AI session notes with no vendor in the data path
A cloud scribe is a business associate and needs a signed BAA. A tool that never sends anything anywhere is a different question entirely — but consent still isn't optional.
Not legal or compliance advice, and we make one of these tools, so read us critically. Every regulation and ethics standard below is linked to its source.
Short answer: under 45 CFR §160.103, anyone who creates, receives, maintains, or transmits PHI on your behalf is a business associate and needs a signed BAA. A cloud AI scribe does all four. A tool that runs entirely on your Mac puts nobody in that path — but it does nothing about your duty to get the client's consent before recording.
The BAA question, stated precisely
It's worth being careful here, because the usual vendor phrasing is wrong. Plenty of tools say “we can't read your data, so no BAA is needed.” That does not follow. HHS has addressed the closely related case of a cloud provider that stores only encrypted PHI and holds no decryption key, and the reported position is that it is still a business associate — because it maintains the PHI, whether or not it can read it.
So “no access” is not the test. The test is whether a third party is in the path at all. That's the honest distinction for a local tool: not that we can't see your sessions, but that nothing is ever sent to us to see. There is no server, no storage, and no company standing between you and the recording.
One caveat that cuts against a lot of “on-device” marketing, including ours if we ever got sloppy: a product can process audio locally and still ship telemetry, crash logs, or support diagnostics containing PHI. Local inference alone doesn't settle it. What settles it is nothing PHI-bearing leaving the machine, which is the sort of claim you should be able to verify — the source is public.
Psychotherapy notes: keep the transcript separate
This is the most practically useful thing on this page, and it's frequently missed.
45 CFR §164.501 defines “psychotherapy notes” as notes recorded in any medium that document or analyse the contents of a counseling session and that are kept separate from the rest of the individual's medical record. That separation is not a formality — it's part of the definition. Notes that get bundled into the general chart are simply not psychotherapy notes, and lose the heightened protection that normally requires specific authorization to disclose.
Explicitly excluded from the category, and therefore part of the ordinary record regardless of where you file them:
- Medication prescription and monitoring
- Session start and stop times
- Treatment modalities and frequency
- Results of clinical tests
- Any summary of diagnosis, functional status, treatment plan, symptoms, prognosis and progress
The implication for AI notes: a raw session transcript is exactly the kind of artefact that benefits from being stored separately, and exactly the kind that tools tend to dump straight into the chart. Decide deliberately where it lives.
Every ethics code says get permission first
| Body | Standard | Requirement |
|---|---|---|
| APA | 4.03 — Recording | Obtain permission from all persons before recording their voices or images |
| NASW | 1.03(h) — Informed Consent | Obtain informed consent before making audio or video recordings |
| ACA | B.6.c — Permission to Record | Obtain permission from clients prior to recording sessions |
None of the three carves out an exception for transcription-only or AI-assisted recording. The duty attaches to recording, whatever it's for. And if you practise in an all-party-consent state, that's a separate legal obligation stacked on top of the ethical one — see our guide to recording consent laws.
If you work with substance use disorder records
42 CFR Part 2 sits on top of HIPAA and is stricter. A 2024 final rule brought it closer to HIPAA for treatment, payment and operations, but SUD counseling notes still require specific separate consent, and Part 2 records carry a protection HIPAA has no analog for: they generally cannot be used in legal proceedings against the patient without consent or a qualifying court order. Treat transcripts accordingly.
What therapists are actually saying
The objections are not really about compliance paperwork. From Proof News reporting (June 2026) on clinicians pushing back on their health system's rollout:
“Is five minutes of my time worth the possibility of a data breach?”
— Jess Metzinger, associate clinical social worker
“The longer you have those recordings and those transcripts out there, the more likely there could be a breach.”
— Lisa Whelan, LCSW
Linda Michaels, a psychologist and co-founder of the Psychotherapy Action Network, put the objection to cloud scribes more bluntly still, calling it “taking advantage of vulnerable people at a vulnerable time.”
There's a quieter concern too, and no architecture fixes it: recording changes the room. As the APA's director of digital health noted, being recorded makes people uneasy — and an hour of therapy is not a meeting. A client who is managing their own disclosure because something is listening is getting less from the session. That's a reason to ask properly and to be able to say no, and I'll turn it off without it being a big deal.
Practical setup
- Put recording in your informed consent document, and get consent again verbally the first time you use it with an existing client.
- Store transcripts separately from the chart if you want the psychotherapy notes protection to apply.
- Turn on FileVault. Local-first moves custody to you; an unencrypted laptop is a worse custodian than a competent vendor. Encrypted PHI also sits differently under the Breach Notification Rule, though don't take our word for the specifics — that one is worth a compliance check.
- Delete what you don't need. The recording is usually the risky artefact, and the note is the thing you actually wanted.
- Read the note before it goes in the chart. Transcription errors cluster exactly on medication names, dosages and dates.