How-to guides
Privacy & Cyber SecurityTwo to three hours per tool, plus the time the vendor takes to answer in writing

How to Assess an AI Scribe for Privacy Compliance

An eight-step procedure for a practice manager to run before the practice relies on an AI scribe: check whether it is a medical device under the TGA test, map where the audio, transcript and note go, read the training and secondary-use terms, apply APP 8 and the NSW and Victorian transfer rules, set retention, write the consent process, fix the contract, and update the privacy policy, collection notice, AI policy, PIA and training. The practice stays responsible for a vendor's tool, and the clinician for every note it drafts.

Assess an AI scribe in eight steps before the practice relies on it: what it does under the TGA's device test, where the data goes, whether it trains on it, the cross-border and interstate rules, retention, consent, the contract, and the practice's own documents. The practice remains responsible for a vendor's tool, and the clinician for every note it drafts.

This guide is the procedure, step by step. What an AI scribe is, and the obligations it carries, is in our AI scribe glossary entry. The wider picture sits in our healthcare privacy and cyber security pillar.

Eight steps to assess an AI scribe, each with the evidence it leaves: a device check with an ARTG search record and the vendor's written regulatory status; a data flow map; the training clause and chosen setting; an APP 8 and state transfer assessment; a retention record; the consent process, form and script; signed terms checked against a contract list; and an updated privacy policy, collection notice, AI policy, PIA and training record. Together they form the evidence file for RACGP F11.A and F11.B.

Before you begin

Have these open, with their dates:

  • The vendor's privacy policy and terms of service
  • Its security or trust page and any sub-processor list
  • The practice's own privacy policy and APP 5 collection notice
  • Your AI acceptable use policy template
  • Your privacy impact assessment template
  • The ARTG search page

A scribe may already be in use: a clinician's own subscription, or a feature switched on inside the practice software. The ANAO reported on 21 September 2026 that of the practice management software Services Australia lists, "approximately one-fifth refer to using AI, particularly AI scribes", and at least one vendor's help centre says AI features are enabled by default. RACGP 6th edition F11 says "practices remain responsible for their safe and appropriate use" of third-party AI tools, and the RACGP's AI scribes fact sheet tells owners to set a policy on which scribes are permitted and inform tenant GPs.

F11 applies only to practices that use AI, and accreditation under the NGPA Scheme still runs on the 5th edition, so this is preparation, not a deadline.

Step 1: Check what the tool does and whether it is a medical device

A scribe that only transcribes and summarises is not a medical device. The TGA's test (updated 30 January 2026): "Digital scribes intended only to transcribe and translate clinical conversations into written records without performing analysis or interpretation are not considered medical devices", but one that "analyses or interprets clinical conversations, for example by generating a diagnosis, differential diagnosis or treatment recommendation not explicitly stated by the healthcare practitioner, is considered a medical device." A device meeting that test must be in the ARTG before supply, or it "is being supplied illegally."

List everything the tool does beyond transcription and summary: diagnosis or differential suggestions, treatment suggestions, MBS item suggestions, decision-support add-ons. Search the ARTG by the manufacturer's name, and ask the vendor in writing for its regulatory status (F11). Recheck after every update: the TGA asks whether updates "have introduced new functionality that may change the intended purpose."

The RACGP's two documents disagree: its fact sheet says scribes "do not require regulation by the TGA", while F11 says transcription tools "may be classified as medical devices." Apply the TGA's own test. The ACSQHC warns an unintended suggestion "may trigger the requirement for inclusion in the ARTG", and Avant asks first: "Was the AI designed for a medical purpose? ... We recommend you do not use AI in a clinical context if it was not developed for a medical purpose."

Suggested MBS item numbers must be verified against Medicare requirements (RACGP); we cover AI billing and the ANAO's findings in a separate post. From 1 November 2026 the TGA's clinical decision support exemption is amended to require that qualifying software does not make a clinical diagnosis and displays the logic behind any recommendation; see our separate post.

Step 2: Map where the audio, transcript and note go

Map five layers for every scribe: audio, transcript, the drafting model, the draft, and the final note. For each, find where it is processed and stored, how long, who can access it, and whether it leaves Australia or the state.

A data flow chain for an AI scribe: audio captured in the consult room or telehealth call, transcription, the drafting model at the AI provider, the draft note on the vendor platform, and the final note in the practice's clinical record. At each hop ask where the data is, for how long, who can access it, and whether it leaves Australia or the state. Crossing the Australian border engages APP 8 and section 16C; crossing a state border engages NSW HPP 14 and Victorian HPP 9. The clinician reviews the draft before import.

