← Back to blog

· Lex Hamilton

AI Scribe Patient Consent: What a Defensible Consent Flow Requires

What consent for an ambient AI scribe actually requires: recording, transmission, retention, and a consent record the documentation tool did not write.

Last reviewed: September 2026

Patient consent for an ambient AI scribe is permission to make and transmit a recording of a clinical encounter, and it is a separate question from whether the health system is HIPAA compliant. A signed notice of privacy practices governs how protected health information is used once it exists. Consent governs whether the recording that creates it may be made at all. In all-party consent states, that permission has to come from everyone in the room, before the recording starts, and it has to be documented by something other than the tool doing the recording.

Three health systems are currently defending proposed class actions on exactly this distinction. None has been found liable. All three are worth reading closely anyway, because the complaints describe a gap that most deploying organizations have not closed.

Table of contents

Consent for ambient documentation covers four distinct events, and a flow that addresses only the first one is incomplete.

The first is recording: audio of the encounter is captured. The second is transmission: that audio leaves the exam room for a vendor's servers, which is what converts a local clinical conversation into a third-party data flow. The third is retention: the audio and transcript persist somewhere for some period, and the American Bar Association's Health Law Section is direct that both constitute electronic protected health information. The fourth is secondary use: whether the recording is ever used to train or refine a model.

Patients routinely conflate these. A patient who agrees to "notes being taken" has not necessarily agreed to audio leaving the building. The disclosure that a reasonable patient could act on names all four, and names them before the microphone is live.

Ambulatory care is where this lands hardest right now, because that is where ambient scribes deployed first and fastest.

Why isn't a HIPAA notice or a signed BAA enough?

A business associate agreement allocates responsibility between a health system and a vendor. It does not obtain anything from the patient. It is an agreement the patient is not party to and generally never sees.

The ABA's guidance for health counsel puts the point plainly: ambient recording "may require more than standard HIPAA notices," and organizations should assess whether explicit, visit-level disclosure or consent is required. California's Confidentiality of Medical Information Act adds formalities that a general notice will not satisfy. Alston & Bird notes that the statute prescribes specifics down to font size, which means a consent that is legally adequate in substance can still fail on execution.

There is also a staleness problem that has nothing to do with statute. In reporting on the Sharp HealthCare litigation, the San Diego Union-Tribune noted that the notice of privacy practices published on Sharp's website was dated April 14, 2003. Whatever that document contemplates, it does not contemplate this. A notice written two decades before a technology existed is not informing anyone about it.

What are the ambient scribe lawsuits actually alleging?

The first suit was filed on November 26, 2025, in San Diego Superior Court, on behalf of a Sharp HealthCare patient named Jose Saucedo. The complaint alleges that Sharp began using an ambient documentation tool in April 2025 and recorded encounters without notice or consent, and that Saucedo discovered the recording of his July appointment only by reading his own visit notes afterward. It estimates that more than 100,000 patients may have been recorded during the rollout, and seeks damages, correction of the records, and an injunction. California's penal code permits damages of $5,000 per violation. Sharp has said patient safety and privacy are its top priorities and that it cannot comment on pending litigation.

In April 2026, a second case was filed in the Northern District of California against Sutter Health and two MemorialCare entities, pleading claims under the California Invasion of Privacy Act, the Federal Wiretap Act, and CMIA. The complaint alleges patients "did not receive clear notice that their medical conversations would be recorded by an artificial intelligence platform, transmitted outside the clinical setting, or processed through third-party systems." The three elements it says were missing are worth memorizing, because they are the shape of the exposure: clear notice of recording, meaningful choice, and properly documented authorization.

The vendor is not a defendant in either case. The health systems are. That allocation is not an accident, and it is consistent with how the vendors themselves describe the obligation: guidance in one vendor's customer support materials tells clinicians to follow their own organization's recommended guidelines for patient consent. The tool ships with a suggested script. It does not ship with a consent program, and it was never going to.

Similar litigation is pending in Illinois. These are allegations that have not been tested, but the theory of liability is now on file in two jurisdictions and does not depend on any patient being harmed by an inaccurate note.

Patients appear to sort the responsibility much the same way. In the JAMA Network Open study, 64.1% of patients held the physician accountable for a medical error linked to ambient documentation, while 76.7% put responsibility for a data-security breach on the vendor. The courts are naming the health system, patients are naming the clinician in the room, and nobody is absolving the organization that chose to deploy the tool.

The most instructive allegation in the Sharp complaint is not about the recording. It is about the documentation of consent.

The complaint alleges that the tool automatically inserted statements into medical charts recording that patients "were advised" the visit was being recorded and that they "consented," in encounters where the patient says no such conversation occurred. The ABA names this failure mode in general terms as a known compliance vulnerability of the category: AI-generated records may state that consent was obtained when it was not.

Structurally, this is the same problem that shows up everywhere else in clinical AI. The system that performed the action also generated the record attesting that the action was authorized. When one pipeline produces both the thing requiring permission and the evidence that permission was given, the second artifact cannot corroborate the first. It is the self-audit problem applied to consent rather than to clinical accuracy, and it has a sharper edge here: a fabricated clinical detail can at least be contradicted by the rest of the chart, while a fabricated consent attestation looks exactly like a real one.

It is also a case where the note can be perfectly faithful to what the system did and still be false about the world, which is the distinction between a transcript being accurate and a note being correct. And because the attestation appears in a familiar template field, in a chart the clinician is signing dozens of times a day, it is the kind of machine-generated line that stops being read, which is how oversight quietly erodes.

For a compliance officer this collapses into one problem. If the consent record lives only in the system that did the recording, the organization cannot prove consent to anyone who disputes it.

