# Your AI Scribe Is Recording. Did Anyone Ask the Patient?

> HIPAA is only half the problem when AI listens to a patient visit. Massachusetts and New Hampshire recording law is the other half, and the rules differ.

- Canonical: https://www.rnits.com/blog/hipaa-compliant-ai-medical-practice-scribes-consent
- Provider: RNITS — cybersecurity-first managed IT for small businesses
- Phone: (978) 226-8931
- Talk to RNITS: https://www.rnits.com/contact · Free cyber security audit: https://www.rnits.com/free-cyber-security-audit
- Published: 2026-08-11
- Category: Compliance
- Tags: HIPAA, AI Governance, Compliance, Healthcare IT

Most small practices did not decide to adopt AI. It showed up.

The EHR vendor pushed an update, and now there is an ambient AI scribe in the visit screen with a microphone button. Microsoft turned on Copilot inside a license the practice already paid for. The billing service added an AI claim-review step and mentioned it in a release note nobody read. Somewhere in there, a front-desk employee started using ChatGPT to rewrite letters, because it was faster.

Nobody bought an AI strategy. Each of those tools is now a HIPAA question. Nine months later the practice is running four AI systems that touch patient information, and if a patient asked which ones had heard their medical history, no one in the building could answer.

That is the actual compliance problem, and it is not primarily a HIPAA problem. HIPAA is the part everyone worries about. The part that has generated actual lawsuits this year is state recording law, and in our service area it works differently on either side of the border.

## The rule nobody localized

Ambient AI scribes are genuinely good technology. A clinician who used to spend two hours a night finishing notes gets that time back. We are not going to tell you not to use one. But understand what the tool does mechanically: it records the audio of a conversation between two people, sends it somewhere to be processed, and produces text.

HIPAA governs what happens to the protected health information in that recording. It has almost nothing to say about whether you were allowed to make the recording in the first place. That question belongs to state wiretap law, and it carries criminal penalties that HIPAA does not.

Here is where the generic advice you will find online falls down. Most articles about AI scribes lump Massachusetts and New Hampshire together as "all-party consent states" and move on. That is wrong about one of them, and the difference matters operationally.

### Massachusetts prohibits secret recording, not unconsented recording

The Massachusetts wiretap statute, [M.G.L. c. 272, § 99](https://malegislature.gov/Laws/GeneralLaws/PartIV/TitleI/Chapter272/Section99), defines an unlawful interception as the act of using a device "to secretly hear, secretly record, or aid another to secretly hear or secretly record the contents of any wire or oral communication."

The operative word is _secretly_. In **Commonwealth v. Jackson**, 370 Mass. 502 (1976), the Supreme Judicial Court held that a party's actual knowledge that the recording is happening is enough to defeat the secrecy element. Express permission is not the legal test in Massachusetts. Notice is.

The penalties are not trivial. Unlawful interception carries up to five years in state prison, or up to two and a half years in a house of correction, or a fine up to $10,000, and the statute also supports civil suits by the person recorded.

### New Hampshire actually does require consent

Cross into Nashua and the standard changes. Under RSA 570-A:2, it is unlawful to record an in-person or telephone conversation without the consent of all parties. Not notice. Consent.

The penalty splits based on whether the recorder was part of the conversation. A participant who records without everyone's consent commits a misdemeanor, punishable by up to a year and a $2,000 fine. Someone who was not a party and intercepts the conversation commits a felony, facing up to seven years and a $4,000 fine.

So New Hampshire is the stricter of the two, which is the opposite of what most practices assume, because Massachusetts has the louder reputation.

**The practical answer is to build one workflow to the stricter standard.** If your practice has offices in Lowell and Nashua, or clinicians who cover both, you do not want two consent procedures. Announce the recording, get an affirmative verbal acknowledgment from the patient, and document that you got it. That satisfies New Hampshire's consent requirement and clears Massachusetts' secrecy bar with room to spare.

One caveat, stated flatly: this is a summary of statutes and one case, not legal advice about your practice. Before you deploy a scribe, have your counsel look at your specific consent language. It is a short conversation and a cheap one.

## The lawsuit that made this concrete

If this felt theoretical until now, it stopped being theoretical in April.

On April 8, 2026, patients filed a class action in the U.S. District Court for the Northern District of California against Sutter Health and MemorialCare over their use of Abridge's ambient AI scribe. The core allegation is that clinical conversations were recorded, transmitted to outside systems for processing, and turned into documentation without meaningful patient consent. The claims include the California Invasion of Privacy Act, the Confidentiality of Medical Information Act, state unfair competition law, common-law invasion of privacy, and the federal Wiretap Act. Plaintiffs are seeking a nationwide class covering two years.

Two details are worth sitting with.

First, **Abridge is not a defendant.** The health systems are. The vendor sold a tool; the provider chose to point it at patients. When this goes wrong, it goes wrong for the covered entity, and a reassuring sentence in a vendor's marketing does not transfer the liability.

