Skip to main content
For practices using DAX, Nabla, Suki, Abridge

Your AI scribe is a HIPAA business associate. Are you covered?

Ambient AI documentation tools record and process patient information — which makes the vendor a HIPAA Business Associate. That triggers two requirements most practices have missed: a signed BAA with the AI vendor, and a Security Risk Analysis updated to include the tool.

The AI Scribe HIPAA Readiness Review closes that gap with documentation you can hand to an examiner, your malpractice carrier, or your attorney.

Federal RMF methodology NIST AI RMF CompTIA SecAI+
$497 flat
One-time · no retainer required
  • 60-minute Risk Snapshot call
  • Written Security Risk Analysis (scoped to your AI tools)
  • BAA gap list across every AI vendor you use
  • AI Acceptable Use Policy your staff can follow
  • One-page remediation priority sheet
Book the Review →

Prefer to talk first? Book a free 15-min call · sanchez@ironsentinelhq.com

Why this is urgent: The most common HIPAA enforcement findings against small practices are a missing or outdated Security Risk Analysis and inadequate Business Associate Agreements — exactly the two gaps a new AI scribe creates. Your EHR vendor's BAA does not cover a separate AI tool.

Three steps, about two weeks.

  1. Book & intake. Pay the flat $497, then a 60-minute call where we map the AI tools you use, who approves them, and where patient information flows.
  2. Analysis. We produce a written Security Risk Analysis scoped to those tools, check every AI vendor for a signed BAA, and draft an AI Acceptable Use Policy customized to your vendors and staff roles.
  3. Delivery call. We walk you through the findings and a prioritized remediation list — what to fix first, and what's already fine.

Documentation, not a sales pitch.

Security Risk Analysis

The HHS-required analysis, scoped to your AI documentation tools — the document examiners ask for first.

BAA Gap List

Every AI vendor touching PHI, and whether a Business Associate Agreement is actually in place.

AI Acceptable Use Policy

A written, staff-ready policy on approved tools, the no-sensitive-data rule, and human review.

Remediation Priority Sheet

A one-page, plain-English list of what to fix, in order — no 80-page report nobody reads.

Scope & data handling: This engagement reviews your tools, vendors, configurations, and policies — it is designed not to require access to actual patient records (PHI). If any step would involve PHI, we put a Business Associate Agreement in place with you first.

Before you book

Our EHR vendor handles our HIPAA compliance.

Your EHR vendor's BAA covers the security of data inside their system. A separate AI scribe is a new Business Associate relationship your EHR vendor has nothing to do with — and the Security Rule requires you to assess every vendor that touches PHI independently.

We're a small practice — are we really a target?

Most HIPAA settlements in recent years have been with small and mid-size practices, not hospital systems — frequently for a missing Security Risk Analysis or inadequate BAAs. Those are the two things this review fixes.

We don't use an AI scribe yet.

Good position to be in — it's faster and cheaper to set up governance before you adopt the tool than to remediate after. We can scope the review to your planned tools.

What happens after?

Many practices keep their documentation current with an ongoing vCISO advisory retainer — but that's optional and never required. This review is a complete, standalone deliverable.

Find out if your AI scribe is a gap.

Flat $497, no retainer required. Or book a free 15-minute call to talk it through first.

Book the Review →