# Is Your AI Scribe a HIPAA Business Associate?

> A business associate creates, receives, maintains or transmits PHI. Viewing is not on the list, the conduit exception is narrow, and the test reaches subcontractors too.
>
> Source: https://rankshieldmd.com/resources/is-your-ai-scribe-a-business-associate/ · RankShieldMD (verifiable AI & post-quantum security for healthcare)

Resources // HIPAA
# Is your AI scribe a business associate? Four words in the regulation decide it.

Create, receive, maintain or transmit. Viewing the data is not on that list, which is why "we can never see your recordings" answers a question nobody asked. The test also travels past your vendor to whoever they hand the audio to.
Read the guide →   Ask a question       45 CFR 160.103  Conduit exception · narrow  PHI-free · non-device
Published August 31, 2026

**A business associate is anyone who creates, receives, maintains or transmits protected health information on behalf of a covered entity. Viewing it is not one of the four. An ambient scribe receives audio of a clinical encounter and usually maintains it, which puts it inside the definition regardless of whether anyone at the vendor can read it, and the same test applies to whoever that vendor passes the audio to next.**

Ambient documentation is the fastest-moving AI category in small practices, and it is usually bought the way software is bought: a demo, a price, a security page. The HIPAA question gets settled by a sentence in a sales conversation, and the sentence is often the wrong one. This guide covers the actual test, why the most common vendor reassurance is irrelevant to it, how far down the supply chain it reaches, and what a signed agreement still cannot tell you afterward.

## The four words that decide it

Under 45 CFR 160.103, business associates are those that "create, receive, maintain or transmit" protected health information on behalf of a covered entity. [1]

Read that list again and notice what is absent. Access is not there. Viewing is not there. Understanding the contents is not there. The definition is about what an entity does with PHI in a custodial sense, not about what it perceives. That distinction is the whole of this article, because nearly every objection a vendor raises is an argument about perception.

An ambient scribe receives audio of a clinical encounter. That audio is PHI. In almost all deployments it also maintains that audio, or a transcript derived from it, for at least as long as it takes to produce a note, and frequently much longer for quality review or model evaluation. Receive and maintain are two of the four verbs.

## Why "we can never see your data" is not an answer

The most common reassurance is some version of end-to-end encryption: the vendor cannot decrypt your audio, therefore it is not really handling your PHI.

OCR addressed exactly this reasoning in the cloud computing context, and rejected it. A provider that maintains ePHI qualifies as a business associate even where it provides no-view services, and lacking an encryption key does not exempt a provider from business associate status. Data storage companies qualify as business associates regardless of whether they actually view the information they hold. [1][2]

This is worth stating plainly because the argument sounds so reasonable. Not being able to read the data is a genuinely good security property, and a vendor that offers it is doing something right. It simply is not responsive to the question of whether they are a business associate, and a vendor presenting it as though it were has either misread the rule or is hoping you will not check.

## An ambient scribe is not a courier

The other route out is the conduit exception, and it is narrower than its reputation.

The exception is limited to transmission services, whether digital or hard copy, including any temporary storage of transmitted data incident to such transmission. [1] HHS has described it as a narrow exception intended to exclude only entities providing mere courier services. [1] The postal service carrying a paper chart and a pure internet service provider moving packets are the model cases.

The hinge is persistence. A courier holds your material only as an unavoidable side effect of moving it. A scribe holds audio so that it can generate a note, and often keeps a transcript afterward so the note can be reviewed, the model evaluated, or a dispute investigated. That is not storage incidental to transmission. It is the point of the product.

Which means a CSP that maintains ePHI for the purpose of storing it qualifies as a business associate and not a conduit, even where it does not actually view the information. [1][2] A scribe is further from the courier case than a storage provider is, not closer.

## The chain nobody maps

Here is the part that survives a good procurement process and still goes unexamined.

HHS has said that the same interpretations that apply to determining whether a first-tier contractor is a business associate also apply to determining whether a subcontractor is a business associate. [1] The test does not stop at the party you contracted with. It follows the PHI.