Second, notice which body of law is doing the work. These are privacy and wiretap claims brought by patients, not a HIPAA enforcement action brought by the government. HIPAA has no private right of action. State recording and privacy statutes frequently do. A practice can be entirely defensible under HIPAA and still be the defendant in this kind of case.

## Why "we have a BAA" does not reach this

The reflex answer, when any of this comes up, is that the vendor signed a Business Associate Agreement.

A BAA is necessary and it is not sufficient. It is a contract about how a business associate handles PHI. It does not grant you permission to record a person, and it does not create patient consent. The part that surprises people most: it usually does not cover every feature of the product it is attached to. Coverage tends to be scoped to specific service tiers and specific surfaces, with the integration and connector features carved out by name.

We wrote that up in detail already, including which AI vendor tiers can get a BAA at all and which features sit outside the covered surface even when one is signed. If you have not worked through your own tools at that level, [start there](https://www.rnits.com/blog/ai-security-questionnaire-guardrails-smb). It determines everything below.

## So what does compliance actually look like

Six things. None of them requires new software. All of them are configuration, writing, and one uncomfortable inventory.

### 1. A risk analysis that names your AI systems

This is the boring one that generates the fines.

The Security Rule has required an accurate, thorough risk analysis since it took effect, at 45 CFR § 164.308(a)(1)(ii)(A). Incomplete or missing risk analysis remains the single most frequently cited deficiency in OCR investigations. In 2025 OCR closed 21 settlements and civil monetary penalties, its second-highest annual total on record, collecting just over $8.3 million.

Nearly every risk analysis we read at a small practice was written before ambient AI existed and has not been touched since. It inventories the server, the workstations, the EHR, and the backup. It does not mention the scribe, Copilot, the AI feature in the billing portal, or the browser extension somebody installed.

An AI system that touches PHI is in scope. If it is not in the document, the document is not accurate, and "we did a risk analysis in 2023" is not a defense that survives contact with an investigator.

### 2. Minimum necessary, applied to the prompt

Here is the requirement almost nobody applies to AI, and it applies even when the BAA is perfect.

Under 45 CFR § 164.502(b), you disclose the minimum PHI necessary to accomplish the purpose. A signed BAA does not suspend that rule. So when a staff member pastes an entire twelve-page chart into an AI tool to get one lab value interpreted, that is a minimum-necessary problem regardless of what contract sits behind the tool.

This is a training issue with a concrete rule attached: ask the narrow question with the narrow data. It is also, usefully, the same habit that produces better output.

### 3. Audit controls that can answer "what went in"

45 CFR § 164.312(b) requires mechanisms that record and examine activity in systems containing PHI.

The test is simple and most practices fail it: if a patient asks what AI tools processed their information and what those tools received, can you produce an answer? For the scribe, that means knowing which encounters were recorded, where the audio went, how long it is retained, and whether it was used for anything besides your note. For general-purpose assistants, logging varies enormously by vendor and tier, and for some tools the honest answer is that the log does not contain the content at all.

Find out now, in writing, per tool. Discovering the gap during a patient complaint is the expensive version.

### 4. A consent moment that actually happens

A policy that says patients are informed is not the control. The control is the sentence a clinician says out loud at the start of the visit, every time.

Make it short enough to be said naturally, and make it ask for an answer rather than announce a fact:

> "I use an AI assistant that listens and drafts my notes so I can focus on you instead of the keyboard. It records our conversation. Is that all right with you?"

Then three operational requirements behind it. Someone records the answer in the chart. Declining is genuinely available and costs the patient nothing. And staff know what to do when a patient says no, which means the workflow has a functioning manual path, not a shrug and a recording anyway. A signed general notice at the front desk does not substitute for this, and a patient who never heard the microphone mentioned is exactly the plaintiff in the April complaint.

### 5. The vendor chain past the first vendor

Your scribe vendor is a business associate. The cloud it runs on is a subcontractor. The speech model it calls might be a fourth party.

Under 45 CFR §§ 164.308(b) and 164.502(e), those obligations flow down, and you are entitled to know the chain. Three questions get you most of the way: Who are your subprocessors for audio and text? Is our data used to train or improve any model, and if so, is that opt-out or opt-in? What is the retention period for the raw audio, and can we set it to zero?

Ask in email. Keep the reply. A vendor that cannot answer plainly has told you something.

### 6. A written breach-determination path

This is the one that saves a practice in a bad week.

PHI lands somewhere it should not. Pasted into a consumer AI tool, say, or captured by a scribe for a patient who declined. The question is whether that is a reportable breach. HIPAA does not treat every impermissible disclosure as one. Under 45 CFR § 164.402 you run a four-factor risk assessment: the nature and extent of the PHI, who received or used it, whether it was actually acquired or viewed, and how well the risk has been mitigated. If you cannot demonstrate a low probability of compromise, it is a breach and notification obligations start.