F11 lists the vendor questions: "Does the AI vendor confirm compliance with the Privacy Act and APPs?" "Can collected data be used or sold for secondary purposes?" "How is patient data encrypted, stored, and destroyed?" The RACGP fact sheet points to the source: "within the product's terms and conditions, terms of service or privacy policy." Avant adds: is data identifiable or de-identified, encrypted, stored in Australia or overseas; "If the information is not available, you should ask the provider directly."

The OAIC flags both legs: "where the servers are located and whether personal information could be disclosed outside of Australia", and "whether a third party receives personal information" through the product. A 2026 departmental brief made the same point: "Some suppliers may be unaware their cloud platforms send data outside Australia."

Read the legal page, not the product page. In pages read on 24 September 2026, one vendor's trust page said data was stored locally, while its privacy policy listed a transcription supplier "provided from the USA." Record what the terms say, with their effective date, not the marketing page.

LayerWhat to find outWhere to lookRecord
AudioProcessed where, stored or not, for how longPrivacy policy, terms, help centreQuote and date
TranscriptStored where, how long, who can accessSameQuote and date
Drafting modelWhich provider, which region, sub-processorSub-processor list, privacy policyProvider name and region
Draft noteWhere held before import, how longTerms, settingsRetention setting
Final noteIn the practice's clinical recordPractice softwareConfirm it imports into the record

Step 3: Check the training and secondary-use terms

Do not accept a "we never train on your data" line without reading the next sentence. The OAIC warns some products let the vendor "collect the data input by customers for further training", and that it is often "difficult to establish that a secondary use for AI-related purposes ... was within reasonable expectations", so the organisation should "seek consent for that use and/or offer individuals a meaningful and informed ability to opt-out." The ACSQHC's guidance says data sharing and secondary use "require explicit consent"; the APS's guidelines tell psychologists to "prevent data being used for training."

Watch for the carve-out. In terms read on 24 September 2026, one vendor answered "No. We never use your patients' data to train or improve any AI models," then added: "We fine-tune the AI on de-identified, aggregated usage patterns, and doctor verbal feedback." Ask whether feedback includes note text, and whether it can be switched off.

The OAIC's controls to look for include "turning off features that would disclose personal information" and "prohibiting your staff from entering personal information in the AI inputs." Record the setting you chose and the clause it rests on. No OAIC guidance yet addresses training offshore on data stored in Australia; treat that as untested and get the vendor's answer in writing.

Step 4: Apply the cross-border and interstate rules

If the scribe sends data offshore, APP 8 applies and the practice answers for the recipient. APP 8.1 requires "reasonable" steps to ensure the overseas recipient does not breach the APPs, and under section 16C a breach by the recipient "is taken ... to be a breach of those Australian Privacy Principles by the APP entity." You cannot contract out of accountability.

One narrow exception: OAIC guideline 8.14 treats storage-only cloud hosting as a "use" rather than a disclosure, but only where a binding contract limits the provider to that purpose, binds subcontractors to the same terms, and gives the practice "effective control", including the ability to retrieve or delete the data "at the end of the contract."

Guidance on location varies: the ACSQHC expects Australian storage "unless the patient has provided explicit consent for their data to be managed offshore", while the RACGP fact sheet says only "Ideally." Neither is an APP.

State law adds a second border. NSW's Health Privacy Principle 14 bars transferring health information out of the state unless an exception applies, such as the recipient being bound by "substantially similar" protections; hosting in another Australian state counts as a transfer. Victoria's Health Complaints Commissioner states HPP 9 as: "the holder has a responsibility to ensure that the privacy of the information is safeguarded" when data travels outside the state. For benchmarking only, Victorian public health services (not private practices) must use scribes that "store and process data in Australia" and complete a PIA first.

Step 5: Set retention for audio, transcripts and notes

Vendor retention varies widely. In terms read on 24 September 2026, audio retention ranged from not stored at all to "up to a week"; transcripts ran from 24 hours to 6 months depending on settings. The RACGP fact sheet notes "Most AI scribe providers do not store captured audio content." Turn the vendor's setting into a written practice decision.

The Privacy Act follows control, not location: an entity "holds" information if it has "possession or control of a record" (s 6(1)). APP 11.2 requires destruction or de-identification once information is no longer needed, and APP 12.1 gives patients a right to access it. The TGA tells patients they have "the right to view the personal information ... at any time."

