HIPAA compliant AI scribe

A HIPAA compliant AI scribe, line by line.

A HIPAA compliant AI scribe is not a badge. It is a signed BAA, minimum-necessary data capture, access controls, an audit trail, breach terms and clear rules about audio. Here is what each requirement means for a psychiatric practice, how Psynopsis handles it, and what to ask any vendor, including us.

Data handling
What happens to a visit
Per encounter
Audio Processed in real time, never stored
Transcript Encrypted at rest (AES-256), US hosting
Training Your data is never used to train models
BAA Included on paid plans
Access NPI-verified clinicians only
Coverage
HIPAABAA42 CFR Part 2
Facts as published on /compliance/ and /privacy-policy/.

The requirements

What “HIPAA compliant AI scribe” actually has to mean

HHS does not certify software as HIPAA compliant. When a vendor says it, they are asserting that the product meets the Privacy, Security and Breach Notification Rules and that they will sign a BAA. Six things have to be true for that claim to hold. This is a plain-language explanation for clinicians, not legal advice; your compliance officer or counsel has the final word for your practice.

A signed Business Associate Agreement

Any vendor that creates, receives, maintains or transmits protected health information on your behalf is a business associate, and HIPAA requires a written BAA before that happens. The BAA sets what the vendor may do with PHI, the safeguards it must keep, how quickly it must report a breach, and that its own subcontractors are bound the same way. Encryption does not substitute for it.

Minimum necessary

PHI use and disclosure is limited to what the task needs. For a scribe that means capturing the encounter, not the rest of your screen; keeping clinical data off the browser; and giving each person access to the notes they need, not the whole practice.

Access controls

The Security Rule expects unique user identification, authentication, role-based access and session controls so that only authorized people reach ePHI. For an AI scribe, who is allowed to open an account matters as much as how they log in.

Audit controls

Systems that hold ePHI must record activity so access can be examined after the fact. HIPAA documentation is retained for six years. If a vendor cannot tell you who accessed a note and when, it cannot support your own compliance program.

Breach obligations

Under the Breach Notification Rule a business associate must report a breach of unsecured PHI to you without unreasonable delay, and you in turn notify patients, and HHS, within the required windows. Your BAA should state the vendor’s reporting timeline. PHI that is properly encrypted is treated differently from unencrypted data if it is lost, which is why encryption at rest and in transit is standard.

Transmission and storage safeguards

PHI moving between your browser, the vendor and its subprocessors must be protected in transit, and stored data must be protected at rest. Ask where the data lives and which subprocessors touch it.

How Psynopsis handles each

Requirement by requirement, with the source

Every row below is taken from our published compliance and privacy policy pages. If a claim is not there, we do not make it here.

RequirementWhat Psynopsis doesDocumented
Business Associate AgreementBAAs are offered to covered entities and included with all paid plans. A copy is available for review before you subscribe: email compliance@psynopsis.ai and it is sent within one business day. Enterprise plans include a custom BAA.Compliance page
Minimum necessaryThe Chrome extension captures only the audio stream of the tab you start it on, never page content, text or browsing history. The web app keeps no clinical data in the browser. Clinical records live in one FHIR R4 data store.Privacy policy, sections 2 and 8
Access controlsOnly licensed clinicians with a valid NPI can open an account; NPIs are verified against the NPPES database. Access is role-based, and web sessions use httpOnly cookies.Compliance page, privacy policy section 3
Audit controlsAccess to PHI is logged and auditable, with a complete audit trail. Audit logs are retained for six years.Privacy policy, sections 6, 9 and 10
Breach obligationsA documented breach notification process per HIPAA requirements. Breach notification timelines for clinical data are defined in your BAA, which controls over the privacy policy for PHI.Privacy policy, section 6
Encryption and hostingAES-256 at rest, TLS 1.3 in transit (HTTPS for the API, WSS for audio streaming). All server-side data is hosted on HIPAA-compliant cloud infrastructure in the United States.Privacy policy, section 9
AudioAudio is processed in real time for transcription and immediately discarded. It is never stored, backed up or used for any purpose beyond generating the transcript. Post-session dictation involves no patient audio at all.Compliance page
Model trainingClinical data, audio and transcripts are never used to train AI models.Privacy policy, section 4
SubprocessorsEvery partner that handles PHI is under a BAA: Deepgram (real-time speech-to-text, no storage), Azure OpenAI (note generation, no model training), Aidbox by Health Samurai (FHIR clinical data store), Azure Blob Storage (files, no PHI) and Azure Communication Services (transactional email).Privacy policy, section 4
Retention, export and deletionYou own your documentation. Notes are retained for the life of the account or as state medical-records law requires, can be exported at any time in standard formats, and are permanently deleted on request with written confirmation.Privacy policy, section 10
Request a BAA copy

Sent within one business day, no sales call required.

Ask any vendor

Twelve questions for any HIPAA compliant AI note taker

Take this list into every demo. A good vendor answers each one in writing; a great one has already published the answers.

  1. 1

    Will you sign a BAA before I enter any PHI, and on which plans?

    No BAA, no PHI. A vendor that will only sign after a sales call is telling you where compliance sits on its list.

  2. 2

    Is session audio stored? For how long, and where?

    Ambient scribes differ most here. “Deleted after processing” and “retained 30 days for quality” are very different exposures.

  3. 3

    Is my data, my transcripts or my notes used to train models?

