Somewhere in a California exam room right now, a patient is telling her doctor about a symptom she has never told anyone else. She signed a stack of intake paperwork on the way in. She probably didn’t read most of it. And an AI scribe is transcribing every word, sending the audio to a cloud server, and turning it into a clinical note before she has even put her shoes back on.
While none of that is illegal, it might be. And three federal class actions filed in the last twelve months suggest the plaintiffs’ bar has decided the answer is yes.
Key Takeaways
- Three federal lawsuits highlight legal risks associated with AI scribes in healthcare, specifically regarding patient consent.
- HIPAA compliance does not protect against state wiretap laws, which require consent before recordings begin.
- Recent legal developments indicate a shift towards requiring explicit consent for AI documentation in various states.
- Practices should ask vendors detailed questions about recording, consent workflows, and data handling related to AI scribes.
- The future may involve a national standard for consent procedures, driven by legal precedents and patient protection concerns.
Table of contents
The lawsuit nobody in healthcare AI wanted
On April 8, 2026, three California patients sued Sutter Health and MemorialCare in the U.S. District Court for the Northern District of California. The complaint says both health systems used Abridge’s ambient AI scribe to record clinical conversations, transmit the audio to external servers, and generate notes, all without informed patient consent. The claims cite the California Invasion of Privacy Act (CIPA), the California Confidentiality of Medical Information Act, and the Federal Wiretap Act. CIPA damages start at $5,000 per interception. Across a hospital system’s patient population, that number gets ugly fast.
The Sutter case is not an outlier. Four separate lawsuits against Otter.AI have been consolidated in the same federal court under In re Otter.AI Privacy Litigation, testing whether an AI notetaker that joins a Zoom call counts as an unauthorized third-party interceptor under wiretap statutes written decades before Zoom existed. Then, on July 30, 2026, a Florida plaintiff filed Chamberlain v. Granola against a “bot-free” meeting AI on essentially the same theory. Different products, different industries, same argument.
That argument is worth understanding, because it applies to your organization whether you run a clinic, a sales team, or a consulting practice.
The HIPAA trap with AI scribes

Here is the misconception that got Sutter and MemorialCare sued.
Most healthcare buyers assume that if a vendor is HIPAA compliant, has signed a Business Associate Agreement, and encrypts data end to end, they are legally covered when they turn on an AI scribe. That assumption is wrong. The reason it’s wrong is that HIPAA and state wiretap law are two completely separate bodies of law regulating two completely separate things.
HIPAA governs how protected health information can be used and disclosed. Under HIPAA, a covered entity can use PHI for treatment, payment, and operations without a separate patient authorization. An AI scribe that captures a visit and turns it into a note generally falls within that permitted use, provided the vendor operates as a business associate under a signed BAA.
State wiretap and recording-consent laws work differently. They govern the act of recording itself. They don’t care what happens to the recording afterward. They care whether the recording was legal to make in the first place. In twelve states (California, Illinois, Pennsylvania, Florida, Massachusetts, Washington, Maryland, and a handful of others) every party in a conversation has to consent before the microphone comes on.
So a provider can be perfectly HIPAA compliant on Monday and get sued for a wiretap violation on Tuesday. The BAA doesn’t preempt state law. The encryption doesn’t matter. What matters is whether the patient knew she was being recorded and agreed to it before the recording started.
Why 2026 changed the risk calculus
Ambient AI scribes operated in a legal gray zone for years, and most providers never had to think about it. That gray zone is closing.
Three things happened this year…
- The Sutter and MemorialCare complaints signaled that plaintiffs’ lawyers now understand the theory well enough to bring it up repeatedly, and the Otter and Granola filings show the same theory being pressure-tested against meeting notetakers.Â
- On January 1, 2026, the Texas Responsible AI Governance Act took effect and now requires physicians to disclose to patients that an AI system is involved in their care. Texas is a one-party consent state. Physicians there could have relied on their own consent to satisfy the wiretap statute. The legislature basically said that isn’t good enough anymore.Â
- Courts started grappling with what it means, legally, for a machine to “intercept” a conversation. The pending Otter motion-to-dismiss ruling will be the first federal read on whether a bot in a Zoom call qualifies as a wiretap. Whichever way it goes, the compliance floor is rising.
If you are still relying on a checkbox in a patient portal or a line buried in intake paperwork to cover you, the ground under that assumption is moving fast.
The interstate rule almost nobody talks about
Here’s a wrinkle that catches even careful operators off guard. California’s law, under the Kearney precedent, can apply to a phone call or video consultation whenever a California resident is on the line, even if the other party sits in a one-party state. So a Texas clinic doing a telehealth visit with a California patient, or a Chicago sales team on Zoom with an Illinois prospect, may be governed by the stricter state’s rule.
For anyone running telehealth, this collapses the “we’re a one-party state, we’re fine” defense. For anyone running a national sales operation or a multi-state provider network, it means the safest posture is to design for the strictest jurisdiction and stop trying to slice the country into a patchwork.
What a well-run deployment looks like
None of this means AI scribes are a bad idea. They are one of the highest-leverage tools healthcare has adopted in a decade. The productivity gains are real. The burnout relief is real.
To see what disciplined implementation looks like at scale, CareMed Primary & Urgent Care’s rollout across seven Long Island locations is worth studying. Using AI Scribe, CareMed increased same-day encounter closures from 55% to 90%, saved 21 staff hours per week through connected automation, and recovered more than 120 previously missed appointment slots each month.
CareMed operates in New York, a one-party consent state, so their operational profile isn’t directly exposed to the CIPA theory driving the California lawsuits. But the reason their deployment worked is the same reason a deployment in Los Angeles or Philadelphia would need to work. Connected systems. A clinical team that actually understands what the AI is doing during a visit. Workflows that log who did what, when. That baseline discipline is also what makes proper consent workflows possible.
If your practice can’t cleanly log an encounter, you can’t cleanly document who consented to what either.
What buyers should actually be asking AI scribe vendors
If you’re deploying or evaluating an ambient AI scribe, the questions worth asking a vendor go well past “are you HIPAA compliant.” For starters, here’s a brief checklist…
- Where does the audio physically go, and how long is it retained?Â
- Is any part of the transcript, or the audio itself, used to train the vendor’s models?
- Can a provider or patient stop the recording mid-encounter, and if so, what happens to the audio already captured?Â
- Does the tool support all-party consent workflows for California, Illinois, and the other ten strict-consent states?Â
- What happens when a family member, interpreter, or trainee is in the room?Â
- Does the vendor’s BAA specifically address recording-consent obligations, or only PHI handling?
An operations platform that ties consent, documentation, billing, and audit trails together is what makes those questions answerable in the first place. That’s a big part of why a cloud-based practice management platform with integrated audit trails matters the most. If consent lives in one system, the recording lives in a second, and the medical record lives in a third, then the day a plaintiff asks you to prove informed consent for a specific encounter on a specific date, you’ll have three log files to reconcile and a compliance officer with a headache.
Where this is headed for AI Scribes
The plaintiffs’ bar has found a legal theory that works, a technology category scaling faster than regulators can keep up with, and a group of defendants with the resources to pay statutory damages. That combination isn’t going anywhere.
The most likely outcome over the next twelve to eighteen months is a de facto national standard: explicit, documented, revocable, per-encounter consent for AI documentation, obtained before the recording begins, regardless of what your state’s wiretap statute technically requires. The organizations that get there voluntarily will spend far less on defense than the ones who wait for their own class action.
AI scribes aren’t going away. Neither are the wiretap statutes. Whether they can live together inside your practice depends less on which vendor you picked than on how carefully you built the workflow around it.











