Is AI for Therapy Notes HIPAA Compliant?
Is it HIPAA compliant to use AI for therapy notes?
Yes, if the vendor signs a business associate agreement and handles protected health information accordingly. HIPAA does not prohibit AI. It regulates who may touch PHI and under what safeguards. An AI scribe or note generator that processes session content is a business associate by definition. Without a signed BAA in place, using it is a disclosure of PHI to an unauthorized party, whatever the tool's marketing says.
What HIPAA actually requires of an AI vendor
A business associate, under the Privacy Rule, is an entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. A tool that ingests your session audio, your dictation, or your rough notes and returns a progress note is squarely inside that definition. So is the cloud provider it runs on, which is why subcontractor flow-down clauses exist.
A serviceable BAA obligates the vendor to use and disclose PHI only as the agreement permits, to implement safeguards, to bind its own subcontractors to the same terms, to report security incidents and breaches to you, and to return or destroy PHI when the relationship ends. If the agreement is silent on model training, that silence is a problem rather than a reassurance.
The Security Rule then requires administrative, physical, and technical safeguards: access controls, unique user identification, audit logging, transmission security, and workforce training. Encryption is technically an addressable specification, which in practice means a vendor without it needs an extremely good story.
Two things clinicians routinely get wrong. First, the vendor's BAA does not make you compliant. It makes them accountable to you. Your own risk analysis, access policies, and training obligations remain yours. Second, there is no federal HIPAA certification. Nobody issues one. A vendor advertising that it is "HIPAA certified" is telling you something interesting about its marketing department. The Office for Civil Rights publishes its guidance at hhs.gov, and none of it involves a certificate.
The questions to ask before you turn it on
Send these in writing and keep the answers. A vendor that will not answer in writing has answered.
| Question | Answer that should worry you | Answer you want |
|---|---|---|
| Will you sign a BAA, and does it cost extra? | "Available on enterprise plans" | Yes, for every customer, at no charge, before any PHI moves |
| Do you train models on my clients' data? | "De-identified data may be used to improve our services" | No, and the prohibition is written into the BAA |
| Is session audio stored, and for how long? | "Retained for quality purposes" with no stated window | Not stored, or deleted on a stated schedule you can verify |
| Who are your subprocessors? | "We don't disclose our vendors" | A named, current list, each bound by a downstream agreement |
| Where is the data processed? | Unspecified, or offshore without disclosure | Named regions, disclosed, with contractual limits |
| Can I export everything if I leave? | "Contact support" or PDFs only | Structured export of records on demand, without a fee |
| What happens if you have a breach? | Vague reference to "applicable law" | Notice to you within a defined period, with specifics |
The training question deserves elaboration, because vendors answer it slipperily. HIPAA does permit a business associate to de-identify PHI where the agreement allows it, and properly de-identified data falls outside HIPAA entirely. But a psychotherapy transcript is close to the hardest thing in medicine to de-identify. Clients name their employer, their street, their children, the date of the accident. When a vendor's terms say "de-identified," ask which method they use and who verified it. Very often the honest answer is that they stripped the obvious names and hoped.
Recording consent is a separate problem from HIPAA
HIPAA governs what happens to the PHI once it exists. It says nothing about whether you may record a person in the first place, and that question is answered by state law and your licensing board.
A number of states require every party to a conversation to consent to its recording, not just one. Professional ethics reinforce this independently: the APA Ethics Code requires permission before recording the voices or images of the people you serve, and other licensing boards carry parallel provisions. Telehealth adds a wrinkle worth checking, because platforms differ in whether an ambient assistant is producing a stored recording or only a transient transcript, and the answer changes what you are consenting to.
The practical version is short. Put it in your written informed consent. Say it out loud the first time and document that you did. Give clients a real option to decline, and actually turn the tool off for those who do. If your practice uses telehealth, confirm what the video platform records independently of your note tool. None of this is legal advice, and your state's rules and your board's rules govern.
Psychotherapy notes get extra protection, including from your AI
HIPAA defines "psychotherapy notes" narrowly: notes recorded by a mental health professional analyzing the contents of a private counseling session, kept separate from the rest of the medical record. They require specific authorization for most disclosures, and they are excluded from the designated record set.
The definition excludes medication prescription and monitoring, session start and stop times, modalities and frequencies of treatment, results of clinical tests, and any summary of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress to date. In other words, the payer-facing progress note is not protected by this provision at all.
If you keep process notes, decide deliberately whether your AI tool should ever see them, and default to no. The AI's job is the progress note, which is the document that goes to payers and reviewers. Your protected file only qualifies for the protection if it is genuinely stored separately, which means a folder in the same chart labeled "psychotherapy notes" may not do what you think it does.
The clinical risks no BAA covers
Compliance is the easy half. The harder problems are clinical, and they do not appear in any contract.
A language model can produce a clean, plausible sentence describing an intervention you did not deliver, or an instrument score nobody administered. This is not a rare catastrophic failure; it is a routine tendency toward fluent completion. You sign the note. The note is yours. "The software wrote it" is not a defense in a records request and it is not a defense to your board.
Homogenization is the second risk, and it is quietly funny: notes generated from the same underlying model tend to sound alike, and notes that look alike across clients and dates are precisely what auditors flag as cloned documentation. A tool sold to reduce your compliance risk can manufacture a new one.
The third is detail leakage. A transcription-driven note faithfully captures the neighbor's full name, the employer, the sister's diagnosis, the specific address. Minimum necessary applies to what you write down, not only to what you send. Someone still has to decide what belongs in a permanent record, and that someone is you.
The fix for all three is boring and non-negotiable: read the note before you sign it, every time. If a product's central pitch is that you never have to read the note, it is pitching you documentation you cannot defend.
What good looks like
The bar is not complicated. A vendor that signs a BAA with every customer without charging for it, will answer the table above in writing, does not train on your clients' data, and produces a note you can read in under a minute and correct in the editor.
That is the bar we hold ourselves to. Congruent's BAA is free and available to every customer, including during the 30-day trial that does not ask for a credit card, and every AI feature is included in both plans at $20 per clinician per month for Solo and $29 for Practice, with no add-on fees. How AI progress notes handle your data is documented on the security page, which is where you should be reading it for any vendor, this one included.
The compliance answer is a signed BAA and a vendor who will put its practices in writing. The clinical answer is that the note belongs to you, and the model is a fast typist with no license. For what the finished note has to contain, see the CMS documentation requirements.