What to Include in a HIPAA BAA with an AI Scribe Vendor: Essential Clauses and Compliance Checklist

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

What to Include in a HIPAA BAA with an AI Scribe Vendor: Essential Clauses and Compliance Checklist

Kevin Henry

HIPAA

July 18, 2026

7 minutes read
Share this article
What to Include in a HIPAA BAA with an AI Scribe Vendor: Essential Clauses and Compliance Checklist

Choosing an AI scribe for clinical documentation means entrusting a vendor with Protected Health Information. A precise Business Associate Agreement (BAA) defines legal boundaries, security expectations, and operational playbooks so you can deploy ambient clinical intelligence without compromising HIPAA compliance.

Business Associate Agreement Requirements

Your BAA should make clear that the vendor is a Business Associate handling PHI on your behalf, with permissions limited to services necessary to capture, transcribe, summarize, and deliver clinical notes. Spell out responsibilities and your enforcement rights.

Essential clauses to include

  • Permitted/required uses and disclosures: restrict PHI processing to defined scribe functions and the minimum necessary standard.
  • Safeguards: require administrative, physical, and technical controls aligned to the HIPAA Security Rule, including risk analysis and ongoing risk management.
  • Non-disclosure: prohibit uses or disclosures not expressly permitted by the BAA or HIPAA.
  • Incident and breach reporting: mandate timely reporting of security incidents and breaches, with details and cooperation obligations.
  • Individual rights support: ensure the vendor helps you fulfill access, amendment, and accounting of disclosures requests.
  • Oversight: require cooperation with audits, assessments, and Department of Health and Human Services (HHS) investigations.
  • Subcontractors: forbid subcontracting PHI functions without prior approval and a flow‑down Subcontractor BAA.
  • Return/Destruction: on termination, return or destroy PHI and certify completion, subject to feasible archival limits.
  • Termination for cause: allow termination if the vendor materially breaches or cannot cure noncompliance.
  • Documentation: require policy evidence and records retention consistent with HIPAA’s documentation requirements.

Data Handling and Model Training Restrictions

AI scribes rely on speech recognition and language models. Your BAA should precisely govern how data is ingested, processed, stored, and excluded from training.

Key restrictions to add

  • Model Training Prohibition: bar the vendor from using your PHI to train, fine‑tune, or evaluate models unless you give explicit, written authorization with defined controls.
  • De‑identification standards: if you ever authorize limited research or improvement use, require HIPAA de‑identification (Safe Harbor or Expert Determination) and documented risk assessments.
  • Data flow controls: define approved data sources (e.g., live mic streams, uploaded audio), processing locations, and storage boundaries; prohibit export to unmanaged systems.
  • Log hygiene: prevent PHI in application logs, error traces, analytics, and support tickets; require redaction and access restrictions.
  • Environment segregation: separate production, staging, and development; never copy PHI to test systems without your written approval and encryption.
  • Support access: require just‑in‑time, time‑boxed access with ticketing and audit trails for any vendor personnel exposure to PHI.

Data Encryption Standards

Encryption must protect PHI at rest and in transit, with strong key management and verifiable implementation.

  • At rest: mandate AES-256 Encryption for databases, object stores, file systems, backups, and portable media.
  • In transit: require TLS 1.2+ (prefer TLS 1.3) for all client, API, and inter‑service traffic; disable weak ciphers and protocols.
  • Key management: specify secure generation, rotation (time‑based and event‑driven), storage in HSM or equivalent, and separation of duties.
  • Customer control: where feasible, allow BYOK/HYOK to segregate your data cryptographically from other tenants.
  • Validation: prefer FIPS 140‑2/140‑3 validated crypto modules and require annual attestations or independent assessments.

Subcontractor Management Clauses

AI scribe vendors may rely on speech engines, cloud platforms, or human-in-the-loop QA. Your BAA should give you visibility and control.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

  • Approval and notice: require written approval before adding or replacing any subprocessor that touches PHI, plus advance change notifications.
  • Flow‑down: obligate a Subcontractor BAA that imposes the same privacy, security, breach, and deletion duties as your primary BAA.
  • Due diligence: mandate security reviews, risk assessments, and documented controls before onboarding subcontractors.
  • Right to audit: retain rights to review subcontractor controls, reports, or third‑party attestations.
  • Liability: keep the vendor fully responsible for subcontractor actions and omissions.
  • Data locality: define approved hosting regions and prohibit transfers outside them without your consent.

