AI from the Exam Room: A Practical Field Guide for Clinicians
How to think about ambient scribes, OpenEvidence, Copilot, and everything else without losing sleep — or your license.
A note up front: This essay is one practicing physician’s perspective and is not legal advice. Rules, products, and vendor terms change. Before you act on anything here, consult your compliance officer and counsel and verify the current details with your institution.
If you practice clinical medicine in 2026, AI has already arrived in your workflow. Maybe it’s the ambient scribe your group rolled out last fall. Maybe it’s the OpenEvidence tab you keep open on your second monitor. Maybe it’s Copilot quietly summarizing your inbox. Or maybe it’s a colleague pasting a patient’s history into a consumer chatbot in the workroom and hoping nobody notices.
I want to talk about all of that — calmly, practically, and in a way you can actually use on Monday morning. The goal isn’t to scare anyone off these tools. They’re genuinely useful. The goal is to help you sort the must-dos from the should-dos from the nice-to-haves, so you can adopt with confidence.
Here’s the punch line: HIPAA wasn’t rewritten for AI. The same framework that has governed faxes, EHRs, and email for two decades broadly governs AI tools, too. What has changed is the surface area. There are more places PHI can land, and a few of them are owned by companies you’ve never heard of. A handful of newer rules — updates to the HIPAA Security Rule, Section 1557’s nondiscrimination provisions for AI in patient care, and a growing patchwork of state AI laws — layer on top.
So here’s how I think about it.
The starting point: the BAA
If a tool is going to touch protected health information — even just hear it, even just to summarize it back — the foundation is a signed Business Associate Agreement (BAA) between your organization and the vendor.
A BAA is essentially a contract that says: “We will treat your patients’ data with the care HIPAA requires of you.” Reputable enterprise AI vendors offer one. The free, consumer-grade version of the same product generally does not.
So when someone asks, “Can I use ChatGPT for this?” the honest answer is, “Which ChatGPT?” The consumer app on your personal phone is a different legal product from ChatGPT Enterprise running under a signed BAA at your institution. Same brand, different posture.
That distinction — enterprise tier with BAA vs. consumer tier without — is the single most important thing to internalize. It applies to Microsoft Copilot, to Gemini, to Claude, to most of the major tools.
What I’d treat as non-negotiable
A short list. These are the things I wouldn’t skip in my own practice:
A signed BAA covering the specific product and tier you’re using. Not a website promise. An executed contract your privacy officer can produce on request.
Use the tool only through your institutional account. Personal logins on a corporate tool can break the BAA chain.
Know your state’s recording-consent law before turning on an ambient scribe. Roughly a dozen states (including California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Montana, Pennsylvania, and Washington, among others) require all-party consent in at least some circumstances. Several states also now have AI-specific disclosure rules — California’s AB 3030, Utah’s and Colorado’s AI consumer laws, and in Texas, TRAIGA. Check your jurisdictions; the patient-encounter context matters.
Document the patient’s consent to recording where required, and have a written script your team uses consistently.
You, the clinician, remain responsible for what ends up in the chart. Read what the AI wrote before you sign it. Every time.
Don’t put PHI into any tool you haven’t confirmed is covered. When in doubt, de-identify or wait.
Substance-use disorder records are different. 42 CFR Part 2 imposes a higher consent bar than HIPAA, and most general AI BAAs don’t cover it. If you treat SUD patients, raise this specifically with your compliance team before using any AI tool on those encounters.
Most clinicians can satisfy this list without changing much about how they practice.
What’s strongly recommended
These aren’t required in the same way, but they’re how thoughtful practices stay out of trouble and get more out of these tools:
Tell your patients you use AI. A sentence in the intake packet and a brief verbal mention before the scribe starts recording goes a long way. Patients overwhelmingly accept this when asked; some resent discovering it later.
Update your Notice of Privacy Practices to reference AI tools and ambient documentation. Your compliance officer likely already wants to do this — let them.
Confirm the “no-training” clause. Your BAA should specify that the vendor will not use your patient data to train their public models. Read the clause; the wording varies.
Know who the subprocessors are. Your ambient scribe vendor probably runs on top of an OpenAI, Anthropic, Azure, or Google model. Those subprocessors should be covered by the vendor’s BAA chain. Ask.
Pay attention to bias and equity. HHS OCR’s Section 1557 nondiscrimination provisions for AI “patient care decision support tools” took effect in 2025. The practical version: have a way to notice when an AI tool is performing differently across patient groups, and have a written policy on use and oversight.
Be aware of the FDA line. Most ambient scribes and search tools aren’t regulated medical devices. AI that autonomously diagnoses, recommends specific treatments, or auto-generates orders may be. If a tool is creeping in that direction, ask whether it has FDA clearance for that use.
Keep a list of approved tools and share it with your team. The single most common real-world problem isn’t the tool you chose — it’s a well-intentioned colleague using something nobody knew about.
Verify before you sign. Treat every AI-generated note, message, or recommendation as a starting draft, not a finished product.
What’s optional but smart
An annual review of the AI tools in use across your practice. Vendor data policies change more often than you’d think.
Brief in-service training for staff on what can and can’t go into which tool. Twenty minutes once a year prevents most of the trouble.
