A year ago, AI scribes were the shiny new thing at every behavioral health conference. Now a growing number of group practices are quietly walking them back — and in a few cases, banning them outright.
If you run a multi-provider agency, this isn’t a fringe concern anymore. It’s a compliance question with your name on it.
The Question Every Practice Owner Should Be Asking
Is AI safe for therapy notes? The honest answer is: it depends entirely on what “safe” means to you — and most agencies asking the question are really asking two separate things: is it accurate, and is it defensible if we get audited. AI note takers in therapy struggle on both fronts, and the reasons are worth understanding before you sign a vendor contract.
1. The Accuracy Problem Is Bigger Than Vendors Admit
AI therapy notes accuracy has become one of the most scrutinized issues in behavioral health tech this year. Independent evaluations comparing ambient AI-generated notes to physician-authored ones have found a meaningfully higher hallucination rate in the AI-drafted notes — instances where the AI recorded something that didn’t actually happen in the session. In a clinical record, that’s not a rounding error. A fabricated detail in a treatment plan, a missed safety plan, or a follow-up that silently disappears from the note isn’t cosmetic — it’s clinical and legal exposure the moment a client’s care is questioned.
For behavioral health specifically, the stakes are higher than in general medicine. Sessions involve safety planning, risk assessments, and disclosures that must be recorded exactly as they happened — not paraphrased by a language model guessing at intent.
2. The HIPAA Exposure Is Real, Not Theoretical
This is where the legal argument gets sharp. In April 2026, patients filed a proposed class action against a major health system alleging that an ambient AI documentation tool recorded patient-clinician conversations and generated notes without adequately informed consent. The case is a warning shot for every practice using similar tools, not just the defendants.
A few things every agency owner should understand about HIPAA compliant therapy notes and AI:
- A signed Business Associate Agreement (BAA) is the floor, not the finish line. Any AI vendor that creates, receives, transmits, or stores PHI on your behalf must be bound by a BAA — but a BAA alone doesn’t resolve consent, retention, or subprocessor risk.
- Consent is a separate legal question from HIPAA. State wiretap and privacy laws can apply on top of HIPAA when a tool records session audio, which is exactly why the class-action exposure above matters even for practices that had a BAA in place.
- “Zero retention” needs verification, not trust. Agencies need to confirm what that actually covers — prompts, audio, and transcripts can all persist somewhere in a vendor’s pipeline even when the marketing page says otherwise.
- Model training on your clients’ sessions is its own risk category. If a vendor ever fine-tunes on real encounter data, that use typically requires patient authorization beyond routine treatment, payment, or operations — something most practices never explicitly obtain.
None of this means AI scribes are inherently unusable. It means the compliance burden of vetting them — BAAs, subprocessor lists, retention policies, consent workflows — is significant, ongoing, and falls squarely on the practice owner, not the vendor.
3. Insurance Auditors Don’t Care Why the Note Is Wrong
This is the argument that gets underrated. Therapy documentation for insurance audits has one standard: the note has to accurately reflect what happened in the session, in the clinician’s own clinical judgment. It doesn’t matter whether an inaccurate entry came from a rushed clinician or an AI’s best guess — an auditor treats a fabricated or unsupported detail the same way either way.
Group practices already operating at scale — 20, 30, 50+ providers — carry outsized audit risk simply because of volume. Layering in a documentation tool with a measurable hallucination rate multiplies that exposure across every provider using it, every session, every week. When you’re trying to pass a therapy insurance audit, “the AI wrote it” is not a defense a payer will accept.
Why Agencies Are Choosing Non-AI Documentation Instead
This is the real shift happening in the market right now. Rather than spending months vetting AI vendors’ BAAs, subprocessor chains, and retention policies — and still carrying residual risk if any of it turns out to be misrepresented — a growing number of agencies are moving to non-AI therapy documentation software built on deterministic, rule-based logic instead.
The appeal is straightforward:
- No hallucination risk, because there’s no generative model guessing at content — notes are built from clinician-entered clinical decisions, not inferred from audio.
- No audio capture, no wiretap exposure, no consent gray area — because there’s nothing being recorded in the first place.
- No model training question, because there’s no model being trained on client sessions.
- A documentation trail that’s fully explainable during an audit, because every field maps directly back to a clinical choice the provider made.
This is precisely the gap that behavioral health EHR and session note software built on conditional logic — rather than AI generation — are designed to close. The note-writing gets faster and more consistent without introducing a new category of compliance risk on top of an already audit-heavy industry.
The Bottom Line
AI note takers promise speed. But for behavioral health agencies, speed that comes with unresolved HIPAA exposure, open consent questions, and a documented accuracy gap isn’t a good trade — especially when insurance auditors and plaintiffs’ attorneys are actively testing these tools in 2026.
If your agency is weighing whether to adopt, expand, or roll back AI documentation tools, the questions to ask aren’t about features. They’re about the BAA, the audio retention policy, the subprocessor list, and how the note holds up if a client’s chart is ever pulled for audit.
Sources:
- Foley & Lardner — HIPAA Compliance Risks with AI Scribes in Health Care
- Paubox — How to Evaluate AI Clinical Scribes for HIPAA and Consent Risks
- Basil AI — Are Ambient AI Scribes HIPAA Compliant? The Sutter Health Lawsuit
Explore insightful articles on NoteNest Blog, where our expert authors share valuable knowledge on productivity, organization, and note-taking strategies to boost efficiency.