AI Governance
AI Scribes in Healthcare: Efficiency Without Exposing PHI

The most popular AI tool in healthcare is also the easiest to deploy quietly
Ask a clinician what they would do with an extra hour a day, and you will hear the same answer: see the patient instead of the screen. That is the promise of the AI scribe, an ambient tool that listens to a clinical encounter, transcribes it, and drafts a structured note for the clinician to review and sign. For physicians drowning in documentation, the appeal is immediate and real.
It is also why AI scribes are spreading faster than the governance around them. A single clinician can sign up for a scribe app, point it at a patient conversation, and start saving time before anyone in IT, privacy, or compliance knows the tool exists. The efficiency arrives instantly. The privacy exposure arrives just as fast, only quieter.
The good news: you do not have to choose between efficiency and protecting personal health information (PHI). With the right questions, the right contract, and the right assessment, you can have both. This post walks through how an AI scribe actually handles PHI, the risks worth taking seriously, and the governance steps that let you say yes with confidence rather than crossing your fingers.
Where the PHI actually goes
To manage the risk, you first have to see it. An AI scribe is not one thing; it is a chain of data flows, and PHI moves through each link. The recording of a clinical conversation is among the most sensitive data a healthcare organization handles, because it captures not just a diagnosis but the patient's own words, tone, and context.
A typical ambient scribe touches PHI at several stages:
- Capture: audio of the encounter is recorded on a device or in an app, often a clinician's phone or a room microphone.
- Transmission: that audio is sent, usually to the vendor's cloud, for processing.
- Processing: a speech-to-text model transcribes the audio, and a language model summarizes it into a clinical note.
- Storage: the transcript, audio, and draft note may be retained by the vendor, sometimes well beyond the encounter.
- Return: the draft note flows back to the clinician and, ideally, into the electronic medical record (EMR).
- Secondary use: in some products, recordings or transcripts may be used to train or improve the vendor's models, the single most important flow to identify and shut down.
The risks worth taking seriously
Not every theoretical risk deserves equal weight. A few, though, separate a safe deployment from a breach waiting to happen, and they map directly to the obligations Canadian custodians carry under PHIPA in Ontario, the Health Information Act (HIA) in Alberta, Quebec's Law 25, and PIPEDA where it applies.
- Training on patient data. If the vendor uses your recordings to improve its models, PHI leaves your control in a way that is effectively irreversible. This must be contractually prohibited. In Alberta, the OIPC has been explicit that using personal health information to train AI models is not permitted under the HIA and cannot be justified by consent, so do not assume a consent checkbox makes it acceptable.
- Data residency and cross-border transfer. Many scribe vendors process and store data in the United States. That triggers cross-border transfer considerations; under Quebec's Law 25, a privacy assessment is required before communicating personal information outside Quebec at all, and in the public sector cross-border storage may be restricted outright. Know where the audio lives.
- Over-collection and retention. A scribe that keeps raw audio indefinitely creates a standing pool of highly sensitive data. Data minimization means keeping only what you need, only as long as you need it.
- Accuracy and the human-in-the-loop. AI-generated notes can hallucinate, mishear medication names, or invent details. The clinician, not the model, remains accountable for the record, so review before signing is non-negotiable.
- Quiet adoption (shadow AI). The biggest risk is often the one nobody approved: a clinician using a free consumer scribe app on a personal device, outside any agreement or safeguard.
Consent and the patient in the room
Recording a patient encounter is a collection of personal health information, and patients have a right to know it is happening. In most Canadian healthcare contexts, that means transparency and, depending on the circumstances and your regulator's guidance, the opportunity to decline being recorded by an AI tool.
Practically, this is less burdensome than it sounds. A short, plain-language script, "I use a secure AI tool to help me write my notes so I can focus on you. It records our conversation, and I review everything before it goes in your chart. Is that okay?", respects the patient and builds trust rather than eroding it. Document how consent is obtained, and have a fallback for patients who decline.
