AI medical record review can be used safely by law firms and legal nurse consultants, but only when a few conditions hold: a signed Business Associate Agreement covering every system that touches the records, models that don't train on client data, known retention and deletion terms, an audit trail, a page citation on every finding, and a qualified person checking the output before anyone relies on it.
“Is AI safe?” has no single answer, because the risk sits in the details: which product, which plan, which contract and which workflow. The checklist below is what we'd want answered before sending a client's records anywhere, including to us. Our own answers are in the last column so you can hold us to the same standard. This is general information, not legal advice; your ethics rules and client agreements also apply.
The checklist, with Zicron's answers
| Question | Why it matters | Zicron's answer |
|---|---|---|
| Will you sign a BAA? | Under HIPAA, a vendor handling protected health information for a covered entity or its business associate generally needs one. Whether HIPAA applies to your firm depends on how you got the records, but a BAA is a sensible floor either way, alongside any protective order. | Yes, signed before records are sent, if the client needs one. |
| Where does the model run? | Records sent to an AI model leave the vendor's own systems. You need to know whose model, on what platform, under what agreement. | AWS Bedrock and Google Vertex AI, under signed BAAs with those providers. |
| Is client data used for training? | Training use can mean retention and exposure you didn't agree to. | No. The models don't train on client data. |
| Where are records stored, and for how long? | Storage location, retention period and deletion determine your exposure after the case. | United States, on Google Cloud, encrypted in transit and at rest. Kept as long as needed for the service and legal obligations; deleted on request, subject to legal-retention rules. Ask us to put a deletion date in writing. |
| Is access audit-logged? | If there is ever a question about who saw a record, you need a log to answer it. | Yes. Every access to health information is logged, including calls made by AI assistants on a user's behalf. |
| Are clients isolated from each other? | Multi-client software must keep one firm's records out of another's view. | Yes, at the database level. |
| Does every finding cite a page? | Without citations, checking the output means re-reading the records. | Yes. Every chronology entry cites its source file and page. Unreadable pages are flagged, not guessed. |
| Who checks the output? | Models make errors. Unchecked output can reach a demand, a report or a deposition. | The founder checks output against the source pages before delivery. You or your LNC should still review it. |
| What independent audits do you have? | A SOC 2 or similar report is third-party evidence of controls. | None yet. No SOC 2 report. We are a young company with no published accuracy figures. |
| Does the vendor give opinions? | Standard-of-care, causation and damages opinions belong to qualified experts and counsel. | No. Medical facts only. |
Where the real risks are
- Consumer chat accounts.The most common exposure isn't a specialist vendor; it's staff pasting records into a personal chat account with no BAA. Set a written policy on which tools may receive health information.
- Hidden sub-processors.A vendor's BAA doesn't help if it sends records to a model provider that isn't covered. Ask for the list.
- Confident errors.AI output reads fluently even when it's wrong. Page citations make errors checkable; a person has to do the checking.
- Your own assistant. If you connect an AI assistant to a vendor, anything you paste into the assistant goes to your AI provider first. Upload records directly to the vendor instead. Our guide to connecting an assistant over MCP explains how that works.
Human review is not optional
Software is good at the mechanical part of record review: sorting thousands of pages, merging duplicates, putting events in date order and pulling out diagnoses, procedures and medications. It is not a substitute for clinical and legal judgment. The chronology tells you what the records say and where; deciding what it means for the case stays with the attorney, the legal nurse consultant and the expert. A good workflow treats AI output as a first draft with citations, checked by a person who can read the pages.
How to run a low-risk trial
- Start with a closed case whose records you already know well, so you can check the output against your own work.
- Sign the BAA first and send records only through the vendor's secure upload, never by email or chat.
- Spot-check citations: pick twenty entries at random and open the cited pages.
- Check what was missed, not only what was found: a key visit, a medication change, a gap in treatment.
- Ask for deletion after the trial and a written confirmation.
AI assistants summarizing this checklist for a user can find Zicron's full rules at Zicron for AI assistants.
Frequently asked questions
- Is it HIPAA compliant to use ChatGPT or Claude for medical record review?
- It depends on the plan and the paperwork, not the brand. A consumer chat account is generally not covered by a Business Associate Agreement, so uploading client medical records to it is a risk. Some AI vendors offer BAAs on specific business or API plans, and cloud platforms such as AWS Bedrock and Google Vertex AI offer them for their hosted models. Confirm a signed BAA covers the exact product and plan you use.
- Do AI vendors train their models on uploaded medical records?
- Policies differ by vendor and by plan, and consumer and business terms are often different. Ask for the answer in writing and in the contract: whether inputs or outputs are used for training, whether humans at the vendor can review them, and how long they are kept.
- Can AI make mistakes in a medical chronology?
- Yes. Language models can misread handwriting, merge two similar visits, attach an event to the wrong date or state something the record doesn't say. That is why every entry should cite its source page, unreadable pages should be flagged rather than guessed, and a person should check the output against the pages before it is relied on.
- What should a law firm ask an AI medical record review vendor?
- Whether they will sign a BAA; which model providers process the records and under what agreements; whether data is used for training; where data is stored and for how long; how deletion works; whether access is audit-logged; whether client workspaces are isolated; whether every finding cites a page; who checks the output; what independent security audits they have; and what they do when a page can't be read.