the wrong patient record
a plausible sentence that was never said
These are test scenarios, not prevalence claims. This article does not claim a product-specific error rate or that AI documentation improves accuracy, care, clinician burden, coding, or payment.
Require review before a draft becomes the final note, correction of material errors, and a fallback when the output is unusable. Define staff-edit rules, correction attribution, and late changes after signing.
Add the behavioral-health exceptions before activation
Psychiatric records are not one uniform category. Some encounters may involve separately maintained psychotherapy notes, Part 2 substance use disorder records, minor records, or other specially protected information.
The 2024 Part 2 final rule became effective April 16, 2024, and required compliance by February 16, 2026. Application depends on the program, records, and facts. The rule also created separately maintained SUD counseling notes. A general AI-scribe checklist is not a Part 2 or state-law analysis.
Before activation, identify which encounter types the tool may not process until additional controls are approved:
If the team cannot determine the governing rule, permitted data use, retention path, and reviewer for a sensitive encounter type, that encounter type remains outside the pilot.
Make “not ready” a valid launch decision
An effective pre-launch review produces one of three outcomes for every unresolved control:
PASS
The required evidence exists and the control is approved.
HOLD
The answer is missing, contradictory, or unacceptable.
Not applicable
The control does not apply, with the reason documented.
Keep the launch on hold when material questions remain about roles, secondary use, recording rules, retention and deletion, access and incidents, record classification and human review, specially protected records, or fallback. That is not resistance to technology. It is the difference between testing a tool and transferring an uncontrolled data flow into psychiatric care.
The practical rule
Four questions are enough:
What data exists? Who can use it? How does it leave? Who verifies what enters the record?
If any answer is unknown, name an owner and keep that part of the rollout on hold. A signed BAA can be necessary. A smooth demo can be encouraging. Neither replaces a mapped data flow, verified controls, a patient workflow, and a documented decision about the clinical record.
Sources
Electronic Code of Federal Regulations, 45 C.F.R. § 160.103 — Definitions, including business associate and subcontractor, reviewed July 27, 2026.
Electronic Code of Federal Regulations, 45 C.F.R. § 164.502 — General rules for uses and disclosures of protected health information, reviewed July 27, 2026.
Electronic Code of Federal Regulations, 45 C.F.R. § 164.504(e) — Business-associate contract requirements, reviewed July 27, 2026.
Electronic Code of Federal Regulations, 45 C.F.R. § 164.308 — Administrative safeguards, reviewed July 27, 2026.
Electronic Code of Federal Regulations, 45 C.F.R. § 164.312 — Technical safeguards, reviewed July 27, 2026.
Electronic Code of Federal Regulations, 45 C.F.R. § 164.316 — Security Rule policies, procedures, and documentation, reviewed July 27, 2026.
Electronic Code of Federal Regulations, 45 C.F.R. § 164.410 — Notification by a business associate, reviewed July 27, 2026.
Electronic Code of Federal Regulations, 45 C.F.R. § 164.524 — Individual access to protected health information, reviewed July 27, 2026.
Electronic Code of Federal Regulations, 45 C.F.R. § 164.526 — Amendment of protected health information, reviewed July 27, 2026.
HHS Office for Civil Rights, Guidance on HIPAA and audio-only telehealth, including electronic recording and transcription technologies, reviewed August 14, 2026. Page last reviewed June 23, 2026.
HHS Office for Civil Rights, Guidance on HIPAA and cloud computing, reviewed August 14, 2026. Page last reviewed December 23, 2022.
HHS Office for Civil Rights, HIPAA Security Rule notice of proposed rulemaking, reviewed August 14, 2026. Status: proposed; HHS states the current Security Rule remains in effect.
HHS Office for Civil Rights and SAMHSA, Fact Sheet: 42 C.F.R. Part 2 Final Rule, updated January 30, 2026 and reviewed August 14, 2026. Status: final; effective April 16, 2024; compliance required February 16, 2026.
This issue was selected from a public/provider discussion signal about AI-assisted charting. That signal is used only to generate the research question. It does not establish prevalence, safety, effectiveness, accuracy, patient preference, burden reduction, a legal duty, a clinical standard, or vendor compliance.
General educational information for U.S. psychiatric practice governance. Not legal, privacy, security, billing, compliance, or clinical advice; does not approve a vendor or workflow. Verify the actual workflow with current authoritative sources and qualified reviewers.