Clinical regulators are paying attention here. The College of Physicians and Surgeons of Ontario has published advice on using artificial intelligence in clinical practice, including AI scribes, reinforcing that physicians should inform patients and obtain consent before recording, and that professional accountability for the record sits with the clinician regardless of which tool drafted it.
The vendor questions that actually matter
Most of a scribe's privacy posture is decided by the vendor and locked into the contract. A polished marketing page is not a safeguard; the answers to specific questions are. Before any deployment, get clear, written responses to the following:
- Do you use our audio, transcripts, or notes to train or improve your models, ever, in any form? Get this in writing as a prohibition.
- Where is data processed and stored, and can we require Canadian residency?
- Who are your subprocessors, and do any of them touch PHI?
- How long do you retain audio, transcripts, and notes, and can we set or shorten that retention?
- What is your breach-notification commitment, and how fast will you notify us?
- Do you sign a written agreement that names us as the custodian and you as the service provider acting only on our instructions?
- What security practices and independent attestations do you hold, and will you share evidence such as a SOC 2 report or equivalent? If a vendor cannot or will not answer these clearly, that is your answer. Treating an AI scribe like any other high-risk vendor, with real due diligence rather than a quick demo, is the difference between a defensible deployment and an unmanaged one.
When you need an AI PIA, and why it is the deployment plan, not the paperwork
Introducing an AI scribe into clinical workflows is exactly the kind of change a Privacy Impact Assessment (PIA) exists to manage, and in several jurisdictions it is not optional. In Alberta, the OIPC's September 2025 guidance requires custodians to complete and submit a PIA before using an AI scribe under the HIA. Under Quebec's Law 25, a privacy assessment is required before personal information is communicated outside Quebec. Ontario's public-sector reforms now require a PIA before collecting personal information under FIPPA; PHIPA custodians are not captured by that specific rule, but a PIA remains the established best practice for a change this significant. An AI PIA follows the same backbone as a traditional one, data mapping, legal authority, risk analysis, mitigation, but extends the lens to model training, secondary use, accuracy, and ongoing change.
Done early, the PIA is not a compliance afterthought; it is the deployment plan. It forces the data-flow mapping, the vendor questions, the consent approach, and the retention rules into one document before the tool touches a single patient. Done late, after the scribe is already in dozens of exam rooms, it becomes an exercise in documenting risk you can no longer easily undo.
An AI PIA is also a living artifact. Model updates, new features, and vendor releases can shift the privacy picture, so the assessment should be revisited when the tool changes, not filed and forgotten.
A practical path to a safe deployment
Putting it together, here is the sequence that lets a healthcare organization adopt AI scribes without exposing PHI:
- Map the data flow end to end before choosing a tool: capture, transmission, processing, storage, return, and any secondary use.
- Run an AI PIA early, and treat its findings as deployment requirements rather than suggestions.
- Lock the protections into the contract: no model training on your data, Canadian residency where required, defined retention, breach notification, and audit rights.
- Set the consent approach and a plain-language script, with a documented option for patients who decline.
- Keep the clinician in the loop, with every note reviewed and signed before it enters the record.
- Shut down shadow AI with a clear policy on which tools are approved and which are not.
- Re-assess when the tool changes, because the privacy risk changes with it.
Efficiency and protection are not a trade-off
AI scribes are one of the rare healthcare technologies where the efficiency gains are obvious and immediate. That is precisely why they deserve deliberate governance rather than quiet adoption. The organizations that get this right are not the ones that move slowest; they are the ones that ask the right questions first, write the protections into the contract, and let an AI PIA turn a risky pilot into a defensible program.
If you are evaluating an AI scribe, or discovering that clinicians are already using one, Privacy Horizon helps healthcare organizations across Canada assess the tool, run the AI PIA, and put the right safeguards in place, so you keep the hours you save and the trust you have earned.
Related reading
- Can you use AI scribes in healthcare while protecting PHI
- When do you need an AI PIA