The AI Medical Scribe Security Checklist Every Buyer Should Run

Vet an AI scribe’s security the same way you’d vet anything that holds your patients’ words: by what it does with the audio, what it encrypts, who can see the notes, and what it will put in writing. Run the ten checks below in order. The first one that gets a vague answer tells you most of what you need to know.

That’s the whole method. The rest of this page is the checklist itself, what a good answer sounds like, and where the honest weak spots are, including ours. We sell a scribe, so read this with appropriate suspicion and test every claim during a trial.

Key takeaways

  • The audio question decides more than any other. A scribe that keeps no recording has nothing to breach or subpoena.
  • Encryption is non-negotiable: TLS 1.2 or newer in transit, AES-256 at rest. Demand both in plain words.
  • “SOC 2 certified” is not a real claim. SOC 2 produces a CPA report, not a certificate.
  • The BAA is the legal floor. No business associate agreement, no deal, on any plan.
  • Of the ten checks, three are about audio, encryption, and access. Those three filter out most weak vendors.
10checks

In this buyer-run security checklist, ordered by how fast each one disqualifies a vendor

0archive

The target audio policy: processed in memory, discarded at note draft, nothing retained

3checks

Audio, encryption, and access do most of the filtering; the rest confirm what those three imply

The 10-point AI scribe security checklist

Run these in order, with the vendor on the call. Write down the answers. The point isn’t to collect a perfect score, it’s to catch the one bad answer that ends the evaluation.

#CheckA good answerA weak answer
1What happens to the visit audio, and when is it deleted?Processed in memory, discarded at note draft. No archive.”We retain it for model improvement” with no deletion timeline.
2Is traffic encrypted in transit?TLS 1.2 or newer, every connection.”Bank-grade security,” no version named.
3Are notes encrypted at rest?AES-256 on notes and account data.Hand-waving, or “in our cloud provider.”
4Is access role-scoped and logged?Yes, every access logged, logs reviewable.”Our team accesses data as needed.”
5Will you sign a BAA for a practice my size?Yes, every customer, before any real visit.Tier-gated, or “enterprise only.”
6Does BAA coverage reach the subprocessors that touch audio?Yes, the speech-to-text vendors are named and covered.”Our cloud is compliant,” no subprocessor answer.
7What’s your SOC 2 status, honestly?Type II underway / report on request, stated plainly.”SOC 2 certified” (no such thing).
8Is my audio or note text used to train models?A written answer, separate for audio and text.”We follow applicable law.”
9Can I export and delete any visit myself?Yes, anytime, and you can test it in a trial.Export by support request, delete unclear.
10What happens to my data if I cancel?Return or destruction, with a timeline, in the contract.Buried in a ToS, or silence.

Notice what’s missing: accuracy percentages, “military-grade” anything, per-specialty templates, certification logos. Those decorate a slide and decide nothing about whether your patients’ data is safe. Checks 1 through 4 do most of the filtering.

Why the audio question comes first

A visit recording is the most revealing artifact an AI scribe ever touches. It holds the digressions, the names, the thing the patient immediately walked back, all the stuff that never made it into the structured note you signed. The note is the curated record. The audio is the unedited version of the same hour.

So the retention answer is the whole ballgame. If a vendor stores audio, that recording is protected health information, reachable in litigation and exposed in a breach. A vendor that processes audio in memory and discards it the moment the note is drafted has nothing to hand over. No clever encryption story beats simply not keeping the file.

Our position, stated as ours: visit audio is processed in memory and discarded once the note is drafted. There’s no audio archive anywhere, not on our side and not on the practice’s. If you want the cross-vendor version of this question, what happens to your visit audio across major scribes walks through how different products answer it. Ask every vendor for a one-sentence answer with a timeline, and book a demo where the audio question goes first.

What encryption and access logging should actually look like

Checks 2 through 4 are where “trust us” meets the facts. None of these three is optional.

In transit, every connection between the capture device, the service, and your browser should run TLS 1.2 or newer. Table stakes in 2026. A vendor that won’t name the version is either hiding something or doesn’t know it.

At rest, notes and account data stored on disk should be encrypted with a strong, current standard. AES-256 is the common one. Ours uses AES-256 at rest, and for low-connectivity clinics, offline capture is encrypted on the device with AES-256-GCM before anything syncs.

Then access. Encryption stops outsiders; access controls stop the wrong insiders. Every read of a note should be role-scoped, every access logged, the logs reviewable. “Our team has access as needed” is the answer you don’t want to hear.

The full version of our answer, what’s encrypted, who can access what, what’s logged, lives on the security page, written to be read with this checklist in hand.

How to read a vendor’s compliance claims without getting played

Check 7 is where marketing language gets loosest, so be precise here.

SOC 2 is a report, not a certificate. It’s a voluntary framework from the American Institute of CPAs, and the output is a report from an independent CPA firm, not a badge. A Type II report covers how controls operated over a period, typically 3 to 12 months. So “SOC 2 certified” is a phrase the framework doesn’t support. The honest claims are “Type II underway” (the audit is in progress) or “Type II report available on request” (it’s done). Ours is underway with an independent assessor. We’ll say that plainly and not a word more.

