Three patients sued Sutter Health and MemorialCare in April. Not one of them alleges the tool wrote anything false. The allegation is that their visits were captured and sent outside the exam room to be processed, and that nobody told them first. That is a governance problem, and reading the note before you sign it is no answer to it. Eight questions, and you will know which of your answers exists as a document rather than as somebody's memory.
Not legal advice. State recording and medical records law varies.·No scribe vendor is named, and no referral fees are taken from any of them.·Checked July 2026
Most practices have made the right call on most of these. The gap is almost never the decision. It is that the decision lives in one person and cannot be shown to anybody outside the practice.
Answer the eight questions and your readout appears here, including which one to start with.
Filed April 8, 2026 in the Northern District of California, Washington et al. v. Sutter Health et al., No. 4:26-cv-03012. This is the fastest way to see why hallucination rates are the wrong argument to be having.
| Pleaded | What that statute concerns |
|---|---|
| California Invasion of Privacy Act | The state wiretapping and eavesdropping statute, which covers recording a confidential communication. |
| Confidentiality of Medical Information Act | The California statute governing disclosure of a patient's medical information. |
| Federal Wiretap Act | The federal interception statute. |
| Unfair Competition Law | The California unfair business practices statute. |
| Invasion of privacy | The common law claim, pleaded alongside the statutory ones. |
| Not pleaded | Any allegation that the note was inaccurate, or that the AI wrote something false. |
A plain summary of the causes of action in one complaint, not a prediction of how it resolves and not legal advice. The case was pending when this page was written. Note also that the tool named in the complaint is not named here: a vendor in active litigation adds nothing to the argument.
Take them in order. One through three have live litigation attached, so they are where a practice with only an afternoon should spend the afternoon. Four is the one a malpractice carrier asks about.
The part most practices skip, and the part the lawsuit is about. What the patient is told, in what words, and whether it happens before the recording starts. Who says it, because the front desk and the clinician give different answers today. Whether the consent lands in the chart or only in someone's memory of the conversation. The opt-out path, and what actually happens when somebody uses it. And your state's recording law: some states require all parties to consent to a recording, and a clinical encounter is a recording.
Having one is not the same as having read one. The vendor is named as a business associate. Subcontractors are addressed, because the company selling you the scribe is often not the company running the model. A retention period appears in writing, for the audio and the transcript as separate items. Deletion on termination is specified, with a timeframe.
Draw it. One page, boxes and arrows, from the room to wherever it ends up. Which systems hold the raw audio, and for how long after the note is drafted. Whether it leaves the country. Whether your data trains the vendor's model, and whether that is opt-in, opt-out or not offered. Get that one in writing rather than from a salesperson. And what is retained if you cancel.
This is the one your malpractice carrier is asking for. The note is a draft until a clinician reads it, and the policy should say so explicitly. Define what review means: skimmed for obvious errors and checked the medication list and the plan against what I remember are different standards, and only one survives a deposition. Name what is never accepted without direct verification. Medications and any negation belong on that list, because denies chest pain and reports chest pain differ by one word.
Unique accounts, no shared logins ever. Multi-factor authentication on the scribe, same as the EHR. Offboarding: when a clinician leaves, scribe access is revoked the same day as EHR access. This is the one almost always missed, because the scribe was never on the offboarding checklist to begin with.
Whether an AI drafted note is identifiable as one in the chart. The amendment path when a patient reads their note and disputes it, which happens more now that patients can read their notes the same day. And retention that matches the schedule you already follow for records, rather than whatever the vendor defaults to.
The recording captures the wrong patient, or two patients. Who is told, and when. Who decides whether it is a breach, named as a person rather than a role. And where that decision is written down, because a documented decision that something was not a breach is itself required evidence. The practices that lose this argument are usually the ones who made the right call and never wrote it down.
The shortest section and the one that changes the most. Write down who approved this tool, on what date, and what they looked at. One paragraph is enough. When I ask a practice who approved their scribe, I get a name rather than a document. That is fine until the day it is not, and the day it is not is the day somebody outside the practice is asking.
