HIPAA compliant AI is any AI tool that handles Protected Health Information under a signed Business Associate Agreement, protects that information in transit and at rest, retains only what it needs, and never trains its models on patient data. The label is not automatic and no certification grants it. It applies the same way to an AI scribe that listens to visits and to an AI assistant that drafts letters or summarizes records.
An AI medical scribe can be HIPAA compliant, but the label is not automatic. Compliance depends on specific, checkable things: whether the vendor will sign a Business Associate Agreement, how Protected Health Information is protected in transit and at rest, how little is retained, and whether patient content is kept out of AI model training. Here is what each requirement means and how ClinicFrame answers it.
What makes an AI medical scribe HIPAA compliant?
| Requirement | ClinicFrame |
|---|---|
| Signed BAA | Included with every account, on every plan, not gated to enterprise |
| Audio retention | None; audio is processed live and discarded, only the transcript persists |
| Training on patient data | Never; providers operate under agreements that exclude customer content |
| Access and auditability | Your account only; sessions carry an audit trail, deletions are recoverable |
| Infrastructure | HIPAA-compliant |
How do you check whether an AI tool is HIPAA compliant?
Five questions settle most cases. Ask them of any AI scribe, note taker or assistant before patient information goes in, and expect written answers.
- Will you sign a BAA, and on which plan? A BAA gated to an enterprise tier means the advertised price is not the price of compliant use.
- What happens to the audio and the transcript? How long each is kept, where, and who can delete it.
- Is patient content used to train models? Yours or a third party's. The answer has to be no, in the contract, not in a blog post.
- Who can access the data? Inside the vendor, inside their providers, and inside your own account, with an audit trail.
- Where does the processing run? Encryption in transit and at rest is the floor; the vendor should name the infrastructure and its compliance posture.
Which ClinicFrame tools are HIPAA compliant AI?
Both products on the platform, under one account and one BAA. ClinicFrame Scribe is the ambient AI medical scribe: it listens to the visit, runs real-time medical transcription, writes the note and discards the audio. CompliantChatGPT is the HIPAA-compliant AI assistant for the work between visits, with PHI anonymization built in. The requirements in the table above hold for both; see how PHI is protected for the infrastructure detail.
Why is a BAA the first thing to check with any AI scribe vendor?
A Business Associate Agreement is the contract that makes a vendor legally accountable for PHI. If an AI scribe will not sign one, using it with patient information is a compliance problem regardless of its features. If it only signs on the enterprise tier, then the advertised entry price is not the real price of compliant use. ClinicFrame includes a BAA with every account. For what the agreement should cover and why enterprise-gating it is a red flag, see BAAs for AI medical scribes.
Is ClinicFrame a HIPAA-compliant AI note taker for therapy?
Yes. The same compliance holds when ClinicFrame is used as an AI note taker for behavioral health: a BAA on every account, audio that is never stored, and no training on patient content. It generates DAP and BIRP session notes, and for telehealth no bot joins the call, so the client sees only you. See AI progress notes for therapists.
What does HIPAA compliance not take off your plate?
HIPAA governs the tool and the vendor; your professional documentation duties remain yours. Two habits keep you on the right side of both: review every note before it enters the record, and obtain patient consent for recording where your state requires it. See patient consent for AI scribes and how audio and PHI are handled.