State law applies to the identifiable record: MIPS notes that in Victoria, the ACT and NSW health information must be kept "for at least seven years from when a patient was last consulted or until a child reaches the age of 25 years, whichever occurs later", and that this applies to identifiable information only. RACGP F8.E requires "procedures for the storage, retention, and destruction of records." Work out your periods with our medical record retention calculator.

Two points to decide and write down, not resolve: whether a vendor-held transcript must be produced on an APP 12 request or a subpoena, and what happens to a partial note when a patient withdraws mid-consultation. The ACSQHC says delete the data; F11 says document the withdrawal and stop, without addressing what is already recorded.

Consent has two legs: informed consent to the tool, and state laws on recording conversations. No single rule covers either, so your medical defence organisation decides which standard the practice follows.

Body and dateWhat it says
RACGP 6th edition F11.A (26 August 2026)The practice "facilitates processes for members of the clinical team to obtain and document informed consent from patients when aspects of care will be delivered using AI". Practices "need to inform patients of how these tools use their health information (for example, what information is collected, where it is stored and who has access to it)" and of the right to withdraw, with "a clear and accessible mechanism for patients to opt out."
RACGP AI scribes fact sheet (October 2025)"Obtain patient consent to use an AI scribe at the beginning of each consultation." "Ask your MDO if they require written consent ... If written consent is not required, you can obtain patient consent verbally and record this in your consultation notes."
Ahpra and the National Boards (reviewed 22 August 2024)"Make sure you obtain informed consent from your patient, and ideally note the patient's response in the health record." "the AI transcription software should include an explicit consent requirement as an initial step before proceeding."
ACRRM checklist (June 2025)"Obtain explicit consent before using the AI scribe before each consultation." "Avoid relying on implied consent, always seek active patient agreement." "Record consent in the clinical notes."
APS guidelines (11 February 2026; guidelines are members only)"written informed consent before using AI or emerging technologies that involve client data, influence clinical decision-making, or contribute to client records." "Blanket consent for 'AI use' is not sufficient."
APA statement (August 2026)Patients "must consent to this use without coercion and that this is documented appropriately." Ahpra's guidance "takes precedence" if inconsistent.
ACSQHC ambient scribe scenario (August 2025)Consent may be documented "on registration forms (paper or electronic), as part of online booking terms and conditions, through privacy collection notices with opt out options or in the healthcare record." "The nature of consent will be situational and largely determined by your organisation."

Ahpra's word is "ideally"; never record that Ahpra requires consent to be noted.

A matrix of what seven bodies say about consent for AI scribes. RACGP F11.A: obtain and document informed consent. RACGP fact sheet: at the beginning of each consultation; ask your MDO if written consent is required. Ahpra: obtain informed consent and ideally note the response. ACRRM: before each consultation; avoid relying on implied consent. APS: written informed consent; blanket consent is not sufficient. APA: without coercion and documented appropriately. ACSQHC: privacy collection notices with opt out options are one way to document consent; on withdrawal stop recording and delete. Recording law is a separate leg: NSW Surveillance Devices Act section 7, maximum 100 penalty units or 5 years for an individual, 500 penalty units for a corporation.

The recording-law leg: under s 7 of the Surveillance Devices Act 2007 (NSW), recording a private conversation without consent carries a maximum of "500 penalty units (in the case of a corporation) or 100 penalty units or 5 years imprisonment ... (in any other case)", with exceptions under s 7(3) where all the principal parties consent, expressly or impliedly, or one principal party consents and the recording is reasonably necessary to protect their lawful interests or is not made to communicate the conversation to non-parties. Avant reads consent from all parties as required in the ACT, NSW, SA, Tasmania and WA, and "prudent" elsewhere; whether a scribe counts as a listening device "has not been considered by the courts." MIPS: unconsented recording of each consultation "may be a separate offence."

Before the consultation. Cover it on the registration form, pointing to the AI scribe section of your privacy policy (MDA National).

The first conversation. Avant's script:

"I have started using an AI software tool that listens to our consultation and then summarises the information into a clinical record. This means that I can have a conversation with you without having to stop and take notes. When you leave, I will check that the information is correct and then add it to your file. The recording is stored securely and when I am finished the draft is deleted."

Ask if they have questions, note they can decline at any time, and match the storage sentence to your actual vendor (Step 5); a bare mention of "software" is not enough (Avant).

Later consultations. Verbal confirmation, documented, is enough after the first detailed conversation (Avant), consistent with the RACGP and ACRRM's "before each consultation."