Peer institutions have already published what they do, which makes this less theoretical than it looks. Asked by the Union-Tribune what its practice was, UC San Diego Health described requiring an annual written consent plus verbal consent from the patient and all parties in the exam room at each visit. Kaiser Permanente said its process calls for the care team to ask patients and the individuals accompanying them for permission before using the tool. Rady Children's described a limited pilot in which clinicians are required to obtain consent before use. A fourth large system in the same market declined to say whether it uses such a tool at all.

Read against the complaints, the elements those flows share are the elements that matter:

  • Disclosure happens before the recording starts, by a person. In the JAMA Network Open study the most common approach was exactly that: a verbal conversation between patient and clinician before the encounter. Texas has now made it an explicit statutory requirement rather than a best practice: under the Texas Responsible Artificial Intelligence Governance Act, effective January 1, 2026, providers must disclose the use of AI in diagnosis or treatment before or at the time of interaction, except in emergencies.
  • Everyone in the room is asked, not just the patient. All-party consent means all parties. A spouse, an adult child, or a caretaker is a party to a confidential communication, and Alston & Bird flags this as a live question for any organization assessing its exposure.
  • The disclosure names transmission, not just recording. "I'm going to record this" and "this recording goes to an outside company that will process and store it" are different disclosures, and only the second describes what happens. A 2025 quality-improvement study in JAMA Network Open, covering 18 clinicians and 103 patients in ambulatory practices at a large urban academic health center, measured the gap. Given basic information about the tool, 81.6% of patients consented. When the disclosure also covered the AI features, data storage, and corporate involvement, that fell to 55.3%. The fuller disclosure is the honest one, and it costs roughly a quarter of the consent rate. That trade is worth naming out loud, because a program built on the first number is not measuring consent so much as measuring what patients agree to before they know what they are agreeing to.
  • Refusal is easy, free, and does not change the visit. Consent that a patient cannot practically decline is not consent. If declining means an awkward negotiation with the person about to examine them, the flow is not working, whatever the paperwork says.
  • Consent is revocable, and asked more than once. Sara Geoghegan, senior legal counsel at the Electronic Privacy Information Center, argues consent should be obtained on its own rather than buried in intake paperwork, and should be "freely informed and can be rescinded." Her framing of the interval is the memorable one: "Once every 10 years is not enough."
  • The record of consent is independent of the tool. Written in the chart by the clinician, captured in the EHR's own consent module, or logged in a system with a different owner. Anywhere except a field the documentation tool populates about itself.
  • The vendor agreement backs the promise. The ABA's counsel guidance is that a BAA should address model use, subcontractors, training-data restrictions, audit rights, and post-termination data deletion. A patient told their recording will not train a model is owed a contract that says so, and the questions worth putting to a vendor before signing are set out in our guide to evaluating ambient AI vendors.

How much does the answer change by state?

Enough that a single national script is a liability rather than a simplification.

California generally requires all-party consent before a confidential conversation is recorded, which is the foundation of every case discussed here. One-party consent states do not impose the same threshold on the recording itself, though CMIA-style medical confidentiality rules, state health privacy statutes, and the disclosure obligations attaching to third-party transmission still apply. Texas has moved separately, adding an affirmative AI disclosure duty in TRAIGA and, in SB 1188, requiring that a practitioner review AI-generated records and barring the offshoring of electronic medical records, including at third-party vendors.

A health system operating across state lines is operating under several regimes at once. This is a question for counsel in each jurisdiction, and nothing here is legal advice. The governance point is narrower and does not depend on resolving the legal one: an organization should be able to say, for any given encounter, what it disclosed, who agreed, and where that is written down.

Where this fits

The consent question is where clinical AI governance becomes concrete for people who do not otherwise think about model behavior. There is no accuracy metric that fixes it. A scribe can produce flawless notes and still have been deployed unlawfully, which is a useful reminder that accuracy and governance are not substitutes for one another.

A few things a hospital can do this quarter, none of which require buying anything:

  • Find out where your consent attestations come from. If the answer is "the documentation tool," you have a provenance problem that will surface the first time a patient disputes one.
  • Read your notice of privacy practices with a date in mind. If it predates the technology, it is not doing the work you are relying on it to do.
  • Watch one clinic session. Not the policy. The actual disclosure, said out loud, to an actual patient, with a family member present. Flows fail in the room, not on the page.

The third one is the one that gets skipped, and I would argue it is the only one that tells you what is actually happening. A policy describes the flow you designed. A clinic session shows you the flow you have.

The pattern underneath is the one that recurs across clinical AI: a system's own output is not evidence about that system. That holds when the output is a diagnosis, and it holds when the output is a line saying the patient agreed.

What does your consent record look like when the tool that wrote it is the thing in dispute?

Frequently asked questions

Is a signed HIPAA notice of privacy practices enough to cover ambient scribe recording?

Generally not on its own. A notice of privacy practices governs how protected health information is used and disclosed. It does not obtain permission to create an audio recording of an encounter, which in all-party consent states is a separate requirement. The ABA Health Law Section advises that ambient recording may require more than standard HIPAA notices, including explicit visit-level disclosure.

Does the AI vendor or the health system own the consent obligation?

In the litigation filed so far, the health systems are the defendants and the vendor is not. Vendor documentation generally directs clinicians to follow their own organization's consent guidelines. The deploying organization owns the obligation.

Does verbal consent need to be documented, and where?

Yes, and the documentation should not depend on the recording tool. If the only record that consent was obtained is a field populated by the system that made the recording, that record cannot serve as independent evidence in a dispute over whether consent happened.

Do family members in the room need to consent?

In all-party consent states, every party to the confidential conversation does. Health systems that have described their practice publicly generally include everyone present in the exam room.

Further reading