AI documentation for licensed therapists: what is allowed, what is risky
A practical look at where AI can support clinical documentation, where it introduces real compliance exposure, and the questions to ask any vendor before client information touches their system.
AI note-taking arrived in behavioral health faster than most practices could evaluate it. The appeal is obvious: documentation is the largest non-billable time cost in a clinical week. The exposure is equally real, because clinical notes are among the most sensitive records that exist.
This guide is a practical framing, not legal advice. Every practice should confirm its own obligations with counsel and with its licensing board.
Where AI genuinely helps
The safest wins are the ones that never require the tool to make a clinical judgment.
- Structuring what you already wrote. Turning your own shorthand into a formatted note.
- Drafting from your dictation. You speak the note, the tool formats it, you edit and sign.
- Surfacing continuity. Reminding you what was open at the end of the previous session.
- Between-session summaries the client shares deliberately. Client-owned evidence, brought into the room by the client.
In each case the clinician remains the author. The tool reduces typing, not responsibility.
Where the risk concentrates
Risk rises sharply at three boundaries.
- 1.Ambient session recording. Capturing full audio of a session creates a new, highly sensitive record that must be disclosed, consented to, retained, and eventually destroyed under policy. Consent must be specific and documented, and in many jurisdictions all parties must agree.
- 2.Model training on client content. If a vendor may use your inputs to improve its models, client material has left your control in a way you cannot reverse.
- 3.Anything resembling diagnosis or risk prediction. Tools that suggest diagnoses or flag risk levels can create a documentation trail you did not intend and cannot fully explain.
If the note would be uncomfortable to read aloud in a records request, the tooling around it deserves the same scrutiny as the note itself.
Questions to ask before a vendor touches client data
Bring these to the vendor in writing.
- Will you sign a Business Associate Agreement, and what does it exclude?
- Is client content ever used to train or evaluate models, including in aggregate or de-identified form?
- Where is data stored and processed, and which subprocessors have access?
- What is the retention default, and can it be shortened or set to zero?
- Can a client's record be fully deleted on request, including from backups, and on what timeline?
- Is access audit logged, and can I export those logs?
- What happens to my data if the company is acquired or shuts down?
A vendor that cannot answer the training and retention questions plainly is answering them.
Consumer health data laws changed the calculus
Practices often assume HIPAA is the only relevant regime. Consumer health privacy laws, including Washington's My Health My Data Act and similar state statutes, extend protections to health-related data held by entities that are not covered providers. That matters when a client uses a consumer app and then shares its output with you, or when a practice adopts a tool that is not a covered entity or business associate.
The practical implication: the client-facing tool and the clinical record now sit under different rules, and the boundary between them should be intentional rather than accidental.
A workable policy for a small practice
Most practices do not need a legal department. They need a written page that says:
- 1.Which AI tools are approved, and for what task.
- 2.What may never be entered: names, contact details, identifiers, verbatim disclosures.
- 3.Who reviews and signs every AI-assisted note before it enters the record.
- 4.How clients are informed, and where that disclosure is documented.
- 5.When the policy is reviewed, and by whom.
Where Numa fits
Numa is client-owned rather than clinician-owned. A client builds their own record of patterns from conversations they already have, and decides whether to bring it into a session. That keeps the sensitive material on the client's side of the line, and gives the practitioner context that arrived by consent instead of by surveillance.
Support for practitioner-facing workflows is on the roadmap, and it will ship with the agreements and controls this category requires rather than ahead of them.
Common questions
- Is AI note-taking HIPAA compliant?
- No tool is compliant on its own. Compliance depends on a signed Business Associate Agreement, how data is stored and retained, and how your practice uses it. Ask for the BAA in writing before entering any client information.
- Can I record sessions if the client agrees verbally?
- Treat verbal agreement as insufficient. Document specific written consent covering recording, storage, retention, and any third-party processing, and confirm your state's all-party consent rules.
- What about de-identified data used for model training?
- De-identification reduces but does not eliminate risk, and standards vary. If a vendor requires training rights on client content, assume that content is out of your control and decide accordingly.