Recording it. In the clinical note: the tool was used and consented to, what happens to the transcript, and that the clinician checked the summary (MDA National).

Withdrawal. Document it, stop unless clinically necessary and re-authorised, and offer an alternative (F11); the ACSQHC adds: delete the data.

Psychology and physiotherapy. The APS requires written, tool-specific consent; the APA requires consent "without coercion" and "documented appropriately", with Ahpra's guidance taking precedence.

Patients who cannot consent. Get consent from "the appropriate substitute decision-maker" (Avant).

One point left open: PP4 says "It is not acceptable for consent to be sought for the first time in the consulting room"; whether a scribe vendor is a third party is not stated. Our AI scribe patient consent form carries the script and the record line.

Step 7: Fix the contract

F11 requires that "contracts with vendors address data handling, consent, and accountability." Everything from Steps 2 to 5 should be in the signed terms, not just the marketing pages.

Data processing terms. Per guideline 8.14, the contract must limit the provider to the stated purpose, bind subcontractors to the same terms, and give the practice effective control.

Sub-processor list. Get the current list in writing, with a commitment to notify changes.

Breach notification. Guideline 8.16 expects the contract to require a breach response plan that notifies the practice. Under the Privacy Act, where one breach is an eligible data breach of several entities, one entity's compliance with the assessment duty (30 days under s 26WH) and the notification duty means those duties no longer apply to the others (ss 26WJ and 26WM). The OAIC says the entity with "the most direct relationship" with the affected individuals should notify: usually the practice. What to do once a breach happens is our separate guide; see notifiable data breach.

Exit and deletion. Confirm data can be "retrieved or permanently deleted ... at the end of the contract", how to disengage, termination notice, and access to historical data.

Indemnity. Avant warns its own indemnity policy "will not cover liability you take on under a contract if you take on liability beyond the general law", and recommends advice before agreeing to any indemnity clause; ACRRM says the same. Ask your own insurer.

Update notices. Get a commitment to notice of updates that "change the intended purpose" (TGA) or cause "unexpected changes in AI behaviour" (RACGP CG7).

Our third-party data sharing agreement template covers the data-handling terms.

Step 8: Update your documents and train the team

F11.B requires a process to "assess and evaluate the use of AI ... prior to implementation" and to monitor it afterwards. This step writes that process down.

Privacy policy. F9.A requires the policy to address overseas disclosure and how document automation is used "so that only the relevant medical information is included in referral letters." The RACGP's template has fill-ins for the scribe's name and whether it shares data overseas. Digital Rights Watch found only "4 out of the 60" AI-scribe practices it reviewed explained the use in their privacy policy. From 10 December 2026, APP 1.7 adds a disclosure duty for automated decision-making that a scribe proposing a diagnosis or treatment may trigger; the deadline and the drafting are in our post on the ADM deadline.

Collection notice. If the developer can access personal information, the OAIC says that disclosure belongs in your APP 5 notice.

AI policy. Record which scribes are permitted, how breaches are reported, and who monitors compliance (RACGP); Avant adds: "appoint a person ... responsible for monitoring use of the AI scribe." Our AI acceptable use policy template is the place to record this.

Privacy impact assessment. Not mandatory for a private practice, but the OAIC recommends one as part of "privacy by design", and the ACSQHC says "consider" one. Victorian public health services must complete one. Start from our PIA template.

Training. F4 requires training on "the safe and effective use of these systems" and "the importance of clinical oversight", updated regularly.

Incidents. CG7 requires the incident process to cover AI issues and warns that "Identifying AI-related issues must not rely solely on feedback or complaints."

Note review. Review notes "as soon as possible after consultations" (RACGP); MDA National warns unreviewed notes "are deemed to have been reviewed and approved." Bodies differ on labelling: ACSQHC yes, ACRRM optional, RACGP silent. Decide one rule. The record standard is unchanged: PSR Regulations s 6 requires each entry dated, sufficient, timely and comprehensible to another practitioner.

Monitoring. F11 suggests team feedback, auditing AI-generated outputs, and reviewing updates for new risks.

What good looks like

The eight steps leave a file of evidence: the ARTG search, the data flow map, the training setting, the cross-border assessment, the retention decision, the consent process, the checked contract, and the updated documents. F11 is not yet assessed under the NGPA Scheme, so the mapping below is our suggested mapping, not the RACGP's.

