Healthcare AI & Medical Scribes

Abridge

High risk

Enterprise ambient clinical documentation platform, deeply integrated with Epic, that records clinician-patient conversations and generates structured notes.

Verified 2026-08-31Abridge AIwww.abridge.com

Is Abridge safe for confidential data?

Abridge's vendor-side posture is strong — enterprise-only contracting, SOC 2 Type 2, HIPAA-compliant US data centers, encryption throughout — but the live risk is patient consent at the point of care. A proposed class action filed in November 2025 (Saucedo v. Sharp HealthCare, San Diego County Superior Court) alleges that visits at a Sharp medical group were recorded through Abridge without legally valid patient consent, raising California all-party wiretap and CMIA claims, and further alleges that notes incorrectly recorded that patients had consented; plaintiff's counsel estimate roughly 100,000 encounters are at issue. The allegations are unproven, and they target the deployment as much as the vendor — but they make clear that a signed BAA does not answer the consent question, and that consent workflow design is where ambient-scribe risk now concentrates.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Enterprise (only tier)
Not verified

Sold to health systems under negotiated contracts, typically embedded in Epic workflows. No self-serve or free tier, so shadow adoption is unlikely — the risk sits in deployment decisions, especially consent.

Data handling

Training on inputs

Governed by enterprise contract; Abridge's public materials describe enterprise-grade, HIPAA-compliant handling. Health systems should confirm training and product-improvement rights in their own agreement.

Retention

Contractually defined per health system; recordings and transcripts are processed within Abridge's HIPAA-secure environment. Confirm audio retention windows in your agreement.

Residency

Data is stored and processed in HIPAA-secure, US-based data centers. No published Canadian residency option, which is a gap for PHIPA-governed deployments.

Compliance

  • SOC 2Yes
  • GDPR / DPANot verified
  • HIPAA BAAYes

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • Enterprise-only contracting with BAA
  • Epic-integrated deployment and access control
  • 256-bit encryption in transit and at rest
  • SOC 2 Type 2 report via trust center
  • Negotiated retention and security terms

Frequently asked questions

Is Abridge HIPAA compliant?

Yes — Abridge operates as a business associate under enterprise contracts, holds a SOC 2 Type 2 report, and stores data in HIPAA-secure US data centers. HIPAA compliance is not the open question for Abridge; recording consent under state wiretap laws and provincial health privacy statutes is, and that obligation belongs to the deploying health system.

What is the Abridge patient-consent lawsuit about?

A proposed class action filed November 26, 2025 in San Diego County Superior Court (Saucedo v. Sharp HealthCare) alleges that a patient's visit at Sharp Rees-Stealy was recorded through Abridge's ambient AI without his knowledge, in violation of California's all-party consent wiretap law and the Confidentiality of Medical Information Act. The complaint also alleges notes were auto-populated with statements that patients had consented when they had not. The allegations have not been proven, and similar suits have since been filed against other California systems using ambient AI.

We are deploying an ambient scribe — what should we take from this?

Treat consent as a designed, documented workflow: verbal consent captured before recording starts, signage and intake disclosures, an opt-out path, and no boilerplate consent language inserted into notes automatically. And note that an enterprise scribe does not end shadow AI — clinicians without scribe access, or between systems, still paste patient details into free consumer tools, which is a separate exposure to govern.

Policy changelog

  • Initial entry published from Abridge's published security documentation and cited coverage.

Abridge is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles