Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

AI-PIA · Clinical care providers

AI Privacy Impact Assessment for Mental Health & Counselling Practices

An AI-PIA gives a counselling practice the documented analysis behind adopting an AI scribe or a chatbot-based screening tool, before it is listening to a client's disclosures. Ontario's AI-scribe program work points to major documentation-time savings driving fast adoption, and that speed is exactly why the consent, transcript-custody and bias questions need answering in advance, not discovered after a tool has already recorded its first session.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What the assessment examines before AI enters the room

An AI scribe is unlike any charting tool that came before it: it captures the entire spoken conversation, not a summary the clinician chose to write down.

What the microphone actually captures

Whether the tool records continuous audio, transcribes in real time without retaining audio, or does both, since each model carries a different privacy footprint for the same session.

Where the transcript lives afterward

Which servers hold the raw transcript, for how long, and whether it is deleted once a clinical note is generated from it or kept indefinitely by default.

Who at the vendor can see session content

Human review for quality assurance or model improvement is common in AI products generally, and needs a direct answer for a tool processing therapy disclosures specifically.

Whether client consent covers this specifically

Existing consent language written for the practice-management platform rarely anticipated a third party listening live, which means consent often needs to be re-obtained, not assumed.

Regulatory map

What the assessment documents compliance with

No statute names AI scribes specifically, so the assessment applies existing consent and custodian principles to a tool that did not exist when they were written.

Consent to electronic practice

CRPO's Standard 3.4 requires informed consent before delivering services electronically, and an AI scribe listening to the session is squarely inside what that consent needs to cover.

Primary source →

Custodian accountability for the vendor

Under PHIPA, engaging an AI scribe does not transfer the custodian's obligations; the practice remains accountable for how the vendor handles the resulting transcript.

Read our guide →

Vendor privacy vetting under OntarioMD's program

OntarioMD's AI-scribe vendor-of-record work sets out privacy and secure-data-storage expectations for participating tools, a useful reference point even for practices sourcing a scribe independently.

Primary source →

PIPEDA's purpose limitation

Any secondary use of a session transcript, for model training or analytics beyond generating the clinical note, needs to fit within what the client actually consented to.

Read our guide →

What goes wrong

What the AI-PIA is designed to catch before adoption

These are not abstract AI-governance concerns; each is a specific failure mode of a tool listening to a live therapy session.

  • A raw transcript surviving longer than anyone realized

    A vendor that retains full session transcripts by default, rather than deleting them once a note is generated, leaves an unusually detailed record of a client's disclosures sitting outside the practice's control.

  • Consent theatre instead of real consent

    A generic mention of recording buried in intake paperwork does not equal informed consent to an AI system processing the conversation, a gap the assessment is built to close.

  • Bias in AI-assisted intake triage

    A tool that scores risk or urgency from intake responses can encode assumptions that disadvantage certain presentations or populations, which needs review before it influences how quickly someone is seen.

  • Screening chatbots collecting more than they disclose

    A chat-based intake or screening tool can gather sensitive responses under a casual conversational interface that understates how much is being recorded and where it goes.

Our ai-pia for mental health & counselling practices

What the AI-PIA delivers for an AI scribe or screening tool

The deliverable is written for the practice owner deciding whether to adopt, and for the College or a client who later asks how that decision was made.

Young woman taking a mental health break to write in her journal stares out the window with coffee in hand
  1. Tool-by-tool data handling review

    For each AI scribe or screening tool assessed, an analysis of audio capture, transcript storage, retention, human access and vendor infrastructure, resolved into a clear recommendation.

  2. Consent language specific to the tool

    Draft consent wording naming the AI tool, what it does, and what a client is agreeing to, ready to fold into intake and telepractice consent documents.

  3. Bias and misuse considerations

    A practical review of where an intake-triage or chatbot tool's outputs could disadvantage certain clients, with oversight steps to catch it.

  4. Regulatory alignment overview

    How the proposed use lines up with CRPO's electronic-practice standard, PHIPA custodian duties and PIPEDA, stated plainly without claiming to certify compliance.

  5. A record built to be shown

    A completed assessment formatted so it can be produced for a College inquiry, an EAP panel review, or a client who asks how their session came to be transcribed by an AI tool.

How the engagement runs

How the assessment runs for your practice

  1. Step 1

    Identify the tool and its reach

    We confirm exactly what the AI scribe or screening tool captures, from live audio to intake form responses, and how it fits into your current workflow.

  2. Step 2

    Assess the vendor

    Transcript storage, retention, human access and any secondary use are reviewed against the vendor's actual documentation and terms, with follow-up questions where they are unclear.

  3. Step 3

    Draft consent and guardrails

    Consent language and any usage conditions are written to close the specific gaps found, ready for the practice to put in front of clients.

  4. Step 4

    Decide and document

    Findings and the resulting decision, approve, approve with conditions, or hold off, are recorded in a format the practice can produce later if asked.

What it costs

What affects AI-PIA pricing for a counselling practice

The main drivers are how many AI tools are under review, whether the tool is a full session scribe versus an intake chatbot, and how much vendor documentation already exists versus needs to be requested. Assessing one AI scribe under trial is a compact engagement; reviewing a scribe alongside a chatbot-based screening tool is a broader one.

Tell us which tool you are considering and we will price the assessment against it.

Mental Health & Counselling Practices: AI-PIA questions, answered

That depends entirely on the vendor, which is exactly what the assessment establishes before adoption rather than after. Some tools delete the raw transcript once a clinical note is generated; others retain it for a defined period or indefinitely, sometimes with vendor staff able to access it for quality review or model improvement. Getting a specific, documented answer from the vendor, not a marketing summary, is the core of the review.

The assessment looks at what data the triage tool uses to score urgency or risk, whether that scoring has been tested for consistent treatment across different presentations and populations, and what human oversight exists before a triage decision affects how quickly someone is seen. Where the vendor cannot explain how the tool reaches its output, that opacity itself becomes part of the risk finding.

Yes. A chatbot collecting intake or screening responses raises the same core questions as an AI scribe, what it captures, where it goes, who can see it, plus its own added concern: a conversational interface can make a client feel they are chatting informally when in fact detailed, sensitive responses are being logged. The assessment treats screening chatbots as a distinct tool category with their own review.

Especially then, since a free trial is often when the least due diligence happens and the most session data has already been captured by the time anyone asks questions. Trial terms can differ meaningfully from paid-tier terms on data use and retention, so the assessment is most valuable done before the trial starts, not after several weeks of sessions have already gone through the tool.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.