The clinician signs the note. The practice owns the system around it.
By Allison Sikorsky, DNP, PMHNP-BC
Founder & CEO, PMHScribe
The clinician who reviews and signs an AI-generated note remains professionally responsible for the accuracy and appropriateness of the documentation. But responsibility does not stop there.
When a behavioral health practice selects the platform, approves its uses, trains clinicians, and sets expectations for oversight, leadership is responsible for the conditions under which that note was created. The clinician owns the final note. The practice owns the workflow around it.
That distinction matters as AI becomes part of routine clinical work. In the American Medical
Association’s 2026 survey of nearly 1,700 physicians, 81% reported using AI professionally. Twenty-eight percent used it to document billing codes, medical charts, or visit notes. Although the survey was not specific to behavioral health, it reflects a broader shift: AI-assisted documentation is no longer an edge case.
The question for behavioral health leaders is no longer simply, Should we allow AI scribes?
It is: What must remain true when we do?
An AI scribe can listen, organize, and draft. It can spare a clinician from reconstructing an encounter after the patient has left and replace the blank screen with a useful starting point.
What it cannot do is assume professional responsibility for the record.
Before signing, the clinician must decide whether the note is accurate, clinically useful, appropriately limited, and faithful to the encounter. A fluent paragraph may contain an unsupported conclusion. A
complete-looking history may omit the change that shaped the treatment plan. A factually accurate summary may include a personal detail that does not belong in the medical record.
Signing is more than the last administrative step; it is the point at which the clinician accepts the documentation as their own.
That carries particular weight in behavioral health, where meaning often lies in the relationship between facts.
A medication remained unchanged, but why? Risk was assessed, but what changed since the last visit? A diagnosis was reconsidered, but which observation led to that decision?
AI can carry these elements into a draft. Only the clinician can determine whether the draft preserves the meaning of the encounter.
Telling providers to “review every note” is necessary. It is not a governance strategy.
Individual vigilance cannot make up for an unclear system. When every clinician is left to decide which encounters are appropriate, what review is sufficient, how to explain the technology to patients, and
when to report a concern, the practice has distributed uncertainty instead of managing it.
Healthcare organizations are increasingly treating responsible AI use as a patient-safety, quality, privacy, and governance issue, not simply a technology purchase. The Joint Commission and Coalition for Health
AI have published guidance addressing AI governance, patient privacy and transparency, data security,
quality monitoring, safety-event reporting, risk and bias assessment, and education. The AMA has also developed an eight-step framework for implementing, overseeing, and scaling AI in care settings.
These resources were created for healthcare organizations broadly, but the principle applies at any size, accountability must exist at both the note level and the system level.
A workable policy should answer six questions:
1. Which uses are approved?
Define the approved platform, who may use it, and where it fits. Can it be used for psychiatric
evaluations, medication management visits, therapy sessions, substance-use treatment, telehealth
encounters, or post-visit dictation?
The answer may differ by encounter. A routine follow-up does not carry the same documentation and privacy considerations as a psychotherapy session or an evaluation involving highly sensitive substance- use information. The policy does not need to anticipate every clinical situation, it does need to keep
clinicians from inventing the rules one patient at a time.
2. What must the clinician review before signing?
“Review the note” is too vague to create a shared standard. Depending on the encounter, a meaningful
review may cover:
• Patient identity and encounter details
• Symptoms, functional changes, and relevant history
• Medication names, doses, changes, adherence, and adverse effects
• Mental Status Examination findings
• Suicide, violence, and other risk-related documentation
• Diagnoses and changes in diagnostic thinking
• Clinical assessment and treatment rationale
• Follow-up instructions and plan
• Unsupported statements, omissions, and unnecessary sensitive detail
This should not become a second full documentation exercise. The aim is to direct attention to the
places where a polished error, omission, or missing rationale could matter most.
3. Where is the boundary between a draft and the medical record?
Teams need to know where AI-generated drafts are stored, who can access them, how long they are retained, and how finalized notes enter the EHR. They should also know whether the platform stores audio, transcripts, generated notes, or some combination of the three.
PMHScribe uses real-time speech-to-text and does not save audio recordings. The clinician reviews and edits the generated note before copying the final version into the EHR. That creates a deliberate point of human review before the documentation enters the chart.
Draft status and record-retention obligations can depend on how information is used, maintained, and
governed. Practices should define the workflow clearly and obtain guidance appropriate to their legal and compliance obligations rather than assuming every draft is treated the same way.
4. What will patients be told?
Patients should not have to infer why a device is listening during a mental health encounter.
Decide how clinicians will explain the tool, respond to questions or objections, and proceed when a patient is uncomfortable. Consent and disclosure requirements vary by jurisdiction, care setting, technology, and whether audio is recorded or processed in real time. Each practice should follow its policies and seek guidance appropriate to the states and populations it serves.
There is also a relational standard beyond minimum compliance. A clear explanation can reassure patients that the technology supports documentation, while the clinician remains responsible for both the care and the final note.
Transparency should feel like clinical respect, not a technical disclaimer.
5. How was the vendor evaluated?
A convincing note is not enough.
Vendor review should address how protected health information is handled, what data is retained, whether customer data is used to train models, how access is controlled, which safeguards are in place, and how incidents are reported. When a vendor meets the HIPAA definition of a business associate, HHS
requires an appropriate written business associate contract or other arrangement. Clinical fit deserves equal attention. Does the platform understand behavioral health note structures? Can clinicians separate what is necessary for the record from the larger story shared in a session? Does the workflow invite thoughtful review or passive acceptance? Is support available when the output is wrong?
Privacy, security, clinical quality, workflow, and accountability belong in the same purchasing decision.
