HIPAA Compliant AI Note Taker: Send These Questions Before Client Audio
Outline
The sales engineer already played the demo note. Your 2 p.m. client is in the waiting room. The remaining question is not whether the draft looks tidy. It is whether that client’s audio can go through the tool without creating a copy of protected health information (PHI) you cannot contract, delete, or defend.
You already have a HIPAA compliant AI note taker in view. Send the questions below in writing. Mark pass or fail on each answer before any real session hits the microphone.
Educational material for licensed US mental-health clinicians and practice owners. Not legal advice, not a BAA, and not a product ranking. Federal HIPAA citations below are from official HHS and eCFR pages checked September 2026. State recording rules and vendor plans change. Verify current HHS guidance, your contracts, and qualified counsel before you rely on any workflow.
HIPAA does not certify products
HHS does not issue a software badge that makes a tool “HIPAA certified.” A covered entity must have a contract or other written arrangement with a business associate that meets 45 CFR 164.504(e). HHS states that a business associate cannot self-certify or be certified by a third party as a substitute for that contract.
Treat a homepage HIPAA mark as a claim to test. It is not a pass, and it is not a scored HIPAA compliant AI note taker.
What a BAA does, and what it does not
If the vendor needs access to your clients’ PHI to provide the service, including hosting audio, transcripts, or notes on its servers, it is generally a business associate. HHS business associate guidance says you obtain satisfactory assurances in a business associate agreement (BAA) before that access.
A BAA, in the HHS sample provisions, is supposed to:
- Limit how the vendor may use and disclose PHI
- Require safeguards, including Security Rule duties when ePHI is involved
- Flow those duties to subcontractors who touch the same PHI
- Require the vendor to report breaches of unsecured PHI to you
- Address return or destruction of PHI when the work ends
A BAA does not:
- Certify the product
- Replace your own risk analysis, workforce rules, or device controls
- Prove that recording a session is lawful in your state
- Make an auto-filed draft a defensible chart entry
- Travel down to a cheaper plan that was not named in the signed paper
If you do not already have one product in the room and you are still comparing therapy scribes, finish that shopping on the 2026 AI medical scribe comparison for therapists, then come back with a single vendor to score.
How to run the vendor call
Email the questions the day before. On the call, write the answer in the Vendor answer column. Then mark Pass or Fail against the fail line, not against how confident the sales engineer sounded.
Do not accept “we are HIPAA certified” as an answer to the BAA row. Do not accept “encrypted” as an answer to retention, training, or subprocessors. Do not put a real name, date of birth, or session story into a demo account to “see how it handles PHI.”
Use fictional content until the signed BAA covers the exact tier you will buy.
Questionnaire for the HIPAA compliant AI note taker in front of you
Fill the header, then one row at a time. A blank Vendor answer is a fail. A verbal promise with no written follow-up is a fail until the email arrives.
| Field | Your notes |
|---|---|
| Practice | |
| Reviewer | |
| Vendor / product | |
| Date | |
| Call / ticket |
Scroll the table sideways to view every column
| Check | Question to send | Fail line | Vendor answer | Pass or fail |
|---|---|---|---|---|
| Signed BAA | Will you sign a BAA before any PHI (audio, transcript, or note) is created? | Fail: no BAA, BAA only after go-live, or a certification claim in place of a BAA. HHS does not certify software. | ||
| Recording consent | How does the product support documenting client consent before recording or transcribing a session? | Fail: no consent path, or recording can start before a consent flag exists. | ||
| Raw audio | Do you retain raw audio? For how many days? Who can play it back? | Fail: cannot state a retention period, or audio has no access log. | ||
| Transcripts | Do you retain transcripts separately from the signed note? For how long? Can we delete them without deleting the note? | Fail: transcripts persist with no end date, or cannot be deleted on their own. | ||
| Model training | Is client audio, transcript, or note content used to train models (yours or a subprocessor's)? | Fail: yes, "maybe", or de-identified training with no written stop that actually stops the flow. | ||
| Subprocessors | List current subprocessors (transcription, storage, LLM) and confirm each has a BAA or equivalent. | Fail: no list, "on request only", or the LLM vendor is unnamed. | ||
| Deletion at end | On contract end, what PHI is returned or deleted, in what format, and in how many days? | Fail: no written return or deletion timeline, or backups kept with no end date. | ||
| Access controls | Unique user IDs, MFA, role-based access, and an audit log of who viewed a recording or note? | Fail: shared logins, no MFA, or no access log for audio or transcript. | ||
| Export | Can we export signed notes, transcripts we own, and audit logs in a usable format without a professional-services fee? | Fail: screenshots only, or export held until a paid migration. | ||
| Breach notice | How fast will you notify us of a breach of unsecured PHI so we can meet our own notice duties? | Fail: no written notice timeline, or "we notify regulators, not you". | ||
| Clinician sign-off | Can a draft note enter the legal record without a licensed clinician action? | Fail: auto-file, auto-sign, or "the AI is the author". |
Call verdict
Count the rows. Then write the hold-or-proceed line before anyone schedules a live recording.
