You don't need a law degree to vet an AI vendor. You need a short list of plain questions, asked in writing, before any client data moves. This post gives you that list. It also shows why each question is about to matter more. A proposed federal rule would turn most of them into legal requirements, and the vendors who can't answer them today are the ones who will scramble later.
Why did this get urgent in 2026?
This spring, NPR ran two stories on therapists using AI tools to record sessions and draft notes (NPR, May 2026). The stories named Berries, Blueprint, and SimplePractice. In one, a client found out mid-session that she was being recorded. She said she felt "completely violated." That's what happens when a tool enters the room before the questions do.
The breach numbers point the same way. From 2018 to 2023, reports of large health-data breaches rose 102%, per HHS OCR (December 2024). The number of people affected rose 1,002% over the same window, driven by hacking and ransomware. In 2023 alone, a record 167 million Americans were caught in large health-data breaches. A solo practice can't stop a ransomware crew. But you do choose your vendors. That choice is the one lever you fully control.
So if you're weighing a notes tool, start with what an AI notes tool actually saves. Then run the checklist below before you sign anything.
What is a BAA, in plain terms?
HIPAA is the federal law that protects health information. Anything that ties a client to their care is PHI, short for protected health information. A session recording is PHI. So is a transcript, a draft note, even an appointment time with a name on it. When an outside company handles PHI for you, HIPAA requires a contract called a business associate agreement, or BAA. That contract makes the vendor legally responsible for guarding the data and for telling you when something goes wrong.
Two things a BAA is not. It is not a government seal. There is no official HIPAA certificate, so a "HIPAA" badge on a website proves nothing by itself. And it is not automatic protection. A BAA is only as strong as the words inside it.
APA's practitioner guide for evaluating AI tools says to check three things before you adopt any tool (APA Services, October 2024): whether the company offers a BAA at all, whether it uses your data to train its AI model and lets you opt out, and how long it keeps your data. Those three checks are the spine of the list below.
The checklist: 10 questions to ask before you sign
Ask these by email, before any client data moves. Save the answers in the same folder as your signed BAA. If the proposed federal rule becomes final, several of these stop being favors and become requirements.
1. Will you sign a BAA, and does it cover your whole service? Some vendors sign a BAA for the core product only. Support tools, analytics dashboards, and subcontractors can sit outside it. Ask what's in scope. A vendor who won't sign a BAA at all is not a vendor you can use with client data. 2. Does my client data train your AI model? Training means the company uses your data to teach its system. Pieces of your clients' words could shape the product everyone else uses. APA's guide says to verify this, and to ask whether you can opt out, before adopting (APA Services, October 2024). Get the answer in the contract, not in a sales email. 3. How long do you keep my data, and what does "delete" mean? Ask for the retention terms in writing: how long recordings, transcripts, and drafts are kept. Ask whether deleting also clears backups, and how fast. 4. Who else touches the data? Vendors use subcontractors. Any subcontractor that handles PHI needs its own agreement. Ask for the list of who they are. 5. How fast will you tell me when something goes wrong? HIPAA sets outer time limits for breach notices. Your BAA can set a tighter clock. The proposed HIPAA update would require a vendor to alert you within 24 hours of switching to its backup systems (HHS OCR fact sheet, December 2024). Ask for that clock now. 6. Is my data encrypted at rest and in transit? Encryption scrambles data so a thief can't read it. "At rest" means where it's stored. "In transit" means while it moves. The proposed rule would make both mandatory. 7. Does every login require a second step? That second step is called multi-factor authentication, or MFA. Think of the code your bank texts you. The largest health-data breach in U.S. history started at Change Healthcare, a UnitedHealth Group company, through one login that had no second step. About 190 million people were affected, per UnitedHealth's own estimate (Fierce Healthcare, January 2025). 8. Will you prove your security to me every year? The proposed rule would require business associates to verify their safeguards to the practices they serve once every 12 months, with a written analysis by an expert and a written certification (HHS OCR fact sheet, December 2024). A strong vendor won't wait to be forced. 9. What happens to my data if you shut down or get bought? AI companies change hands fast. Ask what the contract says happens to stored PHI on that day, and who inherits the BAA. 10. Can I export my data in a usable format? Your notes are your clinical record. If leaving the tool means losing them, you never really owned them.
