Business

AI Scribe data policy: what your EHR's data policy actually means for your practice

Clinicians are asking harder questions about AI data practices. Learn what to look for in your EHR's data governance policy and why it matters for your patients and your practice.

Melissa Bhatia
Melissa Bhatia
Published on Jul 27, 2026
Updated on Jul 27, 2026

You've likely already weighed the tradeoffs of AI-assisted documentation. The efficiency gains are impressive, but you might have a lot of outstanding concerns.

Over the past several weeks, a policy update from a major EHR vendor has sparked significant backlash across the clinician community. The core issue is AI session transcripts being retained by default, with de-identification cited as sufficient protection. Professional organizations have pushed back, online forums are running hundreds of responses, and clinicians who thought they understood what they'd signed up for are realizing the fine print had changed.

This matters beyond any one platform or policy update. It's a signal that the industry hasn't caught up to the questions practitioners are rightfully asking about who controls session data, how it's used, and what "de-identified" actually means when the content is a clinical encounter.

Is de-identified session data actually private?

HIPAA Safe Harbor de-identification removes 18 specific identifiers: name, date of birth, address, and so on. For many types of healthcare data, this framework holds up reasonably well.

Clinical session transcripts are a different problem. Encounter content is inherently contextual and often highly specific: a patient's living situation, the details of a chronic condition, what they said about a recent procedure, the concerns they raised that aren't in the chart. These aren't isolated data points; they're narratives. As AI systems become more capable of connecting disparate information across large datasets, the re-identification risk that seemed theoretical a few years ago is increasingly concrete. 

The argument that Safe Harbor is sufficient for this type of data is being challenged by professional organizations who note, correctly, that the framework predates the AI capabilities now being used to process clinical content. EHR vendors citing HIPAA compliance as a complete answer are sidestepping a more nuanced conversation.

There's also an informed consent dimension that's largely unresolved. Most existing consent frameworks weren't built with AI transcription in mind. Clinicians want clarity on what patients are actually agreeing to when an embedded AI tool processes their sessions, who is responsible for explaining it to them and in what terms, and what recourse patients have if they object. 

5 questions to ask your EHR about AI data retention

Whether you're evaluating a new platform or reviewing what you already use, these questions will help you distinguish EHRs that have made intentional, security-first decisions on behalf of their customers from those whose data practices are driven by business interests.

  1. Does your AI tool retain transcripts after a note is generated? If yes, get specifics: where, for how long, and who can access them. De-identified is not the same as deleted.
  2. Is session data used to train or improve AI models? "Improving our AI" can mean a lot of things. Ask directly whether patient encounter content, at any stage of processing, feeds model training, and ask whether you can opt out of that use without losing functionality. 
  3. What are the current default settings, and have they changed? Platforms update data policies. If you enabled an AI feature months or a year ago, the terms governing it may have changed since. Default opt-in changes in particular often happen without proactive user notification.
  4. Can patients specifically consent to — or decline — AI transcription? Your general consent forms likely don't cover this. Your EHR should be able to support granular, feature-level consent that you can document in the chart.
  5. What happens to data if the company is acquired? "We don't sell or share data with third parties" is a policy, not a legal protection in the event of M&A. It's worth asking.

An EHR committed to their customers and data security should be able to answer these questions clearly and confidently.

{{free-trial-signup}}

What responsible AI documentation should look like

Reducing administrative burden is a meaningful goal for practice owners across every specialty, and it doesn't have to come at the cost of data governance. The two can coexist when vendors build with both as a priority. 

A reasonable standard for clinical AI means transcripts used to generate a note should be deleted once that note exists, patient encounter content should not be in the training pipeline without explicit consent, policy changes should be communicated proactively rather than buried, and the answers to the questions above should be easy to get and easy to understand.

How Healthie approaches AI data

Intelligence by Healthie is built around a straightforward principle: session transcripts are deleted after a note is created, and patient encounter content is never used to train AI models. Healthie's data practices are documented and publicly available because clinicians deserve to know exactly what they're agreeing to before using any feature.

Trust is foundational to effective, longitudinal care, and Healthie's infrastructure is designed to protect and support the patient-provider relationship across every specialty and care modality. Healthie also recognizes that HIPAA compliance obligations extend to the EHR you work with, and its approach is built to support your compliance posture, not just its own.

Why this moment matters: moving forward with AI 

What's happening across the clinical community right now isn't just frustration with one EHR vendor's policy. It's a recalibration of expectations, with clinicians recognizing that AI data governance deserves the same scrutiny as any other area of due diligence, and that blanket assurances like 'we take privacy seriously' are no longer sufficient.

AI-assisted documentation can be significantly beneficial for private practices. The goal isn't to avoid it but to demand better from the platforms that deliver it. Your EHR's approach to patient data is a values statement. As you evaluate your current platform or consider alternatives, it's worth asking whether those values match yours.

Launch, grow & scale your business today.

