AI Scribes Are Here — Is Your Organization Ready?

Artificial intelligence (AI) is now starting to write clinical notes.

This real-time documentation is a significant development because it reduces the overall time physicians spend drafting clinical notes and tackling their administrative workload outside normal working hours,, which in turn helps mitigate burnout. For these reasons, health systems, physician practices and other health care institutions may consider implementing AI scribes and, therefore, should understand the legal implications and risks.

What Are AI Scribes?

AI scribes listen to and transcribe patient-clinician conversations, generating clinical documentation in real time or shortly after an encounter. The AI scribe is an ambient listener, processing conversational language without the patient or clinician needing to tailor their interaction to the AI tool. Beyond the benefits listed above, 56% of patients reported that AI scribes improved patient-clinician interactions by allowing clinicians to focus more on patients and less on documentation.

Although questions remain about the long-term impact of AI scribes, their growing adoption among clinicians is creating new legal and compliance challenges that organizations cannot afford to ignore.

Legal and Compliance Risks

HIPAA and Patient Privacy

AI scribes raise important Health Insurance Portability and Accountability Act (HIPAA) compliance and patient privacy concerns because the vendors collect, process, and often store protected health information (PHI). Health care organizations and vendors may improperly use patient data to train AI models, fail to implement adequate cybersecurity safeguards or enter into business associate agreements that provide insufficient privacy and security protections. Unauthorized use of PHI or failure to comply with applicable privacy requirements could expose health care providers to liability.

Additionally, HIPAA grants patients the right to access and request amendment of PHI maintained in a designated record set (DRS). Ambiguity exists on whether the AI scribe’s notes in draft form or its recordings constitute a DRS. Health care organizations should review their policies to ensure that they address circumstances in which the AI scribe’s output constitutes a DRS. In addition, the AI scribe’s draft notes and recordings may be subject to applicable record-retention requirements. HIPAA generally requires covered entities to retain certain documentation for six years, although state record-retention requirements may impose longer retention periods.

Informed Consent Considerations

AI scribe use may implicate state recording and wiretapping laws. Currently 12 states require all-party consent, meaning that every participant in the conversation must consent to the recording. Thus, clinicians may need to obtain consent from the patient and any accompanying individuals each time an AI scribe is used. Even when consent is initially provided, patients and other participants may later withdraw that consent, so it is important for the health care organization to adopt a policy on how long and under what conditions a recording is retained.

Accuracy and Liability Concerns

AI scribes remain prone to transcription errors and hallucinations that can compromise the accuracy of clinical documentation. Clinicians remain responsible for the final content of the medical record and should ensure that AI-generated documentation accurately reflects the patient’s condition, treatment decisions and clinical reasoning. Because clinicians’ memories may fade over time, health care organizations should establish policies that balance efficiency benefits with accurate clinical records. Accordingly, health care organizations should require a timely clinician review of all AI-generated notes to help mitigate patient safety risks and potential malpractice liability.

Data Security and Cybersecurity Risks

AI scribes introduce cybersecurity risks into a health care organization’s electronic ecosystem because they often require the collection, transmission, storage and processing of large volumes of patient information by third-party vendors. If health care organizations fail to adequately vet vendor security practices or implement appropriate technical and contractual safeguards, a cybersecurity incident could expose PHI, trigger breach-notification obligations, and result in regulatory scrutiny.

While AI scribes can serve as valuable tools that improve efficiency and support clinical documentation, health care organizations should carefully evaluate the associated privacy, compliance and liability risks to develop an effective governance and risk-management strategy.

Print

Close
stevens and lee logo
Your Privacy

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose to not allow certain types of cookies. Click on the categories on the left to find out more and change your default settings. Blocking some types of cookies may impact your experience on this website.