That distinction is the whole point of this article. A signed Business Associate Agreement tells you where your data can legally live. It says nothing about whether you obtained valid consent to record the conversation in the first place. Those are two separate questions, and this lawsuit is testing the second one.
What Is the Washington v. Sutter Health Lawsuit, Actually?
Three plaintiffs, Christina Washington, Dennis Gueretta, and Rebecca Matulic, filed suit against Sutter Health and Memorial Healthcare Services on April 8, 2026, in the U.S. District Court for the Northern District of California, case number 4:26-cv-03012-KAW (HIPAA Journal, April 14, 2026). The case was independently corroborated by trade outlet TechTarget's healthcare security desk the same month (TechTarget/Xtelligent Healthcare, April 2026).
The suit centers on Abridge, an ambient AI scribe that listens to a visit and drafts clinical documentation. The complaint alleges patients weren't given adequate notice or a real chance to decline before their conversations were captured and processed. This isn't a brand-new story breaking this month. The filing is from April, and it's part of a widening pattern rather than a fresh news event, which matters if you're deciding how urgently to act on it.
Why Isn't This a HIPAA Case?
The complaint deliberately avoids HIPAA and instead leans on California's wiretap and privacy statutes, because Abridge already signs Business Associate Agreements with the health systems that use it. That single fact tells you where the real exposure sits for any practice using a scribe tool: not in where the data ends up, but in how the recording started.
Named claims in the suit include the California Invasion of Privacy Act, the Confidentiality of Medical Information Act, California's Unfair Competition Law, the federal Wiretap Act, and common-law invasion of privacy (HIPAA Journal and Becker's Hospital Review, April 2026). Becker's framed it plainly: the case is really about consent, not about where the vendor stores the transcript. A vendor can hold a valid BAA and still be sued over how the recording was obtained. Those are separate legal questions, and a practice that treats "HIPAA-eligible" as a finish line is answering only one of them.
For a solo or group practice, that means your vendor's BAA protects you against one category of risk. It does nothing for you if a client later argues they never meaningfully consented to being recorded, or didn't understand what an "ambient AI scribe" actually captures. Practices already navigating this ground can see how the general consent question plays out for therapy notes specifically in AI Scribe in Therapy: Consent & Whose Note It Is. This case adds the sharper, statutory version of that same problem.
What About the Sharp HealthCare Case?
A second, separate lawsuit against the same vendor adds weight to the pattern without being part of the same case. Saucedo v. Sharp HealthCare was filed in San Diego County Superior Court around November 26, 2025, months before the Sutter suit and against a different defendant (MobiHealthNews and KPBS, December 2025).
The Sharp complaint alleges something specific and, frankly, worse than a missed disclosure: that Abridge auto-generated language stating the patient "was advised of/consented to recording" and inserted it into more than 100,000 patient charts, regardless of whether that consent was ever actually given. If accurate, that's not a gap in a workflow. That's a system fabricating a compliance record for you.
Keep the two cases straight. Sutter is federal, filed April 2026, over the recording itself. Sharp is state court, filed in late 2025, over auto-inserted consent language in the chart. Same vendor, same underlying tool, two different fact patterns, two different courts. Together they read less like an isolated incident and more like a vendor-wide exposure across every health system that deployed the same product.
How Often Do AI Scribes Get the Note Wrong?
A peer-reviewed study found hallucinations, meaning fabricated or inaccurate content, in 31% of ambient-AI-generated clinical notes, compared with 20% in physician-authored "gold standard" notes, a statistically significant difference (p=0.01) using a modified PDQI-9 evaluation framework (Frontiers in Artificial Intelligence, 2025).
Read that carefully, because it's easy to misquote. It is not a range describing AI error alone. It's a head-to-head comparison: human notes hallucinate at 20%, AI notes at 31%. Humans get things wrong too. AI got things wrong more often, and at a rate high enough that a peer-reviewed study flagged it as statistically meaningful, not noise. For a clinician whose note is the legal record of what happened in session, an 11-point gap in fabricated content is not a rounding error.
