AI scribes are listening: five security questions to settle before rollout
Ambient AI scribes give clinicians time back, and they do it by recording the most sensitive conversations in healthcare. Before a hospital switches one on, five questions need a clear answer.
Why hospitals want them
The case for ambient voice technology is strong. NHS England reports that in a major study AI scribes raised direct patient interaction time by 23.5%, cut appointment length by 8.2%, and let emergency departments see 13.4% more patients per shift. In January 2026 it opened a national self-certified supplier registry to speed up local procurement.
What has already gone wrong
Two early cases show where the risk sits.
In Ontario, a physician left a hospital in June 2023 but stayed on a clinical rounds invite under his personal email. In September 2024 an AI notetaker on his personal device joined the meeting on its own and transcribed details of seven patients. The provincial privacy commissioner closed the case in April 2026, pointing to missed offboarding, personal email use and meetings without a lobby.
In California, a patient filed a proposed class action against Sharp HealthCare in November 2025. He alleges an ambient scribe recorded his appointment without consent, and that he only found out by reading his notes.
Neither case involved a hacker or a faulty model. Both came down to who was allowed to record, and whether anyone had agreed to it.
1. Who is the scribe working for, right now?
Every recording should be tied to one authenticated clinician, not to a ward login or a workstation that someone else left unlocked. The note enters the record under a name, and that person must provably be the one who was in the room. Access to the scribe should end on the same day as every other access when someone leaves.
2. Does the patient know?
NHS England's guidance asks organisations to be transparent about what is recorded, what the output will be, who will use it and how it is stored. Where the law requires every party to agree to a recording, as in California, consent has to be a step in each visit, not a line in a privacy notice.
3. Where does the audio go, and for how long?
A voice recording can identify a person, which makes true anonymisation very hard in healthcare. Ask the supplier how long audio, transcripts and outputs are kept, whether any of it trains their models, which subcontractors touch it, and how deletion works when the contract ends.
4. Is it a medical device?
NHS England draws the line at function. A product that only produces a transcript a clinician can easily check is not a medical device. One that uses generative AI to summarise, or prompts the clinician to act, probably is, and the supplier registry expects at least MHRA Class 1 registration. The deploying organisation still owes its own clinical safety case (DCB0160) and a data protection impact assessment.
5. Who checks the output, and what happens when the model changes?
The clinician must review and approve every note before it is used. NHS England lists the reasons: errors with complex terminology and fast speech, uneven accuracy across accents, and automation bias once users start to trust the tool. It also warns of indirect prompt injection against the language model. Contracts should give the hospital notice of model updates and the right to audit, a point the American Bar Association also makes.
The takeaway
The technology is not the hard part. The open work is identity, consent and governance: knowing which clinician a recording belongs to, proving the patient agreed, and controlling where the audio goes next. Hospitals that settle those five questions first get the time savings without the lawsuit.