Plainstart Back to the kit

Article

Questions to Ask Before Your Practice Adopts an AI Scribe

This article covers procurement and data governance only. Clinical judgment, patient safety, the suitability of any AI tool for clinical use, and professional obligations to patients are outside its scope entirely. Those questions belong to clinicians, your professional body, and regulators. Nothing here should be read as legal, compliance, or professional advice. It is general guidance, and your own advisers decide what applies to your practice.

Why the Procurement Questions Come First

An AI scribe sounds straightforward: the tool listens, it produces a note, the clinician reviews it. The workflow appeal is obvious. But before any clinician in your practice speaks a single word near an active microphone, the people responsible for operations and data governance need answers to a specific set of questions.

Vendors in this space are selling fast. Marketing materials are confident. The answers that matter, however, are not in the brochure. They are in the data processing agreement, the subprocessor list, and the responses your contact gives when you ask questions they were not expecting.

This article gives you those questions, in plain language, before you sign anything.


1. Where Does the Recording Go, and Where Does the Transcript Go?

These are two separate questions. The audio recording and the text transcript may be handled by different systems, stored in different locations, and subject to different retention rules.

Ask the vendor to name the specific countries where audio is processed and where transcripts are stored at rest. "Secure cloud infrastructure" is not an answer. Ask for the name of the cloud provider, the region, and whether any processing crosses a border, even temporarily.

Then ask how long each type of data is retained. Some vendors keep audio for a short period and transcripts longer. Some keep both indefinitely unless you configure a deletion schedule. Some have a default retention period buried in their terms that you will not find unless you look.

Ask whether retention is configurable by the practice, and if so, what the actual steps are to change it. If the vendor says data is deleted after 30 days, ask how that deletion is confirmed and whether you receive any record of it.


2. Does the Vendor Train Models on Your Content?

This is the question most practice managers do not ask until after they have signed.

Many AI products, including transcription tools, reserve the right to use customer data to train or improve their models. This is commonly buried in a terms-of-service clause rather than disclosed upfront. The clause may apply by default unless you opt out, and opting out may require a different contract tier or a written request.

Ask directly: does the vendor use recordings, transcripts, or any derived data from your practice to train, fine-tune, or evaluate AI models? Ask for the specific clause in the agreement that addresses this. Then ask what evidence you would receive if you wanted to verify that your content has not been used. A policy statement is not evidence. A contractual commitment, with audit rights, is closer to evidence.

If the vendor cannot point to a specific clause, or if the clause permits training by default, treat that as a material fact in your evaluation, not a minor detail.


3. Who at the Vendor Can Access the Material?

Ask for the vendor's internal access policy. Specifically:

  • Which employee roles have access to audio recordings and transcripts?
  • Is access logged, and are those logs available to you on request?
  • Does the vendor use any third-party human reviewers for quality assurance? If so, where are those reviewers located?
  • Are subcontractors or subprocessors involved in any part of the workflow?

Human review of clinical conversations is common in transcription services. It is not necessarily a reason to walk away, but it must be disclosed, and the people doing the review need to be operating under appropriate confidentiality terms. Ask to see the subprocessor list, and ask whether that list is updated when subprocessors change, and how you are notified.


4. What Happens to Your Data If You Leave?

This is a governance question that is easy to forget when you are evaluating a product and the relationship feels cooperative.

Ask what happens to all data held by the vendor when your subscription ends. Specifically: is it deleted, and on what timeline? Can you export everything before cancellation? In what format? Is there a window during which data remains accessible after you cancel, and what access controls apply during that window?

Some vendors delete data promptly on cancellation. Others retain it for months under their standard terms. Some retain aggregated or anonymised versions indefinitely. The agreement should tell you. If it does not, ask for a written clarification before you sign.


5. How Is Patient Consent Captured, and Who Is Responsible for It?

Whatever privacy rules apply where you operate, which vary by jurisdiction and are worth checking with your own adviser, the question of patient consent to AI-assisted recording is not theoretical. Patients are in the room. Their health information is being processed by a third-party system.

Ask the vendor whether they provide any tools or workflows for capturing consent. Then ask who bears responsibility for obtaining it. Vendors will almost always place that responsibility on the practice. That is a reasonable position, but it means you need an operational answer before the tool goes live.

The practice needs to decide: when and how is a patient told that an AI tool is recording the consultation? Is verbal notice sufficient under whatever rules apply to you, or do you need written consent? What happens if a patient declines? Does the clinician have a simple way to pause or disable the tool for that consultation?

Your professional body or adviser is the right source for answers on what your obligations are. This article does not answer that question. What this article can tell you is that you need the answer before go-live, not after.

A starting point for building a written policy around how your practice uses AI tools is the Plainstart AI policy for medical and health practices, which is available free and written in plain language for practice teams.


6. What Is the Practice Committing to Operationally?

Read the acceptable-use terms. Many AI scribe vendors restrict how you can use the product, what integrations are permitted, and what you are required to do in the event of a data incident.

Common operational commitments include: notifying the vendor within a specific timeframe if you become aware of a breach, completing security training required by the vendor, maintaining certain technical configurations, and restricting access to authorised staff only.

These are reasonable commitments, but you need to know about them before you agree to them, and you need to check whether your practice has the capacity to meet them.


A Worked Example: The Answer That Stopped the Evaluation

A practice with four clinicians identified an AI scribe product they wanted to trial. The product manager ran a standard evaluation: demo, pricing call, reference check with another practice. Everything looked acceptable.

Before signing, the practice manager sent a short list of written questions to the vendor's sales contact. One question was: "Does your platform use practice recordings or transcripts to train or improve AI models, and where is this addressed in the agreement?"

The vendor's response confirmed that by default, anonymised transcripts were used for model improvement. Opting out required a request to their enterprise team and was available only on their highest-tier plan, which was roughly three times the price quoted.

The practice did not proceed. Not because training on data is automatically unacceptable, but because the default had not been disclosed at any point during the evaluation, and the terms they had been shown did not make it obvious. The practice manager's view was that if the vendor had not flagged this voluntarily, there was no basis for confidence about what else had not been flagged.

The evaluation stopped. A different vendor was identified. The questions were asked again at the start, not the end.


Before You Sign: A Short Checklist

These are the areas to have written answers on before any agreement is executed.

Storage locations for audio and for transcripts, named specifically. Retention periods for both, and whether they are configurable. Whether the vendor trains on practice content, and what the contractual position is. Who has internal and third-party access, and whether access is logged. What happens to data on exit, and on what timeline. What the practice is responsible for operationally under the terms.

Clinical judgment, patient safety, and your professional obligations sit outside every item on that list. Those belong to your clinicians and your advisers. The list above belongs to whoever is responsible for procurement and data governance in your practice. That work needs to happen first.


This article is general guidance for practice managers evaluating procurement decisions. It is not legal, compliance, clinical, or professional advice. Your own advisers determine what applies to your practice and your jurisdiction.

Free, no email required

Build your own AI usage policy in about two minutes

Answer eight questions and the full policy writes itself around your business. Copy it, download it, put it in front of staff today.

Open the policy generator