A short written AI use policy. One page is plenty: “Use the approved tools through your work account; don’t paste PHI into anything else; verify outputs before they hit the chart.”
How this looks in practice, tool by tool
(Vendor specifics change. Verify the current product, tier, and BAA status with your institution before relying on any of this.)
Ambient scribes (Abridge, Microsoft Dragon Copilot, Suki, Ambience, Heidi, Commure, and others): These have become the workhorse use case. If your group has signed a BAA with the vendor, you have a reasonable foundation. Get the patient’s verbal okay — something like, “I use an AI tool that helps me write the note so I can spend more time looking at you instead of the screen; is that all right?” — document it, and read the draft before you sign it. The drafts are getting good. They aren’t perfect. Medication doses, laterality, and negatives are common places they slip.
OpenEvidence: OpenEvidence announced HIPAA-compliant handling of PHI for U.S. covered entities in 2025, with a BAA mechanism. It’s become a useful resource for “I haven’t seen this in a while, what’s the current evidence?” moments between patients. Practical notes: confirm with your institution that the BAA path you’re on actually covers your use (individual vs. enterprise enrollment can differ), log in through your institutional account where possible, and treat the answers as a well-cited starting point — the citations are real, but verify the ones that drive a decision.
Microsoft 365 Copilot (Enterprise / commercial): This is generally included as an in-scope service under Microsoft’s HIPAA BAA for Microsoft 365, which many health systems already have. Useful for summarizing your inbox, drafting letters, pulling themes out of a long Teams thread. The catch is configuration: Copilot can read anything you can read, so loose SharePoint or OneDrive permissions can surface PHI from misfiled documents. Worth asking your informatics team: “Have we tightened permissions before turning Copilot loose?” Note also that Microsoft sells multiple Copilot products; the consumer / personal-account versions don’t carry the same protections.
ChatGPT, Claude, Gemini — the general-purpose ones: Useful for de-identified questions, board review, drafting a patient education handout, rewriting a letter to a payer. For anything with PHI, the appropriate path is an institutional enterprise tier under a signed BAA. The consumer apps generally aren’t the right tool for patient-specific use. The enterprise tiers are increasingly being deployed by health systems — if yours has, use it within its sanctioned scope.
The EHR’s built-in AI (Epic’s note-drafting, in-basket reply suggestions, etc.): Generally covered under your existing EHR BAA, which makes these the lowest-friction options. Draft quality varies; same habit applies — read before you sign or send.
A few myths worth retiring
“If I de-identify it, I can use any tool.” Mostly true in spirit, but real de-identification is harder than it looks. A combination of age, geography, occupation, and a rare diagnosis can be re-identifiable even without a name. When in doubt, use a BAA-covered tool.
“HIPAA bans AI.” It doesn’t. HIPAA is largely technology-neutral. It requires that whoever handles PHI on your behalf agrees to handle it the way you would.
“The AI is the doctor now.” It isn’t. The note has your signature. The order has your name on it. AI is a tool — like a stethoscope with a very large vocabulary — and you remain responsible for the decision.
“If the vendor says they’re HIPAA-compliant, that’s enough.” It’s necessary but not sufficient. The signed BAA and the way you actually use the product matter, too.
The mindset I’d encourage
Treat AI tools the way you’d treat a sharp new intern. Capable, fast, sometimes startlingly good, occasionally wrong in confident ways. You wouldn’t let an intern sign your notes without reading them. Don’t let the AI either.
And give yourself permission to actually use these tools. Many of the clinicians I know who’ve adopted ambient scribing report less after-hours charting and more energy at the end of the day. Those using point-of-care AI search make better-informed decisions in tight moments. Those using Copilot spend less time on inbox triage. The published experience is still maturing, and results vary by workflow and specialty, but the direction is real.
The legal framework is mature enough to act on, while the details keep evolving. The tools are good enough to help. The remaining work is organizational hygiene — signed BAAs, sensible policies, a little patient transparency, and an honest conversation with your compliance team — and then it’s just medicine, with better tools.
That’s the picture as I see it. Sign the paperwork, use the enterprise account, tell your patients, read what the AI wrote, and get on with taking care of people.
If your institution hasn’t sorted out which AI tools are sanctioned, ask. The answer in 2026 is rarely “none” — more often, someone in compliance has already done the work and forgotten to tell the clinicians.
Doug Fullington, MD, is a practicing internist with a primary care group practice in Plano, Texas, and writes AI from the Exam Room about what is changing in the exam room as AI tools enter clinical practice. He has no financial relationships with the AI tool vendors named in this essay.
Follow him at dfullington.substack.com, linkedin.com/in/drdougfullington, and x.com/DougFullington.
Independence disclaimer. The views expressed here are my own and independent from my affiliation with my group practice.
PHI and AI clinical tools note. Even when a platform has a signed BAA, the HIPAA minimum-necessary standard still applies. Many clinical questions can be answered with de-identified details (age, sex, relevant history) without names, dates of birth, or MRNs. Check your institution’s policies, which may add restrictions beyond HIPAA.
Not legal advice. This essay reflects one clinician’s perspective and is not legal, compliance, or regulatory advice. For decisions about specific tools or workflows, consult your organization’s compliance officer and qualified counsel.



Really helpful, I didn't really under the BAA until I read this. Thanks!