Healthcare AI

Ambient AI scribe security, privacy and consent.

Security measures for ambient clinical documentation come down to three questions: what happens to the audio, who can reach it, and what evidence supports the answer. This guide walks the audio lifecycle and its controls, the vendor security review, the retention limits that reduce exposure, and the consent law the Sharp HealthCare complaint put in front of every health system.

35 min read Reviewed Aug 26, 2026
Joe Braidwood
Joe Braidwood
CEO, GLACIS
35 min read

Executive Summary

A proposed class action filed against Sharp HealthCare entities in November 2025 alleges that a clinic recorded a patient encounter with an ambient documentation app without the patient’s consent. Becker’s Hospital Review described the allegation; the San Diego Superior Court index confirms the filing and lists Sharp entities as defendants. The allegations have not been treated here as adjudicated facts.

Abridge was identified in the reporting as the app used during the encounter. It is not listed as a defendant in the public court index reviewed on August 26, 2026. This guide therefore focuses on the operational questions the dispute surfaces: when recording starts, what the patient was told, what data leaves the room, who can access it, how long it remains, and what evidence exists for each answer.

Recording and medical-information rules are jurisdiction- and fact-specific. The controls below are practical review guidance, not a claim of legal sufficiency. The page was reviewed for currentness on August 26, 2026; no public merits disposition in Saucedo was verified during that review.

Nov 2025
Sharp Case Filed
121
JAMA Study Users
103
Patients in Study
81.6%
Basic-Information Response

In This Guide

The Sharp HealthCare Complaint

Saucedo v. Sharp HealthCare, case 25CU063632C, was filed in San Diego Superior Court on November 26, 2025. Becker’s reported that plaintiff Jose Saucedo claims a Sharp Rees-Stealy clinic recorded a July 2025 appointment with Abridge’s ambient clinical documentation app without his consent, and that he learned of the recording after reading his visit notes. Sharp declined to comment to Becker’s on pending litigation.

Those statements describe the plaintiff’s allegations. They are not findings by a court. The public court index lists Sharp Community Medical Group, Sharp HealthCare, Sharp Rees-Stealy Medical Group, and SharpCare Medical Group as defendants. It does not list Abridge as a defendant. This review did not verify a public merits ruling or class-certification decision as of August 26, 2026.

Complaint Allegations Are Not Adjudicated Facts

Treat the case as a reason to test the workflow, not as proof that any defendant or vendor violated the law. A health system should be able to reconcile the patient-facing consent event, the recording state, the generated note, and the retention or deletion record for the same encounter.

Legal Theories Require a Fact-Specific Analysis

California Penal Code § 632 applies when a person intentionally records a confidential communication without the consent of all parties. Whether a particular encounter, device, notice, participant, or data flow satisfies each element is a legal question. Other CIPA provisions use different language and should not be collapsed into a universal “all AI recording is wiretapping” rule.

CIPA’s civil-remedy provision can make statutory damages available to a person injured by a proven violation, but an amount is not automatic for every recording. Liability, statutory fit, defenses, standing, class treatment, and the number of legally cognizable violations remain matters for a court.

Recent CIPA cases often turn on the particular statutory clause, whether a communication was confidential, when interception occurred, what the service provider could do with the data, and whether the decision was only at the pleading stage. A motion-to-dismiss ruling that permits allegations to proceed does not adjudicate liability.

The “Capability” Issue Is Not Automatic Liability

Some federal-court decisions have considered whether a service provider had the capability to use intercepted information for its own purposes. That analysis is sometimes described as a “capability test.” It is not a generally applicable rule that every vendor with a product-improvement clause is liable. The safer practical response is to map the actual data flow and contract: permitted uses, training and improvement rights, subprocessors, retention, access, and whether those terms match the deployed configuration.