Scroll the table sideways to view every column
| Pass count | Fail count | Hold or proceed | What must change before PHI goes in |
|---|---|---|---|
Automatic hold, even if other rows look clean:
- Signed BAA is fail
- Model training is fail
- Subprocessors is fail
- Clinician sign-off is fail
Those four are not “phase two.” They are the difference between a demo and a second copy of the chart you cannot explain to a board, a payer, or a client.
The HIPAA Security Rule still expects access control, audit controls, integrity, authentication, and transmission security for ePHI. A pretty note does not cover those technical safeguards.
Email you can paste to the vendor
Send this as a ticket, not a chat. Ask them to answer in writing, named to the plan you would buy.
We are evaluating your product as a HIPAA compliant AI note taker for an outpatient therapy practice. Please answer each item for the exact plan named below, not for a higher tier.
Plan under review:
- Will you execute a BAA before any audio, transcript, or note is created? Please send the BAA, not a certification claim.
- How is recording or transcription consent captured before capture starts?
- Default raw-audio retention in days, who can play audio, and whether playback is logged.
- Transcript retention, separate from the signed note, and whether transcripts can be deleted without deleting the note.
- Is client audio, transcript, or note content used to train your models or a subprocessor’s models? If de-identified training exists, how do we turn it off in a way that actually stops the flow?
- Current subprocessor list for transcription, storage, and the LLM, with confirmation each has a BAA or equivalent.
- On termination: return or deletion format, timeline in days, and backup expiry.
- Unique user IDs, MFA, role-based access, and audit export for view, export, and delete events.
- Export formats for signed notes, transcripts we own, and audit logs, and whether that export is billed as professional services.
- Written breach-notice clock to our practice after a breach of unsecured PHI.
- Can a draft become the legal record without a licensed clinician action?
Please reply in writing. We will mark pass or fail against those answers before any client audio is used.
Printable fields for the same eleven rows live in the Vendor Due Diligence Pack. Email it to yourself so you are not scrolling back to copy the table during the call.
Email the Vendor Due Diligence Pack
Sheet 1 is the fillable AI-vendor questionnaire with a pass/fail column. Sheets 2 and 3 cover EHR export counts and a synthetic-claim demo if those buying questions are next.
- Fillable AI-vendor questionnaire with a pass/fail column for BAA, retention, training, and sign-off
- EHR export and count-reconciliation workbook with a vendor email to send before cutover
- Synthetic-claim demo scorecard for eligibility through note-to-claim
Free. We'll email the PDF link right away. We may also send the occasional therapist toolkit. Unsubscribe any time.
Where should we send the link?
We'll email the PDF link right away. You'll also get the occasional therapist toolkit. Unsubscribe any time.
✓ Check your inbox
We've sent you the PDF
The download link is on its way to your inbox, usually within a minute or two. The email will come from Emosapien (hello@team.emosapien.com); check your spam folder if you don't see it.
You're also on the weekly therapist toolkit list. Unsubscribe any time from the email footer.
Worked call: Maya scores one vendor in 18 minutes
Maya is an LCSW in a two-clinician practice. The vendor is already on a second demo. She does not need another feature tour. She is scoring one HIPAA compliant AI note taker on paper.
She pastes the email, names “Growth” as the plan, and shares her screen on the questionnaire. Eighteen minutes later the sheet looks like this.
