Industries · Healthcare practices

AI for medical practices: govern the scribe, the inbox and the chatbot before OCR or a patient asks.

Ambient scribes are in the exam room, AI is drafting patient messages, and phone agents are booking appointments. HIPAA did not change; what changed is how many vendors now touch protected health information. AboveBoard turns HIPAA, the new state disclosure laws and the Joint Commission's responsible-AI guidance into forty controls, an independent review and a verified score for your compliance officer, your payers and your board.

+55%reported AI incidents in 2025 (362 vs 233 the year before)
Stanford AI Index, Apr 2026
57%of employees say they hide their AI use from their employer
KPMG / Univ. of Melbourne, Apr 2025 (n=48,000)
78%of senior leaders lack full confidence their organization could pass an independent AI governance audit within 90 days
Grant Thornton, Apr 2026 (n=950)
Who is asking

HIPAA, state legislatures, the Joint Commission and your payers.

HIPAA and OCR

Any AI vendor that creates, receives, maintains or transmits PHI on your behalf is a business associate and needs a business associate agreement before PHI flows. The Security Rule's risk analysis has to include AI tools, the minimum-necessary standard applies to what you paste into them, and the breach-notification clock starts when an AI tool exposes PHI. OCR investigates on complaint, and a patient who learns their visit was recorded without notice is a complaint.

State AI disclosure laws

California AB 3030 (effective Jan 1, 2025) requires a disclaimer and instructions for reaching a human on generative-AI patient communications about clinical information. Texas TRAIGA (Jan 1, 2026) requires healthcare providers to disclose AI use in treatment under its companion provisions (Baker Botts, Jul 2025). Utah's AI Policy Act requires licensed professionals to disclose generative AI in high-risk interactions (as amended 2025). Colorado SB 26-189 (Jan 1, 2027) covers healthcare decisions: notice, a 30-day explanation after an adverse outcome, human review and three years of records (Seyfarth, May 2026). Connecticut SB 5 (Oct 1, 2026) also reaches healthcare (Ropes & Gray, Jun 2026).

The Joint Commission and CHAI

The Joint Commission and the Coalition for Health AI issued Responsible Use of AI in Healthcare guidance in September 2025 and launched a voluntary RUAIH certification on June 2, 2026, open to any healthcare organization. It covers governance, data management, risk and bias mitigation, safety monitoring, and transparency and training (Fierce Healthcare, Jun 2026). Hospital systems will pursue it, and will start asking the practices they refer to and contract with what their AI governance looks like.

Payers, health systems and your carrier

Payer credentialing, health-system affiliation and value-based contracts increasingly carry AI questions, and liability and cyber underwriters are adding AI questionnaires and endorsements (Fenwick, Jun 2026). Half of privacy and security professionals admit entering non-public data into generative AI tools (Cisco, Apr 2025); in a practice, that data is PHI.

What is actually in use

The AI tools practices are running today

Clinical documentation

Ambient AI scribes that record the visit and draft the note, AI inbox-message drafting inside the EHR, dictation and transcription. These generate the medical record, so the clinician's sign-off is the control that matters most.

Front desk and patient contact

AI phone agents and scheduling bots, website chatbots that answer clinical-adjacent questions, appointment reminders and patient-portal replies, translation. Each one talks to patients, and each one is covered by the new disclosure laws.

Revenue cycle and operations

Coding and charge-capture assistants, prior-authorization automation, claims-denial drafting, ChatGPT and Copilot for letters, policies and referrals. Often on personal accounts, often with PHI pasted in.

The five domains, in a practice's language

What the AboveBoard Standard asks of a healthcare practice

Forty controls, eight per domain, scored on evidence. Here is how they read when the data is PHI and the reviewer could be OCR.

Domain 1 · 20 pts

Governance & Accountability

A written AI policy adopted by leadership, a named owner (compliance officer, practice administrator or medical director) with authority to switch off a tool, an inventory of AI tools and use cases with risk ratings, and AI governance folded into the HIPAA compliance program.

Evidence examples: the policy with its approval date; the register listing the scribe, inbox drafting, phone agent and billing AI with an owner and a risk rating for each; the HIPAA compliance-program section that cross-references AI; the obligations memo covering AB 3030, Texas and Utah disclosure duties.

Domain 2 · 20 pts

Data Security & Privacy

PHI classified so staff know it never enters an unapproved tool, an approved-tool list, a BAA plus no-training and retention terms for every approved vendor, single sign-on, retention rules for audio and drafts, patient notice and consent for recording, and AI tools included in the Security Rule risk analysis.

Evidence examples: the BAA and vendor terms review log for the scribe vendor, with the training-on-data clause and audio-retention period highlighted; the Security Rule risk analysis entry for AI tools; the patient notice and consent script for ambient recording.

Domain 3 · 20 pts

Operational Controls

A clinician reviews and signs every AI-drafted note and message before it enters the record or reaches a patient; notes are sampled for accuracy; the incident plan covers an AI tool exposing PHI or a harmful drafting error and maps to breach notification; vendor model changes are tracked; AI-assisted notes are identifiable in the chart.

Evidence examples: the documentation policy stating the AI draft is not the note until signed; the monthly note-sampling log with corrections; the incident-plan section referencing HIPAA breach notification; the EHR flag that tags AI-generated drafts.

