Unless the contract or the integration says otherwise, the ambient scribe vendor keeps the transcript. It sits on the vendor’s own systems, under the vendor’s own retention terms, and what reaches the health system is the finished clinical note, not the underlying recording or a record of what the model was given to produce it. A signed business associate agreement is the condition HIPAA sets for that arrangement. It does not, by itself, let the health system answer what the model received for one encounter, how long the vendor keeps the recording, or whether either has actually been deleted.
Is the ambient scribe vendor a business associate?
Yes, when it handles PHI for a covered entity. HIPAA defines a business associate at 45 CFR 160.103 as a person who, on behalf of a covered entity and other than as a member of its workforce, creates, receives, maintains, or transmits protected health information for a function or activity HIPAA regulates, or who provides certain services to it, such as consulting, management, or administrative services, that involve disclosing PHI. An ambient scribe that listens to an encounter, generates a transcript, and returns a note is creating, receiving, and transmitting PHI on the covered entity’s behalf, which makes the vendor a business associate and makes a business associate agreement a precondition, under 45 CFR 164.502(e), for letting the vendor create, receive, maintain, or transmit that PHI at all.
The vendor cannot design its way out of that status. HHS guidance on cloud computing and business associates confirms that a service provider is still a business associate even where it stores only encrypted PHI and holds no decryption key, a configuration HHS addresses directly as a no-view service. The same reasoning covers a scribe vendor that says it does not retain the audio, or that its systems are encrypted throughout. Performing the function on the covered entity’s behalf is what creates the obligation, not what the vendor happens to be able to see. Where PHI reaches a tool with no BAA in place at all, the exposure is more basic than anything in this piece: Is ChatGPT HIPAA compliant covers what a BAA changes and what it does not.
What should the business associate agreement say about retention, return, and deletion?
It should say exactly how long the vendor holds the audio, how long it holds the generated transcript, and what happens to both when the relationship ends, because HIPAA requires the contract to address these points without setting a specific number for any of them. 45 CFR 164.504(e)(2) sets out what a business associate contract must establish: the permitted and required uses of PHI, safeguards consistent with the Security Rule, a duty to report any use or disclosure the contract did not authorize, the same restrictions extended to any subcontractor, and, at termination, a duty to return or destroy all PHI the business associate holds and retain no copies, or, where return or destruction is not feasible, to extend the contract’s protections to that PHI and limit further use to the reasons it could not be returned or destroyed.
None of that fixes a retention window for the transcript itself. HIPAA leaves the number to the contract, which means the health system has to ask for it rather than assume the regulation supplied one.
| What 45 CFR 164.504(e) requires | What to confirm with the vendor |
|---|---|
| Permitted and required uses of PHI are defined | Whether that definition covers the raw audio and the generated transcript separately |
| Safeguards consistent with the Security Rule | Where the audio and transcript are stored, and under whose keys |
| Return or destroy PHI at termination, no copies retained | A stated retention period for audio and transcript, and the deletion mechanism, not just the promise |
| The same restrictions bind any subcontractor | Whether a subprocessor handles transcription or model inference, and under what agreement |
Is the ambient scribe transcript part of the designated record set?
It can be. 45 CFR 164.501 defines a designated record set as a group of records maintained by or for a covered entity that is the medical and billing records about individuals kept by or for a covered health care provider, or that is used, in whole or in part, to make decisions about individuals. The test is functional, not locational: it does not matter whether the transcript sits on the covered entity’s server or the vendor’s, or what either party calls it. When a transcript is itself used to make decisions about the patient, the definition points toward including it. As far as we can find, HHS has not published guidance specifically addressing ambient scribe transcripts, so whether a given health system’s transcript falls inside the designated record set is a classification call for the health system’s privacy counsel to make before a request arrives, not something this page can settle for every deployment.
Where a transcript is classified as part of the designated record set, that classification has a direct consequence under 45 CFR 164.524. The right of access reaches PHI in a designated record set maintained by or for the covered entity, and HHS guidance confirms that the right extends to PHI in a designated record set a business associate maintains on the covered entity’s behalf, not only what sits on the covered entity’s own systems. In that case, a patient requesting their record triggers the timeline in 164.524(b)(2): 30 days to act, extendable once by up to 30 more days with written notice, and that clock runs whether or not the transcript is easy to retrieve from the vendor.