Scroll the table sideways to view every column
| Check | What they said | Mark | Why |
|---|---|---|---|
| Signed BAA | "BAA after you go live on Growth." | Fail | PHI would exist before the contract. |
| Recording consent | In-app toggle, session cannot start record without it. | Pass | Capture is blocked until the flag exists. |
| Raw audio | "We do not keep audio." Support chat later: 24-hour buffer, no playback log. | Fail | Period was not stated on the call, and playback is unlogged. |
| Transcripts | 30 days, deletable without deleting the signed note. | Pass | Separate object, dated end. |
| Model training | "De-identified data may improve the model. No opt-out on Growth." | Fail | The stop does not exist on the plan she would buy. |
| Subprocessors | "Happy to share under NDA." LLM unnamed. | Fail | No current list. |
| Deletion at end | 30-day export, then delete. Backups "follow our cloud provider." | Fail | Backup has no end date. |
| Access controls | Unique logins, MFA, admin audit export. | Pass | Matches the access-control ask. |
| Export | PDF and DOCX, no professional-services fee. | Pass | Usable formats. |
| Breach notice | "Without unreasonable delay." No number of days to the practice. | Fail | You cannot plan your own individual and HHS notice clocks from that phrase. |
| Clinician sign-off | Draft stays draft until a licensed user clicks Sign. | Pass | AI is not the author. |
Pass count: 5. Fail count: 6. Verdict: hold.
What must change before PHI goes in: BAA executed before any object is created; written opt-out that stops training on Growth; dated subprocessor list that names the LLM; playback log or zero audio buffer; backup expiry in days; a notice clock to the practice, not only to regulators.
Maya does not “pilot with one real client to keep momentum.” She sends the fail list. If the vendor cannot close it, she keeps notes in the chart she already has.
The breach-notice row is scored against the HHS Breach Notification Rule, not against a sales phrase. If the remaining question after privacy is how a therapy-shaped draft is reviewed and signed, look at AI clinical notes for therapists. That workflow still sits behind the questionnaire. It does not skip it.
Recording consent is a different track from HIPAA
The HIPAA Privacy and Security Rules govern how covered entities and business associates handle PHI. Recording a session can also depend on state law, your board, telehealth setting, payer or clinic policy, and what you told the client.
A signed BAA is not proof that recording is lawful in your jurisdiction. A state consent form is not a substitute for HIPAA safeguards. Score both:
- Federal and contract track: BAA on the live tier, safeguards, minimum necessary access, retention, breach notice, workforce rules
- Consent and professional track: whether recording is allowed, how you disclose AI transcription, how refusal works, and where that consent lives in the chart
Do not treat a client’s nod on camera as a completed consent row if the product can start capture with no flag. Do not treat the consent row as a pass on BAA.
After the sheet: hold, fix, or proceed
Hold. Any automatic-hold row failed, or you still have verbal answers only. Keep live audio out. Hold real sessions until the HIPAA compliant AI note taker in front of you can pass those rows in writing.
Fix, then re-score. The vendor sends a BAA, a subprocessor list, a training opt-out, or a retention setting. Re-mark the row. Do not carry a pass forward from the last call if the plan name changed.
Proceed to a simulated trial. BAA on the purchased tier is executed. Settings match the sheet. You run fictional sessions first. Then, if recording is allowed and consented, you run a short real-caseload sample and time edit-and-sign work. The clinician still signs. A draft you have not reviewed is not a note.
If session audio is easier to open than a progress note, your access map is upside down. Fix roles before you add volume.
What Emosapien is, and is not, on this buying question
Emosapien is therapy notes software. As of September 2026, the HIPAA-compliant therapy notes page states that it drafts SOAP, DAP, BIRP, GIRP, and PIE progress notes for the clinician to review, edit, and sign. It is not a HIPAA certification, not a full EHR, not legal advice, and not a ranking of other note takers.
As of September 2026, a BAA is available on Professional and Enterprise, not on Free. Session content is not used to train public models. Encryption in transit and at rest, access controls, and related safeguards are published on Emosapien security and BAA terms. Score those claims with the same questionnaire you would send anyone else. If a row fails, hold.
As of September 2026, the pricing page publishes the free plan at 10 progress notes per month with no credit card required. Use it to run this test on fictional sessions. Keep identifiable client audio out until a signed BAA covers the plan you will actually use.
Run the questionnaire on a free Emosapien workspace
Start on the free plan and run this test yourself with fictional sessions. You remain the author of every signed note.
Start free and score the workflowReferences
- U.S. Department of Health and Human Services. Instead of entering into a contract, can business associates self-certify or be certified by a third party as compliant with the HIPAA Privacy Rule?
- U.S. Department of Health and Human Services. Is a software vendor a business associate of a covered entity?
- U.S. Department of Health and Human Services. Business Associates
- U.S. Department of Health and Human Services. Sample Business Associate Agreement Provisions
- 45 CFR 164.504(e). Organizational requirements: Business associate contracts
- U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule
- U.S. Department of Health and Human Services. Breach Notification Rule