Live Index·Vol Vol. 2026.07·
ISSN 2026-07

reference · 10 min read · Updated 2026-07-01

HIPAA and BAA Checklist for Behavioral Health AI Scribes

What HIPAA actually requires of an AI scribe

Any vendor that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity is a business associate and must execute a Business Associate Agreement (BAA). AI scribes handle session audio and generated notes; both are PHI. A BAA is not optional and cannot be waived by clicking through a terms-of-service page.

HITECH extends direct HIPAA enforcement to business associates, so the vendor — not just your practice — is on the hook for breach notification, minimum-necessary handling, and access controls.

The 10 questions to send every vendor

Send these in writing. The answers belong in the contract or DPA, not on a marketing page.

  1. Will you sign a BAA on the exact plan I'm buying?
  2. What subprocessors do you use, and are they all under BAA with you?
  3. Where is PHI stored, and is it encrypted at rest and in transit?
  4. What is the audio-retention window, and can I shorten it or opt into zero-retention?
  5. Do you use my client data to train models? Under what consent, and can I opt out contractually?
  6. What audit logs do I get access to, and how long are they retained?
  7. What is your breach-notification SLA to me as the covered entity?
  8. What security attestations do you hold — SOC 2 Type II, HITRUST CSF, ISO 27001?
  9. What is my data-export path on cancellation, and how quickly is my data deleted?
  10. For SUD records — what is your 42 CFR Part 2 posture, and does the BAA cover Part 2 explicitly?

How to read a subprocessor list

Most AI scribes rely on at least one foundation-model provider (OpenAI, Anthropic, Google) and often a separate ASR provider. Each is a subprocessor and inherits your PHI exposure.

  • Look for zero-retention or no-training clauses with each named subprocessor.
  • US-only data residency should be verifiable end-to-end, not just at the vendor's edge.
  • Any change to the subprocessor list should trigger written notification with the ability to object.

BAA and vendor red flags

Any single red flag is a reason to slow the pilot. Two or more should end the evaluation.

  • BAA offered only on enterprise tiers while consumer tiers are marketed to clinicians.
  • Vague or verbal answers on model training or audio retention.
  • 'HIPAA compliant' claim with no BAA, no SOC 2, and no subprocessor list.
  • Free tiers that ingest real client audio without a BAA in place.
  • Ambient scribes that don't cleanly separate PHI from telemetry, analytics, or product logs.

The SUD compliance overlay

If any of your clients are in SUD treatment, the standard HIPAA answer is not sufficient. 42 CFR Part 2 requires patient consent for most disclosures — including to other treatment providers — and imposes redisclosure prohibitions that HIPAA does not.

Ask directly: does the vendor's BAA name Part 2 records? Does the vendor's platform record the specific consent required? Twofold Health and Eleos Health document explicit Part 2 postures in our 2026 review.

Annual compliance review checklist

Vendor posture drifts. Recheck the following every 12 months, or immediately after any breach or subprocessor change.

  • Current SOC 2 Type II report on file (dated within the last 12 months).
  • Subprocessor list unchanged, or changes acknowledged in writing.
  • Audio-retention setting still matches your policy.
  • Model-training opt-out still active in contract.
  • For SUD: Part 2 posture unchanged and BAA language current.

Frequently asked questions

Do I need a BAA for an AI scribe?
Yes. Any AI scribe that receives session audio or generates notes handles PHI, which makes the vendor a HIPAA business associate. A signed BAA is required before you use the product with real clients.
Is a HIPAA-compliant AI scribe enough for SUD counseling?
Not always. Substance-use treatment records are additionally governed by 42 CFR Part 2, which restricts disclosure beyond HIPAA. Confirm the vendor's Part 2 posture — and that the BAA explicitly covers Part 2 records — in writing.
What is the difference between SOC 2 Type I and Type II?
SOC 2 Type I is a point-in-time snapshot of a vendor's controls. Type II tests that controls operated effectively over a period (usually 6–12 months). For a healthcare vendor, insist on Type II.
Should I care about HITRUST?
HITRUST CSF certification is a stronger security signal than SOC 2 alone in healthcare. It is not universal among behavioral-health AI scribes yet; SOC 2 Type II is the current baseline.
What retention window should I ask for?
Common defaults are 30–90 days for audio and indefinite for the generated note. For high-sensitivity SUD or trauma work, ask for zero-retention or same-day audio deletion; several vendors now offer this as a configurable option.

Sources and references

Continue reading