Most of what's been written on this site about AI and OT/SLT compliance covers who has to consent and which state's wiretap statute applies. Those questions matter, but they are not the ones that actually surface in an audit or a malpractice review. What gets checked then is narrower and more mechanical: does the audit log show who touched the record and when, does the consent form still exist and is it retrievable, and can you show that a licensed clinician, not a piece of software, reviewed the note before it counted as the official record. Those are documentation mechanics, not legal theory, and they are the six questions below.
1. My AI scribe says it logs activity. Does that satisfy HIPAA's audit control rule?
Not automatically. The HIPAA Security Rule's audit controls standard (45 CFR 164.312(b)) requires hardware, software, and procedural mechanisms that record and examine activity in any system containing electronic protected health information: who accessed a record, when, from where, and what changed. In plain terms, you need a log of who did what and you need to actually be able to review it. Many AI scribe tools log that a note exists and when it was created, but fewer surface who viewed it afterward, and fewer still distinguish what the AI generated from what the clinician edited before signing off, which is the distinction that actually matters if a note is ever questioned.
So what for you: before your next AI scribe renewal, ask the vendor directly whether the audit log separates AI-drafted text from your own edits and whether that log is exportable, not just whether "activity is logged" in general terms.
2. How long do I have to keep the consent form a patient signed before I started recording sessions?
Two different clocks apply here, and conflating them is a common, avoidable error. HIPAA's Security Rule sets a six-year retention requirement (45 CFR 164.316(b)(2)(i)), but that rule governs your practice's own compliance documentation: policies and procedures, business associate agreements, risk assessments, security incident logs. It is not a retention period for an individual patient's clinical record or the consent form tied to it. What actually controls that form is state medical record retention law, which varies by license and by state: commonly five to seven years for adult OT and SLT records, ten years in a handful of states (Georgia, Kansas, South Carolina, and Tennessee among them, per state-by-state retention compilations), and considerably longer for pediatric records, often until the patient reaches the age of majority plus several more years. These figures come from secondary compliance-guide compilations rather than a single federal register, so confirm your own state's statute and license-specific requirement directly before setting a retention policy.
So what for you: don't answer "how long do I keep this" with "HIPAA says six years." That six-year figure covers your policy documents. Your patient consent forms run on your state's clock, and pediatric records run longer than you probably assume.
3. If a Medicare reviewer asks me to prove I actually reviewed my AI-drafted note before signing it, what do I show them?
The same evidentiary standard Medicare already applies to a corrected paper chart. CMS's Program Integrity Manual and Medicare Administrative Contractor guidance (Noridian, current Jurisdiction E and F documentation-amendment rules) treat any late entry, addendum, or amendment to a medical record the same way: it must carry the current date and time, clearly reference the original entry, and be signed, and corrections made after a claim has already gone through medical review carry less weight than the original record. An AI-drafted note that moves from raw transcript to signed clinical note with no visible record of what you actually changed in between sits in the same gap. If your review and edits happen inside the AI vendor's own interface rather than your EHR's audit trail, ask whether that edit history exports with the note or stays locked inside the vendor's own system, because a reviewer can only see what actually reaches your record.
So what for you: treat your AI scribe's edit history the same way Medicare already treats a corrected paper chart: dated, attributable, and exportable into your own EHR, not a draft that only exists inside someone else's software.
4. Do I need a brand-new consent every time I turn on a new AI feature, or does my original form still cover it?
Treat a materially different use as needing fresh consent rather than assuming last year's signature still covers it. The clearest statutory example of this principle comes from Colorado's psychotherapy AI law (HB 26-1195, effective 12 August 2026), which defines consent as tied to a specific purpose and manner of use and requires new consent when that purpose changes materially, such as moving from ambient transcription alone to a feature that also drafts referral letters or flags risk indicators. That is a psychotherapy-specific statute and does not bind OT or SLT practices directly, but the underlying logic, that consent has to match what you actually disclosed, holds up as sound documentation practice regardless of your state or discipline.
So what for you: re-disclose and re-consent whenever you switch on a materially different AI capability. Don't stretch one signed form to cover a feature the patient never actually heard described.
5. My AI vendor's dashboard shows the consent timestamp. Is that enough, or does it need to live somewhere else too?
Keep a copy inside your own patient file, not solely inside the vendor's dashboard. Compliance guidance for AI scribe consent consistently makes this point: the signed consent form belongs in the patient's compliance file alongside your business associate agreement and any opt-out record, because a vendor's own dashboard is a system you do not control. It may not survive if you switch tools, the vendor changes its retention policy, or you need the record years after the vendor relationship has ended. The vendor's log is a convenience copy. Your own patient file is the system of record.
So what for you: export or otherwise duplicate the consent record into your own patient file the same day it is signed, rather than trusting a third-party dashboard as your only copy of it.
6. What actually gets flagged in an audit or malpractice review if none of this is in place?
Two separate things, and neither requires the AI to have made a clinical error to hurt you. Weak or missing audit controls are treated by HHS's Office for Civil Rights as an aggravating factor across published HIPAA enforcement actions, meaning a missing audit trail can turn a moderate finding into a worse one on its own (compiled from industry review of published OCR resolution agreements; confirm against a specific enforcement action before citing a precise figure). Separately, in a malpractice or licensing-board review, the absence of a clear record showing what the AI drafted versus what the clinician actually reviewed and changed undermines the basic defense that a licensed professional, not a piece of software, exercised clinical judgment on that note.
So what for you: the audit trail and the consent log are not paperwork for its own sake. They are the two things that prove a human, not a tool, is accountable for what is in the record.
If you want an outside read on whether your current AI scribe's audit trail and consent workflow would actually hold up under review, book a free 20-minute call. We'll walk through what your specific vendor exports against what your state and payer actually require.
The bottom line
None of this is a reason to slow down on using AI for documentation. It is a reason to stop treating the paperwork underneath the AI as an afterthought. Set your consent form's actual retention clock by your state and license, not by HIPAA's six-year policy rule. Confirm your AI scribe's audit log actually separates what the AI drafted from what you changed, and confirm that log exports into your own record rather than staying inside someone else's dashboard. Those three checks take an afternoon, and they are the difference between a documentation system that holds up under review and one that only looks like it does. For the state-by-state consent rules that apply before you ever hit record, see 13 states, and the patient can't consent. For the safeguarding duties that sit alongside consent for vulnerable caseloads, see AI HIPAA rule delayed to 2027. Safeguarding duty isn't. And for how OT's own documentation structure maps against these requirements, see OT's paperwork has 5 stages, not 1.
The Clinical AI Briefing
One practical AI insight for healthcare practices every week. No hype. Evidence and outcomes only.
Related: 13 states, and the patient can't consent · AI HIPAA rule delayed to 2027. Safeguarding duty isn't. · OT's paperwork has 5 stages, not 1
This article is for informational purposes only and does not constitute legal advice. Federal, state, and payer documentation requirements change frequently and vary by license and jurisdiction; confirm current requirements with legal counsel and your state licensing board before relying on anything above.