Using AI Scribes - How about Patient Consent?

Current as of July 17, 2026. If you’re evaluating or already rolling out an ambient AI scribe, patient consent needs to be part of that plan from day one — not a policy you write after go-live. Two pending California lawsuits — against Sutter Health and MemorialCare in federal court, and against Sharp HealthCare in San Diego Superior Court — show exactly what happens when a facility doesn’t have a real consent workflow: allegations that ambient AI scribes recorded patient exam-room conversations without adequate consent, triggering California’s Confidentiality of Medical Information Act (CMIA), its two-party consent wiretapping law (CIPA), and the federal Wiretap Act. Neither case has been decided, but the statutes underneath both suits set a concrete bar regardless of how the litigation ends: CIPA alone carries a $5,000-per-violation civil remedy with no requirement to prove actual harm, and that exposure applies to any "provider of health care" under California law — not just acute-care hospitals.
Next re-check dates: September 15, 2026 (after the Sutter motion-to-dismiss hearing) and November 1, 2026 (after the Sharp demurrer hearing).
Why patient consent belongs in your AI-scribe rollout plan, not an afterthought
An ambient AI scribe is a tool that listens to a clinical encounter and drafts the visit note automatically, without the clinician typing or dictating separately. If your facility is evaluating one of these tools, or already has a pilot underway, two pending lawsuits now show exactly what’s at stake if patient consent isn’t built into your workflow before go-live.
On July 13, 2026 — four days before this post’s research pass — Sutter Health filed two motions to dismiss the Washington v. Sutter Health case: one for failure to state a claim (Rule 12(b)(6)) and one challenging jurisdiction (Rule 12(b)(1)). A hearing is set for September 3, 2026; opposition briefs are due July 27, reply briefs August 3. Separately, in Saucedo v. Sharp HealthCare, the original demurrer and motion-to-strike hearing was vacated on May 15, 2026 and is now calendared alongside a case management conference for October 23, 2026. No answer has been filed in either case, and no ruling exists yet in either one.
That makes the September 3 hearing worth tracking if you want to see how these consent theories hold up at the pleading stage — but don’t wait for a ruling to decide whether your own consent process is solid. The underlying statutes are not contested, and they apply to your facility regardless of how the litigation comes out.
Two cautionary examples: what plaintiffs say went wrong
Washington et al. v. Sutter Health et al.
Filed April 8, 2026 in the U.S. District Court for the Northern District of California (docket 4:26-cv-03012, Judge Haywood S. Gilliam Jr.), the complaint names patients Christina Washington, Dennis Gueretta, and Rebecca Matulic against Sutter Health and Memorial Healthcare Services/MemorialCare Medical Foundation. It alleges the defendants deployed Abridge’s ambient AI scribe to capture, transmit, and process audio of clinical encounters — including symptoms, diagnoses, prescriptions, treatment plans, family medical history, and mental health information — without adequate patient consent. The causes of action pled are CMIA, CIPA, California’s Unfair Competition Law, the federal Wiretap Act, and common-law invasion of privacy.
Saucedo v. Sharp HealthCare
Filed November 26, 2025 in the Superior Court of California, County of San Diego (case 25CU063632C), plaintiff Jose Saucedo alleges that during a July 2025 exam at a Sharp Rees-Stealy clinic, a clinician used Abridge’s ambient AI scribe to record the visit via a microphone-enabled device without asking for or obtaining consent, that the audio was transmitted to a third-party vendor’s cloud, and that Sharp’s EHR system inserted boilerplate language stating patient consent had been obtained even though Sharp had no standardized workflow to obtain it. The claims pled are CIPA and CMIA. As alleged by the plaintiff — not yet established by any court — the suit seeks class certification covering more than 100,000 California patients.
Both cases remain pending and contested: every factual allegation above is alleged, not judicially found, and neither the motion to dismiss nor the demurrer has been ruled on as of this writing. But notice what’s actually being alleged — not a novel or freak failure, but the ordinary failure mode of rolling out AI tooling without a consent step designed into the workflow from the start, including, in Sharp’s case, an EHR system that reportedly inserted boilerplate language claiming consent had been obtained when no standardized process existed to obtain it. That specific failure mode is worth designing around before your own rollout, not after.