Nobody says what they are. That is what the eight above are.
Almost every conversation about AI scribes is a conversation about hallucination rates, and that argument has a comfortable ending: you read the note before you sign it. Consent has no comfortable ending. Once the capture has happened, reviewing the note afterward does not undo it. The April complaint and the carrier guidance below are both governance problems rather than accuracy problems, which is exactly why the usual answer does not reach them.
Separately, at least two malpractice carriers, TMLT and MICA among them, have circulated guidance taking the position that when a scribe fabricates something and the physician signs it, the exposure belongs to the physician rather than the vendor. That is carrier guidance rather than a court ruling, and your own carrier's position is the one that governs you. It is the clearest reason to write down what item four actually means in your practice.
None of this is an argument against using these tools. The clinicians I work with who use one are noticeably calmer at the end of the day than the ones who do not, and I would not want to take that back from them. This is the paperwork that lets you keep it.
There is a great deal of material circulating with confident figures on AI scribe hallucination rates and on how many minutes a day the tools give back. Some of those numbers may well be right. Almost none of the coverage repeating them has read the underlying study, and much of it cites other coverage.
We only put numbers in front of people when we can point at where they came from. So this page names a court, a district, a filing date and a docket number, and a set of causes of action you can read for yourself. Where two sources disagreed on a detail, the detail was cut rather than hedged: that is why a third defendant listed by one outlet and not the others does not appear here, and why the scribe vendor named in the complaint does not either.
Eight things belong on paper: how and when patients are told the visit is being captured, and what happens when someone opts out; a business associate agreement that names subcontractors and states retention and deletion in writing; a drawn path showing where the audio goes and how long each system keeps it; a written standard for what reviewing a draft note means before a clinician signs it; rules for who may start a recording, including same day offboarding; how an AI drafted note is identified and amended in the chart; who decides whether a mistaken capture is a breach and where that decision is written down; and a short record of who approved the tool and on what date. Take them in that order, because the first three are the ones with live litigation attached.
Three patients filed suit against Sutter Health and MemorialCare on April 8, 2026 in the Northern District of California, in Washington et al. v. Sutter Health et al., No. 4:26-cv-03012. The complaint pleads the California Invasion of Privacy Act, the Confidentiality of Medical Information Act, the federal Wiretap Act, the California Unfair Competition Law, and common law invasion of privacy. It does not allege that the AI recorded or wrote anything inaccurately. The allegation is that the encounters were captured and sent outside the exam room to be processed, and that nobody told the patients first.
It solves the accuracy problem and not the consent one. Reading a draft before you sign it is a real answer to whether the model wrote something false. It is no answer at all to whether the patient agreed to be recorded, because the capture has already happened by the time there is a draft to read. The two risks need different controls, and most practices have only thought about the first one.
At least two malpractice carriers, TMLT and MICA among them, have circulated guidance taking the position that when a scribe fabricates something and the physician signs it, the exposure belongs to the physician rather than the vendor. That is carrier guidance rather than a court ruling, and the position your own carrier takes is the one that governs you. It is also the clearest reason to write down what review before signature actually means, because a documented standard is the thing a carrier asks to see.
No. The clinicians who use one are noticeably calmer at the end of the day than the ones who do not, and that is worth keeping. This is the paperwork that lets a practice keep the tool without carrying an undocumented decision. If you work through all eight and cannot answer three of them, that is not a crisis. It is the normal starting position for a practice that adopted a scribe the way almost every practice adopted one, which is that a clinician tried it and it spread.
One district court ruling, or one carrier changing its position, changes what item four has to say.
Security, Sized Right is a monthly issue on what actually changed: what the enforcement record shows, what carriers started asking for, and what either one means for a practice too small to have a security team. It is written from real client work, not from vendor research.
You can read the current issue in full before deciding whether to subscribe.
Every one of the eight above is something a HIPAA security risk analysis is supposed to surface, and the output is the dated, documented record an investigator or a carrier asks to see. Seqora runs that assessment as a guided workflow. See a finished sample, or run one on a demo practice right now. No signup.