When you embed an AI scribe in a product you sell to health systems, your vendor stops being your private implementation detail. Under HIPAA the scribe becomes your subcontractor, you are required to obtain written assurances from it, and you remain accountable for its compliance. In practice that means its security posture is now answered for in your security review, by you.
Most platforms discover this in the middle of an enterprise deal, when a questionnaire arrives asking where session audio is stored and nobody on the call knows.
You Are Accountable for Your Vendor's Posture
Selling documentation software to a covered entity generally makes you a business associate. Embedding another company's scribe underneath makes that company your subcontractor — and under the HIPAA Omnibus Rule, subcontractors are business associates in their own right.
The operative requirement is that a business associate must obtain satisfactory assurances, in writing, that any subcontractor handling PHI on its behalf will apply the same restrictions and conditions that apply to the business associate itself. Accountability does not transfer with the work.

The Artifacts to Have Before the First Review
Enterprise security reviews are largely document requests. The deals that move are the ones where the answers already exist in a folder:
Artifact | Who produces it | Usually requested |
|---|---|---|
Subprocessor list, including your scribe vendor | You | Almost always, early |
Data flow diagram showing where audio and PHI travel | You | Almost always |
Executed BAA between you and your vendor | Both | Almost always |
Vendor's independent security report (SOC 2 Type II, HITRUST or equivalent) | Vendor | Frequently, and under NDA |
Vendor's penetration test summary | Vendor | Frequently |
Retention and deletion policy for audio and transcripts | Vendor, restated by you | Frequently, and it stalls deals |
Incident response and breach notification plan across the chain | Both | Increasingly common |
Evidence of encryption in transit and at rest | Vendor | Almost always |
Note the middle column. Half of these are not yours to produce, which is exactly why they take weeks if you have not arranged access in advance.

The Questions That Actually Stall Deals
Security reviewers are not usually trying to fail you. Deals stall on a small set of questions that platforms cannot answer about somebody else's system:
- Where is session audio stored, in what region, and for how long?
- Is customer data used to train or improve the vendor's models, under any circumstances?
- Who at the vendor can access PHI, under what controls, and is that access logged?
- Can data be deleted on request, and what is the verified completion time?
- What happens to PHI held by the vendor when our contract with you ends?
What to Require Contractually So You Can Answer
The time to secure these is at contract, not during a review. None is unusual, and a partner team that resists all of them is telling you something:
- The right to receive the vendor's current independent security report annually, under NDA.
- Advance notice of changes to the vendor's own subprocessors, with a right to object.
- Committed support for your security questionnaires, with a stated response window.
- A defined breach notification window that is shorter than your own obligation to your customers, so the chain does not run out of time above you.
- Documented deletion on request, with confirmation you can pass to your customer.
Termination Is the Clause Everyone Skips
Reviews increasingly ask what happens at the end, and it is the question platforms answer worst. When your customer leaves, or when you change scribe vendors, PHI is sitting in a third party's systems under an agreement your customer never signed.
Settle three things in writing: what is returned, what is destroyed, and on what timeline — plus who certifies that it happened. A termination clause that says data will be "returned or destroyed" without specifying which, by when, or with what evidence is a clause you cannot pass to a security reviewer.
Bottom Line
Embedding an AI scribe imports a second company's security posture into every enterprise deal you run. That is a manageable cost if the artifacts, contractual rights and termination terms are arranged before the first questionnaire arrives, and an expensive one if they are arranged during it.
The practical test for any vendor, Twofold included: ask for the subprocessor list, the retention policy and the deletion timeline. If those take more than a day to produce for you, they will take longer when a health system asks.