Red flags that end the conversation
Some answers should stop the process on the spot:
- The vendor won't sign a BAA. That's a no, full stop.
- The website advertises a "HIPAA certification." No agency issues one, so the badge means nothing.
- Nobody can tell you whether your data trains the model.
- Nobody can name the subcontractors.
- MFA is "on the roadmap." The biggest breach in history walked through that exact gap.
Will the proposed HIPAA update make these questions law?
Probably, in some form. On January 6, 2025, HHS published a proposed update to the HIPAA Security Rule in the Federal Register. It's the first full overhaul since the standards were published in 2003 (they were last touched in 2013). The biggest shift is simple. Today, many safeguards are "addressable," which lets a company argue that a safeguard wasn't reasonable for its setup. The proposed rule ends that. Every safeguard would be required.
For the vendors on your list, the proposal adds hard duties (HHS OCR fact sheet, December 2024): encryption at rest and in transit, MFA on logins, a 24-hour alert when they switch to backup systems, and yearly written proof of their safeguards delivered to you.
One caution. This is a proposed rule, not a final one. The comment period closed March 7, 2025, and no final rule has been issued as of July 2026. If a vendor claims it already "meets the new HIPAA rule," that alone is a red flag. There is no new rule yet. But a vendor who can answer all ten questions today won't scramble when one arrives.
Insurers already run AI on your claims
Commercial insurers already use AI in claims review and prior authorization. Regulators have noticed. At least 25 states have issued guidance on insurer AI use, built on the NAIC model bulletin, as of early April 2026 (KFF, May 2026). Illinois, California, Texas, Maryland, Utah, Alabama, and Washington have gone further and updated their insurance standards for AI in claims review.
Read that as your floor. If a state expects an insurer to answer for its AI, you can expect the company holding your session recordings to answer for its own. Asking these questions doesn't make you difficult. It applies the same standard the system is already being held to. (And if an Optum "clinical review" call shows up on your calendar, that's its own playbook.)
Consent is your job, not the vendor's
A signed BAA protects the data. It does not tell your client a machine is in the room. In June 2025, APA issued ethical guidance on AI in the professional practice of psychology (APA, June 2025). It says clinicians must get informed consent by clearly explaining an AI tool's purpose, its benefits, and its risks. The NPR story above shows the cost when that conversation gets skipped. Trust breaks in one sentence and takes months to rebuild.
A plain script works: "I use a tool that records our session and drafts my note. I review every note myself. Here's what the company can and can't do with the recording. You can say no." We wrote a longer guide on AI scribes, consent, and whose note it is. Tell clients before the first recording, and document the consent.
Where VibeCheck fits
This checklist is the bar I hold every vendor to, because I'm a clinician and my license sits behind every note. It's also the bar we built VibeCheck to clear: clinician-built, HIPAA-eligible infrastructure, and a signed BAA before client data moves. If you want to run the ten questions against our answers, book a call. We like this conversation. It tends to turn into what therapists keep saying they want from AI: real help with the work that doesn't spend your clients' trust to get it.
FAQ
Do I need a BAA before using an AI tool with client data?
Yes. If a tool touches anything that can identify a client and their care, HIPAA requires a BAA first. APA's guidance says to verify the vendor offers one before adopting the tool (APA Services, October 2024). No BAA, no client data. There's no exception for free trials or pilots.
Is the new HIPAA Security Rule in effect?
No. It's a proposed rule, published January 6, 2025. The comment period closed March 7, 2025, and no final rule has been issued as of July 2026. Treat its requirements as a preview, and as a smart bar to hold vendors to today.
What does "training the model on my data" mean?
Some AI companies use customer data to teach their systems. Pieces of that data can shape the product other customers use. APA's guide says to ask whether the company trains on your data and whether you can opt out (APA Services, October 2024). Get the answer in writing, in the contract.
Do I have to tell clients I use an AI tool?
Yes. APA's June 2025 ethical guidance says clinicians should get informed consent by clearly explaining the tool's purpose, benefits, and risks (APA, June 2025). Do it before first use, in plain language, and note it in the record.