AI-assisted documentation is most useful when it handles structure and first-draft language while the clinician retains judgment. That distinction matters because a therapy note is not simply a summary of a conversation. It is a clinical record used for continuity of care, treatment planning, billing, audits, client access requests, and sometimes legal proceedings.
The practical question is therefore not only “Can this model write clearly?” It is “Can my practice use this workflow with appropriate privacy safeguards, informed choices, accurate documentation, and meaningful review?”
What AI can—and cannot—do in a therapy note
A purpose-built tool can organize supplied information into SOAP, DAP, BIRP, GIRP, intake, or treatment-plan sections. It can remind a clinician to distinguish client report from observation, connect an intervention to a treatment goal, and turn fragmented dictation into a readable draft.
Those are language and organization tasks. They are not the same as clinical judgment.
AI cannot independently establish that a reported fact is true, determine that an intervention actually occurred, or know that a risk question was asked unless that evidence is present in the input. A fluent sentence may still be inaccurate. A system can also omit an important qualifier, overstate progress, or turn uncertainty into a definitive conclusion.
The safest division of labor is:
| AI may assist with | The clinician must own | | --------------------------------- | ------------------------------------------------- | | Organizing supplied facts | Choosing what is clinically relevant | | Drafting section language | Verifying facts and attribution | | Applying a selected format | Assessing risk and responding appropriately | | Improving clarity and concision | Diagnostic formulation and clinical decisions | | Flagging a possible missing field | Determining whether the field was assessed | | Producing an editable first draft | Final review, correction, authentication, and use |
This boundary also explains why a generic chatbot is not interchangeable with a clinical documentation service. The quality of a note matters, but so do the contract, data flow, access controls, retention rules, and behavior of downstream vendors.
Progress notes are not the same as psychotherapy notes
HIPAA uses “psychotherapy notes” as a specific term. The U.S. Department of Health and Human Services describes them as notes created by a mental health professional that document or analyze the contents of a counseling conversation, are kept separate from the medical record, and receive special protections.
HHS also explains that psychotherapy notes do not include summaries of diagnosis, functional status, treatment plan, symptoms, prognosis, or progress to date. Those elements commonly appear in the clinical record. See the HHS explanation of mental-health information and psychotherapy notes.
That difference matters when designing an AI workflow. A clinician should know which type of information is being created, where it will be stored, who can access it, and whether the practice intentionally keeps any separate process notes. Do not assume that calling a document a “therapy note” determines its legal category.
HHS further states that, with limited exceptions, individuals may access information in designated record sets, including clinical case notes and SOAP notes, while separately maintained psychotherapy notes are treated differently. See HHS guidance on the individual right of access.
A respectful drafting rule follows from this: write progress notes with the expectation that they may be read by the client and other authorized parties. Include what supports treatment, continuity, and requirements; avoid unnecessary intimate detail that does not serve the record’s purpose.
The HIPAA questions to ask before using an AI tool
“HIPAA compliant” is not a magic product label, and no software purchase makes a practice compliant by itself. Compliance depends on the roles of the parties, the actual data flow, contracts, safeguards, policies, workforce behavior, and risk management.
Before protected health information enters an AI documentation workflow, ask these questions.
1. Will the vendor sign a Business Associate Agreement?
When a cloud service creates, receives, maintains, or transmits electronic protected health information on behalf of a covered entity, HHS says the parties generally must enter a HIPAA-compliant Business Associate Agreement. This remains true even when the cloud provider stores only encrypted ePHI and does not hold the encryption key. Read the HHS cloud-computing guidance.
A BAA should not be treated as a badge. Review which service is covered, the permitted uses and disclosures, safeguard obligations, breach responsibilities, subcontractor requirements, and what happens to PHI at termination. HHS provides sample BAA provisions and an explanation of required concepts.
2. What information is collected, and is all of it necessary?
Map every input and output: live audio, uploaded audio, transcript, typed summary, identifiers, generated note, analytics, error logs, and backups. Ask whether each item is required to produce the note.
The HIPAA minimum-necessary standard generally requires reasonable efforts to limit certain uses, disclosures, and requests for PHI to what is needed for the purpose. Its application is context dependent, including exceptions, so practices should interpret it with appropriate compliance guidance. The underlying principle is still useful when designing a documentation workflow: do not collect more sensitive data merely because a form permits it. See HHS guidance on the minimum-necessary requirement.
