HIPAA BAA checklist for an AI therapy scribe

Yes, under the federal Health Insurance Portability and Accountability Act (HIPAA), an AI therapy scribe needs a signed HIPAA business associate agreement (BAA) before it processes a single session. Any vendor that receives, stores, or transmits protected health information (PHI) on behalf of your practice is a business associate under HIPAA, and the law requires a written BAA before that relationship begins. Purpose built AI therapy scribes generally sign BAAs. Consumer AI tools generally do not, no matter what their marketing says.
This checklist walks through the eight things to verify before you trust an AI scribe with session data, written for therapists and practice owners evaluating tools in 2026.
The short version
Any AI scribe handling PHI as part of its service to you as a covered entity is a HIPAA business associate and must sign a BAA with your practice before use. A "HIPAA compliant" badge is not the same as a BAA: make sure to sign the actual contract. There are eight things to check: the BAA itself, audio retention, transcript retention, AI training policy, sub-processors, deletion on termination, independent security evidence, and 42 CFR Part 2 if you treat substance use disorders. Psychotherapy notes carry extra protections under 45 CFR 164.501 that many general healthcare AI scribes were never designed around. Understand how your PHI is handled and how to export it if you stop using the vendor, and confirm you can retrieve usable records before real PHI enters the system. Upheal processes PHI of covered entities under its own BAA (effective March 25, 2026), and providers accept the BAA during signup, before any PHI enters the platform.
Do AI therapy note tools sign HIPAA business associate agreements?
Established AI therapy scribes sign a BAA before you share any client PHI, as HIPAA requires. Not all AI tools do, and that difference is the line between a compliant workflow and an impermissible disclosure. The U.S. Department of Health and Human Services (HHS) identifies vendors that handle PHI on a practice's behalf, including transcription and cloud services, as business associates that require a BAA. Read the definition in HHS's business associate guidance.
A "HIPAA compliant" claim does not necessarily mean a BAA is in place:
| "HIPAA compliant" marketing claim | Signed BAA |
|---|---|
| A self description with no legal weight on its own | A binding contract required by federal law |
| Cannot be enforced if the vendor mishandles PHI | Obligates the vendor to safeguard PHI and report breaches |
| Often appears on consumer tools that will not sign a BAA | Only exists if the vendor actually executes it with your practice |
| Verified by reading a website | Verified by a countersigned document in your records |
If a vendor advertises HIPAA compliance but will not execute a BAA with your practice, it is not a HIPAA compliant choice for session data. That single question filters out many consumer AI tools. For example, ChatGPT Free, Plus, and Business have no BAA option as of September 2026, which is why pasting session content into them is a HIPAA violation. We covered the version by version picture in is ChatGPT HIPAA compliant.
It is also important to check the scope of the BAA your usage falls under. A BAA can exist while excluding a product, feature, or account type you plan to use, so confirm the named legal entity and the specific service are covered before connecting the tool.
The 8 point BAA checklist for evaluating an AI therapy scribe
A signed BAA is the entry ticket, not the finish line. These eight checks cover what the agreement and the vendor's data practices need to say before PHI flows.
- A BAA is signed before any PHI is shared. The agreement must be executed before the first session is recorded or uploaded, not after a trial period. The cleanest version builds acceptance into signup itself; either way, keep the countersigned copy in your vendor file.
- Audio data retention is stated, specific, and short. The vendor should say exactly what happens to session audio after your note is generated, including whether deletion is the default and whether you control any exceptions.
- Transcript and note data retention are defined separately from audio. Transcripts are PHI even after the audio is gone. Check how long transcripts persist, where they are stored, and how you delete them. Your clinical record retention obligations are yours: the vendor's defaults do not replace your state's retention rules.
- AI model training on session data is prohibited or strictly consent gated. The BAA or the vendor's binding terms should state in writing whether session data can train AI models. "Service improvement" and "model training" are not the same thing, so require the documents to distinguish them and to say which data, if any, is de-identified first.
- Sub-processors are disclosed, including the underlying AI model provider(s). Your PHI does not stop at the AI scribe vendor. HIPAA requires the business associate to bind every subcontractor that touches PHI to the same restrictions, so make sure your contract covers who handles model inference, storage, and support, and how you are informed about changes.
- Deletion and return of data on termination are contractual. The BAA should state what happens to your practice's data when you leave: returned or destroyed, at whose choice, on what timeline, and whether sub-processor copies are included. Test the export with synthetic data before you rely on it.
- Security evidence goes beyond the HIPAA claim. HHS does not certify or endorse any product as HIPAA compliant, so a vendor claiming HIPAA certification is overstating it. Ask instead for independent evidence such as a SOC 2 Type II report or HITRUST certification, and check whether security testing is ongoing rather than a one time audit.
- 42 CFR Part 2 is addressed if you treat substance use disorders. Records from Part 2 programs carry consent and disclosure rules beyond HIPAA. If that is your caseload, confirm the vendor understands Part 2 before any record touches the tool.
A vendor that answers all eight in writing is doing this properly. A vendor that answers only the first is asking you to take the rest on faith. For a broader look at how AI scribes handle data, see our guide to the privacy of AI notetakers.
Psychotherapy notes get extra protection under HIPAA
HIPAA treats psychotherapy notes as a specially protected category, separate from the rest of the medical record, under 45 CFR 164.501. Psychotherapy notes are a clinician's private analysis of a conversation, kept apart from the official record, and most uses or disclosures require the client's specific authorization under 45 CFR 164.508(a)(2).
This matters when choosing a scribe because a tool built for general healthcare documentation likely has no concept of that separation. An AI scribe built for mental health should keep psychotherapy notes distinct from progress notes, so that specially protected psychotherapy notes never mix into the record that gets shared with payers or other providers, or disclosed in response to a subpoena. When you evaluate a tool, ask where psychotherapy notes are stored, who can access them, and whether they are excluded from anything the vendor processes for other purposes.
