HIPAA compliant AI scribe
A HIPAA compliant AI scribe, line by line.
A HIPAA compliant AI scribe is not a badge. It is a signed BAA, minimum-necessary data capture, access controls, an audit trail, breach terms and clear rules about audio. Here is what each requirement means for a psychiatric practice, how Psynopsis handles it, and what to ask any vendor, including us.
The requirements
What “HIPAA compliant AI scribe” actually has to mean
HHS does not certify software as HIPAA compliant. When a vendor says it, they are asserting that the product meets the Privacy, Security and Breach Notification Rules and that they will sign a BAA. Six things have to be true for that claim to hold. This is a plain-language explanation for clinicians, not legal advice; your compliance officer or counsel has the final word for your practice.
A signed Business Associate Agreement
Any vendor that creates, receives, maintains or transmits protected health information on your behalf is a business associate, and HIPAA requires a written BAA before that happens. The BAA sets what the vendor may do with PHI, the safeguards it must keep, how quickly it must report a breach, and that its own subcontractors are bound the same way. Encryption does not substitute for it.
Minimum necessary
PHI use and disclosure is limited to what the task needs. For a scribe that means capturing the encounter, not the rest of your screen; keeping clinical data off the browser; and giving each person access to the notes they need, not the whole practice.
Access controls
The Security Rule expects unique user identification, authentication, role-based access and session controls so that only authorized people reach ePHI. For an AI scribe, who is allowed to open an account matters as much as how they log in.
Audit controls
Systems that hold ePHI must record activity so access can be examined after the fact. HIPAA documentation is retained for six years. If a vendor cannot tell you who accessed a note and when, it cannot support your own compliance program.
Breach obligations
Under the Breach Notification Rule a business associate must report a breach of unsecured PHI to you without unreasonable delay, and you in turn notify patients, and HHS, within the required windows. Your BAA should state the vendor’s reporting timeline. PHI that is properly encrypted is treated differently from unencrypted data if it is lost, which is why encryption at rest and in transit is standard.
Transmission and storage safeguards
PHI moving between your browser, the vendor and its subprocessors must be protected in transit, and stored data must be protected at rest. Ask where the data lives and which subprocessors touch it.
How Psynopsis handles each
Requirement by requirement, with the source
Every row below is taken from our published compliance and privacy policy pages. If a claim is not there, we do not make it here.
| Requirement | What Psynopsis does | Documented |
|---|---|---|
| Business Associate Agreement | BAAs are offered to covered entities and included with all paid plans. A copy is available for review before you subscribe: email compliance@psynopsis.ai and it is sent within one business day. Enterprise plans include a custom BAA. | Compliance page |
| Minimum necessary | The Chrome extension captures only the audio stream of the tab you start it on, never page content, text or browsing history. The web app keeps no clinical data in the browser. Clinical records live in one FHIR R4 data store. | Privacy policy, sections 2 and 8 |
| Access controls | Only licensed clinicians with a valid NPI can open an account; NPIs are verified against the NPPES database. Access is role-based, and web sessions use httpOnly cookies. | Compliance page, privacy policy section 3 |
| Audit controls | Access to PHI is logged and auditable, with a complete audit trail. Audit logs are retained for six years. | Privacy policy, sections 6, 9 and 10 |
| Breach obligations | A documented breach notification process per HIPAA requirements. Breach notification timelines for clinical data are defined in your BAA, which controls over the privacy policy for PHI. | Privacy policy, section 6 |
| Encryption and hosting | AES-256 at rest, TLS 1.3 in transit (HTTPS for the API, WSS for audio streaming). All server-side data is hosted on HIPAA-compliant cloud infrastructure in the United States. | Privacy policy, section 9 |
| Audio | Audio is processed in real time for transcription and immediately discarded. It is never stored, backed up or used for any purpose beyond generating the transcript. Post-session dictation involves no patient audio at all. | Compliance page |
| Model training | Clinical data, audio and transcripts are never used to train AI models. | Privacy policy, section 4 |
| Subprocessors | Every partner that handles PHI is under a BAA: Deepgram (real-time speech-to-text, no storage), Azure OpenAI (note generation, no model training), Aidbox by Health Samurai (FHIR clinical data store), Azure Blob Storage (files, no PHI) and Azure Communication Services (transactional email). | Privacy policy, section 4 |
| Retention, export and deletion | You own your documentation. Notes are retained for the life of the account or as state medical-records law requires, can be exported at any time in standard formats, and are permanently deleted on request with written confirmation. | Privacy policy, section 10 |
Sent within one business day, no sales call required.
