The-Legal-Gray-Area-Inside-Your-AI-Scribe

AI Scribe Compliance in 2026: 3 Legal Risks US Clinics Are Getting Wrong

Chances are, someone in your clinic already uses an AI scribe, and you might not even know it. Nearly a third of US doctors now use one to write their notes, up from 20% to 29% in under a year, according to a Doximity survey of more than 3,100 physicians. Physician use of AI tools overall grew 81% in a single year, per AMA data.

That’s a lot of exam rooms, a lot of recordings, and a lot of clinics building habits around a tool nobody has fully mapped the risk of yet.

But here’s the part vendors tend to skip during the sales pitch. The tool, AI medical scribe, itself works fine. What decides whether your clinic ends up in a lawsuit, an audit, or a payer dispute is how you manage everything happening around it, starting with something as simple as whether the patient in that exam room even knew they were being recorded. 

Patients Are Suing Over Recordings, Not Bad Notes

The moment an AI scribe starts listening, it’s recording a private conversation between a patient and their doctor, and that single fact, more than anything to do with note quality, is what’s driving a wave of lawsuits clinics never saw coming.

In April 2026, patients sued Sutter Health and MemorialCare in federal court over exactly this. They claimed their visits were recorded and sent through an AI tool without clear notice or consent, according to Medscape reporting

A similar suit had already hit Sharp HealthCare months earlier, and the plaintiffs in the newer case want the court to certify a class covering everyone seen at those systems over the past two years.

However, it’s tempting to assume your HIPAA paperwork already handles this, since HIPAA feels like the catch-all for anything touching patient data. But a signed business associate agreement with your AI vendor only governs how patient data gets handled once it exists. It never answers whether you were allowed to make the recording in the first place, and that earlier question comes down to state recording law instead.

Nine states require consent from everyone in the room before a conversation can be recorded, and five more split the rule depending on whether the conversation happens in person or over the phone. So if your clinic sees telehealth patients across state lines, you end up following the strictest law touching any one of them, not the law where your office happens to sit. 

In California, violating the two-party consent rule under the Invasion of Privacy Act can carry damages of $5,000 per violation, spelled out directly in Penal Code section 637.2, and once you multiply that by a full patient panel, the number stops looking theoretical fast.

That’s why the fix has to happen before the recording ever starts. If your intake process doesn’t include a separate, logged consent step outside the AI tool itself, you have no way to prove notice was given the moment someone challenges it later. And once that recording turns into a signed note sitting in the chart, a different story begins, one about who takes the blame if something in it is wrong.

Signing the Note Makes It Yours, Legally

Now, suppose the AI scribe has drafted the note, the physician skims it between patients, and with one click, they sign it. That click matters more than most doctors realize, because no AI scribe on the market has FDA authorization as a medical device. 

Vendors sell and classify these tools as administrative software specifically so they can skip that review, and while that works out fine for the vendor, it leaves the physician who signs the note carrying all the weight.

A University of Illinois law professor who studies health AI liability put it plainly in Medical Economics. Nothing in current law shifts malpractice responsibility from the treating physician to the AI vendor, so if a note contains a dangerous omission and the physician signs it, that chart belongs to them, legally, no matter who or what drafted it.

Which brings us back to accuracy, and this is the part vendors don’t love talking about. A pilot study of AI-generated notes across 31 physicians found 94.7% free of significant errors, which sounds solid until you look at what’s hiding in the remaining share.

 Accidental omissions showed up in 18% of the flagged notes, made-up content in 11.5%, and incorrect details in 9.3%. Picture a cardiac workup that really happened but never made it into the note. On paper, years later, that gap can look like negligence, even though the care itself was fine all along.

And the error rate doesn’t land evenly across every patient in that exam room, either. Speech recognition models behind most scribes are trained mostly on standard American English, so researchers at Columbia Nursing, in a npj commentary, found the underlying transcription systems are measurably less accurate for Black patients’ speech than for white patients’.

 So if your patient population is linguistically or racially diverse, this risk isn’t background noise spread thin across everyone. It clusters on specific patients, and a single blended accuracy number from your vendor will never show you where.

Therefore, before rolling this out any further, get the following in writing.

  • A policy requiring a full read of every AI note before signature, not a skim
  • A vendor error rate broken down by note section, not one combined number
  • A sample of test transcripts from a range of accents and speech patterns in your own patient base
  • Written confirmation from the vendor on FDA classification and whether it retains or trains on your data

Fuller Notes Are Triggering Downcoding, and New Laws Are Pushing Back

Now, follow that note one step further, past the physician’s signature and into the billing department. Here, the same thoroughness that makes AI notes riskier for liability also makes them fuller, and fuller notes end up changing what your clinic bills for that visit. 

A PHTI analysis found that one multihospital system saw level 5 encounters rise 5% and level 4 encounters rise 7% after adopting an AI scribe, which translated to roughly $1,000 more revenue per provider, per month.

Payers noticed fast, and they didn’t sit still. Starting in October 2025, Cigna began automatically reducing many level 4 and 5 E/M claims by one level unless the documentation clearly supported the higher complexity, a policy brief on the resulting coding arms race reports, and other insurers have rolled out similar reviews since.

Here’s where the story turns in your favor, and it’s something most clinic administrators haven’t caught up to yet. States started pushing back against exactly this kind of automated downcoding in 2026. Indiana’s law, tracked as House Bill 1271 and effective July 2026, bans insurers from using AI as the sole basis to downcode a claim without a human reviewing the actual medical record. 

Illinois passed a matching Senate Bill 3114, the Transparency in Downcoding Act, and Georgia’s Senate Bill 444 now requires a qualified human reviewer in every coverage determination that involves AI. So if a payer in one of these states downcodes your claims using an algorithm alone, you have real legal ground to push back on now, beyond just a phone call to your billing rep.

There are two things worth doing with that leverage. Pull a coding distribution report from before and after your rollout and keep it on file, since it’s the cleanest evidence you can hand an auditor if your billing pattern shifts. And if a payer denies or downcodes a claim without human review, check whether your state has passed a law like the ones above, and cite it directly in your appeal.

The Bottom Line

So, the clinics that end up in trouble with AI scribes usually have perfectly good technology behind them. Their real problem is treating a recording device like any other documentation tool, when it clearly needs its own set of rules from the moment the patient walks in. A single BAA covers data handling, but consent to record is a separate ask that has to happen earlier. A high accuracy number can still hide a lot of unevenness underneath it. And thanks to the new state laws, a payer’s algorithm doesn’t get to have the final say on your claims anymore. 

Write down the rules for consent, reviexw, and billing before the next audit finds the gap for you. Do that, and the AI scribe finally saves time the way it was supposed to, without creating new risk along the way.

    Request a Demo

    Dr. Girirajtosh Purohit

    Dr. Giriraj Tosh Purohit is an experienced Product Manager and Security officer with a strong background in healthcare technology and management consulting. With expertise spanning clinical workflows, EHR, RCM, Digital Health, and AI-driven products, he has been instrumental in shaping innovative healthcare solutions.