Write down who runs that analysis, what evidence they gather, and where the determination is filed, before you need it. Doing this for the first time under a deadline is how practices either over-report or, worse, quietly decide it was nothing.

## The 2026 mandate that is not actually law

You are going to get sold on this one, so it is worth being direct.

Vendors and consultants are marketing hard on the "new 2026 HIPAA Security Rule requirements": mandatory asset inventories, network mapping, the end of "addressable" controls. The [Notice of Proposed Rulemaking](https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information) is real. It published January 6, 2025, and the comment period closed that March.

It is not law. In the Fall 2026 Unified Agenda, HHS moved those amendments to its Long-Term Actions list, with anticipated final action in **July 2027**. That is a delay of more than a year from the previously floated timeline, and proposed rules change materially between proposal and final.

Two honest conclusions from that, and they point in opposite directions.

Do not buy anything today on the premise that a 2026 federal deadline is coming, because it is not. And do the asset inventory anyway, not because the NPRM might require it, but because you already need it for the risk analysis you are already obligated to have, and because you cannot answer a single question in this article without knowing which AI systems are running in your practice.

Anyone selling you urgency on a rule that is 11 months from a _proposed_ final action is telling you how they sell. That is the pattern our whole [HIPAA compliance work](https://www.rnits.com/services/hipaa-compliance-services) is built to push back on.

## What penalties look like now

The numbers moved this year, so if you are working from an older figure, update it.

Effective January 28, 2026, HHS applied its annual inflation adjustment. The four tiers now run: $145 to $73,011 per violation where the practice did not know and could not reasonably have known; $1,461 to $73,011 for reasonable cause; $14,602 to $73,011 for willful neglect corrected within 30 days; and $73,011 to $2,190,294 for willful neglect left uncorrected. The annual cap per violation category is $2,190,294.

The important structural detail is that tier depends on knowledge and correction, not on the size of the incident. A practice that finds a problem, documents it, and fixes it is in a different tier than one that was told and did nothing. Documentation is not paperwork here. It is the evidence that determines which row you land in.

## What to do this month

In the order we would tackle it:

1. **Inventory what is actually running.** Not a survey. Go look. Check the EHR's feature settings for ambient documentation, the Microsoft 365 admin center for Copilot license assignments, the credit card statement for AI subscriptions, and browser extensions on the front-desk machines.
2. **For each one, answer three questions in writing.** Does it touch PHI? Is there an executed BAA that covers the tier and features you use? Does it record audio?
3. **Fix the consent moment first** if anything records. It is the fastest change and the one with criminal exposure attached.
4. **Add the AI systems to your risk analysis.** If the document predates them, it is out of date by definition.
5. **Send the subprocessor and retention questions** to every AI vendor touching PHI. Keep the answers.
6. **Write the breach-determination page.** One page, named roles, four factors.
7. **Train once, specifically.** Twenty minutes on minimum necessary in prompts and what to do when a patient declines recording. Generic security awareness training does not cover either.

None of that is a project. It is a couple of afternoons, and every item is cheaper before you need it than during.

## Where we come in

The hard part of this work is not technical. It is that it sits between IT, clinical workflow, and law, and at a fifteen-person practice it lands on the office manager, who already has a full job.

That is the gap our [virtual CISO service](https://www.rnits.com/services/vciso) fills. A person who reads the vendor appendix, checks whether the control operates the way the policy claims, and tells you straight when the honest answer is "not yet." When AI governance needs to become actual written policy your staff will follow, that is [AI governance](https://www.rnits.com/services/ai-governance) work, and it is usually one page shorter than you expect. Neither one requires a platform.

We are also not going to tell you to rip out the scribe. Clinician burnout is a real operational risk, and ambient documentation is one of the few tools that measurably helps. The goal is to run it in a way that survives a patient question, an OCR inquiry, and a plaintiff's lawyer, which mostly means announcing it, scoping it, logging it, and writing down what you decided.

RNITS is an IT and cybersecurity company in Tyngsboro, Massachusetts, working with small medical, dental, and behavioral health practices across New Hampshire and Massachusetts. Onsite within about 150 miles, remote nationally.

If AI has already arrived in your practice and nobody has mapped it, [get in touch](https://www.rnits.com/contact) and we will go through the actual systems, tiers, and consent language with you.

The Rnits Company. The un-MSP. (978) 226-8931.

---

**RNITS** — New Hampshire & Massachusetts (onsite within 150 miles of Tyngsboro, MA); remote support nationwide

RNITS (The Rnits Company) · 404 Middlesex Road, Suite 9, Tyngsboro, MA 01879 · (978) 226-8931 · info@rnits.com

Contact: https://www.rnits.com/contact · Free cyber security audit: https://www.rnits.com/free-cyber-security-audit