    Ask for the answer in writing, and check that it also covers the vendor’s subprocessors.

  4. 4

    Who are the subprocessors that touch PHI, and are they under BAAs?

    Speech-to-text and language-model providers are usually third parties. Each one needs its own BAA chain.

  5. 5

    Where is data hosted?

    US hosting is the default expectation for US practices; confirm it rather than assume it.

  6. 6

    How is data encrypted at rest and in transit?

    Look for specific standards, not the word “encrypted”.

  7. 7

    Who can create an account?

    Clinician verification (NPI or license) keeps a clinical tool from becoming a consumer one.

  8. 8

    Can I get an access log for a note?

    You will need it the first time a patient asks who saw their record.

  9. 9

    What is your breach notification timeline to me?

    It should be in the BAA, in days, not “promptly”.

  10. 10

    Can I export everything and have it deleted?

    Leaving should be as clean as arriving.

  11. 11

    Is there a workflow that does not record the patient?

    Some patients decline recording, and some state recording laws require all-party consent. You need a second mode, not a workaround.

  12. 12

    How are SUD records and psychotherapy notes handled?

    42 CFR Part 2 and HIPAA psychotherapy-note protections add rules that a general-medicine scribe may never have met.

Substance use records

42 CFR Part 2, and psychotherapy notes, are a second layer

HIPAA is the floor. Two more rules matter in psychiatry. 42 CFR Part 2 governs the confidentiality of substance use disorder treatment records from federally assisted programs: they carry their own consent requirements for disclosure and cannot simply flow with the rest of the chart. A 2024 final rule aligned Part 2 more closely with HIPAA, including a single patient consent for future treatment, payment and operations uses, but the records still need to be identifiable and separately controllable. Separately, HIPAA gives psychotherapy notes extra protection only when they are kept apart from the rest of the medical record.

A scribe built for primary care may never have met either rule. One built for psychiatry has to treat them as part of the note, not an exception to it.

What Psynopsis does for these records

  • Strict separation between psychotherapy notes and progress notes
  • Substance use record protections under 42 CFR Part 2
  • Consent-based disclosure controls
  • Audit trail for all access to protected records

As published on /compliance/ and in section 7 of the privacy policy. Whether your practice is a Part 2 program is a determination for you and your counsel.

The no-recording option

Post-session dictation: HIPAA compliance without a microphone in the room

Some patients will not be recorded. Some states require every party’s consent to record. Some visits are simply not the kind you want on tape. Post-session dictation is a second workflow, not a fallback: after the patient leaves, dictate a short summary and receive a complete, structured psychiatric draft. No session audio exists at any point.

  • No patient audio is involved at all
  • Same templates, MSE structure and medication checks as the ambient workflow
  • Dictation is processed in real time and never stored
  • Works between rooms on rounds or between telehealth visits
See post-session dictation
Post-session dictation
Follow-up, 2-minute summary
Input
Session audio None Not recorded
Clinician dictation Real time, never stored
Output
Draft note Diagnosis-organized, MSE populated
Review Clinician edits and signs
AI draft — clinician review required before signing.

HIPAA questions psychiatric clinicians ask

Is Psynopsis a HIPAA compliant AI scribe?
Yes. Psynopsis implements the administrative, physical and technical safeguards HIPAA requires, offers Business Associate Agreements to covered entities (included with all paid plans), encrypts PHI with AES-256 at rest and TLS 1.3 in transit, hosts data on HIPAA-compliant US infrastructure and logs all access to PHI. There is no government HIPAA certification for software; what you can verify is the BAA, the safeguards and the documentation, all of which are published on our compliance and privacy pages.
Do I need a BAA before I start?
If you are a covered entity, HIPAA requires a BAA before a vendor handles PHI on your behalf. A BAA is included with all paid Psynopsis plans, and you can request a copy for review before subscribing by emailing compliance@psynopsis.ai; it is sent within one business day so it can be signed before any PHI is entered.
Is patient audio recorded or stored?
No. Audio is processed in real time for transcription and immediately discarded. It is never stored on our servers, backed up, or used for any purpose beyond generating the transcript. If you use post-session dictation, no patient audio is involved at all.
Is my data used to train AI models?
No. Clinical data, audio, transcripts and generated notes are never used to train AI models, and our subprocessor for note generation (Azure OpenAI) operates under a BAA with no model training.
Which third parties handle PHI?
Deepgram for real-time speech-to-text (no storage), Azure OpenAI for note generation (no model training), Aidbox by Health Samurai as the FHIR R4 clinical data store, Azure Blob Storage for files that contain no PHI, and Azure Communication Services for transactional email. Each is bound by a HIPAA Business Associate Agreement. The full list is in section 4 of the privacy policy.
Can I use an AI scribe without recording the patient?
Yes. Post-session dictation lets you dictate a short summary after the patient leaves and receive a complete structured draft. Nothing from the session is recorded, which also sidesteps state recording-consent questions and patient discomfort with a live microphone.
Where is my data stored, and can I delete it?
All server-side data is stored on HIPAA-compliant cloud infrastructure in the United States. You retain full ownership of your documentation, can export it at any time in standard formats, and can have it permanently deleted on request with written confirmation.
No credit card required

Compliance you can read before you sign.

BAA on every paid plan, audio never stored, data never used for training. Start free on real visits or ask for the BAA first.

HIPAA compliant · BAA included · Audio never stored