Domain 4 · 20 pts

Workforce Capability & Training

Training completed by 90%+ of clinicians, front-desk, billing and administrative staff; role-specific modules; reviewer training for clinicians on what an AI note gets wrong; signed acknowledgments; a leadership governance session.

Evidence examples: the completion report alongside the annual HIPAA training record; the acknowledgment file; the clinician reviewer-training deck and attendance.

Domain 5 · 20 pts

Transparency & Client Trust

Patients are told when AI is involved in their care communications and when a visit is recorded; "AI-powered care" claims are reviewed; payer and health-system questionnaires are answered from a standard bank; complaints involving AI have an owner and a response time.

Evidence examples: the AB 3030 disclaimer on generated patient messages; the posted AI-use statement in the waiting room and on the website; the last three payer or health-system AI questionnaires, consistent with each other.

Three gating controls

No practice is listed at any level with a zero on G1 (written policy), D3 (vendor terms reviewed) or O1 (human review before client-facing output). In a practice, O1 is the clinician's signature on the note.

Read the full rubric
What a verified score gets you

One evidence file for OCR, the payer, the health system and the board.

Payer and health-system questionnaires

The AI and vendor-security sections are answered once from verified evidence, with a registry link. Affiliation and credentialing teams get consistency.

Liability and cyber renewal

The application's AI questions map to G1, D2, D3, O1, O3 and W1. Attach the report and the year-stamped badge. Coverage decisions remain the carrier's.

Physician-owners, the board and RUAIH readiness

A plain-English report by domain with gaps and fixes. Practices heading toward Joint Commission RUAIH certification use the evidence file as their starting point.

What this is, in one sentence.

AboveBoardAI issues a score and a verification under a private, voluntary standard; it is not HIPAA certification (no such thing exists), not Joint Commission certification, not clinical validation of any AI tool, and not legal advice. It verifies that your AI governance practices exist and are evidenced on the review date. See What is an AI audit?

Your first 30 days

A plan the practice administrator can run between clinic days.

Days 1–3: Snapshot and inventory

Take the free Snapshot. List every AI feature in the EHR, phone system, website and billing stack, plus the general assistants staff use. Note which ones touch PHI. That is your register.

Days 4–10: BAAs, terms and the policy

Confirm a BAA and reviewed terms for every PHI-touching tool; retire the ones you cannot paper. Adopt an AI acceptable-use policy (our template has healthcare notes) and add AI to your Security Rule risk analysis.

Days 11–20: Sign-off rule, patient notice, training

Write the documentation rule: the AI draft is not the note until a clinician signs it. Post the AI-use statement and script the recording notice. Roll out Academy Foundations and collect acknowledgments.

Days 21–30: Sampling, incident plan and the assessment

Start a monthly note-sampling log. Add the AI section to your incident plan. Start the full assessment; Snapshot answers carry over.

Pricing for practices and groups

$7,500 a year for practices of 1–49 people. Everything included.

Growth Firm (50–249) $18,000; Established Firm (250–999) $42,000; Enterprise (1,000+) from $75,000. Every tier includes the assessment, independent review, score, badge, registry listing, board report and Academy Foundations. Dental, behavioral health, therapy, specialty and multi-site groups are all in scope.

Questions practices ask

Do we need a business associate agreement with our AI scribe vendor?

If the tool creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a business associate agreement before PHI is shared. Ambient scribes, AI inbox-drafting tools, transcription services and coding assistants all handle PHI. The BAA is necessary but not sufficient: you also need to know whether the vendor trains on your data, how long audio and drafts are retained, and who its sub-processors are.

Do we have to tell patients we use an AI scribe?

Increasingly, yes. California AB 3030 (effective Jan 1, 2025) requires a disclaimer and human-contact instructions on generative-AI patient communications about clinical information. Texas requires healthcare providers to disclose AI use in treatment under its 2026 AI law (Baker Botts, Jul 2025), and Utah requires licensed professionals to disclose generative AI in high-risk interactions. Recording a visit also raises state consent rules. Most practices adopt a short verbal notice plus a posted statement, and document it.

Is AboveBoard the same as Joint Commission RUAIH certification?

No. The Joint Commission, with the Coalition for Health AI, launched its voluntary Responsible Use of AI in Healthcare certification on June 2, 2026, open to any healthcare organization (Fierce Healthcare, Jun 2026). AboveBoardAI is a private, voluntary standard for firms that use AI, priced for practices of 10 to 1,000 people, and it covers the same governance ground: policy, data, human oversight, training and transparency. Many practices treat AboveBoard as the practical first step, or as the governance program for non-clinical operations.

Does AboveBoard evaluate whether our clinical AI is accurate or safe?

No. AboveBoard does not test AI models or clinical tools and never certifies that an output is correct. It verifies that the practices which catch errors exist and are evidenced: a clinician signs every AI-drafted note, notes are sampled for quality, incidents are logged and acted on, and vendors are monitored.

How much does an AI audit cost for a medical practice?

AboveBoardAI is priced annually by headcount: $7,500 for practices of 1 to 49 people, $18,000 for 50 to 249, $42,000 for 250 to 999 and from $75,000 for 1,000 or more. Every tier includes the assessment, independent review, score, badge, registry listing, board report and Academy training for all staff. See pricing.