How long does the vendor keep the transcript, and the audio behind it?
There is no single answer, and HIPAA does not supply one. The rule requires a business associate agreement and requires that agreement to address return or destruction at termination, but it does not fix a retention period for PHI itself. Separately, the six year retention duty at 45 CFR 164.316(b)(2) applies to the covered entity’s own required Security Rule documentation, meaning its policies, procedures, and the written record of the actions and assessments the rule requires, not to how long a vendor may hold a transcript or an audio file. State law can set retention periods for the medical record itself, and those periods vary from state to state, so check the current statute for the state in question rather than assume a number, including the six year HIPAA documentation figure, applies to the clinical record.
What is answerable is what to ask the vendor. Get, in writing, a stated retention period for the raw audio and a separate one for the generated transcript if they differ, confirmation of whether the audio is deleted once the transcript is generated, what the retention terms say happens at contract termination, and whether those terms live in the BAA itself or in a separate order form that can change without renegotiating the BAA. A vendor’s marketing page is not a source for any of this. Its BAA and its published data handling documentation are.
Can the health system show what the model received for one encounter, months later?
Not from its own systems when the scribe runs entirely on the vendor’s infrastructure, and that gap is what this whole question is really about. 45 CFR 164.312(b) requires audit controls: mechanisms that record and examine activity in the information systems that contain or use electronic PHI. When an ambient scribe runs entirely on the vendor’s infrastructure, any log of what the model received and returned is created there too, which leaves the covered entity depending on a system it does not operate, and can reach only as far as the contract allows, for the record of what the model was given.
This is where the six year figure gets misapplied. 45 CFR 164.316(b)(2) requires the covered entity to retain its required Security Rule documentation for six years. It says nothing about retaining a model’s input and output for a given encounter, and no provision in the Privacy Rule or the Security Rule does either. Whatever ability a health system has to reconstruct what a model received for one encounter six months ago comes from what it built or bought to capture that at the time, not from a HIPAA retention clock. An OCR inquiry, a malpractice discovery request, or a patient’s own access request can all ask this question, on a timeline the health system does not control, and a request forwarded to the vendor is not the same as a record the institution holds.
If the transcript is part of the designated record set, a patient’s access request and an OCR inquiry can both reach it. Whether the health system can answer either from its own record, or has to ask the vendor and wait, is a question the institution can settle before it is asked, not after.
Sources
The citations above are drawn from the following primary sources, read current as of September 2026.
- 45 CFR 160.103, definition of business associate
- 45 CFR 164.501, definitions including designated record set and record
- 45 CFR 164.502(e), disclosures to business associates
- 45 CFR 164.504(e), business associate contracts
- 45 CFR 164.312(b), audit controls
- 45 CFR 164.316(b), documentation requirements and time limit
- 45 CFR 164.524, access of individuals to protected health information
- HHS, guidance on HIPAA and cloud computing
- HHS, FAQ on cloud service providers that store only encrypted electronic PHI
- HHS, FAQ on the right of access to PHI a business associate maintains
Where Verillian fits
Verillian governs AI use on the devices your organization manages. A checkpoint on each device sits between your people’s AI tools and agents and the AI providers they reach. For the Anthropic API format it enforces your policy before a request leaves the device; for the other providers your policy names, it records the usage. Each record is signed on the device it came from and hash-chained to the one before it, and your own admin server flags any entry that does not link or verify when it arrives, so the record is tamper-evident and stays on your own infrastructure. Redaction is best-effort, not a guarantee that every value is caught. The admin server runs where you choose: on-prem, private cloud, or air-gapped. Mac is supported today, with Windows and Linux in early access. For a health system, that record can help evidence the audit controls 45 CFR 164.312(b) asks for over AI use that starts on managed devices, outside the scribe’s own integration, with each entry bound to the device and person it came from. The architecture is aligned with the HIPAA Security Rule, not certified, because HHS does not recognize certifications against it.
Verillian does not see inside a vendor’s own cloud. When a vendor’s service calls a model on the vendor’s servers, as an ambient scribe or a hosted report-writing tool does, the record of what that model received is created on the vendor’s side, and the contract is your lever for it. What Verillian gives you is the record of AI use that starts on your own devices.
See how this maps to healthcare and other regulated sectors, and what a business associate agreement changes on the ChatGPT question.