F11 indicator (short form)Evidence from this guide
F11.A obtain and document informed consentThe Step 6 consent process, the consent form, a sample of notes with consent recorded
F11.A deidentification and anonymisationStep 3 training settings and Step 2 map of identifiers
F11.A identified data only where clinically necessary and explicitly authorisedThe scribe policy naming permitted tools and who authorised them
F11.A discuss implementation with the team and identify training needsTeam meeting minutes and the F4 training record
F11.A governance, accountability and compliance with legislationThe named responsible person, the PIA, the Step 4 cross-border assessment, the contract checklist
F11.A clinical oversight of AI outputsThe note-review rule and labelling decision
F11.A clinicians accountable for care decisionsThe scribe policy statement that the clinician is the author
F11.B assess before implementationThis completed eight-step assessment, dated
F11.B monitoring, review and quality improvementThe CG7 incident category, an audit of a sample of notes, the update review log

Signing the note without reading it. MDA National: the record is deemed approved whether or not the clinician checked it.

Treating a waiting-room sign as consent. MDA National: "A sign in the waiting room ... will not protect you."

Assessing the product page instead of the terms. Step 2's example: the trust page and the privacy policy disagreed.

Letting contractor GPs bring their own scribe. The RACGP tells owners to set permitted scribes; F11 says the practice remains responsible regardless.

Accepting an indemnity clause without asking the insurer. Avant's policy will not cover liability taken on beyond the general law.

The next action: run Step 1 and Step 2 on every scribe already in use, including any AI features switched on inside the practice software.

Two documents carry most of this assessment into daily use. The AI scribe patient consent form gives you the patient information notice, the consult script and the consent record line from Step 6, with space for your own vendor's retention and data-location answers from Steps 2 and 5. The AI acceptable use policy records the permitted tools, the named responsible person, the note-review rule and the incident category from Step 8, so contractor and employed clinicians work to one rule. The AI Scribe Governance Pack turns these eight steps into a fill-in assessment record for each scribe, alongside the vendor questionnaire, the register and the F11 evidence map this guide's table points to.

Frequently asked questions

How do I assess an AI scribe for privacy compliance?

Work through eight steps: check the TGA's device test and search the ARTG; map where the audio, transcript and note go; read the training terms; apply APP 8 and the state transfer rules; set retention; write the consent process; fix the contract; and update your privacy policy, collection notice, AI policy, PIA and training. Keep a dated file of evidence as you go.

Is our AI scribe a medical device?

No, unless it analyses or interprets the conversation, for example by generating a diagnosis or treatment recommendation the practitioner did not state. If it does, it must be in the ARTG before supply in Australia. Search the ARTG by the manufacturer's name, and recheck after every update.

Can an AI scribe store patient data overseas?

Yes, if APP 8 is satisfied, but under section 16C the practice answers for the overseas recipient's conduct. The ACSQHC expects Australian storage unless the patient explicitly consents to offshore management, and in NSW, HPP 14 also restricts interstate transfer, so hosting in another state needs an exception too.

Do we need a privacy impact assessment for an AI scribe?

Not mandatory for a private practice. The OAIC recommends one as part of privacy by design, and the ACSQHC says to consider one. Victorian public health services must complete a PIA before implementing a scribe, but that rule binds public services, not private practices.

Who notifies patients if the scribe vendor has a data breach?

One notification discharges the others. Where a breach affects multiple entities, one entity completing the assessment duty (s 26WJ) and notification duty (s 26WM) means the others do not have to. The OAIC says the entity with the most direct relationship with the affected individuals should notify, usually the practice.

Should we sign a vendor's indemnity clause?

Ask your insurer first. Avant states that its own Practitioner Indemnity Insurance Policy will not cover liability taken on under a contract beyond the general law, and recommends advice before agreeing to an indemnity clause. ACRRM says the same: do not assume liability in any vendor agreement.

Can a doctor at our practice use their own AI scribe?

Only if the practice's policy permits it. The RACGP tells owners to set out which scribes are permitted and inform all tenant GPs and staff, and F11 says the practice remains responsible for third-party tools regardless. A clinician's personal subscription does not shift that responsibility.

Do we have to label AI-drafted notes?

No body requires it by law. The ACSQHC says to label records where AI was involved, ACRRM treats a statement as optional, and the RACGP is silent. Decide one rule, write it into the scribe policy, and apply it consistently.

Last reviewed

30-day free trial

Be the practice the assessor compliments.

Choose your frameworks and work through the checklist. Walk into your next visit with your evidence linked and current, and nothing left to chase.

No credit card required
Australian data residency (Sydney)
Cancel anytime