Business

AI Scribe data policy: what your EHR's data policy actually means for your practice

Clinicians are asking harder questions about AI data practices. Learn what to look for in your EHR's data governance policy and why it matters for your patients and your practice.

You've likely already weighed the tradeoffs of AI-assisted documentation. The efficiency gains are impressive, but you might have a lot of outstanding concerns.

Over the past several weeks, a policy update from a major EHR vendor has sparked significant backlash across the clinician community. The core issue is AI session transcripts being retained by default, with de-identification cited as sufficient protection. Professional organizations have pushed back, online forums are running hundreds of responses, and clinicians who thought they understood what they'd signed up for are realizing the fine print had changed.

This matters beyond any one platform or policy update. It's a signal that the industry hasn't caught up to the questions practitioners are rightfully asking about who controls session data, how it's used, and what "de-identified" actually means when the content is a clinical encounter.

Is de-identified session data actually private?

HIPAA Safe Harbor de-identification removes 18 specific identifiers: name, date of birth, address, and so on. For many types of healthcare data, this framework holds up reasonably well.

Clinical session transcripts are a different problem. Encounter content is inherently contextual and often highly specific: a patient's living situation, the details of a chronic condition, what they said about a recent procedure, the concerns they raised that aren't in the chart. These aren't isolated data points; they're narratives. As AI systems become more capable of connecting disparate information across large datasets, the re-identification risk that seemed theoretical a few years ago is increasingly concrete. 

The argument that Safe Harbor is sufficient for this type of data is being challenged by professional organizations who note, correctly, that the framework predates the AI capabilities now being used to process clinical content. EHR vendors citing HIPAA compliance as a complete answer are sidestepping a more nuanced conversation.

There's also an informed consent dimension that's largely unresolved. Most existing consent frameworks weren't built with AI transcription in mind. Clinicians want clarity on what patients are actually agreeing to when an embedded AI tool processes their sessions, who is responsible for explaining it to them and in what terms, and what recourse patients have if they object. 

5 questions to ask your EHR about AI data retention

Whether you're evaluating a new platform or reviewing what you already use, these questions will help you distinguish EHRs that have made intentional, security-first decisions on behalf of their customers from those whose data practices are driven by business interests.

  1. Does your AI tool retain transcripts after a note is generated? If yes, get specifics: where, for how long, and who can access them. De-identified is not the same as deleted.
  2. Is session data used to train or improve AI models? "Improving our AI" can mean a lot of things. Ask directly whether patient encounter content, at any stage of processing, feeds model training, and ask whether you can opt out of that use without losing functionality. 
  3. What are the current default settings, and have they changed? Platforms update data policies. If you enabled an AI feature months or a year ago, the terms governing it may have changed since. Default opt-in changes in particular often happen without proactive user notification.
  4. Can patients specifically consent to — or decline — AI transcription? Your general consent forms likely don't cover this. Your EHR should be able to support granular, feature-level consent that you can document in the chart.
  5. What happens to data if the company is acquired? "We don't sell or share data with third parties" is a policy, not a legal protection in the event of M&A. It's worth asking.

An EHR committed to their customers and data security should be able to answer these questions clearly and confidently.

{{free-trial-signup}}

What responsible AI documentation should look like

Reducing administrative burden is a meaningful goal for practice owners across every specialty, and it doesn't have to come at the cost of data governance. The two can coexist when vendors build with both as a priority. 

A reasonable standard for clinical AI means transcripts used to generate a note should be deleted once that note exists, patient encounter content should not be in the training pipeline without explicit consent, policy changes should be communicated proactively rather than buried, and the answers to the questions above should be easy to get and easy to understand.

How Healthie approaches AI data

Intelligence by Healthie is built around a straightforward principle: session transcripts are deleted after a note is created, and patient encounter content is never used to train AI models. Healthie's data practices are documented and publicly available because clinicians deserve to know exactly what they're agreeing to before using any feature.

Trust is foundational to effective, longitudinal care, and Healthie's infrastructure is designed to protect and support the patient-provider relationship across every specialty and care modality. Healthie also recognizes that HIPAA compliance obligations extend to the EHR you work with, and its approach is built to support your compliance posture, not just its own.

Why this moment matters: moving forward with AI 

What's happening across the clinical community right now isn't just frustration with one EHR vendor's policy. It's a recalibration of expectations, with clinicians recognizing that AI data governance deserves the same scrutiny as any other area of due diligence, and that blanket assurances like 'we take privacy seriously' are no longer sufficient.

AI-assisted documentation can be significantly beneficial for private practices. The goal isn't to avoid it but to demand better from the platforms that deliver it. Your EHR's approach to patient data is a values statement. As you evaluate your current platform or consider alternatives, it's worth asking whether those values match yours.

Scale your care delivery with Healthie+.

All the tools you need to run your practice & work with patients.
All the tools you need to run your practice & work with patients.

All the tools you need to run your practice & work with patients.
All the tools you need to run your practice & work with patients.