So the real picture is a chain: your practice, the scribe vendor, whatever model host that vendor sends audio or transcripts to, the cloud infrastructure underneath that, and anything further down. Every link that creates, receives, maintains or transmits PHI is caught by the same four verbs.

Your BAA with the vendor is necessary and it is not sufficient, because it does not by itself place the rest of that chain under agreement. That is the vendor's obligation to arrange downstream, and it is a fair question to ask them to evidence rather than assert. It is also why the honest version of the question is not "do you sign a BAA" but "who else touches this audio, and what is your agreement with them."

## What to ask before signing

Five questions, and the last two are the ones that usually reveal a longer chain than the sales conversation described.

Is a BAA executed before any PHI flows, rather than after go-live. Which subcontractors touch PHI, and are they under BAAs with the vendor. Is audio or transcript retained once the note is produced, and for exactly how long. Is any of it used for model training, tuning or evaluation. And what happens to all of it on termination.

The retention and training answers matter most because they determine whether you are dealing with a transient processing step or a durable copy of your patients' encounters sitting somewhere else. They also tend to be the answers that require someone technical to join the call.

## What the agreement still cannot tell you

Suppose all of that goes well. The BAA is signed, the chain is mapped, retention is bounded.

Months later a note is questioned. A BAA cannot tell you which model version produced it, whether the model was the one you approved, or whether the record of that note has been altered since. A contract allocates duties between parties. It is not a record of events, and no amount of contractual care converts it into one.

That is a different kind of question, and it needs something made at the time rather than signed in advance. We covered the mechanics in [proving an AI scribe note is genuine](https://rankshieldmd.com/resources/prove-ai-scribe-note-genuine-audit-trail/), and the separate obligation to put the scribe into your risk analysis in [adding your AI scribe to your SRA](https://rankshieldmd.com/resources/ai-scribe-hipaa-risk-analysis/). Business associate status, risk analysis, and per-note provenance are three distinct duties that people routinely collapse into one, and satisfying any of them leaves the other two open.

## What we are careful never to claim

Business associate status is a legal determination and it belongs to your counsel, not to a vendor page and not to this article. Nothing here is legal advice, and a specific product's facts can change the analysis.

RankShieldMD is not a medical device, does not render or score clinical decisions, and never sees PHI. It does not make anyone HIPAA compliant, does not negotiate your agreements, and does not decide who in your chain is a business associate. What it does is narrow and checkable: it binds a model version to an output at the moment it happens, in a tamper-evident, PHI-free record a third party can verify without trusting us. That supports the evidentiary question a contract cannot reach.

## References

- [1] Holland & Hart Health Law Blog. *HIPAA, Business Associates, and the Conduit Exception.* Collects the 45 CFR 160.103 definition, the transmission-services limit on the conduit exception, HHS's "mere courier services" characterization, the no-view cloud position, and the subcontractor interpretation. [hhhealthlawblog.com](https://hhhealthlawblog.com/hipaa-business-associates-and-the-conduit-exception/)
- [2] U.S. Department of Health and Human Services. *Guidance on HIPAA & Cloud Computing.* OCR's position that a CSP creating, receiving, maintaining or transmitting ePHI is a business associate, including where it provides no-view services and does not hold the encryption key. [hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html)
- [3] U.S. Department of Health and Human Services. *Business Associates.* The definition and the covered-entity relationship. [hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html)

Knowledge check
## Check your read on the business associate test.