Data Retention and Deletion Policies

Set clear guardrails for how long transcripts, audio, and derived notes persist—and how they are removed.

  • Retention schedule: define maximum retention for raw audio, intermediate text, and finalized notes; apply the minimum necessary principle.
  • Data Purging Policy: require automated purge jobs, deletion SLAs (e.g., within 30–90 days of request or contract end), and coverage for replicas and backups.
  • Certificate of destruction: insist on written confirmation when PHI is deleted or returned.
  • Backups and disaster recovery: ensure encrypted backups follow the same retention and deletion timelines.
  • Legal holds: allow exception handling for litigation or regulatory holds, with documented scope and timelines.
  • Customer export: provide secure, structured export of your data prior to deletion for continuity of care.

Breach Notification Terms

Define what constitutes a breach, how quickly the vendor must notify you, and what cooperation you can expect.

  • Breach Notification Timeline: require notice without unreasonable delay and no later than 60 calendar days after discovery, with an initial alert (e.g., within 24–72 hours) for rapid response.
  • Notification content: specify required details—what happened, types of PHI involved, affected individuals (if known), containment steps, and remediation plans.
  • Investigation and cooperation: mandate forensic support, log sharing, and coordination on regulatory and patient notifications.
  • Costs and remedies: clarify responsibility for notification logistics and reasonable mitigation services when appropriate.
  • Security incidents: require reporting of non‑breach security incidents that could materially impact PHI confidentiality, integrity, or availability.

Access and Audit Controls

Strong access governance limits PHI exposure and creates evidence for compliance. Require technical and procedural controls suitable for high‑risk clinical data.

  • Role-Based Access Control: enforce least privilege with job‑based roles, approval workflows, and segregation of duties.
  • Authentication: require SSO, MFA for privileged roles, short session lifetimes, and revocation on termination.
  • Operational access: use just‑in‑time elevation, time‑bound credentials, and “break‑glass” processes with enhanced logging.
  • Audit logging: capture user actions, administrative changes, data access, and exports; protect logs from tampering and retain them per defined schedules.
  • Monitoring and response: specify alerting thresholds, 24×7 monitoring, and incident response playbooks with defined RTO/RPO targets.
  • Change and vulnerability management: require patching SLAs, secure SDLC, code review, and regular penetration tests.

Pulling these threads together in your BAA creates a shared, testable framework. With explicit limits on model use, strong encryption, subcontractor control, disciplined retention and deletion, firm breach obligations, and auditable access, you can safely realize AI scribe efficiency while protecting patient trust and regulatory compliance.

FAQs

What specific HIPAA clauses are required in a BAA for AI scribe vendors?

Include permitted/required uses of PHI, minimum necessary, safeguards, reporting of incidents and breaches, support for access/amendment/accounting, subcontractor flow‑down via a Subcontractor BAA, cooperation with HHS, return/destruction on termination, and termination for cause. These clauses align your vendor’s obligations with HIPAA’s Privacy, Security, and Breach Notification Rules.

How should PHI be protected during model training by AI scribes?

Adopt a Model Training Prohibition by default. If you later permit limited improvement work, require HIPAA‑compliant de‑identification, segregated environments, documented risk assessments, no PHI in logs, and auditable approvals. All processing must follow the minimum necessary standard and explicit, written scope.

What are the encryption standards for PHI in AI scribe solutions?

Mandate AES-256 Encryption for data at rest and TLS 1.2+ (preferably TLS 1.3) for data in transit, with strong key management, rotation, and FIPS‑validated crypto modules. Apply encryption uniformly to databases, object storage, backups, and ephemeral processing caches.

When must vendors notify of a data breach under HIPAA?

They must notify you without unreasonable delay and no later than 60 calendar days after discovery. Your BAA can add a faster initial alert window (for example, within 24–72 hours) so you can start containment, investigation, and any required regulatory notifications promptly.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles