Business associate agreements for AI scribes in 2026: what the paperwork covers

By Kyle Nelson, Founder, Fazit

By Fazit's founder, not a lawyer.

If you searched for "business associate agreement ai scribe", the short answer is yes if the AI scribe creates, receives, maintains, or transmits PHI for a HIPAA covered entity. A business associate agreement controls what the vendor may do with PHI, but it does not mean the client session stayed inside your practice or that no audio record was created.

The legal statements below rely on HHS primary sources. This is not legal advice, and consent and professional conduct duties apply to the person running the call.

Does an AI scribe need a business associate agreement?

HHS's business associate guidance says a business associate generally performs functions or provides services for a covered entity that involve creating, receiving, maintaining, or transmitting protected health information. If your AI scribe processes a clinical encounter, drafts a therapy note from a session, or summarizes a patient call that includes PHI, that is the fact pattern HHS is describing.

HHS's covered entity guidance says a covered entity that engages a business associate to help carry out health-care activities must have a written business associate contract or other arrangement specifying the engagement and requiring HIPAA protections for PHI. In a normal workday, that means a therapist using a cloud scribe for a telehealth intake should be asking for the vendor's BAA before the first patient session enters that system.

HHS's cloud computing guidance is even plainer for hosted software. A cloud service provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate, and the covered entity and cloud service provider must enter into a HIPAA-compliant BAA. If the AI scribe streams session audio to cloud transcription and stores a transcript in the vendor account, the agreement is the document that governs that vendor relationship.

That is why our earlier post on a HIPAA-compliant AI notetaker starts with the paperwork instead of the marketing label. HHS gives the rule: when a vendor handles ePHI for you, the BAA is part of the arrangement.

What does a BAA cover for an AI scribe?

HHS's business associate guidance says a BAA must describe the permitted and required uses and disclosures of PHI by the business associate. It must require the business associate not to use or further disclose PHI except as permitted by the agreement or required by law. If the business associate performs a covered entity's obligations under the HIPAA Privacy Rule, the BAA must require the business associate to comply with the applicable Privacy Rule requirements.

For an AI scribe, that should push your review toward the data path. Ask what the vendor receives during the call, what it stores after the call, whether prompts and generated notes are PHI, and which services process the encounter. A BAA that allows transcription, summarization, support access, and storage is a different arrangement from a tool that never receives the call content.

HHS provides sample BAA provisions covering permitted and required uses and disclosures of PHI and prohibiting uses or disclosures outside the contract or legal requirements. HHS also provides a model business associate agreement. Those are primary sources worth reading before a vendor sales page becomes your compliance analysis.

In practice, the BAA is the contract you check before a patient says something they would not want in a vendor archive. HHS's own model starts from uses, disclosures, safeguards, and duties after the relationship ends.

Does encryption avoid the business associate agreement?

HHS's business associate FAQ says a cloud service provider may still be a HIPAA business associate when ePHI is encrypted and the provider cannot view it because it lacks the decryption key. That point catches a common mistake in AI scribe reviews: encryption can reduce exposure, but it does not automatically remove the vendor from the HIPAA business associate category.

A concrete example: a clinic uses an AI scribe that uploads encrypted encounter audio to a cloud bucket, then processes it through hosted transcription. Even if the vendor says the storage layer is encrypted, the service is still handling ePHI for the covered entity under the HHS cloud guidance. The BAA question remains.

That matters for professionals who read "encrypted" as if it answered the whole confidentiality question. It answers one technical question. It does not answer who receives PHI, who maintains it, what processing occurs, or what the agreement permits.

HHS states that covered entities and business associates must obtain satisfactory assurances from a cloud service provider through a BAA that the provider will appropriately safeguard PHI created, received, maintained, or transmitted for them.

Does a BAA mean the AI scribe is private?

A BAA means the vendor relationship is governed under HIPAA rules for PHI. It does not make an audio path private in the ordinary sense a patient or client means it.

If your AI scribe sends a psychotherapy session to a vendor, the BAA may permit that disclosure and limit what the vendor can do with it. The audio still left the practice environment. The transcript may still exist in a vendor system. The summary may still sit in a hosted account. HHS's cloud computing FAQ says a covered entity or business associate may use a cloud service to store or process ePHI if it enters into a HIPAA-compliant BAA with the cloud service provider and otherwise complies with the HIPAA Rules.

That is lawful architecture, not local architecture. A financial adviser has a different rule set, a lawyer has privilege concerns, and a consultant has an NDA, but the practical question rhymes across all of them: who receives the conversation after the client speaks?

We covered the broader recording issue in does transcription store audio in 2026?. For HIPAA, the BAA is a contract around disclosure. The HHS cloud guidance assumes the cloud provider creates, receives, maintains, or transmits ePHI.

How to compare a cloud AI scribe and a local AI scribe

The comparison that matters is the path of the call content. Fazit's public statement says Fazit is a native macOS menubar app for 1:1 client calls, capture is bot-free, transcription runs on-device using Parakeet via CoreML, notes are generated by a local model on localhost, and output is a plain Markdown file in an Obsidian vault or Apple Notes. The same statement says call audio is never written to disk and every note records audio_retained: false in its frontmatter.

QuestionCloud AI scribe handling PHIFazit local Mac workflow
Does a third party receive call content?Yes, if the service creates, receives, maintains, or transmits ePHI for the covered entity under HHS cloud guidance.Fazit's stated call-content path keeps audio, transcript, and note generation on the Mac.
Does a BAA apply?HHS says a covered entity and cloud service provider handling ePHI must enter into a HIPAA-compliant BAA.If no third party receives PHI for transcription or note generation, the vendor-as-business-associate question is avoided for that call-content path.
Is audio stored?Depends on the vendor's product and agreement.Fazit's stated architecture keeps audio in a fixed-size RAM ring buffer and never writes it to disk.
Where does the finished note live?Often in the vendor account, depending on the product.Fazit writes a Markdown file into your Obsidian vault, or Apple Notes, with no Fazit database holding a copy.

The table is narrow on purpose. Fazit makes no HIPAA certification claim, no SOC 2 claim, and no maturity or scale claim. Account, licensing, payment, model downloads, updates, and optional product analytics are separate from the call-content path described in Fazit's public statement.

For lawyers, the same audio-path analysis shows up as privilege risk, which we covered in AI scribe for lawyers privilege. For therapists and healthcare practices, the HHS question is more specific: did a vendor create, receive, maintain, or transmit PHI for you?

BAA checklist for an AI scribe handling PHI

Use this when a vendor says "HIPAA-ready", "HIPAA-compliant", or "we sign a BAA." The phrase is the start of review, not the end.

  • Confirm whether you are a HIPAA covered entity or business associate before you put patient content into the tool.
  • Ask whether the AI scribe creates, receives, maintains, or transmits PHI or ePHI.
  • Get the BAA before clinical encounter data enters the system.
  • Read the permitted and required uses and disclosures of PHI.
  • Check whether the agreement prohibits uses or disclosures outside the contract or legal requirements.
  • Ask whether audio, transcripts, prompts, summaries, and support logs are included in the PHI flow.
  • Ask which cloud service providers or other processors handle the encounter content.
  • Decide whether you actually need the vendor to receive the session at all.

That last item is the architectural fork. A BAA can govern a vendor's receipt of PHI. It cannot turn a vendor cloud into your local machine.

Where Fazit fits for confidential client calls

Fazit is built for consultants, coaches, lawyers, financial advisers, and therapists with confidentiality obligations on 1:1 client calls. It captures the microphone and the call app's output directly on macOS, with no meeting bot in the participant list. The README states that Zoom gets a one-click start, and other call apps such as WhatsApp Desktop, Meet in a browser, and Slack work through the app picker.

The working-day example is simple. You finish a client call, click stop in the menubar, and a note appears in your vault with the summary, moments worth saving, action items with owners, and a paste-ready follow-up email. Fazit's product facts say transcription and note generation run on the Mac, and the call audio is discarded after transcription instead of being saved as a file.

There is still a consent step. Fazit's own README says the architecture reduces vendor and audio-file exposure, but it does not remove the user's duty to have consent where the law requires it. If you run the call, you own that duty.

For a deeper architecture comparison, read local AI transcription on Mac and Fazit vs. the cloud notetakers. The HHS BAA rule governs vendor handling of PHI; Fazit's design aims at a cleaner starting point where call content does not go to a vendor for transcription or note generation.

Sources