Ambient AI Scribes: Building the Patient Consent and Post-Visit Review File

Dianne Bourque
Dianne Bourque
Holland & Knight (Boston)

Ms. Bourque advises healthcare clients on data acquisition and use in artificial intelligence algorithm training, research, product development, and digital health applications, and counsels providers on HIPAA, 42 C.F.R. Part 2, and state medical privacy law compliance, including review of HIPAA-related contracts and forms and privacy-related due diligence.

William F. Farley
William F. Farley
Holland & Knight (Chicago)

Mr. Farley's data privacy practice includes defending consumer-facing clients in class actions involving website wiretap litigation under federal and state law, including claims under the Video Privacy Protection Act and the Illinois Biometric Information Privacy Act (BIPA), and he advises clients nationwide on data privacy compliance and on responding to data breaches and other security incidents.

Live Video-Broadcast: October 30, 2026

2 hour CLE

Tuition: $195.00
Subscribe to Federal Bar Association CLE Pass...
Co-Sponsored by myLawCLE
Get this course, plus over 1,000+ of live webinars.
Learn More
Training 5 or more people?

Sign-up for a law firm subscription plan and each attorney in the firm receives free access to all CLE Programs

Program Summary

 

Your AI Scribe Is Already a Witness in the Exam Room

Ambient AI scribes now sit inside the exam room, continuously listening, transcribing and structuring what a patient says — work that used to stop at a human note-taker's discretion. Hospitals, health systems and medical practices are deploying these tools faster than their consent forms, retention schedules and vendor contracts can keep pace.

Skip a required all-party consent disclosure, and a recorded encounter becomes an unauthorized recording. Leave HIPAA and state medical privacy authorizations unaddressed, and an AI transcript becomes an unauthorized disclosure. Sign a vendor's standard business associate agreement without AI-specific data-use terms, and the practice inherits the vendor's data-handling risk. Skip post-visit accuracy review, and an AI-generated error becomes part of the legal medical record.

Attendees walk out with a defensible documentation framework: patient-facing consent language, a pre-implementation compliance checklist, contract language for AI-specific vendor terms beyond the standard BAA, and a post-visit review and retention protocol counsel can hand a client the same day.

Key topics to be discussed:

  • HIPAA & Privacy Compliance
    How to apply HIPAA, state medical privacy law, and emerging litigation and regulatory developments to what you capture, transcribe, and store from an ambient AI-recorded encounter.
  • Consent & Disclosure Design
    How to draft patient-facing disclosures and all-party consent documentation that create a defensible compliance record before an ambient AI scribe goes live.
  • Recordings & Data Handling
    How to handle recordings, transcripts, and other patient information an AI-enabled tool creates during the encounter.
  • Risk & Documentation Review
    How to structure post-visit accuracy review and evaluate the privacy, regulatory, and clinical-record risk an AI-generated note creates once it becomes part of the chart.
  • Retention & Governance
    How to set retention and governance rules for AI-generated notes, audio recordings, transcripts, and the underlying data behind them.
  • Vendor Contracts & Audits
    How to negotiate AI-specific vendor terms beyond the standard BAA, assess a vendor's data practices, and audit existing AI vendor arrangements for compliance gaps.

This course is co-sponsored with myLawCLE.

Date / Time: October 30, 2026

  • 12:00 pm – 2:10 pm Eastern
  • 11:00 am – 1:10 pm Central
  • 10:00 am – 12:10 pm Mountain
  • 9:00 am – 11:10 am Pacific

Closed-captioning available

Speakers

Dianne Bourque, Partner | Holland & Knight (Boston)

Ms. Bourque advises healthcare clients on data acquisition and use in artificial intelligence algorithm training, research, product development, and digital health applications, and counsels providers on HIPAA, 42 C.F.R. Part 2, and state medical privacy law compliance, including review of HIPAA-related contracts and forms and privacy-related due diligence. A substantial part of her practice involves counseling researchers and research sponsors on FDA- and OHRP-regulated clinical research, including patient consent, and she has served as counsel to a hospital’s Institutional Review Board and Ethics Committee overseeing those consent processes. She was formerly in-house counsel to an academic medical center and is the first Suffolk University Law School graduate to hold a concentration in Health and Biomedical Law.

