Vet an AI scribe’s security the same way you’d vet anything that holds your patients’ words: by what it does with the audio, what it encrypts, who can see the notes, and what it will put in writing. Run the ten checks below in order. The first one that gets a vague answer tells you most of what you need to know.
That’s the whole method. The rest of this page is the checklist itself, what a good answer sounds like, and where the honest weak spots are, including ours. We sell a scribe, so read this with appropriate suspicion and test every claim during a trial.
Key takeaways
- The audio question decides more than any other. A scribe that keeps no recording has nothing to breach or subpoena.
- Encryption is non-negotiable: TLS 1.2 or newer in transit, AES-256 at rest. Demand both in plain words.
- “SOC 2 certified” is not a real claim. SOC 2 produces a CPA report, not a certificate.
- The BAA is the legal floor. No business associate agreement, no deal, on any plan.
- Of the ten checks, three are about audio, encryption, and access. Those three filter out most weak vendors.
In this buyer-run security checklist, ordered by how fast each one disqualifies a vendor
The target audio policy: processed in memory, discarded at note draft, nothing retained
Audio, encryption, and access do most of the filtering; the rest confirm what those three imply
The 10-point AI scribe security checklist
Run these in order, with the vendor on the call. Write down the answers. The point isn’t to collect a perfect score, it’s to catch the one bad answer that ends the evaluation.
| # | Check | A good answer | A weak answer |
|---|---|---|---|
| 1 | What happens to the visit audio, and when is it deleted? | Processed in memory, discarded at note draft. No archive. | ”We retain it for model improvement” with no deletion timeline. |
| 2 | Is traffic encrypted in transit? | TLS 1.2 or newer, every connection. | ”Bank-grade security,” no version named. |
| 3 | Are notes encrypted at rest? | AES-256 on notes and account data. | Hand-waving, or “in our cloud provider.” |
| 4 | Is access role-scoped and logged? | Yes, every access logged, logs reviewable. | ”Our team accesses data as needed.” |
| 5 | Will you sign a BAA for a practice my size? | Yes, every customer, before any real visit. | Tier-gated, or “enterprise only.” |
| 6 | Does BAA coverage reach the subprocessors that touch audio? | Yes, the speech-to-text vendors are named and covered. | ”Our cloud is compliant,” no subprocessor answer. |
| 7 | What’s your SOC 2 status, honestly? | Type II underway / report on request, stated plainly. | ”SOC 2 certified” (no such thing). |
| 8 | Is my audio or note text used to train models? | A written answer, separate for audio and text. | ”We follow applicable law.” |
| 9 | Can I export and delete any visit myself? | Yes, anytime, and you can test it in a trial. | Export by support request, delete unclear. |
| 10 | What happens to my data if I cancel? | Return or destruction, with a timeline, in the contract. | Buried in a ToS, or silence. |
Notice what’s missing: accuracy percentages, “military-grade” anything, per-specialty templates, certification logos. Those decorate a slide and decide nothing about whether your patients’ data is safe. Checks 1 through 4 do most of the filtering.
Why the audio question comes first
A visit recording is the most revealing artifact an AI scribe ever touches. It holds the digressions, the names, the thing the patient immediately walked back, all the stuff that never made it into the structured note you signed. The note is the curated record. The audio is the unedited version of the same hour.
So the retention answer is the whole ballgame. If a vendor stores audio, that recording is protected health information, reachable in litigation and exposed in a breach. A vendor that processes audio in memory and discards it the moment the note is drafted has nothing to hand over. No clever encryption story beats simply not keeping the file.
Our position, stated as ours: visit audio is processed in memory and discarded once the note is drafted. There’s no audio archive anywhere, not on our side and not on the practice’s. If you want the cross-vendor version of this question, what happens to your visit audio across major scribes walks through how different products answer it. Ask every vendor for a one-sentence answer with a timeline, and book a demo where the audio question goes first.
What encryption and access logging should actually look like
Checks 2 through 4 are where “trust us” meets the facts. None of these three is optional.
In transit, every connection between the capture device, the service, and your browser should run TLS 1.2 or newer. Table stakes in 2026. A vendor that won’t name the version is either hiding something or doesn’t know it.
