Every AI feature in an EMR has the same underlying mechanic: chart content is sent somewhere, processed by a model, and a result comes back. For behavioral health organizations, where the records involved carry some of the most sensitive protected health information that exists, the important questions all live inside that word "somewhere."
The good news is that the questions are answerable, and vendors with sound architectures can answer them plainly. This post gives you the four questions, what strong answers sound like, and the follow-ups that separate a real data posture from a reassuring paragraph.
The four questions
1. Who processes the data?
AI features in most EMRs are built on models operated by a model provider, accessed through an API. You are entitled to know the shape of that arrangement: the EMR vendor is your business associate, and the parties processing your data downstream should be identifiable, not "our AI partners."
2. Under what agreement?
Processing of protected health information belongs under a business associate agreement chain, with the AI processing running through an enterprise-grade arrangement rather than consumer AI endpoints. A vendor who can name the agreement structure has thought about this. A vendor who answers with "it's secure" has given you a sentence, not an architecture.
3. What is retained, and for how long?
The strongest posture available is zero data retention at the model provider: content sent for processing is not stored by the provider and is not used to train models, and outputs return to your record under the same permissions and audit controls as everything else in the system. Whatever the vendor's answer, get it in writing, and note the difference between "we don't train on your data" and "the model provider retains nothing." Those are two different claims; you want clarity on both.
4. Where does the output land?
AI output should enter your record only through your workflows: clinician review and approval, the same role-based permissions, the same audit trail. If output can bypass the controls that govern every other entry in the chart, the AI feature has quietly created a second, weaker front door to your record.
Follow-ups that reveal depth
Once the four headline answers are on the table, three follow-ups test them:
- Does the posture differ by feature? Ambient scribing, note drafting, chart summarization, and reporting may route differently. Ask whether the retention and agreement answers cover every AI feature or only some.
- What do we control? Can your organization adopt AI features selectively, and can processing be scoped by program? Sensitivity is not uniform across a treatment organization, and controls should not be either.
- What would we show an auditor? If your compliance officer needed to document how AI processing works for a security review, what artifacts exist? A vendor with real answers has a document ready. This is also a good moment to loop in your own security and compliance stakeholders, because AI processing belongs in your risk assessment like any other data flow.
Questions your clients may ask you
One more reason to have crisp answers: your clients increasingly ask their own version of these questions, especially where session recording is involved. "Is this being recorded, and where does it go?" deserves an answer a clinician can give in one sentence. Organizations that choose their AI posture deliberately, feature by feature, can give that answer. Organizations that enabled a bundle cannot.
It is also worth knowing that AI adoption does not require recording at all: review, summarization, and drafting from existing chart content operate with no audio involved, which changes the client conversation entirely.
What strong looks like, in one paragraph
A vendor with a sound posture can say something like: AI features run through an enterprise API under a business associate agreement, using a zero-data-retention arrangement where content sent for processing is not stored by the model provider or used for training, and all output returns to the record through clinician review, under the same permissions and audit controls as everything else. Every clause in that sentence is checkable. Ask for it in writing, and ask your counsel to review what comes back.