6. What happens after implementation?
Approval is the beginning of oversight, not the end. Products change. Templates evolve. Teams develop shortcuts. A practice needs a way to monitor note quality, collect clinician feedback, review unexpected
outputs, refresh training, and respond to concerns.
Smaller organizations do not need a large committee. One clinical leader and one operational or privacy
lead may be enough. Together, they can review a limited sample of notes, identify recurring corrections,
ask where the workflow creates friction, and maintain a simple reporting process.
The NIST AI Risk Management Framework organizes this work around four functions: govern, map, measure, and manage. Responsible adoption is not a one-time vendor decision. It is an ongoing management practice.
Behavioral Health Needs a More Specific Standard
Generic AI governance can miss what makes psychiatric documentation different.
Behavioral health notes may contain trauma histories, family conflict, substance use, sexual history, identity, legal concerns, intrusive thoughts, and descriptions of risk. Some of this information is essential
to care. Some may be meaningful in the room but unnecessary in the record. Accurate capture is only
the first test. The final note must preserve what matters without turning a vulnerable conversation into
an indiscriminate transcript.
Clinical reasoning requires the same care. Psychiatric decisions are often made under uncertainty and
understood across time. A useful note does more than list symptoms and actions; it helps another
clinician understand why the plan made sense on that day.
Behavioral health AI governance should therefore protect four things:
• Accuracy: Does the note reflect the encounter?
• Proportionality: Does it include what the record needs without unnecessary sensitive detail?
• Reasoning: Does it preserve the thinking behind the assessment and plan?
• Authority: Did the clinician meaningfully review and control the final documentation?
These are not stylistic preferences, they are part of what makes a clinical record trustworthy.
What Does Good AI Scribe Governance Look Like in a Small Practice?
Good governance does not have to mean enterprise bureaucracy. For a small or mid-sized behavioral health practice, it can be a short, usable system:
1. Approve vetted platforms rather than allowing unreviewed tools.
2. Name a clinical owner and an operational or privacy owner.
3. Define approved uses, patient communication expectations, and the review required before
signing.
4. Document vendor privacy, security, retention, and Business Associate Agreement information.
5. Train clinicians on the workflow and the clinical review standard.
6. Create a simple way to report inaccurate, inappropriate, or concerning output.
7. Revisit performance and policy after significant product or workflow changes, and at regular intervals in between.
The measure of a policy is not how comprehensive it looks in a shared drive. It is whether a clinician knows what to do during an ordinary visit and whether leadership knows what to do when something
goes wrong.
The Next Phase of AI Documentation Is About Leadership
The early conversation about AI scribes focused on capability: Can the tool produce a useful note? Can it reduce after-hours charting? Can it fit into the clinical day? Those questions still matter. As adoption
grows, however, access to AI will become less important than the quality of the system around it.
Strong behavioral health practices will build workflows in which technology saves time, clinicians preserve judgment, patients understand what is happening, and leadership remains accountable for
how the system operates.
The clinician signs the note, the practice must protect what that signature means.
Who is responsible for an AI-generated clinical note?
The clinician who reviews and signs an AI-generated note remains professionally responsible for its
accuracy and appropriateness. The practice is responsible for selecting the tool, establishing policies,
training users, protecting patient information, and monitoring the workflow. Specific legal duties and
liability can vary by jurisdiction and circumstance.
What is AI scribe governance?
AI scribe governance is the system a healthcare organization uses to approve, oversee, and monitor AI-
assisted documentation. It covers approved uses, clinical review, patient communication, privacy and
security, vendor evaluation, training, quality monitoring, and incident response.
What should clinicians check before signing an AI-generated note?
Clinicians should confirm that the note reflects the encounter, correctly documents medications and
risk, preserves the clinical assessment and treatment rationale, includes relevant changes, omits
unsupported information, and avoids unnecessary sensitive detail.
Does an AI-generated draft automatically become part of the medical record?
Not necessarily. Its status may depend on how the draft is used, maintained, and governed. Practices
should define where drafts are stored, who can access them, how long they are retained, how they
move into the EHR, and which legal or organizational record requirements apply.
Does a behavioral health practice need a Business Associate Agreement for an AI scribe?
When an AI scribe vendor creates, receives, maintains, or transmits protected health information on
behalf of a HIPAA-covered entity and meets the definition of a business associate, an appropriate
Business Associate Agreement is generally required. Practices should evaluate the specific service and
seek legal or compliance guidance for their circumstances.
How often should a practice review its AI scribe policy?
Review the policy at regular intervals and whenever the platform, data practices, clinical workflow, applicable requirements, or approved encounter types change. A safety, privacy, or documentation
concern should also trigger review.
Allison Sikorsky, DNP, PMHNP-BC, is the Founder and CEO of PMHScribe and a board-certified
Psychiatric Mental Health Nurse Practitioner. Her career spans clinical practice, telepsychiatry,
healthcare leadership, medical documentation, and behavioral health technology.
She founded PMHScribe after experiencing documentation burden firsthand and focuses on helping
psychiatrists, PMHNPs, therapists, and behavioral health organizations use AI responsibly while
preserving clinician oversight, thoughtful documentation, and human connection.
Learn how PMHScribe works or explore AI-assisted documentation for behavioral health practices.
This article is intended for educational purposes and reflects the author's professional perspective
together with current published guidance. It is not legal, compliance, billing, or medical advice.
• American Medical Association: More than 80% of physicians use AI professionally (2026 survey)
• American Medical Association: Governance for Augmented Intelligence
• The Joint Commission and Coalition for Health AI: Responsible Use of AI in Healthcare
• U.S. Department of Health and Human Services: Covered Entities and Business Associates
• National Institute of Standards and Technology: AI Risk Management Framework