3. How long are audio, transcripts, and drafts retained?
“Deleted” can mean removed from the main interface, queued for deletion, retained in backups, or preserved for a contractual period. Ask for the written policy for each data type and whether the practice can choose a shorter period.
Also ask what happens when an account is closed, a client requests amendment, or the practice needs an export. A usable retention answer is specific enough to inform your own policy.
4. Is client data used to train or improve models?
Ask separately about model training, product improvement, human review, quality assurance, and de-identified or aggregated use. These are not automatically the same activity. The answer should appear in the applicable contract or policy, not only in sales copy.
5. Which subprocessors receive data?
An AI documentation product may rely on hosting, transcription, language-model, monitoring, email, or support vendors. Identify which subprocessors can receive PHI, where processing occurs, and how the primary vendor binds them to appropriate obligations.
6. Which security controls are available to the practice?
Review encryption in transit and at rest, role-based access, multi-factor authentication, audit logs, session controls, deletion tools, incident response, and team permissions. Then configure them. A strong control left disabled does not protect the workflow.
Consent, recording, and practice policy
An AI note workflow may involve recording a session, dictating after the session, uploading existing audio, or typing a summary. These inputs create different privacy and consent considerations.
Recording laws vary by jurisdiction. Professional rules, organizational policy, payer terms, contracts, and client expectations may add requirements beyond HIPAA. A practice should decide—before the first use—whether recording is permitted, how consent is obtained and documented, how a refusal is handled, and which non-recording alternative is available.
Good consent is understandable. It explains what the tool does, what information is processed, whether audio is retained, who receives the information, what alternatives exist, and how the client can ask questions. A checkbox that hides these answers in a long policy is not a substitute for a thoughtful clinical conversation.
The practice also needs an operational policy for:
- approved tools and prohibited consumer tools;
- which data may be entered;
- who may access drafts and client records;
- how the clinician reviews and authenticates a note;
- what to do when a draft contains a serious error;
- how retention, deletion, access, and amendment requests are handled;
- how incidents are reported; and
- when the workflow must not be used.
A five-pass clinical review before signing
Reviewing an AI draft should be a defined task, not a quick glance at polished prose. A short, consistent sequence is more reliable.
Pass 1: factual accuracy and attribution
Confirm that every client report is attributed, every observation was actually observed, and every intervention was actually delivered. Remove invented quotes, dates, symptom frequencies, measures, or mental-status findings.
Pass 2: clinical meaning
Verify that the assessment is supported by the documented data. Check symptom severity, functional impact, treatment response, goal progress, barriers, and the rationale for the next plan. Preserve uncertainty where uncertainty exists.
Pass 3: risk and safety
Never accept a prefilled negative risk statement. Confirm what was asked, what was reported or observed, which protective factors were assessed, what level of risk was determined, and what action followed. If the draft missed an urgent issue, follow the practice’s safety procedure; editing the prose is not the primary response.
Pass 4: privacy and dignity
Remove unnecessary intimate detail, stigmatizing phrasing, speculation, and information about third parties that is not needed for care. Use neutral, behavioral language and consider how the note would read to the client.
Pass 5: requirements and continuity
Check the fields required by the setting, payer, license, and jurisdiction. Confirm that the plan is actionable and connected to the treatment goal. Then authenticate the final record according to policy.
A safer way to prompt a section
A weak prompt says, “Write the Assessment.” A stronger prompt defines evidence, scope, and boundaries:
Using only the documented client report and observations, write a concise clinical formulation that addresses symptom severity, functional impact, response to today’s intervention, progress toward the named treatment goal, and current barriers. Preserve uncertainty. Do not add a diagnosis, risk finding, or fact that was not assessed.
The same pattern works across formats:
- name the evidence that may be used;
- identify the documentation purpose;
- list the required elements;
- prohibit unsupported inference; and
- require clinician review.
You can see this pattern applied section by section in BeeThere’s free SOAP note template, DAP note template, and BIRP note template.
A practical decision framework
AI may be a reasonable fit when the practice has completed a privacy and security review, has an appropriate BAA where required, understands the data lifecycle, offers a consent process suitable for the workflow, trains users, and requires clinician review before a draft enters the record.
Pause when the vendor cannot clearly explain retention or subprocessors, refuses an appropriate BAA, makes ambiguous training claims, or encourages users to treat generated text as final. Also pause when the practice itself has no policy for consent, risk errors, access, deletion, or human review.
The goal is not automation at any cost. It is a documentation process that helps a clinician produce a timely, accurate, clinically useful record while preserving professional responsibility.