What patient consent needs to satisfy under California law before you go live
Cal. Civ. Code §56.10(a) is the first bar your consent process has to clear. It states, verbatim:
A provider of health care, health care service plan, or contractor shall not disclose medical information regarding a patient of the provider of health care or an enrollee or subscriber of a health care service plan without first obtaining an authorization, except as provided in subdivision (b) or (c).
Subdivision (b) covers disclosures that are mandatory without authorization (court orders, subpoenas, search warrants, and similar legally mandated disclosures); subdivision (c) covers disclosures that are permitted but not required (treatment/payment, peer review, licensing review, research, and similar purposes). On the facts alleged in either suit, none of these plainly cover an AI vendor receiving raw audio or transcripts absent a specific patient authorization — which is the gap your own consent process needs to close before a vendor ever receives audio from your facility.
§56.06 defines "provider of health care" more broadly than licensed clinicians and facilities: it deems a business that offers "software, hardware, or mobile applications designed to maintain medical information" for an individual’s own management or for diagnosis/treatment to be a "provider of health care" for CMIA purposes specifically. That’s the textually closest fit for treating an ambient-AI-scribe vendor itself as CMIA-covered — worth raising directly with your vendor’s legal team, though it is a textual reading of the statute, not a confirmed pleading theory in either case; neither complaint’s actual defendant list or CMIA theory on this specific point has been independently verified against the complaint’s full text.
Here’s what getting this wrong actually costs, and it doesn’t fall on the vendor alone: nominal damages of $1,000 for a negligent violation (no proof of actual harm required), plus actual damages where they exist; a knowing or willful violation additionally exposes the violator — potentially your facility — to an administrative fine of up to $25,000.
What California’s two-party consent law (CIPA) requires of your rollout
Cal. Penal Code §632 makes it a crime to record a confidential communication without the consent of every party to it. "Confidential communication" is defined, verbatim, as:
any communication carried on in circumstances as may reasonably indicate that any party to the communication desires it to be confined to the parties thereto, but excludes a communication made in a public gathering or in any legislative, judicial, executive, or administrative proceeding open to the public, or in any other circumstance in which the parties to the communication may reasonably expect that the communication may be overheard or recorded.
That definition is exactly why an exam-room or resident-room conversation — where a patient or resident has no reason to expect a third-party AI vendor is listening — is the fact pattern your consent process has to account for. Cal. Penal Code §637.2 gives a private civil right of action for the entire invasion-of-privacy chapter, and states, verbatim, that a plaintiff can recover:
Five thousand dollars ($5,000) per violation, or three times the amount of actual damages, if any, sustained by the plaintiff, whichever is greater — and it is not a necessary prerequisite to an action pursuant to this section that the plaintiff has suffered, or be threatened with, actual damages.
That $5,000-per-violation, no-actual-damages-required remedy is the number that should shape your rollout timeline: it’s what turned "100,000 patients recorded without a standardized consent workflow" (Sharp’s own alleged facts) into existential class-action exposure for one health system — and it would expose your facility the same way if your own workflow has the same gap.
Why the federal Wiretap Act matters for your rollout too
18 U.S.C. §2511(1)(a) makes it unlawful to "intentionally intercept… any wire, oral, or electronic communication." Standing alone, the federal Wiretap Act is a one-party consent statute — §2511(2)(d) states, verbatim, that interception is not unlawful where one party to the communication has consented, "unless such communication is intercepted for the purpose of committing any criminal or tortious act." That final clause is the "crime-tort exception": a clinician’s own consent to the recording doesn’t excuse the recording from federal liability if it was carried out to commit a separate criminal or tortious act.
Per legal-industry reporting on the Sutter/MemorialCare complaint — not independently confirmed against the complaint’s full text — the theory being pled is that the underlying CIPA or CMIA violation itself supplies the "tortious act" that defeats one-party consent and revives federal liability. The statute text itself is settled federal law, stated flatly above; how it applies to this specific complaint remains the plaintiffs’ pleaded theory, not a holding — no court has ruled that a CIPA violation supplies the tortious act here. The practical implication for your own rollout: a clinician’s awareness of the recording is not automatically enough to clear federal exposure if the underlying state-law violation is present.
