Using AI for therapy notes can be HIPAA compliant, but compliance is a property of the specific tool and its contracts, not of "AI" as a category. The safety question resolves to three concrete facts you can verify with any vendor: whether session audio is stored, whether the transcript persists, and whether your client content is used to train models.
Why this question matters now
AI documentation has moved from novelty to default expectation, and clinicians are right to interrogate it before trusting it with the most sensitive records in medicine. The tension is real: the time savings are significant, but a therapy note carries content that can be subpoenaed, breached, or repurposed in ways a billing record never could.
This post draws on Oasys's proprietary knowledge: direct, ongoing conversations with practicing therapists and practice owners, plus our seat at the infrastructure layer of real practices, where we see how documentation, billing, and consent actually work day to day. Across customer conversations covering dozens of practices and clinicians, AI documentation is the most-discussed feature in every demo, and the same privacy questions surface nearly every time: is the session being recorded, what happens to the audio, and can individual clients opt out. The hesitation is not opposition to the technology. It is the absence of a clear answer to those three questions.
That is the distinction this piece turns on. The risk is not the technology. The risk is an underspecified tool. "AI is unsafe for notes" is mostly a question that has not been asked precisely.
Below we walk through five things therapists commonly get wrong about AI notes and privacy, and what actually happens to the data in each case.
Myth 1: AI therapy notes require recording the session
They do not. A well-built scribe transcribes text in real time and never stores the audio at all, which means there is no recording to leak, subpoena, or retain.
This is the most common misconception, and it surfaces in nearly every demo: therapists and clients conflate "transcription" with "recording." They are different operations. Transcription converts speech to text in the moment. Recording implies a stored audio file that lives somewhere afterward.
Other platforms may be built differently. Oasys does not store audio: it transcribes during the session, and the audio is gone when the session ends. That is the right question to ask any vendor, because the answer determines whether an audio artifact of your sessions exists anywhere at all.
Myth 2: Consent for AI is a practice-wide setting, so if you use it, all clients are on it
Per-client consent is both possible and advisable. A practice-wide on/off switch is a design limitation, not a requirement.
Practices have mixed caseloads. A client with paranoia, a trauma history, a high-profile role, or simply a principled objection to AI should be able to decline without affecting anyone else's care. Granular per-client toggles are the correct model.
Other platforms may be built differently. The standard you want is a control that lives at the level of the individual client, not the whole practice. If declining AI for one client means turning it off for everyone, the tool is forcing a policy decision that should be a clinical one.
Myth 3: The transcript stays in the system after the note is signed
Whether a transcript persists after note completion is a vendor decision, not a fixed property of AI tools. This matters legally, because transcripts that persist are potentially discoverable.
Other platforms may be built differently. Oasys removes the transcript from the medical record one the note is signed and locked, so what remains is the finished clinical record, not a verbatim log of everything said in the room.
The legal exposure is concrete. A persisted transcript is a second, more detailed record of the session that can be reached by subpoena. Clinicians working with sensitive populations, including those who have asked us directly about subpoena risk, should confirm the deletion lifecycle with any platform they use, in writing.
Myth 4: The AI signs off on the note for you
It does not. The AI produces a draft. Nothing gets finalized, billed, or signed without a clinician doing it.
This one comes up as a worry about authorship. Clinicians picture a system that generates a note, closes it out, and leaves them holding responsibility for language they never chose. That is not how a documentation tool works. You are the author of the note. The scribe drafts, the same way a template or a carried-forward prior session drafts.
The practical version of the concern is more specific: can you change the wording, cut a section, or rewrite the whole thing before you sign. The answer should be yes on all three.
Other platforms may be built differently. In Oasys the draft is fully editable until you sign it, the signature is yours, and the note is not locked or attached to a claim until then. Ask any vendor two questions: can a note be signed without a clinician doing it, and can I edit any part of the draft before signing. A clear no and a clear yes are the answers you want.
Myth 5: If AI notes need too much correction, they are not worth the time
This objection is real and fair: a tool that requires heavy fact-checking on every note doubles the work rather than reducing it. The right benchmark is whether the output requires less total time than writing from scratch, across your actual note types.
Performance is not uniform across documentation. Checkbox-heavy mental status sections and highly structured assessments are harder for AI than narrative progress notes. Understanding where a specific tool performs well is more useful than a blanket verdict.
So test it against your real caseload. If a tool saves time on your progress notes but not your structured intakes, that is useful information, not a reason to dismiss the whole category.
So, is it safe?
Safety is verifiable, not assumed. A tool is safe to use for therapy notes when you can confirm each of the following, in writing:
- Audio: the session audio is not stored after the session ends.
- Consent: clients can opt in or out individually, not just practice-wide.
- Transcript: the transcript has a defined deletion lifecycle (Oasys deletes it once the note is signed and locked; other tools vary).
- Training: a signed BAA prohibits session content from being used to train or improve models.
- Fit: the output saves total time on your actual note types, not just the easy ones.
If a vendor answers all five clearly, AI notes are as safe as the rest of your compliant EHR. If a vendor hedges on any of them, the hedge is the signal.
Frequently asked questions
- Is it HIPAA compliant to use AI for therapy notes?
It can be, provided the vendor signs a Business Associate Agreement (BAA) and the AI subprocessor handling PHI is covered by it. HIPAA does not prohibit AI; it requires that any party touching PHI be contractually bound to protect it. Compliance is a property of the specific tool and its contracts, so verify the BAA rather than trusting the label.
- Does AI store or delete my session audio?
That depends on the tool, which is exactly why you should ask. Other platforms may be built differently; Oasys does not store audio at all, transcribing during the session so the audio is gone when the session ends. Ask any vendor directly whether an audio file persists after the session.
- How do I get client consent for AI note-taking?
Obtain informed consent before the first session where AI is used, ideally documented in your intake paperwork, and offer it on a per-client basis. The best practice is a granular toggle so individual clients can decline without affecting your other clients. A practice-wide on/off switch is a design limitation, not a consent requirement.
- Is my session transcript discoverable by subpoena?
A transcript that persists in the system is a record and is potentially discoverable. The protection is a defined deletion lifecycle: Oasys deletes the transcript once the note is signed and locked, while other tools vary. Confirm the deletion policy in writing, especially if you work with sensitive populations.
- Does AI use my notes to train its models?
Only if the vendor agreement allows it. A BAA with the AI subprocessor should contractually prohibit using PHI for model training, so ask plainly: "Is any audio, transcript, or note content used for model training or improvement?" If the answer is unclear or hedged, treat that as a no-go.
Safety here is not a leap of faith. It is a short list of questions with verifiable answers, and the vendors worth trusting are the ones who answer them plainly.
Mohamed Badran··


