There has been some confusion about when a patient authorization is required when using AI scribe or the recording of a patient encounter.
HIPAA permits providers to use and disclose PHI for the Treatment, Payment, and Healthcare operations (TPO). If the provider records the encounter solely to create clinical documentation, then a separate patient authorization is required.
Keep in mind, you must have a signed business associate agreement (BAA). The recording must be secure, and encryption and proper safeguards are in place. Also, this must be disclosed to the patient.
HOWEVER, it is recommended to obtain a patient authorization since many states, including Florida require an authorization from BOTH parties to record audio conversations.
AI Scribe Used for Treatment Documentation
If the provider records the encounter solely to create clinical documentation for treatment, payment, or healthcare operations purposes, HIPAA generally does not require a separate patient authorization.
Medical Provider Requirements
The AI vendor must sign a Business Associate Agreement (BAA). The recording must be secured using encryption and proper technical safeguards.
When Authorization May Be Required
A separate written authorization may be required if the recording is used for marketing, shared outside of treatment purposes, or training outside HIPAA regulated entities.
Some state law requires two-party consent for audio recording (such as Florida).
State wiretapping laws may require patient consent even if HIPAA does not.
AI scribing tools typically record audio of patient encounters, transcribe and process PHI, sometimes store or analyze recordings. That triggers BOTH laws at the same time.
Additional Risk Considerations
Even if HIPAA does not require authorization, patients should be clearly informed that the visit is being recorded. Transparency reduces complaints and scrutiny. Even some malpractice carriers recommend a written acknowledgment.
Practical Best Practice
Providers should be updating their intake paperwork to include this disclosure and adding signage in the exam rooms.
Aris Medical Solutions helps medical practices and business associates understand HIPAA expectations and reduce risk.
Our HIPAA Keeper™ was designed to help organizations:
- Understand where they stand
- Organize required documentation
- Maintain compliance over time
- Be prepared if questions ever arise
Additionally, you will have a HIPAA security analyst to guide and assist you step by step.

To find out where you stand with your compliance, schedule a free HIPAA checkup today at Aris Medical Solutions.