Don’t let AB 2575 stand in for a consent policy
If your compliance team is already tracking AB 2575, don’t mistake it for your consent obligation — conflating the two is a real risk if you’re skimming trade coverage while planning a rollout. AB 2575 (Ortega) would require a health facility or practice using a "covered tool" (an AI or clinical decision support system) to disclose to the licensed professional using it that a direct-care worker may override the tool’s output, and would bar AI vendors/deployers from treating a clinician’s failure to override as a superseding cause that cuts off their own liability. As of July 17, 2026, AB 2575 has passed the Assembly, was most recently amended in the Senate on June 18, 2026, and has not been signed into law.
That’s a genuinely different legal question for your rollout checklist: AB 2575 is about disclosing to a clinician that an AI tool’s output can be overridden, not about whether a patient must consent to being recorded in the first place. No source found in this research connects AB 2575 to the Sutter/Sharp litigation or treats it as a legislative response to those suits. One law-firm analysis, quoted here as its own attributed observation rather than this post’s conclusion, put it this way:
Newer AI laws [in California] focus more on disclosure and deceptive representation than on exam-room audio capture itself, so [ambient-scribe] lawsuits are leaning on older laws like CIPA and CMIA to fill the gap.
Running a skilled nursing or assisted living facility? This applies to you too
If you’re evaluating an ambient AI scribe for a SNF or RCFE rather than a hospital, know this up front: both pending suits are acute-care and ambulatory cases — a hospital system and its affiliated clinics — not nursing-home cases. No lawsuit, and no CDPH, CDSS, or CMS guidance found in this research addresses ambient-AI-scribe consent specifically in a skilled nursing (SNF) or residential care (RCFE) setting. That is a real gap, and this post won’t pretend otherwise: as of this writing, no nursing home has been sued on this theory, and no state regulator has issued guidance on it.
What can be said, honestly, is narrower and textual rather than predictive: CMIA and CIPA are not written to cover acute care only. Both apply, by their own terms, to any "provider of health care" as CMIA defines it, or to any confidential communication as CIPA defines it — categories that plainly include licensed clinics and health facilities generically. That means a SNF or RCFE deploying the same ambient AI scribe technology, in the same way, would face the identical statutory exposure on the same facts — as a matter of how the statutes are written, not as a prediction of how a court would rule on SNF-specific facts.
Fisher Phillips, a law firm advising employers in response to the Sharp suit, frames its own guidance as industry-agnostic, stating:
While healthcare may be the target of this lawsuit, any consumer-facing business using AI voice tools, quality-assurance recording, or conversation-analysis engines should take note.
Separately, Skilled Nursing News reported in January 2026 that skilled nursing operators face rising legal exposure in 2026 tied to documentation, compliance, and resident-privacy concerns generally — but that reporting does not name the Sutter/Sharp ambient-scribe theory specifically or extend it to a SNF fact pattern. Put plainly: the statutes that produced a $5,000-per-violation exposure for a hospital system apply on their face to a SNF running the same technology the same way. Nothing in CMIA or CIPA carves out long-term care — but nothing has tested that in a long-term-care case yet, either.
Building your AI-scribe consent process: a pre-launch checklist
None of what follows is a legal requirement in itself, except where it overlaps with the CMIA/CIPA text above — it’s what named vendors, associations, and law firms are telling the field to do in direct response to this litigation. If you’re building your own rollout plan, treat this as your starting checklist, not the finish line.
- Get explicit, visit-level consent — not a general privacy notice buried in intake paperwork. Abridge’s own published guidance instructs clinicians to introduce the tool and obtain consent using a plain-language script: "I will be using a tool that records our conversation to help me write my clinical note so I can pay more attention to our conversation and less time on the computer. Is that okay with you?"
- Document that consent was actually obtained — not just default-checked. MGMA’s member sample "Patient Consent Form for AI Dictations" covers a plain-language explanation of the tool, where/how long the recording is stored, vendor BAA and HIPAA Security Rule protections, the resident or patient’s right to access, correct, or withdraw consent, and an explicit statement that the AI tool doesn’t make care decisions.
- Map where the audio actually goes. Fisher Phillips recommends tracking who receives recordings and how long vendors retain them, verifying that any EHR-inserted boilerplate like "patient consented" is disabled unless actually true, and building verifiable deletion workflows.
- Give a real opt-out. General attorney guidance converging across multiple firms (Alston & Bird, Thompson Coburn) recommends offering patients or residents a genuine non-AI alternative, not a take-it-or-leave-it consent request.