  • Education & Credentials

Suffolk University, MPA; Suffolk University Law School, J.D. (first Suffolk Law graduate with a concentration in Health and Biomedical Law); Boston College, B.A. Admitted to practice in Massachusetts.

  • Recognition & Leadership

Named in The Best Lawyers in America guide for Health Care Law, 2020–2027, and in the Chambers USA – America’s Leading Business Lawyers guide for Massachusetts Healthcare, 2015–2017 and 2021–2026. Recognized as a Client Service All-Star by the BTI Consulting Group in 2022.

  • Professional Involvement

Member, American Healthcare Lawyers Association, 2005–2025. Former adjunct professor at Stonehill College, teaching an undergraduate course on healthcare law, and a guest lecturer in the Boston College MS in Cybersecurity, Policy and Governance program and at Boston University Law School.

  • Experience

Advised a national clinical lab on incident response and mitigation following a data breach affecting 12 million individuals, avoiding OCR enforcement, and represented a publicly traded precision medicine company in parallel OCR investigations opened by two regional OCR offices after back-to-back large-scale breaches, avoiding enforcement in both. Advised a national telehealth provider on the structure and implementation of its HIPAA compliance program and counseled a national provider of digital health products for oral care in a dispute with an overseas business associate vendor over the return of HIPAA-protected patient records. Provided regulatory and strategic advice, including data acquisition for algorithm training, to the developer of an AI-supported, hand-held medical imaging device and software platform. Served as counsel to the Institutional Review Board of a Massachusetts academic medical center and community hospital system, represented a national high-complexity genetic testing laboratory in structuring a collaborative data repository for testing and clinical outcomes data, and assisted a manufacturer of smart, wireless prescription bottles with structuring its patient interface consistent with privacy and data security law.

 

William F. Farley, Partner | Holland & Knight (Chicago)

Mr. Farley’s data privacy practice includes defending consumer-facing clients in class actions involving website wiretap litigation under federal and state law, including claims under the Video Privacy Protection Act and the Illinois Biometric Information Privacy Act (BIPA), and he advises clients nationwide on data privacy compliance and on responding to data breaches and other security incidents. He is an International Association of Privacy Professionals Certified Information Privacy Professional for the U.S. private sector (CIPP/US) and has used artificial intelligence and automation technology to organize, evaluate, and defend large volumes of claims, and advises clients on legal issues involving the metaverse. His client industries include healthcare and life sciences, banking and financial services, insurance, and technology.

  • Education & Credentials

Loyola University Chicago School of Law, J.D.; University of Michigan, B.A., Political Science. Admitted to practice in Illinois, and before the U.S. District Courts for the Northern District of Indiana, the Southern District of Illinois, and the Northern District of Illinois, and the U.S. Tax Court.

  • Recognition & Leadership

Named a Holland & Knight Emerging Leader, Class of 2020, and selected for the Chicago Bar Association Leadership Institute’s Inaugural Class, 2016.

  • Professional Involvement

International Association of Privacy Professionals, CIPP/US, since 2020; member, Chicago Bar Association. Contributing author, Annals of Health Law, The Health Policy and Law Review of Loyola University Chicago. Maintains an active pro bono practice.

  • Experience

Represented numerous consumer-facing clients defending class actions alleging invasion of privacy and violation of federal and state wiretap law arising from website recording, analytics tools, cookies, and pixels, and represented multiple Illinois employers defending BIPA class actions. Defended clients against claims that consumer website activity was recorded through session-replay software in violation of a state wiretap act, and advises clients on privacy policy and website functionality for compliance with state wiretap laws nationwide. Advises clients in the aftermath of data breaches and other security incidents, including remediation, investigation, and required notifications. Also represents clients in general commercial disputes, including supply chain, trade secret, and breach-of-contract matters, and is an experienced appellate lawyer before state and federal courts.

Agenda

SESSION 1 – Building the Patient Consent and Privacy Framework for Ambient AI Scribes | 12:00pm – 1:00pm

This session examines the privacy, consent, and regulatory considerations healthcare providers should address before deploying ambient AI scribing technology. It will cover HIPAA, state medical privacy laws, all-party consent requirements, and emerging legal developments affecting the recording, transcription, storage, and use of patient encounters. The session will also address how providers can develop patient-facing disclosures and consent documentation that create a defensible compliance record.

