Healthcare AI & Medical Scribes
OpenEvidence
High riskFree, ad-supported AI clinical question-answering tool that reportedly a majority of US physicians now use for point-of-care evidence lookups.
Is OpenEvidence safe for confidential data?
OpenEvidence is the canonical shadow-AI story in medicine: it spread clinician by clinician — NBC News reported that most US doctors now use it — while for its entire early growth period it was not HIPAA compliant, even as clinicians pasted real case details into it. The company announced full HIPAA compliance and a BAA for US covered entities only in April 2025, meaning use before that date involving patient identifiers happened outside any HIPAA framework. Since then some health systems (MaineHealth among them) still direct clinicians not to enter PHI, and the product remains free and ad-supported, which is itself a data-governance consideration. It is a genuinely useful evidence tool; the risk is that it is adopted individually, at no cost, with no compliance officer in the loop, and used with more patient detail than anyone approved.
Risk by plan
The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.
Free to verified clinicians and ad-supported; the company has said core OpenEvidence will always be free. There is no paid tier to upgrade to — governance has to come from policy, the BAA, and monitoring rather than from purchasing.
Data handling
Training on inputs
OpenEvidence does not prominently publish a blanket no-training commitment for user inputs; its announcement stresses that users must input PHI in accordance with the BAA. Treat training and secondary-use rights as unverified and ask directly before permitting PHI.
Retention
Conversations are private by default and persist in the user's account; users can share via email invitation or public link (the vendor recommends public links only for conversations without PHI). No published retention schedule for inputs.
Residency
US-hosted; the HIPAA framework and BAA are directed at US covered entities. No Canadian residency or PHIPA/PIPEDA positioning is published — Canadian clinicians using it with patient details have no stated framework at all.
Compliance
- SOC 2Not verified
- GDPR / DPANot verified
- HIPAA BAAYes
Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.
New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.
Enterprise controls
- BAA for US covered entities (since April 2025)
- Private-by-default conversations
- Clinician identity verification (NPI-based signup)
Frequently asked questions
Is OpenEvidence HIPAA compliant?
Since April 25, 2025, yes: OpenEvidence announced full HIPAA compliance and says US covered entities may input PHI in accordance with its Business Associate Agreement. Before that date it was not, despite already being in wide clinical use. Compliance also depends on the BAA actually applying to your organization's use — an individual doctor's personal account is not automatically covered by anything your organization signed.
Can I put patient information into OpenEvidence?
Only if your organization has decided you can. Even after the April 2025 HIPAA announcement, some health systems — MaineHealth, for example — instruct clinicians not to enter PHI into OpenEvidence because they are not satisfied with its overall safeguards, and the ad-supported model raises questions about data use that the published materials do not fully answer. The safe default is to strip identifiers: the clinical question rarely needs the name, DOB, or MRN.
Why is OpenEvidence called a shadow-AI problem if it is free and popular?
Because its adoption path bypasses every control: clinicians sign up individually with an NPI, for free, and start asking case questions the same day — no procurement, no security review, no BAA execution, no policy. NBC News reported most US physicians use it while few patients know. For a practice, the exposure is not the tool's quality; it is that patient details flow to a third party under terms nobody in the organization has read.
Policy changelog
- Initial entry published from OpenEvidence's published announcements and cited coverage.
Sources
- OpenEvidence HIPAA compliance announcement (April 2025)
- NBC News: Most US doctors are quietly using this AI tool
- Paubox: Is OpenEvidence HIPAA compliant? (2026 update)
This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.
OpenEvidence is probably already in your organization.
Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.
More AI tool profiles
Enterprise ambient clinical documentation platform, deeply integrated with Epic, that records clinician-patient conversations and generates structured notes.
Free AI writing and clinical-answer assistant (renamed from Doximity GPT to Doximity Ask) bundled into the professional network used by a large majority of US physicians.
Self-serve ambient AI medical scribe that listens to patient visits and drafts clinical notes, aimed at solo clinicians and small practices.
AI medical scribe with a free tier, built by an Australian company and marketed to clinicians in the US, Canada, the UK, and Australia.