AI Therapy Notes and HIPAA: A Practical Checklist for Therapists

AI can turn a rough session recap into a clean progress note in minutes. The harder part is working out what happens to the information between speaking and signing.

You do not need to become a cybersecurity specialist. You do need clear answers about the vendor, the data it handles, and the choices you control.

This checklist gives solo therapists and small practices a practical place to start.

First: “HIPAA compliant” is not a product badge

HIPAA applies through the relationship between a covered entity, its business associates, the technology, and the way the technology is used.

A vendor can provide useful safeguards and agreements, but it cannot make every possible use compliant. The practice still decides what information enters the system, who can access it, how accounts are managed, and whether the tool fits its risk analysis and policies.

That is why one logo in a website footer is not enough.

1. Will the vendor sign a BAA?

When a cloud provider creates, receives, maintains, or transmits electronic protected health information on behalf of a covered entity, HHS guidance generally treats that provider as a business associate. A Business Associate Agreement sets out permitted uses, safeguards, reporting duties, and what happens to PHI at the end of the relationship.

Ask:

  • Is a BAA available for my plan?
  • Is it automatic or separately requested?
  • Does it cover every product feature I plan to use?
  • Are important subcontractors addressed?
  • Can I read the agreement before paying?

A free trial may not include the same agreement as a paid clinical account. Check before entering real client information.

2. What information does the tool receive?

AI note tools can work from very different inputs:

  • A short post-session dictation
  • Typed bullet points
  • An uploaded audio file
  • A live or full session recording
  • A transcript created elsewhere
  • An image of handwritten notes

The input method changes the amount and type of information processed. Choose the smallest input that gives you a useful note and fits your workflow.

3. Are recordings or transcripts stored?

Ask for a specific answer:

  • Is the recording stored at all?
  • Is it deleted automatically after processing?
  • Is the transcript retained?
  • Can the practice change the retention period?
  • What is retained in backups?
  • Can an administrator delete the material?

“We protect your data” is not a retention policy.

4. Is client data used to train AI models?

Find out whether prompts, recordings, transcripts, drafts, corrections, or final notes are used to train or improve models.

Look for the answer in the contract and privacy materials, not only a marketing FAQ. If the language allows broad secondary use, ask the vendor to explain it in writing.

5. How is information protected?

Useful questions include:

  • Is data encrypted while sent and while stored?
  • Is multi-factor authentication available?
  • Can the practice control user roles?
  • Are access and activity logs available?
  • How are staff and support access handled?
  • Does the vendor have an incident-response process?
  • Has the product undergone independent security review?

You do not need every certification on the market. You need safeguards appropriate to the service and your practice.

6. Who owns and controls the notes?

Clarify:

  • Can you export notes in a usable format?
  • Can you delete drafts and source material?
  • What happens when a clinician leaves the practice?
  • What happens when the account is canceled?
  • How long does deletion take?
  • Can the vendor suspend access to records?

Portability is especially important for a group practice. The record should not disappear with an individual clinician’s login.

7. Does the AI make a faithful draft?

Security is only one part of a safe documentation workflow. The note also needs to be accurate.

During a trial, watch for:

  • Facts added without support
  • Risk statements that were not assessed
  • Diagnoses or interpretations not provided by the clinician
  • Overly confident language
  • Missing interventions
  • Confusion between speakers
  • Notes that are far more detailed than needed

The therapist remains responsible for reviewing the final record. Treat AI output as a draft, not a signed clinical conclusion.

8. What is the consent workflow?

Recording a session is different from dictating your own recap afterward. Consent rules and professional expectations may vary by location, setting, and recording method.

If you record, decide how you will explain the process, document consent, handle a client who declines, and provide an alternative workflow. Keep it simple and consistent.

9. Can the tool fit your current policies?

Add the vendor and workflow to your practice’s existing processes:

  • Risk analysis
  • Vendor inventory
  • Access management
  • Retention schedule
  • Incident response
  • Staff onboarding and offboarding
  • Recording or consent policy
  • Documentation review and signing

For a solo practice, this can be a short, usable set of documents. It does not need to become a binder nobody opens.

A practical vendor checklist

Use this during a demo or trial:

  • BAA available for the exact plan and features
  • Input methods are clear
  • Recording and transcript retention explained
  • Training-data policy is clear
  • Encryption is described
  • Multi-factor authentication available
  • Roles and access appropriate for the practice
  • Deletion and export processes tested
  • Account closure process explained
  • AI drafts can be corrected easily
  • Clinician review happens before finalization
  • Recording-consent workflow fits the practice
  • Vendor added to the practice risk analysis

Dictation or full-session recording?

Post-session dictation gives the AI a clinician-selected summary. Full-session recording gives it the whole conversation.

Neither is automatically the right answer. Dictation may feel simpler and more selective. Recording may capture details the therapist would otherwise forget. The choice depends on note quality, consent, client comfort, storage, and the way you practice.

See Voice Dictation vs. Recording Therapy Sessions for a full comparison.

How Apollo Notes handles the workflow

Apollo Notes supports several input methods, including voice dictation, typing, recordings, audio uploads, and images of handwritten notes. The site states that it provides a BAA, uses encryption, does not store recordings or transcripts after processing, and does not use session data to train AI models.

Product policies can change, so confirm the current details on the Privacy & Security page and in the applicable agreement before adopting any tool.

Frequently asked questions

Is ChatGPT HIPAA compliant for therapy notes?

Do not decide based on the product name alone. Determine whether the exact service and account offer the required agreement and controls for the proposed use. A consumer chatbot account should not be assumed to be suitable for PHI.

Does a BAA make an AI note tool automatically compliant?

No. A BAA is an important part of the relationship, but the practice still needs appropriate use, access controls, risk analysis, and policies.

Is post-session dictation safer than recording?

It processes less source material, which may simplify the workflow. It can also omit details. “Safer” depends on the full system, agreements, retention, consent, and clinical use.

Can AI sign or finalize a therapy note?

The clinician should review, correct, and take responsibility for the final note. AI is best treated as drafting support.

References and further reading