BREAK | 1:00pm – 1:10pm

SESSION 2 – Building the Post-Visit Review, Record Retention and Vendor Risk File | 1:10pm – 2:10pm

This session focuses on the documentation and risk-management framework that should remain in place after an ambient AI scribe is activated. It will examine post-visit accuracy review, the treatment and retention of AI-generated notes and underlying data, and the contractual protections healthcare providers should seek from technology vendors. The discussion will also address how counsel can identify and mitigate privacy, clinical documentation, and regulatory risks associated with AI-generated patient records.

Credits

Alaska

Approved for CLE Credits
2 General

Our programs are CLE-eligible through Alaska’s recognition of multi-jurisdictional reciprocity.
Alabama

Pending CLE Approval
2 General

Arkansas

Approved for CLE Credits
2 General

Arizona

Approved for CLE Credits
2 General

California

Approved for CLE Credits
2 General

Colorado

Pending CLE Approval
2 General

Connecticut

Approved for CLE Credits
2 General

District of Columbia

No MCLE Required
2 CLE Hour(s)

Delaware

Pending CLE Approval
2 General

Florida

Pending CLE Approval
2 General

Georgia

Pending CLE Approval
2 General

Hawaii

Approved for CLE Credits
2 General

Iowa

Pending CLE Approval
2 General

Idaho

Pending CLE Approval
2 General

Illinois

Pending CLE Approval
2 General

Indiana

Pending CLE Approval
2 General

Kansas

Pending CLE Approval
2 Substantive

Kentucky

Pending CLE Approval
2 General

Louisiana

Pending CLE Approval
2 General

Massachusetts

No MCLE Required
2 CLE Hour(s)

Maryland

No MCLE Required
2 CLE Hour(s)

Maine

Pending CLE Approval
2 General

Michigan

No MCLE Required
2 CLE Hour(s)

Minnesota

Pending CLE Approval
2 General

Missouri

Approved for CLE Credits
2.4 General

Mississippi

Pending CLE Approval
2 General

Montana

Pending CLE Approval
2 General

North Carolina

Pending CLE Approval
2 General

North Dakota

Approved for CLE Credits
2 General

Our programs are CLE-eligible through North Dakota’s recognition of multi-jurisdictional reciprocity. Section 1, Policy 1.14
Nebraska

Pending CLE Approval
2 General

myLawCLE reports attendance to Nebraska on each attorney’s behalf for all programs. Please do not self-report.
New Hampshire

Approved for CLE Credits
120 General minutes

As of July 1, 2014, the NHMCLE Board no longer provides pre- or post-approval of courses. Attendees must self-determine whether a program is eligible for credit, and self-report their attendance online at www.nhbar.org, based on qualification provisions of Rule 53.
New Jersey

Approved for CLE Credits
2 General

Our programs are CLE-eligible through New Jersey’s recognition of multi-jurisdictional reciprocity, except for the courses required under BCLE Reg. 201:2
New Mexico

Approved for CLE Credits
2 General

Nevada

Pending CLE Approval
2 General

New York

Approved for CLE Credits
2 General

Our programs are CLE-eligible through New York’s Approved Jurisdiction Group “B”.
Ohio

Pending CLE Approval
2 General

Oklahoma

Pending CLE Approval
2.5 General

Oregon

Pending CLE Approval
2 General

Pennsylvania

Approved for CLE Credits
2 General

Rhode Island

Pending CLE Approval
2.5 General

South Carolina

Pending CLE Approval
2 General

South Dakota

No MCLE Required
2 CLE Hour(s)

Tennessee

Pending CLE Approval
2 General

Texas

Approved for CLE Credits
2 General

Utah

Pending CLE Approval
2 General

Virginia

Not Eligible
2 General Hours

Vermont

Approved for CLE Credits
2 General

Washington

Approved via Attorney Submission
2 Law & Legal Hours

Receive CLE credit in Washington via attorney submission.
Wisconsin

Pending CLE Approval
2 General

West Virginia

Pending CLE Approval
2.4 General

Wyoming

Pending CLE Approval
2 General

More CLE Webinars
Upcoming CLE Webinars
Managing Tariff and Trade Enforcement Risk in 2026
Managing Tariff and Trade Enforcement Risk in 2026 Mon, September 28, 2026
Live Webcast