Free for a week, then $19 for your first month
Expert Advice

Passing a Security Review With an Embedded AI Scribe

Embed an AI scribe and its security posture enters every enterprise deal you run. The artifacts, contract rights and termination terms to arrange first.

A magnifying glass with a line of scrutiny passing straight through a platform's own product and continuing to a faded vendor panel behind it.

When you embed an AI scribe in a product you sell to health systems, your vendor stops being your private implementation detail. Under HIPAA the scribe becomes your subcontractor, you are required to obtain written assurances from it, and you remain accountable for its compliance. In practice that means its security posture is now answered for in your security review, by you.

Most platforms discover this in the middle of an enterprise deal, when a questionnaire arrives asking where session audio is stored and nobody on the call knows.

You Are Accountable for Your Vendor's Posture

Selling documentation software to a covered entity generally makes you a business associate. Embedding another company's scribe underneath makes that company your subcontractor — and under the HIPAA Omnibus Rule, subcontractors are business associates in their own right.

The operative requirement is that a business associate must obtain satisfactory assurances, in writing, that any subcontractor handling PHI on its behalf will apply the same restrictions and conditions that apply to the business associate itself. Accountability does not transfer with the work.

The structural point
You cannot answer a security review by pointing at your vendor. The reviewer's contract is with you, their remedy is against you, and the assurances they are asking about are ones you are separately obliged to hold.
The HIPAA chain when a platform embeds an AI scribe: the covered entity holds a BAA with the platform as business associate, which holds a BAA with the scribe vendor as subcontractor, while accountability flows back to the platform in the middle.

The Artifacts to Have Before the First Review

Enterprise security reviews are largely document requests. The deals that move are the ones where the answers already exist in a folder:

Artifact

Who produces it

Usually requested

Subprocessor list, including your scribe vendor

You

Almost always, early

Data flow diagram showing where audio and PHI travel

You

Almost always

Executed BAA between you and your vendor

Both

Almost always

Vendor's independent security report (SOC 2 Type II, HITRUST or equivalent)

Vendor

Frequently, and under NDA

Vendor's penetration test summary

Vendor

Frequently

Retention and deletion policy for audio and transcripts

Vendor, restated by you

Frequently, and it stalls deals

Incident response and breach notification plan across the chain

Both

Increasingly common

Evidence of encryption in transit and at rest

Vendor

Almost always

Note the middle column. Half of these are not yours to produce, which is exactly why they take weeks if you have not arranged access in advance.

Security review artifacts split by who produces them. The platform produces the subprocessor list and data flow diagram; the vendor produces the independent security report, penetration test summary, retention and deletion policy, and encryption evidence; the BAA and incident response plan come from both.

The Questions That Actually Stall Deals

Security reviewers are not usually trying to fail you. Deals stall on a small set of questions that platforms cannot answer about somebody else's system:

  • Where is session audio stored, in what region, and for how long?
  • Is customer data used to train or improve the vendor's models, under any circumstances?
  • Who at the vendor can access PHI, under what controls, and is that access logged?
  • Can data be deleted on request, and what is the verified completion time?
  • What happens to PHI held by the vendor when our contract with you ends?
The answer that costs you the quarter
"We'll need to ask our vendor." Reviews are rarely lost on a bad answer. They are lost on a slow one, because a two-week round trip through a third party turns a scheduled review into a stalled deal.

What to Require Contractually So You Can Answer

The time to secure these is at contract, not during a review. None is unusual, and a partner team that resists all of them is telling you something:

  • The right to receive the vendor's current independent security report annually, under NDA.
  • Advance notice of changes to the vendor's own subprocessors, with a right to object.
  • Committed support for your security questionnaires, with a stated response window.
  • A defined breach notification window that is shorter than your own obligation to your customers, so the chain does not run out of time above you.
  • Documented deletion on request, with confirmation you can pass to your customer.

Termination Is the Clause Everyone Skips

Reviews increasingly ask what happens at the end, and it is the question platforms answer worst. When your customer leaves, or when you change scribe vendors, PHI is sitting in a third party's systems under an agreement your customer never signed.

Settle three things in writing: what is returned, what is destroyed, and on what timeline — plus who certifies that it happened. A termination clause that says data will be "returned or destroyed" without specifying which, by when, or with what evidence is a clause you cannot pass to a security reviewer.

Bottom Line

Embedding an AI scribe imports a second company's security posture into every enterprise deal you run. That is a manageable cost if the artifacts, contractual rights and termination terms are arranged before the first questionnaire arrives, and an expensive one if they are arranged during it.

The practical test for any vendor, Twofold included: ask for the subprocessor list, the retention policy and the deletion timeline. If those take more than a day to produce for you, they will take longer when a health system asks.

General guidance, not legal advice
Whether you are a business associate, and what your agreements must contain, depends on your specific arrangement. Confirm with counsel rather than relying on the summary here.

Sources

  • U.S. Department of Health and Human Services. 45 CFR 164.502 — Uses and disclosures of protected health information. eCFR. Source for the requirement at 164.502(e)(1)(ii) that a business associate obtain satisfactory assurances from a subcontractor.
  • U.S. Department of Health and Human Services. 45 CFR 164.308 — Administrative safeguards. eCFR. Source for the parallel Security Rule requirement at 164.308(b)(2).
  • U.S. Department of Health and Human Services. Business Associates guidance. Source for the treatment of subcontractors as business associates following the 2013 Omnibus Rule.
  • The artifact list and contractual terms described here reflect common enterprise healthcare procurement practice rather than a regulatory checklist. Requirements vary by customer; treat this as a starting point for your own review readiness.
  • General guidance, not legal advice. Whether you are a business associate, and what your agreements must contain, depends on your specific arrangement — confirm with counsel.
FAQ

Frequently asked questions

  • Does an embedded AI scribe vendor need its own BAA?

    Yes. If you are a business associate and you embed another company's AI scribe to handle PHI on your behalf, that company is your subcontractor. Under 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2) you must obtain satisfactory assurances in writing that the subcontractor will apply the same restrictions and conditions that apply to you. Since the 2013 HIPAA Omnibus Rule, subcontractors are themselves business associates, and the primary business associate retains accountability for the subcontractor's compliance.

  • What documents does a health system security review ask for?

    Commonly: a subprocessor list, a data flow diagram showing where audio and PHI travel, the executed BAA with your vendor, the vendor's independent security report such as SOC 2 Type II or HITRUST, a penetration test summary, the retention and deletion policy for audio and transcripts, evidence of encryption in transit and at rest, and an incident response plan spanning the chain. Roughly half of these are produced by your vendor rather than by you, which is why access to them should be arranged contractually in advance.

  • Why do security reviews stall on embedded AI vendors?

    Because of answer latency rather than bad answers. Reviewers ask where session audio is stored and for how long, whether customer data trains the vendor's models, who at the vendor can access PHI, whether data can be deleted on request, and what happens to PHI at termination. A platform that has to relay each question to a third party turns a scheduled review into a multi‑week round trip. Securing questionnaire support and a stated response window in the vendor contract is what prevents this.

  • What happens to PHI when you stop using an embedded AI scribe?

    That depends entirely on your termination clause, and it is the term most often left vague. When a customer leaves or you change vendors, PHI may sit in a third party's systems under an agreement your customer never signed. Specify what is returned, what is destroyed, on what timeline, and who certifies completion. A clause stating data will be "returned or destroyed" without naming which, by when, or with what evidence is not something you can hand to a security reviewer.