Scale matters here too. Abridge is deployed at major systems including Johns Hopkins, Mayo Clinic, Mount Sinai, UC Health, MemorialCare, Christus Health, Corewell Health, and Reid Health (HIPAA Journal, April 2026). A hallucination rate that looks small in a lab study compounds fast across that many encounters, and the practices exposed to it aren't limited to two lawsuit defendants.
What Does "HIPAA-Eligible" Actually Cover, and What Doesn't It?
"HIPAA-eligible" describes a vendor's technical and administrative capacity to sign a Business Associate Agreement and handle protected health information under HIPAA's rules. It says nothing about state wiretap law, nothing about whether a client gave informed consent to be recorded, and nothing about whether the AI's output is accurate. Those three gaps are exactly where the Sutter and Sharp complaints live.
This is why "our vendor is HIPAA-eligible" is a necessary answer to a vendor question, not a sufficient one. A practice can have a fully executed BAA and still face a CIPA claim carrying statutory damages of $5,000 per violation, assessed potentially per encounter (Fisher Phillips LLP, 2026). Multiply that by even a modest caseload and the exposure math moves fast, which is exactly the mechanism legal analysts point to as the reason these suits target scale, not just intent.
If you're building or auditing your own AI-vendor questionnaire, the consent question needs its own line item, separate from the data-storage question. A short list of what to ask lives in AI Vendor Questions for Therapists: The BAA Checklist, and if clients are recording sessions on their own devices, the consent conversation runs in both directions, covered in Client Recording Therapy Session: Smart Glasses Policy.
What Should a Solo or Group Practice Owner Do Now?
Start with the consent language itself, not the vendor contract. Confirm your intake or session-start script names the tool by function (ambient recording and transcription for note drafting), states that a human reviews the output, and gives the client a clear way to decline without losing services. Verbal consent noted in the chart is a start; a signed, dated consent form that survives an audit is stronger.
Second, ask your vendor directly whether their output has ever been evaluated for hallucination rate, and whether they'll show you the methodology. If the answer is marketing language instead of a number, that's information too. A 31% figure only matters if you know your own tool's number is lower, not just that a BAA exists.
Third, don't assume a signed BAA closes the consent question. It closes the HIPAA question. Practices that keep those two questions separate, and can point to documented, informed, revocable consent independent of the storage agreement, are in a materially stronger position if a client or regulator ever asks. That separation, consent-first design that doesn't route around the clinician's own review of the note, is the direction we've built toward at VibeCheck.luxury, and it's worth demanding from whatever tool you're already using.
FAQ
Is the Sutter Health AI scribe lawsuit a HIPAA case?
No. The complaint is built on California's Invasion of Privacy Act, the Confidentiality of Medical Information Act, the federal Wiretap Act, and common-law privacy claims, not HIPAA. Abridge already holds Business Associate Agreements with the health systems named, so the exposure sits in state consent and wiretap law instead (HIPAA Journal, April 2026).
Are the Sutter and Sharp HealthCare lawsuits the same case?
No. Washington v. Sutter Health is a federal suit filed April 8, 2026 in the Northern District of California. Saucedo v. Sharp HealthCare is a separate California state-court suit filed around November 26, 2025 against a different defendant. Both involve the same AI scribe vendor, Abridge, but they're distinct cases with different allegations.
How often do AI scribes hallucinate compared with human-written notes?
A peer-reviewed 2025 study found hallucinated content in 31% of AI-generated clinical notes versus 20% of physician-authored notes, a statistically significant gap using a modified PDQI-9 framework (Frontiers in Artificial Intelligence, 2025). Both rates are nonzero, but AI ran meaningfully higher.
Does a signed BAA with an AI scribe vendor protect my practice from these claims?
A BAA covers HIPAA-regulated handling of protected health information. It does not address whether a client gave valid, informed consent to be recorded, which is the actual basis of the Sutter and Sharp complaints. Practices need both a compliant vendor agreement and documented, specific consent to record.
What does CIPA's $5,000-per-violation exposure actually mean for a practice?
California's Invasion of Privacy Act allows statutory damages of $5,000 per violation, and legal analysts note this can potentially be assessed per recorded encounter rather than as a single flat penalty (Fisher Phillips LLP, 2026). That structure is why the exposure scales quickly with caseload rather than staying fixed.