Can AI scribes stay HIPAA compliant during video sessions?
Yes, AI scribes can stay HIPAA compliant during video sessions when the telehealth platform and the scribe both operate under BAAs and the client has consented to recording. Compliance in a video session has three layers: the video platform handling the call, the scribe processing the audio, and your own consent process with the client.
Recording consent is where practices most often slip. HIPAA governs how PHI is protected, but whether you can record the conversation at all is a matter of state law, and several states require consent from all parties to a recording. Get written client consent before the first recorded session regardless of your state, both because it may be legally required and because it is the ethically defensible standard for therapy. The consent conversation also builds trust: clients who understand what the tool does, and that they can decline, engage with it more openly.
If your scribe and telehealth run in one platform under one BAA, you also remove a handoff between vendors, which is one less sub-processor chain to verify.
What a BAA does not do
A BAA does not make your use of an AI scribe HIPAA compliant by itself. It binds the vendor, not your own workflows as a provider. Four things stay your responsibility no matter what the vendor signs:
- Client consent. No BAA replaces informing your clients that an AI tool is part of their care and documenting their agreement. Our AI therapy note consent form guide covers what the form should include, with a sample template.
- Minimum necessary judgment. You decide what goes into the tool. A BAA does not cover oversharing on your side.
- Your own review of the output. AI generated notes are drafts until a clinician reviews and signs them. The BAA does not make the note clinically yours.
- Your security risk assessment. HIPAA expects the practice to assess its own risks, and a vendor contract is one control inside that assessment, not a substitute for it.
Treat the BAA as the floor of the relationship and your consent and documentation practices as the part only you can supply.
How Upheal handles the BAA
Upheal, an AI-native electronic health record (EHR) and note-taking platform for mental health clinicians, publishes its full Business Associate Agreement, effective March 25, 2026, so you can read every clause before sharing anything. Providers accept the BAA during signup, which means the agreement exists before any PHI enters the platform, and one agreement covers the providers in your practice. Keep the copy from your welcome email in your vendor file.
Against the checklist above, as of September 2026:
- Upheal signs a BAA with every practice, accepted at signup before any session data flows.
- Session audio is deleted by default once your notes are generated.
- Upheal does not use session data to train AI unless you and your client both choose it, and consent can be withdrawn at any time. Under the BAA, Upheal will use only de-identified, aggregated, anonymous information to improve the application, and Upheal will not receive direct or indirect remuneration in exchange for any PHI under any circumstances.
- Sub-processors are bound in writing to the same restrictions that apply to Upheal, and third parties that handle session data are barred from logging it or using it to train their own AI.
- On termination, PHI is returned or destroyed at your choice, including PHI held by sub-processors.
- Upheal is HIPAA, PHIPA, PIPEDA, GDPR, and DPA compliant, has completed a SOC 2 Type II audit, and is continuously externally tested.
The full detail, including safeguards and data handling, is on Upheal's privacy and compliance page. Because Upheal combines telehealth, notes, and the clinical record in one platform, the video call and the scribe operate under a single BAA rather than a chain of vendors.
If you want to see how BAA covered AI notes work in practice, try Upheal free.
Frequently asked questions
Is AI note-taking covered under a BAA?
AI note-taking requires a BAA, and it is covered only when the vendor executes one with your practice. The BAA must exist before PHI is shared, and it should name what the vendor may do with audio, transcripts, and notes. Without a signed BAA, using an AI scribe with session data is considered an impermissible disclosure under HIPAA.
Can AI scribes stay HIPAA compliant during video sessions?
Yes, when the video platform and the scribe both operate under BAAs and the client has consented to recording. State recording laws apply on top of HIPAA, and several states require all party consent, so we recommend securing written client consent before the first recorded session.
Is a BAA enough to make an AI scribe HIPAA compliant?
No. A BAA is necessary under HIPAA but not sufficient on its own, and state privacy law can add further requirements. The BAA binds the vendor to safeguard PHI, but your practice still owns client consent, minimum necessary judgment, a security risk assessment, and clinical review of every AI generated note.
Does a free AI note tool still need a BAA?
Yes, price has no bearing on business associate status. A free tool that processes session audio or notes handles PHI and therefore needs a signed BAA just like a paid one. Free consumer AI tools that will not sign a BAA are not compliant options for session data.
What should a BAA with an AI scribe include?
A BAA typically includes, at a minimum: permitted uses of PHI, safeguards, breach and incident reporting, sub-processor obligations, patient rights support, and return or destruction of PHI on termination. This list is not exhaustive. Strong vendors may add specifics on audio retention, transcript retention, and AI training in the BAA or binding terms, so that the eight checks above are contractual rather than promises.
Does Upheal provide a BAA?
Yes, Upheal publishes its BAA, effective March 25, 2026, and providers accept it during signup. The agreement covers the practice, requires return or destruction of PHI at the customer's choice on termination including sub-processor copies, and bars Upheal from receiving any remuneration for PHI.
The bottom line
A BAA is an essential contractual agreement for any covered entity using an AI scribe. Asking for it is the fastest way to separate AI tools built for clinical work from tools that were not. Ask for the agreement first, then work through audio, transcripts, training, sub-processors, deletion, security evidence, and Part 2. And read the exit clause hardest of all: a vendor's security promises matter less if you cannot retrieve usable records when you leave. A vendor with nothing to hide will answer all eight in writing.
Upheal's published BAA covers the contractual side of this checklist, and our privacy and compliance page covers the rest, so you can read both before you sign up. Start free, no credit card required.
Last updated September 22, 2026.

.avif)
.avif)