If you are in crisis, help is available now. Call or text 988 to reach the Suicide & Crisis Lifeline, or text HOME to 741741. If someone is in immediate danger, call 911. This site is information only and cannot provide urgent help.

AI scribes and HIPAA

About clinicgpt.ai: This site is a browser-only demo plus educational content. clinicgpt.ai offers no Business Associate Agreement and is not a HIPAA-covered clinical documentation service. Nothing here is legal advice; practices should consult qualified counsel and their compliance officers.

PHI and the Privacy / Security Rules (one paragraph)

Under the U.S. Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules, protected health information (PHI) is individually identifiable health information held or transmitted by a covered entity (or its business associate) in any form. The Privacy Rule governs uses and disclosures; the Security Rule requires administrative, physical, and technical safeguards for electronic PHI (ePHI). Official materials are maintained by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (HIPAA for professionals; reviewed 2026-07-21). If visit audio, transcripts, or draft notes identify a patient (or could reasonably be used to identify one) and a vendor receives them, you are no longer in “interesting tech demo” territory — you are in regulated data handling.

When an AI vendor is a Business Associate

A Business Associate is a person or entity that performs functions or activities involving PHI on behalf of a covered entity (or another business associate). Classic examples: EHR hosting, claims clearinghouses, transcription vendors, cloud storage of ePHI. An ambient scribe vendor that receives, processes, or stores visit audio, transcripts, or notes for a clinic is typically acting as a business associate.

When that relationship exists, the Privacy Rule generally requires a Business Associate Agreement (BAA) — a written contract that binds the vendor to HIPAA-required safeguards and breach terms (HHS business associate materials; as of 2026-07-21). “We use encryption” or “we’re SOC 2” is not a substitute for a BAA when one is required. Marketing pages that bury the BAA behind enterprise sales may still be business associates the moment PHI flows.

clinicgpt.ai does not offer a BAA. We are not asking you to send PHI here, and the demo is designed so the paste is not our data pipeline.

What “de-identified” actually requires

Teams sometimes say “we’ll just de-identify the transcript and skip the BAA.” HIPAA de-identification is a defined process, not a vibe check. HHS describes two methods (Guidance Regarding Methods for De-identification of Protected Health Information; as of 2026-07-21):

  1. Expert Determination — a qualified expert determines, and documents, that the risk of re-identification is very small under the intended context.
  2. Safe Harbor — removal of a specified list of identifiers (names, geographic subdivisions smaller than a state with exceptions, elements of dates directly related to an individual, contact numbers, device IDs, full-face photos, and others on the HHS list), with no actual knowledge that remaining information could identify the individual.

Visit audio is especially hard: voice itself can be identifying; background conversation can leak names; rare diagnoses plus dates re-identify. Stripping a first name from a transcript while leaving “the 47-year-old mayor of [small town] with [rare condition]” is not Safe Harbor. If you cannot meet a de-identification method end-to-end, assume you still have PHI and need the appropriate agreements and safeguards.

Why a browser-only demo that uploads nothing sits outside this boundary

The clinicgpt.ai SOAP demo formats text in your browser with local patterns. As designed and described in how this demo works:

  • There is no upload of the paste to a ClinicGPT backend for model inference.
  • There is no retention product for transcripts on this domain.
  • There is no production ambient scribe marketed under a BAA here.

That architecture is deliberate. It lets anyone explore SOAP structure without creating a business-associate relationship with this website. It is also why this demo is a poor substitute for a real ambient vendor: real products that listen to live visits almost always do receive PHI and do need the full compliance package.

Closing the tab discards ordinary form state in the browser. That is still not a reason to paste real charts into public pages — treat demos as synthetic data only.

Questions a practice should ask any real scribe vendor

Use this list when evaluating tools elsewhere (clinicgpt.ai sells none of them):

  1. Will you sign our BAA before any PHI flows? If no, stop.
  2. Where is audio stored, in which regions, for how long, and who can access it?
  3. Is data used to train foundation models? Get the answer in the BAA or DPA, not only in a blog post.
  4. What is logged for audit (prompt/version/draft/final), and for how many years?
  5. What happens on subprocessors (ASR vendor, cloud host, support tools)?
  6. How do you handle patient recording consent and multi-state rules?
  7. What is the clinician review workflow, and can signature be forced without open edits?

Deeper checklist: evaluating an AI scribe vendor. Category background: what ambient AI scribes are. Author-of-record: keeping the clinician responsible.

FAQ alignment with this site

QuestionAnswer on clinicgpt.ai
Do you offer a signed HIPAA BAA?No.
Is this a covered clinical documentation product?No.
Does the demo send my paste to a model?No.
Can I use demo output as a chart note?No.
Who operates the site?AdvancedCare USA Inc. — general contact only.

Sources (as of 2026-07-21)

Get in touch