At rest, notes and account data stored on disk should be encrypted with a strong, current standard. AES-256 is the common one. Ours uses AES-256 at rest, and for low-connectivity clinics, offline capture is encrypted on the device with AES-256-GCM before anything syncs.
Then access. Encryption stops outsiders; access controls stop the wrong insiders. Every read of a note should be role-scoped, every access logged, the logs reviewable. “Our team has access as needed” is the answer you don’t want to hear.
The full version of our answer, what’s encrypted, who can access what, what’s logged, lives on the security page, written to be read with this checklist in hand.
How to read a vendor’s compliance claims without getting played
Check 7 is where marketing language gets loosest, so be precise here.
SOC 2 is a report, not a certificate. It’s a voluntary framework from the American Institute of CPAs, and the output is a report from an independent CPA firm, not a badge. A Type II report covers how controls operated over a period, typically 3 to 12 months. So “SOC 2 certified” is a phrase the framework doesn’t support. The honest claims are “Type II underway” (the audit is in progress) or “Type II report available on request” (it’s done). Ours is underway with an independent assessor. We’ll say that plainly and not a word more.
HIPAA isn’t a certification either. No software is “HIPAA certified,” because no such certificate exists. What’s real is narrower: the vendor maps its safeguards to the HIPAA Security Rule, signs a BAA, encrypts PHI, limits access. We map our safeguards to the Security Rule and offer a BAA to every customer. If you want the BAA and consent mechanics in depth, our HIPAA and AI scribes guide goes there.
Then push on check 6, the one most decks skip. A BAA that covers the vendor but not the speech-to-text service their audio passes through is a half-answer. The subprocessors that touch the recording need the same coverage, named in writing. Ask which vendors are in that chain and whether each one is under the BAA. “Our cloud is compliant” is not the same sentence.
A vendor that says “we’re fully compliant” and stops there has told you nothing. The ones worth trusting name the standard, name the status, and put it in writing.
Who owns the data, and can you actually leave?
The last three checks are about exit, and they matter more than most buyers expect. A scribe holds your clinical record. If leaving is hard, the security story isn’t finished, because lock-in is its own kind of risk.
So, three plain questions. Can you export any visit yourself, anytime? Can you delete any visit yourself, anytime? And when you cancel, does the contract actually spell out return or destruction with a timeline? “Your notes belong to your practice” should be a sentence the vendor will put their name on, not a vibe. We hold that notes belong to the practice, exportable and deletable any time, and we never sell or share clinical data. The full version of the exit question, with the lock-in red flags to watch, is in who owns your AI scribe notes.
Where we’d tell you to look elsewhere
Honesty cuts both ways, so here’s the part of the security story we don’t cover. If your security model depends on the scribe writing directly into your EHR through a certified integration, on a vendor-managed audit trail living inside that EHR, or on enterprise features like SSO and SCIM provisioning across a large health system, a deeply EHR-embedded enterprise platform will fit that requirement better than we will. We don’t integrate with EHRs, and we don’t manage identity at health-system scale. That’s a real gap for some buyers, and you should weigh it against the audio-retention advantage rather than pretend it away.
For a solo clinician or a small-to-mid practice, the calculus is simpler: the controls that actually protect your patients are the ones on this list, and the audio policy at the top of it is the one most vendors get wrong.
How to run the checklist in practice
It’s an afternoon of work, and worth doing precisely.
- Send the ten questions before the demo. A vendor who answers in writing, in advance, is a vendor with answers. One who needs a call to “walk you through it” is buying time.
- Make the audio answer a single sentence with a timeline. Everything else is secondary to that one.
- Get the encryption versions in writing, TLS 1.2 or newer and AES-256 at rest, not a slogan.
- Pin the training-data policy separately for audio and for note text. Two questions, two answers.
- Test export and delete yourself during the trial. A function you can’t exercise in a week is a function to doubt.
Our canonical line, so you know exactly what you’re vetting: AI Medical Scribe by Patient Square is an ambient AI medical scribe that listens during the visit and hands back a structured SOAP note, ICD-10 suggestions, and a prescription draft, ready to review and sign about two minutes after the visit. The security posture behind that is on the security page, and the cleanest way to test all ten checks is a quiet week of real visits. Book a demo, put the audio question first, then run the 7-day trial and exercise every claim on this list yourself.