A psychiatric practice is ready to test an AI scribe. The vendor offers a business associate agreement. The demo turns a conversation into a polished note. The plan sounds simple: invite the clinicians, connect the electronic health record, and begin.

Then the unresolved questions appear. Does the tool retain encounter audio? Is the transcript stored separately from the draft note? Can vendor personnel review content for support? Are subprocessors involved? What happens when a patient declines recording? Who catches a reversed negation, a medication error, or a sentence attributed to the wrong speaker?

This fictional composite is not a report about a patient, practice, or product. It illustrates the central governance problem:

Before an AI documentation tool enters a psychiatric encounter, the practice should be able to map what the tool receives, creates, stores, shares, returns, and deletes—and who is responsible at every step.

Federal sources below were reviewed August 14, 2026. They are a U.S. federal baseline, not a state-law conclusion, vendor approval, or clinical standard.

Start with the data path, not the product label

“AI scribe” is a product description. It does not determine the vendor’s legal role or the workflow’s operational risk.

For a HIPAA-covered practice, a non-workforce vendor may be a business associate when it creates, receives, maintains, or transmits protected health information on the practice’s behalf. Subcontractors that handle that information for a business associate can fall within the same federal definition. The answer depends on the actual relationship and data flow, not the product label.

Map each artifact separately:

  • live audio or video

  • stored encounter audio

  • transcript

  • prompts, instructions, and contextual data

  • generated draft note

  • corrections and final signed note

  • metadata and user analytics

  • support copies and quality-review samples

  • audit and incident logs

  • cached data and backups

  • derived data used for analytics, model evaluation, or product improvement

For each artifact, identify who creates it, where it goes, who can access it, how long it remains, and whether it can be returned or deleted. “The vendor does not store the note” is not an answer about audio, transcripts, logs, backups, or derived data.

A business associate agreement answers only part of the launch question

When a vendor is a business associate, HIPAA requires a written contract or other arrangement that meets the applicable requirements, including permitted and required uses and disclosures, safeguards, reporting, subcontractors, and return or destruction of protected health information at termination where feasible.

That is a necessary baseline when the rule applies. It is not a federal certification, a technical audit, an accuracy assessment, or approval to deploy.

The practice still needs clear answers to:

  • May encounter content be used for model training, product improvement, benchmarking, or human review?

  • Which subprocessors receive which data, and can the practice obtain a current list and notice of material changes?

  • What are the retention periods for audio, transcripts, drafts, logs, backups, and derived data?

  • What does “deletion” exclude, and how is deletion verified?

  • Which personnel can obtain privileged access, and is that access logged?

  • Can the practice export its data and retrieve it if service ends?

  • What must the vendor report as a security incident or breach, to whom, and how quickly?

  • What happens during an outage or failed integration?

The current federal breach rule generally requires a business associate to notify the covered entity of a breach of unsecured protected health information without unreasonable delay and no later than 60 calendar days after discovery, subject to the rule’s qualifications. A shorter operational-notice period is a negotiated control, not the federal outer limit.

Put the tool inside the practice’s risk analysis

The current HIPAA Security Rule requires an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information, plus reasonable risk management, activity review, access and audit controls, authentication, incident procedures, and related documentation.

HHS identifies technologies that electronically record or transcribe a telehealth session as creating Security Rule obligations when electronic protected health information is involved. Current guidance directs covered entities to consider risks to recordings and transcripts, including unauthorized access, encryption, authentication, and storage.

Match the analysis to the real system: device and microphone, vendor environment, electronic-health-record integrations, support access, subprocessors, data movement, backups, user provisioning, audit evidence, and the fallback when the tool is unavailable or the draft is unusable. A “HIPAA compliant,” encrypted, locally processed, SOC 2, or HITRUST claim may be relevant evidence. It does not replace that analysis.

The 2024 Security Rule proposal remains proposed; HHS states the current rule remains in effect.

HIPAA is not a nationwide recording-consent answer

HIPAA governs uses, disclosures, safeguards, and rights within its scope. It does not, by itself, answer whether or how an encounter may be recorded. State recording, health-information, board, minor-consent, and related rules can change the analysis. Relevant locations may include the clinician’s state, the patient’s state, and another participant’s state.