HIPAA isn’t a certification either. No software is “HIPAA certified,” because no such certificate exists. What’s real is narrower: the vendor maps its safeguards to the HIPAA Security Rule, signs a BAA, encrypts PHI, limits access. We map our safeguards to the Security Rule and offer a BAA to every customer. If you want the BAA and consent mechanics in depth, our HIPAA and AI scribes guide goes there.

Then push on check 6, the one most decks skip. A BAA that covers the vendor but not the speech-to-text service their audio passes through is a half-answer. The subprocessors that touch the recording need the same coverage, named in writing. Ask which vendors are in that chain and whether each one is under the BAA. “Our cloud is compliant” is not the same sentence.

A vendor that says “we’re fully compliant” and stops there has told you nothing. The ones worth trusting name the standard, name the status, and put it in writing.

Who owns the data, and can you actually leave?

The last three checks are about exit, and they matter more than most buyers expect. A scribe holds your clinical record. If leaving is hard, the security story isn’t finished, because lock-in is its own kind of risk.

So, three plain questions. Can you export any visit yourself, anytime? Can you delete any visit yourself, anytime? And when you cancel, does the contract actually spell out return or destruction with a timeline? “Your notes belong to your practice” should be a sentence the vendor will put their name on, not a vibe. We hold that notes belong to the practice, exportable and deletable any time, and we never sell or share clinical data. The full version of the exit question, with the lock-in red flags to watch, is in who owns your AI scribe notes.

Where we’d tell you to look elsewhere

Honesty cuts both ways, so here’s the part of the security story we don’t cover. If your security model depends on the scribe writing directly into your EHR through a certified integration, on a vendor-managed audit trail living inside that EHR, or on enterprise features like SSO and SCIM provisioning across a large health system, a deeply EHR-embedded enterprise platform will fit that requirement better than we will. We don’t integrate with EHRs, and we don’t manage identity at health-system scale. That’s a real gap for some buyers, and you should weigh it against the audio-retention advantage rather than pretend it away.

For a solo clinician or a small-to-mid practice, the calculus is simpler: the controls that actually protect your patients are the ones on this list, and the audio policy at the top of it is the one most vendors get wrong.

How to run the checklist in practice

It’s an afternoon of work, and worth doing precisely.

  1. Send the ten questions before the demo. A vendor who answers in writing, in advance, is a vendor with answers. One who needs a call to “walk you through it” is buying time.
  2. Make the audio answer a single sentence with a timeline. Everything else is secondary to that one.
  3. Get the encryption versions in writing, TLS 1.2 or newer and AES-256 at rest, not a slogan.
  4. Pin the training-data policy separately for audio and for note text. Two questions, two answers.
  5. Test export and delete yourself during the trial. A function you can’t exercise in a week is a function to doubt.

Our canonical line, so you know exactly what you’re vetting: AI Medical Scribe by Patient Square is an ambient AI medical scribe that listens during the visit and hands back a structured SOAP note, ICD-10 suggestions, and a prescription draft, ready to review and sign about two minutes after the visit. The security posture behind that is on the security page, and the cleanest way to test all ten checks is a quiet week of real visits. Book a demo, put the audio question first, then run the 7-day trial and exercise every claim on this list yourself.

FAQ

Common questions

What is the single most important security question for an AI scribe?

What happens to the visit audio, and when is it deleted. The recording is more sensitive than the note, because it holds everything the patient said before you filtered it into documentation. A vendor that processes audio in memory and discards it at note draft keeps no archive to breach or subpoena. A vendor that retains it for days or weeks keeps that surface open.

Should an AI scribe be encrypted in transit and at rest?

Yes, both, with no exceptions. In transit means TLS 1.2 or newer on every connection. At rest means strong encryption on stored notes and account data, AES-256 being the common standard. A scribe that cannot state both plainly is not ready to hold patient data. Ask for the specifics in writing, not a "bank-grade security" slogan.

Is "SOC 2 certified" a real thing to look for?

No. There is no SOC 2 "certificate." SOC 2 is a voluntary AICPA framework, and the output is a report from an independent CPA firm, not a certification badge. A Type II report covers how controls operated over a period, usually 3 to 12 months. Any vendor claiming to be "SOC 2 certified" is using language the framework does not support.

Does an AI scribe need a BAA in the US?

Yes. In the US a Business Associate Agreement is the legal floor for any vendor that touches protected health information, and an AI scribe always does. The BAA should be available to every customer, not gated behind an enterprise tier, and signed before you feed it a single real visit. No BAA, no deal.

Can I verify a scribe's security claims, or do I just trust the sales deck?

You can verify most of it. Ask for the encryption specifics, the audio retention policy with a deletion timeline, the BAA, the access-logging answer, and the SOC 2 status in writing. Then test the export and delete functions yourself during a trial. A claim you cannot test on a real clinic day is a claim to discount.

Sources

  1. AICPA: SOC 2, SOC for Service Organizations (Trust Services Criteria)
  2. HHS: HIPAA Security Rule (administrative, physical, and technical safeguards)
  3. HHS: Business Associate Contracts (sample provisions)