Questions Counsel and Reviewers Need Answered

Question Operational Evidence Claim Boundary
Was the communication recorded? Capture event, recording indicator, start and stop times A system record does not establish legal consent
What did the patient affirm? Versioned disclosure and encounter-specific response Recorded assent does not establish that disclosure was sufficient
Who received or could access the data? Data-flow map, subprocessor list, access-control and access-log evidence Contract language and actual access are different facts
What happened after note generation? Clinician review state, retention clock, hold status, deletion record Deletion timing depends on applicable record and hold duties

California’s Privacy Framework

California § 632 generally requires all-party consent before intentionally recording a confidential communication. The statute defines confidentiality by the circumstances and the parties’ reasonable expectations; it is not a blanket rule for every communication or every technology. Other jurisdictions differ, sometimes by medium and context, so a static list of “two-party states” is a poor substitute for current legal analysis.

California’s Healthcare AI Advisory

In January 2025, the California Attorney General issued an AI advisory and a healthcare-specific advisory. The office said existing consumer protection, civil-rights, privacy, and professional-licensing laws apply to healthcare AI, and encouraged transparency about whether patient information is used for training and how AI affects care. The Attorney General also said the advisories are not comprehensive.

What the Advisory Supports

Existing California law applies to AI, healthcare entities should test and audit systems, and patients should receive transparency about data use and AI in health decisions.

What It Does Not Do

It does not create one universal consent script, one retention period, or a presumption that a particular ambient scribe is lawful or unlawful.

CMIA: Healthcare-Specific Privacy

California Civil Code § 56.10(a) generally prohibits a provider, health plan, or contractor from disclosing medical information without authorization, but subdivisions (b) and (c) contain required and permitted disclosures. It is therefore inaccurate to say every transfer to a healthcare vendor always requires a separate written patient authorization. The analysis depends on the parties’ roles, the purpose, the contract, and the specific data use or disclosure.

Vendor Processing Questions

For ambient documentation, review whether the provider and vendor have defined permitted uses, whether audio or transcripts can be used for training or product improvement, which subprocessors receive the data, whether access is limited, and how deletion and return obligations work. A BAA is important where HIPAA applies, but neither a BAA nor a generic privacy notice resolves every CMIA, recording-consent, professional-duty, or contract question.

Reviewed Against California Primary Guidance

The California Attorney General’s healthcare AI advisory is guidance, not a product approval or a substitute for counsel. It supports a workflow-level review of transparency, privacy, testing, validation, and accountability.

Retention and Deletion Obligations

There is no universal retention period for ambient audio. The answer depends on the purpose of retention, the provider type, jurisdiction, whether the audio becomes part of a designated record set or another regulated record, contractual commitments, patient-access rules, and any clinical or litigation hold. HIPAA’s retention periods for specified compliance documentation should not be mistaken for a single audio-retention rule.

Audio as Transitory Data

A provider should make an explicit classification decision: is the raw audio a transient input, part of the clinical record, quality-assurance material, or something else? That decision should be consistent across the notice, consent workflow, contract, record policy, patient-response process, and technical configuration.

Data minimization often supports a short period when audio is used only to create a draft note, but “same day” or “one week” is not a legal safe harbor. Choose the shortest period justified by the documented purpose, preserve material subject to a valid hold, and test whether the deletion mechanism actually follows the configured schedule.

AI Training Data Complications

For AI training data, organizations face tension between model improvement needs and privacy obligations:

Which Regulatory Frameworks Apply

Ambient documentation sits inside existing privacy, security, professional-practice, consumer-protection, records, and, depending on functionality, medical-device frameworks. Product labels do not decide which rules apply.

