
AI Scribes in Clinical Documentation: The Privacy Questions to Ask First
Ambient recording of consultations is genuinely useful and creates a new category of sensitive data. What to settle before deployment.
GuardsArm Team
Security Experts

Ambient AI documentation — a device listening to a clinical encounter and drafting the note — is among the fastest adoptions healthcare has seen, and for good reason. Documentation burden is a genuine driver of clinician burnout, and these tools address it directly.
They also create something that did not previously exist: a recording of the consultation, processed by a third party. That is a new category of sensitive data, and the questions below should be settled before deployment rather than after.
Consent
A recording of a clinical encounter captures the patient's words, the clinician's words, and frequently third parties in the room. Settle:
- How is the patient informed, and by whom? Posted notice, verbal explanation, or documented consent?
- Can the patient decline, and does declining actually work in practice — can the clinician proceed without it?
- How is a refusal recorded, so it is honoured at the next visit?
- What about sensitive encounters — mental health, sexual health, child protection, intimate partner violence — where recording may change what a patient is willing to say?
That last point is the most important and the least discussed. A patient who knows the room is being recorded may withhold information, and that is a clinical harm, not just a privacy consideration. Some encounter types warrant a default of not recording.
The questions to put to the vendor
Audio retention is the critical one. Is the recording retained after the note is produced, for how long, and can you require deletion? A vendor holding recordings of consultations indefinitely is a materially different risk from one that transcribes and discards.
Training use. Is your data used to improve their models? This should be contractually prohibited for identifiable health information, and "de-identified for training" needs examining rather than accepting — de-identification of free-text clinical speech is harder than it sounds.
Residency and sub-processors. Where is audio processed and stored, and who else is in the chain? For Canadian custodians this interacts directly with provincial obligations — see Alberta HIA and Quebec Law 25's transfer rules, under which processing outside the province is itself a trigger.
Access. Who at the vendor can listen to recordings, under what circumstances, and is that access logged and available to you?
Accuracy is a safety issue
A generated note is a clinical document. Errors in it become part of the record and inform later care.
Practical requirements:
- Clinician review and attestation before the note enters the record — non-negotiable
- A workable review process, because a tool that produces a long note the clinician skims defeats its own safety model
- Awareness of failure modes, including fabricated detail and misattributed speech in multi-speaker encounters
- Accent, dialect and language performance, which varies and should be evaluated against your actual patient population rather than a vendor benchmark
- A correction route when an error is found after filing
Agreements and assessments
Before deployment:
- A business associate agreement or the provincial equivalent, covering the vendor as a processor of health information
- A privacy impact assessment — in Alberta this must be submitted to the Commissioner before implementation, which is calendar time your project plan must carry
- A security assessment of the vendor, proportionate to the sensitivity. See AI vendor risk
- Clarity on ownership of recordings and transcripts, and what happens to them if you terminate
Where to start
Ask the vendor one question in writing: is the audio retained after the note is generated, and can we require its deletion? The answer tells you what kind of product you are buying and determines nearly every downstream privacy question.
GuardsArm assesses clinical AI deployments and supports the privacy work around them. See healthcare solutions or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


