The Scenario That Keeps Me Up at Night
Imagine you're a clinic administrator at a busy three-physician practice. You've just rolled out an AI scribe that listens to patient visits and drafts the note into your EHR. It's a game-changer for clinician burnout—notes are done in seconds, and your doctors are actually leaving on time. But then, a patient complains to HHS that you shared their mental health counseling notes with a billing vendor without authorization. Your first instinct is to shrug it off—you have a business associate agreement, after all. But as you dig into the details, you realize the AI scribe's vendor, the billing service, and even your own EHR are all touching the same unsecured ePHI. And the clock is ticking.
This is the hidden risk of AI in healthcare: the convenience of automation often blinds us to the compliance reality. We've written before about HIPAA traps in telehealth and AI scribes, but the real issue isn't the technology—it's how we apply the rules in practice. Let's walk through what actually happens when an AI scribe enters your workflow, step by step, and why the "minimum necessary" standard is the part we all ignore until it's too late.
Step One: Know What You're Dealing With
You might think your AI scribe is just a fancy dictation tool, but under HIPAA, it's a business associate. The definition is broad: anyone who creates, receives, maintains, or transmits protected health information on your behalf is a business associate (45 CFR 160.103). That includes the AI vendor, the cloud hosting service, and even the subcontractor that does the natural language processing. If any of them don't have a signed BAA, you're already in violation—even if no breach occurs.
And the stakes are higher than most realize. The annual HIPAA penalty cap was raised to $2,190,294 in 2026 (Federal Register, 91 FR 3665). That's the ceiling for a single calendar year, but even a single violation can cost you up to $73,011 if it's due to willful neglect and you correct it within 30 days. For a small practice, that's potentially devastating. But let's get to the part that's less talked about: the minimum necessary standard.
Step Two: The Minimum Necessary Trap
The HIPAA Privacy Rule requires that when you use or disclose PHI, you make reasonable efforts to limit it to the minimum necessary to accomplish the intended purpose (45 CFR 164.502(b)). This sounds simple, but with an AI scribe, it's a minefield. The AI records the entire visit, including the patient's offhand comments about their marriage or their job—none of which are relevant to the note. But the AI sends the full audio to the vendor for processing. Is that a violation? Arguably, yes, because you're transmitting more PHI than necessary to generate the clinical note.
Let's be concrete: In a typical 20-minute visit, the AI captures everything. The patient mentions a family history of cancer, a past suicide attempt, and a prescription for an antidepressant. The AI scribe's vendor now has all of that in audio form, even if the final note only contains the diagnosis and treatment plan. Under the minimum necessary standard, you should be transmitting only the information needed for the service—but the AI doesn't know that. It's a blunt instrument.
This is where your compliance checklist often fails. You check the box for "BAA signed," but you don't enforce minimum necessary. The Security Rule's technical safeguards (45 CFR 164.312) require access controls, but they don't automatically limit the data flow to a business associate. That's your job.
Step Three: The Breach Notification Clock
Now, suppose the worst happens: the AI vendor's server is hacked, and unsecured PHI is exposed. Under the Breach Notification Rule, you must notify each affected individual within 60 calendar days of discovery (45 CFR 164.404). But here's the kicker: the clock starts when you discover the breach, not when the vendor tells you. If the vendor waits two weeks to inform you, you're still on the hook for the 60-day deadline. And if you don't have a process in place to detect breaches quickly, you could miss the window entirely, triggering additional penalties.
We see this all the time: practices rely on the vendor's breach notification, but they don't have their own monitoring. The HIPAA Security Rule requires you to implement policies and procedures for detecting and reporting security incidents (45 CFR 164.308), but that's often a one-page document that's never tested. In our scenario, you'd need to act fast: identify the affected patients, assess the risk, and prepare notifications. But you're scrambling because you don't even know which PHI was involved.
This is why we recommend a proactive approach: don't wait for the breach to happen. Audit your AI scribe's data flows now. Ask the vendor: what exactly do you store, and for how long? Do you use the data to train your models? If so, that's a disclosure that likely exceeds minimum necessary.
Step Four: The Practical Fix
So what do we actually do? We treat AI scribes like any other high-risk vendor. We start with a risk assessment that maps every piece of PHI the vendor touches, and we require contractual clauses that enforce minimum necessary. We also configure the AI to redact sensitive information at the point of capture—if the patient discusses something unrelated to the visit, the AI should be programmed to exclude it from the transmitted audio. Some AI scribes allow you to toggle on "sensitive content detection," but we find most practices don't enable it because it adds a few seconds to the turnaround time. That's a false economy.
Another practical step: limit the AI's scope. Instead of using it for all patient visits, use it only for visits where the note is complex enough to justify the risk. For a simple cold, the doctor can type a two-line note. That reduces your exposure and keeps the AI out of your most sensitive conversations—like psychotherapy sessions.
And don't forget the physical safeguards. The Security Rule requires protections for your physical systems (45 CFR 164.310), but in the age of cloud-based AI, that's often overlooked. If your clinicians are using personal phones to record visits, that's a physical safeguard failure. We require encrypted devices and a policy that prohibits recording outside of approved rooms.
Quick tip: Set a calendar reminder to review your BAA with your AI scribe every six months. Vendors change their subprocessors without notice, and you need to know if your PHI is suddenly being processed in a new country.
What I'd Actually Do
If you're using an AI scribe, or thinking about it, here's my direct advice: don't sign up for the first vendor that offers a free trial. Instead, run a pilot with a small group of clinicians, but treat it as a HIPAA audit, not a productivity test. During the pilot, record every data flow, every API call, every log entry. Ask the vendor to provide a data retention schedule and a list of all subprocessors. If they can't, move on.
We also need to stop treating the HIPAA Security Rule as a checklist exercise. The administrative, physical, and technical safeguards (45 CFR 164.308, 164.310, 164.312) are meant to be a continuous process, not a one-time certification. In the real world, we see practices that pass a security assessment with flying colors, then ignore the AI scribe's access logs for months. That's how breaches happen.
Finally, consider whether an AI scribe is even necessary. If your practice is already stretched thin, adding a new technology that requires constant oversight might not be the right move. The HITECH Act gave us incentives to adopt EHRs, but it didn't mandate AI. Sometimes the safest choice is the simplest one.
In the end, the risk isn't the AI itself—it's our own complacency. The HIPAA penalty cap may be $2,190,294, but the real cost is the trust of your patients. We should all act like every visit is under a microscope, because with AI, it might be.
Sources
- ONC / HHS (HIPAA Basics) - https://www.healthit.gov/topic/privacy-security-and-hipaa/hipaa-basics
- eCFR 45 CFR Part 164 Subpart C (Security Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
- eCFR 45 CFR Part 164 Subpart D (Breach Notification) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D
- eCFR 45 CFR Part 164 Subpart E (Privacy Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E
- Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!