Federal Developments

Federal Review Points as of August 26, 2026

Regulation Agency Key Requirements
HIPAA Security Rule NPRM HHS/OCR (Jan 2025) Remains a proposal, not the current rule. Continue to follow the current Security Rule and track the HHS OCR rulemaking page.
HIPAA Privacy and Security Rules HHS OCR Analyze permitted uses and disclosures, business-associate terms, safeguards, minimum-necessary rules where applicable, individual rights, and breach duties.
Certified Health IT Requirements ASTP/ONC Applicability depends on the certified health IT and functionality in scope; do not assume every ambient product is covered in the same way.
FDA AI/ML Guidance FDA (Jan 2025) Device status turns on intended use, claims, and functionality. FDA’s device software framework should be applied to the specific product rather than the “scribe” category.

Classification Follows Function

A product that only creates a draft note may present a different FDA question from one that recommends diagnoses, treatment, triage, or alerts. Features and marketed claims can change over time. Review the current product configuration and claims; do not publish the categorical statement that “most scribes are not devices” as though it were an FDA classification.

Security measures for ambient clinical documentation

Consent and security answer different questions. The useful way to review them is as one lifecycle: audio moves through stages between the encounter and the chart, and each stage has a stated rule, a configured control, and evidence whose scope and sufficiency must be assessed.

Stage Control that matters Failure it prevents
Capture Explicit start and stop under clinician control, with a visible recording state Recording that continues past the encounter, or begins before consent
Transport Current encrypted transport appropriate to the deployed client and threat model Interception on hospital wireless or an untrusted network
Storage Encryption at rest, customer-scoped keys, and a named processing region Cross-tenant exposure, and audio processed outside the contracted jurisdiction
Transcription Written commitment that audio and transcript are excluded from model training Use outside the purposes disclosed and contractually permitted
Note generation Access limited to the treating clinician and the minimum necessary support staff Broad internal access to raw encounter audio
EHR write Clinician review and attestation before the note enters the record Unreviewed AI text entering the clinical record
Deletion Audio destroyed on a defined clock, with a per-recording deletion record Retention beyond the documented purpose or configured period

Four controls in that list carry most of the risk, and they are the ones that most often turn out to be assumed rather than verified.

Permitted use is first, because contract and configuration can diverge. Review whether audio, transcripts, draft notes, feedback, and telemetry may be used for training, evaluation, support, safety, or product improvement. Identify subprocessors and confirm that downstream terms match the provider’s commitments.

Access control is second. Ambient audio can capture more of the clinical conversation than the final note, including matters the patient never intended to enter the chart. Role-based access to the note is normal practice; narrower role-based access to retained raw audio should reflect what that audio may contain.

Retention is third. Shortening unjustified retention can reduce breach and secondary-use exposure, but deletion must respect record obligations and valid holds. The configured period should match the disclosed and contracted period.

Deletion evidence is fourth. A schedule states an intention; a per-recording record can show what the deletion service reported for a specific object and time. That record still needs reconciliation with storage architecture, replicas, backups, holds, and coverage. It does not by itself prove complete deletion or legal compliance.

BAA coverage is not control coverage

Where a vendor is a HIPAA business associate, a compliant BAA is a threshold requirement. Its terms define permitted uses and disclosures and required safeguards, among other duties. Review the actual agreement: it may or may not address retention, training, subprocessors, deletion, and evidence rights at the needed level of specificity.

Two gaps recur in review. First, cloud, speech, and model subprocessors can sit behind the contracting vendor and need appropriate downstream restrictions. Second, a signed obligation and an operating event are different evidence. For a particular encounter, a system record can report the configured consent, access, review, and deletion states; independent verification can protect the integrity and provenance of that record. Neither fact alone proves the control was effective or the workflow compliant.

Vendor security review: questions that separate the answers

The questions below are the ones where a strong vendor and a weak one give visibly different answers. Each pairs the answer that should end the conversation with the answer that should continue it.