Frequently asked questions
Do I need patient consent before using an AI scribe at my facility?
Yes, in practice, even though no court has ruled on it yet. Both the Sutter/MemorialCare and Sharp HealthCare cases are pending — Sutter’s motions to dismiss are set for a September 3, 2026 hearing, Sharp’s demurrer and motion to strike for October 23, 2026 — but CMIA and CIPA’s text applies to your facility today, regardless of how either case resolves.
Is a general HIPAA or intake-paperwork notice enough to cover AI-scribe recording?
Field practice points the other way, though this isn’t adjudicated law: MGMA’s sample process and multiple law firms’ guidance describe explicit, visit-level consent — not a blanket privacy notice — as the practical standard emerging in response to this litigation.
What should my AI-scribe consent form actually include?
See the pre-launch checklist above — at minimum, a plain-language description of the tool, where and how long recordings are stored, vendor BAA/HIPAA Security Rule protections, the patient or resident’s right to access, correct, or withdraw consent, and a genuine non-AI opt-out.
What could getting this wrong cost my facility?
Under Cal. Penal Code §637.2, a CIPA violation carries a civil remedy of $5,000 per violation or three times actual damages, whichever is greater — and a plaintiff doesn’t need to prove actual harm to recover it. CMIA separately carries $1,000 in nominal damages per negligent violation, plus a fine of up to $25,000 for a knowing or willful one.
Does this apply to skilled nursing and assisted living facilities the same way it applies to hospitals?
CMIA and CIPA’s text isn’t limited to acute care — both apply to any "provider of health care" or confidential communication as defined, so a SNF or RCFE running the same ambient-AI-scribe technology would face the same statutory exposure on the same facts. That said, no nursing home has actually been sued on this theory, and no state regulator has issued LTC-specific guidance on it as of this writing — this is a textual reading of enacted law, not a report of an actual case.
Is AB 2575 the law requiring consent for AI scribes?
No. AB 2575 addresses disclosing to a clinician that an AI/clinical-decision-support tool’s output can be overridden, and how liability is allocated when it isn’t. It doesn’t address whether a patient must consent to being recorded, and as of July 17, 2026 it has not been signed into law.
Disclaimer: This post is informational, not legal advice. Confirm any change to your facility’s consent or documentation process with your own counsel or state association before acting on it.
Sources
- Washington et al. v. Sutter Health et al., docket 4:26-cv-03012 — PacerMonitor docket mirror (directly verified 2026-07-17).
- Saucedo v. Sharp HealthCare, case 25CU063632C — UniCourt docket mirror (directly verified 2026-07-17; the court’s own case-index portal blocked automated access).
- Cal. Civ. Code §56.10 (CMIA) — California Legislative Information.
- Cal. Civ. Code §56.06 (CMIA definitions) — California Legislative Information.
- Cal. Penal Code §632 (CIPA) — California Legislative Information.
- Cal. Penal Code §637.2 (CIPA civil remedy) — California Legislative Information.
- 18 U.S.C. §2511 (federal Wiretap Act) — Cornell Legal Information Institute.
- AB 2575 (Ortega) bill text and amendment history — California Legislative Information (directly verified 2026-07-17).
- Fisher Phillips, "New Class Action Targets Healthcare AI Recordings: 6 Steps All Businesses Should Consider to Limit Exposure" — fisherphillips.com.
- MGMA, sample "Patient Consent Form for AI Dictations" — mgma.com.
- Medscape, on Abridge’s guidance and consent script — medscape.com.
- Skilled Nursing News, "As AI Enters the Courtroom, Nursing Home Operators Brace for New Legal Threats in 2026" (Jan 2026) — skillednursingnews.com.
Where Relic Care fits in
If you’re already planning to bring an AI-drafted note into your workflow, the tool handling it should show who reviewed and signed off on each entry, and keep a clear record of what was recorded and why — the same audit trail a surveyor or a plaintiff’s attorney would ask for. See how Notes Scribing handles that for long-term care documentation.
And if the compliance side of this — tracking consent, retention, and disclosure obligations across everything your facility runs — sounds like a spreadsheet nobody has time to maintain, that’s what Compliance is built for.
More for the People Running Your Facility

What California's AI Documentation Bill Would Require
AB 2575 would require disclosure and override rights for AI tools in California health facilities — what it could mean for your SNF.


