Are AI scribes HIPAA compliant?
No AI scribe is automatically HIPAA compliant; compliance depends on the vendor and the agreement you sign with it. A scribe vendor records patient conversations on your behalf, which makes it a business associate under HIPAA (45 CFR 164.502(e)): no signed Business Associate Agreement, no recording. You also want written terms on encryption, audio retention, and whether your recordings train the vendor's models. Orion signs a BAA and runs Aurora, its ambient AI scribe, inside the EHR, so one agreement covers the chart and the scribe.
“HIPAA compliant” on a vendor homepage is a marketing label, not a compliance program. The regulation underneath is 45 CFR 164.502(e). Before a vendor handles protected health information on your behalf, HIPAA requires satisfactory assurances, in a written contract, that the vendor will safeguard it. That written contract is the Business Associate Agreement, and 45 CFR 164.504(e) sets out the terms it has to carry. A scribe vendor that records patient visits sits squarely inside that rule, so the test is simple: no signed BAA, no first visit.
The BAA is the floor, not the whole answer. Before any pilot, get three more things in writing. How long is the audio retained, and who can retrieve it? Do your recordings train the vendor’s models, and how do you opt out? And which subcontractors touch the data under their own BAAs?
A bolt-on scribe adds a second vendor, a second BAA, and a second place patient audio lives. Aurora runs inside Orion under one agreement. Orion also adds clinic-side controls most EHRs skip: an IP allowlist and an exportable audit log. You decide who reaches your data, and you can prove what happened.
Ready when you are
See Orion on your own patients.
See Orion run your practice in a live demo, or take a guided Test Drive in a safe sandbox. Your current EHR keeps running the whole time.