Ask Weak answer Acceptable answer
How long is raw audio kept, and what deletes it? Audio is deleted per our retention policy A stated interval, an automated job, and a per-recording deletion record we can produce on request
Is our audio or transcript used to train or improve models? We do not train on customer data The contract clause excluding both audio and transcripts, binding named subprocessors, surviving termination
Who at your company can listen to a recording? Access is restricted to authorized personnel The named roles, the approval path, and an access log the covered entity can review
Which subprocessors touch the audio? We use industry-standard cloud infrastructure A current subprocessor list with processing location and role, and notice terms when it changes
What happens if the clinician never reviews the draft note? Clinicians are expected to review all notes The system blocks the write, or flags the note as unattested in the record
What can you show about a control on a specific encounter? Here is our SOC 2 Type II report A per-encounter record naming what configured controls reported, with integrity and provenance independently checkable

The last row changes what a review can conclude. A SOC 2 Type II report or HITRUST assessment can describe a control environment over a period. A scoped encounter record answers a different question: what the configured system reported for a single encounter at one time. Signatures and independent verification can support integrity and provenance; they do not prove the underlying control ran, was effective, covered every path, or complied with law.

Consent design should be reviewed separately from vendor popularity, funding, or market share. The operative questions are what the patient is told, when and how agreement is captured, how refusal works, whether recording state is visible, and whether the resulting record matches the encounter.

The Consent Gap

A 2025 JAMA Network Open quality-improvement study involved 121 users: 18 clinicians and 103 patients. Among those 103 patients:

81.6%
84 patients with basic information
55.3%
57 patients with more detail

When provided basic information, 84 patients (81.6%) said they would consent; that number was 57 (55.3%) when more detail about AI features, data storage, and corporate involvement was disclosed. This finding describes responses in one quality-improvement study. It does not determine that either disclosure was legally sufficient, nor does it establish a universal consent rate.

Consent Quality Cannot Be Reduced to an Opt-Out Rate

A low refusal rate does not, by itself, prove that a disclosure was clear or legally sufficient; a higher rate does not prove the opposite. Review the actual script, timing, language access, patient understanding, ability to decline, care-setting pressure, and what the system records.

Best Practice Consent Elements

A practical review checklist should cover:

Consent Implementation Checklist

  • Encounter-specific confirmation: Use an affirmative step before recording where counsel and policy require it; do not assume signage alone resolves the analysis
  • Advance information: Explain the purpose, parties, data flow, permitted uses, and retention in accessible language
  • Active recording indicators: On-screen or auditory signals when recording is active
  • Clear refusal path: State what happens if the patient declines and make the non-recording workflow operational
  • Data transparency: Storage location, access controls, corporate involvement, retention periods
  • Records and deletion process: Explain applicable access, amendment, retention, hold, and deletion procedures without promising a right that may not apply

The Path Forward

The Sharp complaint is a useful review prompt, but it is not a forecast of how courts or the industry will treat ambient documentation. Health systems should make deployment decisions from the current product, data flow, jurisdiction, contract, patient communication, and operational evidence. A prediction about one pending case is not a basis for any of those decisions.

Immediate Actions for Healthcare Organizations

Immediate Actions for AI Vendors

Evaluate Benefits Locally

Ambient tools are commonly deployed to reduce documentation burden and support patient-clinician interaction, but outcomes vary by product, specialty, language, workflow, and study design. Measure note quality, correction burden, patient experience, clinician time, safety events, and refusal handling in the deployed environment rather than importing unsourced category-wide benefit percentages.

Cross-Industry Implications

The same analysis applies well outside healthcare. Recording law and privacy liability depend on the communication, the jurisdiction, the consent, the technology, and the data use. CIPA can provide statutory remedies after a proven violation, but damages and aggregation are not automatic. Model exposure with counsel from the actual workflow rather than multiplying a headline figure by every interaction.

Frequently Asked Questions

Do I need patient consent to use an ambient AI scribe?

It depends on jurisdiction, context, and the communication. California § 632 generally requires all-party consent before intentionally recording a confidential communication. Other states differ, and healthcare privacy, professional-duty, contract, and institutional-policy requirements may also apply. Obtain jurisdiction-specific advice rather than relying on a state-count shortcut.