A quick check on the key points. Pick an answer to see whether it holds and why.
Question 1 of 5
Which four verbs in 45 CFR 160.103 decide whether a vendor is a business associate?
Answer: A business associate is a person or entity that creates, receives, maintains or transmits protected health information on behalf of a covered entity. Viewing is not one of the four.    Question 2 of 5
A scribe vendor says it cannot decrypt your audio, so it is not a business associate. Is that right?
Answer: OCR addressed this directly for cloud providers: a provider that maintains ePHI qualifies as a business associate even where it offers no-view services and does not hold the key. Inability to read the data is not the test.    Question 3 of 5
What does the conduit exception actually cover?
Answer: The exception is limited to transmission services, including temporary storage incident to that transmission. HHS described it as narrow and intended to exclude only entities providing mere courier services.    Question 4 of 5
Your scribe vendor sends audio to a third-party model host. What is that host?
Answer: HHS has said the same interpretations that determine whether a first-tier contractor is a business associate also apply to subcontractors. The test travels down the chain rather than stopping at your contract.    Question 5 of 5
What does a signed BAA by itself establish about a specific note months later?
Answer: A BAA is a contract that allocates obligations. It is not a record of what happened. Whether a particular note came from the model you approved is an evidentiary question a contract cannot answer.           Answer engine
## Ask the founder.

Straight answers about verifiable healthcare AI. Tap a question, or type your own.
Jamie Kloncz, founder  verified human  ✓                         Ask me anything about proving your clinical AI. I built RankShieldMD so a small practice can prove its AI, not just be asked to trust it.              Is an ambient AI scribe a HIPAA business associate?  In the ordinary case yes, and the test is narrower than most vendor conversations suggest. Under 45 CFR 160.103 a business associate is a person or entity that creates, receives, maintains or transmits protected health information on behalf of a covered entity. An ambient scribe receives audio of a clinical encounter, which is PHI, and it typically maintains that audio or a transcript for some period. Receiving and maintaining are two of the four qualifying verbs. Whether a specific product meets the definition is a legal determination for your counsel, but the starting position is that it does.  Our vendor says it cannot see our data. Does that matter?  Not to the determination. OCR addressed this directly in the cloud computing context: a provider that maintains ePHI qualifies as a business associate even when it offers no-view services, and lacking the encryption key does not exempt it. Data storage companies are business associates regardless of whether they actually view the information they hold. Inability to read the data is a good security property. It is not an exemption, and a vendor offering it as one has misread the rule.  Could our scribe vendor be a conduit instead?  Almost certainly not. The conduit exception is limited to transmission services, including any temporary storage of transmitted data incident to that transmission, and HHS has described it as a narrow exception intended to exclude only entities providing mere courier services. The postal service and a pure internet service provider are the model cases. A scribe that holds audio or transcripts so it can produce a note, improve a model, or support quality review has persistent access rather than incidental transit, which is the distinction the exception turns on.  What about the model host our vendor uses?  It may be a business associate too. HHS has said the same interpretations that determine whether a first-tier contractor is a business associate also apply to determining whether a subcontractor is one. So the test travels down the chain: your practice, the scribe vendor, whatever model host or cloud service that vendor passes PHI to, and anything further down. Each link that creates, receives, maintains or transmits PHI is caught, and your BAA with the vendor does not by itself put the rest of the chain under contract.  What should we ask a scribe vendor before signing?  Ask where the audio goes, not just where it is stored. Specifically: is a BAA offered and executed before any PHI flows; which subcontractors touch PHI and are they under BAAs with the vendor; is audio or transcript retained after the note is produced, and for how long; is any of it used for model training or evaluation; and what happens to it on termination. The retention and training answers are the ones that most often reveal a longer chain than the sales conversation described.  Does a signed BAA settle the question?  It settles who owes what. It does not record what happened. A BAA is a contract allocating obligations between parties; it cannot tell you months later which model version produced a particular note, or whether the record of that note has been altered since. Those are evidentiary questions, and they need a record made at the time rather than a document signed in advance. The contract and the record answer different questions and neither substitutes for the other.  Can RankShieldMD determine our vendor is a business associate?  No. Business associate status is a legal determination that belongs to your counsel, and nothing here is legal advice. RankShieldMD is not a medical device, does not render clinical decisions, and never sees PHI. What it does is narrower: it produces a tamper-evident, PHI-free record binding a model version to an output at the moment it happened, which speaks to the evidentiary question a BAA cannot reach. It does not make anyone HIPAA compliant.
