Key takeaways: An AI scribe handles protected health information (PHI), which makes the vendor a HIPAA business associate — so a signed Business Associate Agreement (BAA) is required before your first recording. Beyond the BAA, confirm the scribe encrypts PHI in transit and at rest, controls and logs access, does not train its AI models on your patient data, and has BAAs with every subcontractor it relies on. HIPAA is the floor; behavioral health often adds 42 CFR Part 2 and stricter state rules on top.
An AI scribe is HIPAA compliant only when specific safeguards are in place — it is never compliant by default just because a vendor says so. Because the scribe records, transcribes, and stores PHI on your behalf, the U.S. Department of Health and Human Services treats the vendor as a business associate, and a covered entity may not share PHI with a business associate without a compliant Business Associate Agreement (BAA) in place (HHS.gov).
That single requirement trips up more practices than any other. A vendor’s standard NDA or SaaS terms of service does not satisfy HIPAA, because it omits the provisions HIPAA mandates — breach notification, subcontractor flow-down, individual-rights support, and the right to audit. The Office for Civil Rights has settled cases where the only violation was a missing BAA, so “we never had a breach” is not a defense.
Use the checklist below to vet any AI scribe — including ours — before you record a single session.
The HIPAA AI scribe checklist
- A signed BAA, before the first recording. The vendor must offer and sign a BAA, not an NDA. If a sales rep is vague about this, stop. (TasiPsych includes a BAA at no extra cost — see pricing.)
- No model training on your PHI. The agreement should explicitly prohibit using your patient data to train, fine-tune, or improve the vendor’s AI models. “We may use data to improve our services” is a red flag.
- Encryption in transit and at rest. PHI should be encrypted end-to-end and stored encrypted. Ask which standard (e.g., TLS 1.2+ and AES-256).
- Access controls and audit logs. Role-based access, unique user IDs, and logging of who viewed or exported a note are HIPAA Security Rule expectations.
- Defined breach-notification terms. A business associate must report breaches of unsecured PHI without unreasonable delay and no later than 60 calendar days from discovery (HHS Breach Notification Rule). Many risk officers negotiate for notice within 24–72 hours — confirm the timeline in writing.
- Subcontractor BAAs. If the scribe sends audio to a third-party transcription or AI service (often AWS, Google Cloud, or Microsoft Azure), the vendor must have an activated BAA with each one. Ask the vendor to confirm this.
- Data retention and deletion you control. Know how long audio and transcripts are kept and whether you can delete them. TasiPsych permanently deletes session audio after transcription and redacts PHI before any AI processing.
- A current SOC 2 Type II report (at minimum). Independent assurance that the controls above are actually operating, not just promised.
Why “HIPAA compliant” claims need a second look
There is no government “HIPAA certified” seal. Any vendor can put “HIPAA compliant” on a marketing page. Compliance is something a covered entity verifies through the BAA, the security documentation, and the vendor’s actual data practices — not a badge you take at face value. Treat the checklist above as the evidence you collect before trusting a tool with PHI.
Try it yourself: TasiPsych ships with a BAA included, PHI redaction, and audio deletion by default. Start a free 10-day trial — no credit card required.
HIPAA is the floor — behavioral health needs more
For psychiatry, therapy, and counseling, HIPAA is the baseline, not the finish line:
- Psychotherapy notes receive heightened protection under HIPAA and are typically kept separate from the rest of the record.
- 42 CFR Part 2 governs the confidentiality of substance use disorder (SUD) treatment records. A 2024 Final Rule (compliance date February 16, 2026) largely aligned Part 2 with HIPAA — allowing a single patient consent for treatment, payment, and health-care-operations disclosures — while retaining heightened protections, such as limits on using SUD records against a patient in legal proceedings without consent or a court order.
- State law can be more protective than HIPAA — for mental health records specifically — and where it is, the stricter rule applies.
So once you have confirmed a scribe clears the HIPAA checklist, the next question is whether it is actually built for behavioral health: does it document a Mental Status Exam, capture risk assessments, and produce formats like DAP notes? Compliance and clinical fit are two separate evaluations — do both.
How TasiPsych approaches compliance
TasiPsych was built for behavioral health from the ground up, and compliance is part of the product rather than an add-on:
| Safeguard | TasiPsych |
|---|---|
| BAA | Included, no extra cost |
| Model training on your PHI | Never |
| PHI handling | Redacted before AI processing |
| Session audio | Permanently deleted after transcription |
| Built for | Behavioral health (MSE, risk, DAP/BIRP, coding) |
You can see how this fits the broader picture in our guide to an AI scribe for behavioral health, and review the full capability list on Features.
This article is documentation and compliance guidance for behavioral health practices, not legal advice. Confirm your obligations with your own compliance counsel.
Ready to document with compliance built in? Start your free TasiPsych trial — no credit card, BAA included.
Frequently asked questions
Is an AI scribe HIPAA compliant?
An AI scribe can be HIPAA compliant, but it is not automatically so. Because the scribe creates, receives, and stores protected health information (PHI) on your behalf, the vendor is a HIPAA business associate and must sign a Business Associate Agreement (BAA) before processing any patient data. A scribe is only compliant if a BAA is in place, PHI is encrypted in transit and at rest, access is controlled and logged, and any subcontractors (cloud or AI providers) are themselves covered by BAAs.
Do I need a BAA for my AI scribe?
Yes. Under the HIPAA Privacy Rule, a covered entity may not allow a business associate to create, receive, maintain, or transmit PHI without a compliant BAA. A standard NDA or SaaS terms-of-service does not satisfy this requirement, because it lacks HIPAA-mandated provisions such as breach-notification obligations and subcontractor flow-down. Using an AI scribe without a signed BAA is itself a HIPAA violation, even if no breach occurs.
Can an AI scribe use my patient data to train its models?
Only if you allow it — and you generally should not. A HIPAA-conscious vendor will contractually prohibit using your PHI to train, fine-tune, or improve its AI models, and will state this in the BAA. Look for explicit language on data use, data retention, and audio deletion. TasiPsych redacts PHI before AI processing and permanently deletes session audio after transcription.
Is a HIPAA-compliant AI scribe enough for behavioral health notes?
HIPAA compliance is the floor, not the ceiling. Behavioral health adds sensitivity around psychotherapy notes and, in many cases, 42 CFR Part 2 for substance use disorder records, plus state laws that can be stricter than HIPAA. Choose a scribe that is built for behavioral health workflows and treat HIPAA as the baseline you confirm first.