Is posting signage sufficient for consent?

Do not assume so. Sufficiency depends on applicable law and circumstances. A defensible workflow commonly combines advance information, an encounter-specific affirmative confirmation before recording, a visible recording state, and a workable refusal path. The JAMA study on this page did not test legal sufficiency.

How long should audio recordings be retained?

There is no universal one-week rule. Set the period from purpose, record classification, applicable law, contract terms, patient rights, and valid holds. Document the decision, choose the shortest justified period, and verify that deletion follows the configured schedule.

What is the capability test and why does it matter?

Some California federal-court decisions have considered a provider’s capability to use data for its own purposes when evaluating CIPA allegations. Those rulings are fact-specific and include procedural decisions; they do not create automatic liability for every AI vendor or training clause. Analyze the statute, data flow, consent, vendor role, terms, and current case law.

Are ambient AI scribes regulated by the FDA?

FDA status depends on intended use, claims, and functions. A documentation function is not categorically inside or outside device oversight, and diagnostic, recommendation, triage, or alerting features can change the analysis. Review the specific product and its current claims.

What states have two-party consent requirements?

The answer varies by jurisdiction, medium, and context, and a static list can be misleading. California generally requires all-party consent for intentionally recording confidential communications. Multi-state organizations should maintain a current, jurisdiction-specific analysis.

What happened in the Sharp HealthCare lawsuit?

Saucedo v. Sharp HealthCare was filed November 26, 2025. Becker’s reported the plaintiff’s allegation that a clinic recorded a July appointment with Abridge’s app without his consent. These are allegations, not adjudicated facts. The public court index lists Sharp entities, not Abridge, as defendants, and this review did not verify a merits disposition.

What consent rates do patients actually give for ambient AI?

In a JAMA Network Open quality-improvement study of 121 users (18 clinicians and 103 patients), 84 patients (81.6%) said they would consent with basic information, compared with 57 (55.3%) when given more detail about AI features, storage, and corporate involvement. The study did not determine legal sufficiency or a universal consent rate.

What security measures should an ambient AI scribe have?

Evaluate consent and capture state, encrypted transport and storage, processing location, permitted uses, subprocessors, access, clinician review, retention and holds, deletion, and incident response. Seek encounter-scoped evidence where possible. A record can show what configured controls reported; it does not by itself prove that controls ran, were effective, covered the full workflow, or satisfied law.

Does a BAA cover ambient AI scribe security?

Not on its own. A BAA defines permitted uses and disclosures and requires safeguards, among other terms, but exact coverage depends on the agreement. Review retention, improvement uses, subprocessors, security, breach duties, deletion, and evidence rights. A signed BAA does not prove what happened during one encounter.

Key Takeaways

  • Use jurisdiction-specific consent analysis: California generally requires all-party consent for confidential recordings; other rules vary by context and state
  • Reconcile the encounter record: the documented consent state should match the patient-facing event and recording state
  • Map permitted uses: compare contracts, product settings, subprocessors, and actual data flows instead of treating one case-law phrase as automatic liability
  • Justify retention: classify the audio, define the purpose and holds, choose the shortest supported period, and verify the configured deletion process
  • Do not model damages mechanically: CIPA remedies follow a proven statutory violation and fact-specific rulings on liability, standing, defenses, and class treatment
  • Treat the Sharp case as an audit prompt: its allegations are not adjudicated facts and its eventual effect should not be predicted

For more on healthcare AI compliance and evidence infrastructure, explore our other resources:

Need Operational Evidence for an AI Privacy Review?

GLACIS can preserve signed records of what configured consent and privacy controls reported for an in-scope workflow. Signatures support integrity and provenance; whether controls ran, were effective, covered every path, satisfied law, or are accepted by a reviewer requires separate evidence.

Build Your Evidence Pack

Related Guides