Should your AI scribe keep session audio? Questions to ask any vendor
AI therapy notes privacy starts with one question: what happens to the audio? Nine questions to send any scribe vendor, and what a real answer sounds like.
7 min read
An AI scribe listens to your sessions. That one fact separates it from every other tool in your practice, and it means AI therapy notes privacy is a question about audio handling before it is a question about anything else. Vendor security pages tend to answer around it. They will tell you data is encrypted in transit and at rest, which is true of almost every product sold today, and say nothing about whether a recording of your patient describing the worst week of their life is sitting on a server in Virginia.
Here are the questions worth asking, with a note on what a real answer sounds like. You can paste them into an email and read the reply in five minutes. A vendor who has thought about this will answer in specifics. A vendor who has not will answer in adjectives.
Where does the audio actually go?
Ask whether transcription happens on infrastructure the vendor controls or gets forwarded to a third-party speech API. This single answer determines how many companies end up holding your patient’s voice.
A vendor running its own models can tell you which servers, in which region, under whose cloud account, without checking. A vendor calling out to a large speech provider owes you a longer answer: the subprocessor’s name, its retention policy, and confirmation that a BAA covers that leg of the trip. Neither setup disqualifies a product. Vagueness about which one they run does.
Worth adding to the same email: is there a public subprocessor list, and do you get notice before it changes?
Is the audio stored, and for how long?
“We delete audio after processing” and “we retain audio for 30 days” are both defensible policies. They are also very different policies. The second one creates a window in which a breach, a subpoena, or a misconfigured storage bucket exposes recordings rather than text.
If a vendor retains audio, ask why. Sometimes the reason is good: they let a clinician replay a passage when the draft note reads wrong. Sometimes the reason is that nobody got around to writing the deletion job. You want three things back: the reason, the retention period in days, and whether your practice can shorten it or turn it off.
Who inside the vendor can listen to it?
Every company has some path by which an engineer can reach production data. The useful question is whether that path is logged, approved, and rare. Ask what a support engineer sees when you file a ticket about a bad note. Ask whether staff access to customer content generates an audit record, and whether you can request that record for your own practice.
“Nobody can access it” is usually not true, and a vendor who says it either has not looked or is telling you what they think you want to hear. “Two people on the on-call rotation, with a logged break-glass procedure” is a better answer than a stronger claim that turns out to be soft.
Is patient audio used to train models?
Ask this in two parts, because vendors often answer only the first. One: do you train models on customer audio or transcripts, including for quality improvement? Two: does any subprocessor you send data to reserve the right to do so under its standard terms?
Business tiers from the major AI providers generally exclude API traffic from training by default. “Generally” and “by default” are both doing work in that sentence. A vendor who understands their own stack can point at the contract language rather than at a blog post.
Will they sign a BAA, and what does it say?
A signed BAA is table stakes, and it is also the document most people accept without reading. HHS publishes sample provisions that make a decent reference while you read theirs. Two clauses repay the attention. The first is the breach notification window: some BAAs promise notice “without unreasonable delay” and others commit to a specific number of days, and you are the one on the hook for notifying patients. The second is what happens when you leave, including how long they keep your data, what export format you get, and whether deletion happens automatically or only on written request.
If a vendor declines to sign because their tool “only processes de-identified data,” slow down. Session audio is about as identifiable as data gets.
What happens if someone subpoenas the audio?
Practices ask this less often than they should, usually because it feels remote right up until a custody case lands on the calendar. The underlying fact is simple: a vendor can only produce what it holds. If audio is deleted once the draft note exists, there is no recording to hand over, and the conversation moves to the note itself, where your clinical judgment and normal documentation standards apply.
Ask for the vendor’s written policy on civil and government legal requests, whether they notify the customer before producing anything, and whether they publish a transparency report. Small vendors often have no report. A written policy is a reasonable substitute; nothing at all is not.
Can a patient say no to just one session?
Consent captured once at intake is thin consent. A patient who agreed to AI notes in March may not want them in the session where they finally talk about the thing they have spent four months avoiding. The tool should let a clinician switch the scribe off for that hour on the spot, with no form to file and nothing in the interface nudging them back on.
Easy to miss during a demo: is the scribe on unless someone turns it off? Defaults are the real policy of most software. A product where AI notes are opt-in per session produces a very different consent record from one that runs automatically and relies on the clinician remembering.
What does deletion actually mean?
“Deleted” can mean the object is gone from storage, or it can mean a row got flagged and the underlying file leaves backups sometime in the next 35 days. Both are ordinary engineering. Only one of them matches what your patient heard you say.
Three follow-ups: how long does deleted audio persist in backups and logs, are transcripts deleted alongside the audio or kept indefinitely, and is any part of the session content retained for analytics after the note is signed? Usage metadata like minute counts is fine and normal. Content is a different question.
How Valence handles AI therapy notes privacy
Since we are asking you to interrogate vendors, here are our answers in the same order. Transcription runs on our own servers using a self-hosted Whisper-class model, so audio does not leave our infrastructure for a third-party speech API. The audio is processed into a draft and then deleted. We do not store it, and we do not train on it. Sessions are not recorded by default. AI notes are opt-in per session, so a clinician can leave the scribe off for one hour and turn it on for the next. Every note comes back marked as a draft that a clinician reads, edits, and signs. We sign BAAs.
Two structural choices sit behind that. Each practice gets its own database schema rather than a shared table with a practice ID column, and the audit log is on by default rather than sold as an upgrade. Providers see their own caseload; patients see only their own record.
The email you can send this week
Copy this, fill in the vendor name, and send it. It is nine questions, and a vendor who knows their own stack can answer all of them in a single reply without involving a lawyer.
- Where is session audio transcribed: on your own infrastructure, or via a third-party API? If third party, which one?
- Is audio stored after the note is generated? For how many days?
- Who at your company can access session audio or transcripts, and is that access logged?
- Do you or any subprocessor use customer audio or transcripts to train models?
- Will you sign a BAA, and what is your breach notification window?
- What is your policy for responding to subpoenas and law enforcement requests, and do you notify us first?
- Can a clinician disable the scribe for a single session, and is recording on by default?
- When audio is deleted, how long does it survive in backups and logs?
- What happens to our data if we cancel: export format, retention period, deletion process?
If a reply comes back in marketing language, ask again and name the specific item you did not get. The second answer is usually the real one, and a vendor who cannot produce it by the second try has told you something useful.
The same questions apply to every other vendor touching patient data, not only the scribe: the HIPAA checklist for a solo practice.