Before launch, obtain a jurisdiction-specific answer to:

  1. Is notice, consent, or all-party consent required for this recording or transcription workflow?

  2. Must the notice use particular language or be documented in a particular way?

  3. What should happen when a patient declines?

  4. How do the rules apply to minors, guardians, interpreters, family members, or other participants?

  5. Does the practice’s notice of privacy practices, telehealth consent, or other patient-facing material need revision?

A plain-language explanation and a no-recording alternative are operational controls, not a substitute for state-specific legal review.

Decide what becomes part of the record

An AI documentation workflow can create more than one record-like object. Decide, with qualified review, how the practice will treat the transcript, draft, corrections, final note, and any retained audio or supporting data.

HIPAA access and amendment rights apply to protected health information in a designated record set, subject to the rules’ limits. They do not automatically place every temporary AI artifact in that set. Classify each artifact by how it is maintained and used.

Avoid a common retention mistake: the six-year Security Rule retention provision applies to required security documentation—policies, procedures, and required documented actions or assessments. It is not a federal instruction to keep encounter audio, transcripts, prompts, drafts, or model logs for six years.

Define a justified period for each data class—final clinical record, audio, transcripts, drafts, prompts, logs, backups, and derived data—document the authority and purpose, and verify that the system can carry it out. State law, professional rules, contracts, litigation holds, and payer requirements may add obligations.

Treat human review as a workflow control—not an AI-specific HIPAA quotation

Treat the output as a draft until the practice’s authorized clinician-review process is complete. The federal sources reviewed here do not contain an AI-scribe-specific sentence requiring a clinician to verify every generated note. Human review is a record-integrity and clinical-workflow control, not a HIPAA quotation or a nationwide standard of care.

In psychiatric documentation, review for high-consequence errors that can hide inside fluent prose:

  • a negation reversed or omitted

  • a statement attributed to the patient when it came from someone else

  • the wrong medication, dose, timing, or response

  • uncertainty rewritten as certainty

  • historical information presented as current

  • a safety statement omitted, overstated, or assigned to the wrong speaker

  • sensitive relationship or trauma detail copied into the wrong section

  • text inserted into the wrong patient record

  • a plausible sentence that was never said

These are test scenarios, not prevalence claims. This article does not claim a product-specific error rate or that AI documentation improves accuracy, care, clinician burden, coding, or payment.

Require review before a draft becomes the final note, correction of material errors, and a fallback when the output is unusable. Define staff-edit rules, correction attribution, and late changes after signing.

Add the behavioral-health exceptions before activation

Psychiatric records are not one uniform category. Some encounters may involve separately maintained psychotherapy notes, Part 2 substance use disorder records, minor records, or other specially protected information.

The 2024 Part 2 final rule became effective April 16, 2024, and required compliance by February 16, 2026. Application depends on the program, records, and facts. The rule also created separately maintained SUD counseling notes. A general AI-scribe checklist is not a Part 2 or state-law analysis.

Before activation, identify which encounter types the tool may not process until additional controls are approved:

If the team cannot determine the governing rule, permitted data use, retention path, and reviewer for a sensitive encounter type, that encounter type remains outside the pilot.

Make “not ready” a valid launch decision

An effective pre-launch review produces one of three outcomes for every unresolved control:

PASS

The required evidence exists and the control is approved.

HOLD

The answer is missing, contradictory, or unacceptable.

Not applicable

The control does not apply, with the reason documented.

Keep the launch on hold when material questions remain about roles, secondary use, recording rules, retention and deletion, access and incidents, record classification and human review, specially protected records, or fallback. That is not resistance to technology. It is the difference between testing a tool and transferring an uncontrolled data flow into psychiatric care.

Psychiatric-Record-AI-Scribe-Pre-Launch-Gate.pdf

Psychiatric-Record-AI-Scribe-Pre-Launch-Gate.pdf

377.50 KBPDF File

The practical rule

Four questions are enough:

What data exists? Who can use it? How does it leave? Who verifies what enters the record?

If any answer is unknown, name an owner and keep that part of the rollout on hold. A signed BAA can be necessary. A smooth demo can be encouraging. Neither replaces a mapped data flow, verified controls, a patient workflow, and a documented decision about the clinical record.

Sources

This issue was selected from a public/provider discussion signal about AI-assisted charting. That signal is used only to generate the research question. It does not establish prevalence, safety, effectiveness, accuracy, patient preference, burden reduction, a legal duty, a clinical standard, or vendor compliance.

General educational information for U.S. psychiatric practice governance. Not legal, privacy, security, billing, compliance, or clinical advice; does not approve a vendor or workflow. Verify the actual workflow with current authoritative sources and qualified reviewers.