Ask any vendor
Twelve questions for any HIPAA compliant AI note taker
Take this list into every demo. A good vendor answers each one in writing; a great one has already published the answers.
- 1
Will you sign a BAA before I enter any PHI, and on which plans?
No BAA, no PHI. A vendor that will only sign after a sales call is telling you where compliance sits on its list.
- 2
Is session audio stored? For how long, and where?
Ambient scribes differ most here. “Deleted after processing” and “retained 30 days for quality” are very different exposures.
- 3
Is my data, my transcripts or my notes used to train models?
Ask for the answer in writing, and check that it also covers the vendor’s subprocessors.
- 4
Who are the subprocessors that touch PHI, and are they under BAAs?
Speech-to-text and language-model providers are usually third parties. Each one needs its own BAA chain.
- 5
Where is data hosted?
US hosting is the default expectation for US practices; confirm it rather than assume it.
- 6
How is data encrypted at rest and in transit?
Look for specific standards, not the word “encrypted”.
- 7
Who can create an account?
Clinician verification (NPI or license) keeps a clinical tool from becoming a consumer one.
- 8
Can I get an access log for a note?
You will need it the first time a patient asks who saw their record.
- 9
What is your breach notification timeline to me?
It should be in the BAA, in days, not “promptly”.
- 10
Can I export everything and have it deleted?
Leaving should be as clean as arriving.
- 11
Is there a workflow that does not record the patient?
Some patients decline recording, and some state recording laws require all-party consent. You need a second mode, not a workaround.
- 12
How are SUD records and psychotherapy notes handled?
42 CFR Part 2 and HIPAA psychotherapy-note protections add rules that a general-medicine scribe may never have met.
Substance use records
42 CFR Part 2, and psychotherapy notes, are a second layer
HIPAA is the floor. Two more rules matter in psychiatry. 42 CFR Part 2 governs the confidentiality of substance use disorder treatment records from federally assisted programs: they carry their own consent requirements for disclosure and cannot simply flow with the rest of the chart. A 2024 final rule aligned Part 2 more closely with HIPAA, including a single patient consent for future treatment, payment and operations uses, but the records still need to be identifiable and separately controllable. Separately, HIPAA gives psychotherapy notes extra protection only when they are kept apart from the rest of the medical record.
A scribe built for primary care may never have met either rule. One built for psychiatry has to treat them as part of the note, not an exception to it.
What Psynopsis does for these records
- Strict separation between psychotherapy notes and progress notes
- Substance use record protections under 42 CFR Part 2
- Consent-based disclosure controls
- Audit trail for all access to protected records
As published on /compliance/ and in section 7 of the privacy policy. Whether your practice is a Part 2 program is a determination for you and your counsel.
The no-recording option
Post-session dictation: HIPAA compliance without a microphone in the room
Some patients will not be recorded. Some states require every party’s consent to record. Some visits are simply not the kind you want on tape. Post-session dictation is a second workflow, not a fallback: after the patient leaves, dictate a short summary and receive a complete, structured psychiatric draft. No session audio exists at any point.
- No patient audio is involved at all
- Same templates, MSE structure and medication checks as the ambient workflow
- Dictation is processed in real time and never stored
- Works between rooms on rounds or between telehealth visits
HIPAA questions psychiatric clinicians ask
Is Psynopsis a HIPAA compliant AI scribe?
Do I need a BAA before I start?
Is patient audio recorded or stored?
Is my data used to train AI models?
Which third parties handle PHI?
Can I use an AI scribe without recording the patient?
Where is my data stored, and can I delete it?
Go deeper
Compliance and security
HIPAA, 42 CFR Part 2, BAA, encryption, NPI verification and the data-handling summary your compliance officer will ask for.
Read more FeaturePost-session dictation
Dictate a two-minute summary after the visit and get a complete psychiatric note. No recording, no patient audio.
Read more FeaturesSecurity in the product
How data handling shows up in the product itself: extension scope, access, audit trail.
Read more PricingPricing
Basic is free forever; Professional is $75 per clinician per month with a BAA included; Enterprise for practices.
Read moreCompliance you can read before you sign.
BAA on every paid plan, audio never stored, data never used for training. Start free on real visits or ask for the BAA first.
HIPAA compliant · BAA included · Audio never stored