Who's Legally Accountable for an AI-Drafted Nursing Note?

Current as of August 10, 2026. If an AI scribe drafts a nursing note and it turns out to be wrong, accountability defaults to the human who signed it — not the company that built the tool. That’s true today under CMS’s single-signer model, which treats an AI scribe exactly like a human scribe, and under California’s rule naming the person who makes the entry as the record’s "author of record." The AI vendor, meanwhile, sits in a real federal regulatory gap: no clear FDA device rule reaches a pure note-drafting tool, and the one federal transparency rule that could touch it is narrow by design and currently proposed for rollback. None of that changes what CMS’s codified audit-trail requirements already demand of your documentation — regardless of who, or what, drafted it.
Why This Question Is Landing on Your Compliance Desk Right Now
An AI scribe — sometimes called an ambient AI scribe — is a tool that listens to or transcribes a care interaction and drafts the clinical note for a clinician to review and sign, instead of the clinician typing or dictating it themselves. Adding one to your documentation workflow doesn’t change who’s on the hook if a note turns out to be wrong; it just adds a step worth checking before you assume you’re covered.
If your facility has taken a documentation-driven citation in the last survey cycle — an Immediate Jeopardy finding over an incomplete care plan, a deficiency for a missing signature, anything where the note itself was the problem rather than a staffing number — you already know how unforgiving a surveyor is about what’s actually in the chart. Layer an AI scribe into that picture, and the stakes on "who’s accountable if this note is wrong" get sharper, not softer. For a facility already fighting documentation findings, this isn’t a hypothetical question about new technology — it’s the same question your last survey already asked, aimed at a new tool.
The federal government has started catching up here, just not in the direction a lot of trade coverage implies. In July 2025, CMS revised Medicare Learning Network fact sheet MLN905364, "Complying with Medicare Signature Requirements" — its own "What’s Changed" box confirms this is the first CMS document to explicitly address artificial intelligence in clinical documentation. What it actually says is worth its own section, because it’s not what a lot of compliance teams currently assume.
Does CMS Require a Nurse to Co-Sign an AI-Drafted Note?
No. CMS’s own guidance treats an AI scribe exactly like a human scribe: the treating clinician signs the entry to authenticate it, and no second signature is required. MLN905364 puts it directly: "You don’t need to document who or what transcribed the entry," and "we don’t require the scribe to sign or date the documentation." That’s a single-signer model, not a co-signature mandate.
Practically, the clinician who signs an AI-drafted note is making the same representation they’d make signing a note they typed themselves or dictated to a human scribe: that the note accurately reflects the care given. The signature carries the accountability, whether or not a second person ever reviewed the draft.
What Audit-Trail Requirements Actually Apply to an AI-Drafted Note?
The real, binding audit-trail bar here predates AI entirely, and it’s technology-neutral. 42 CFR §483.70(h) requires skilled nursing facility (SNF) medical records to be complete, accurately documented, readily accessible, and systematically organized. CMS’s interpretive guidance at State Operations Manual Appendix PP, tag F842 spells out what an electronic-signature system has to do to satisfy that bar:
- A facility policy naming who’s authorized to sign electronically
- Fraud safeguards around who can create or alter an entry
- An individualized identifier for each staff member — no shared logins
- A timestamp pulled from the system clock at the moment of entry
- An entry that becomes immutable once it’s recorded
- Role-based access controls
None of that language mentions AI, and it doesn’t need to: an AI documentation tool has to satisfy the same five safeguards any EHR does. That’s a concrete, checkable list — a far more useful thing to hand your survey team than a vague sense that "AI-generated notes need a special audit trail."
Is CMS Treating AI as a Driver of Billing Upcoding?
Not by name, and not yet, as of today. CMS’s FY2027 SNF Prospective Payment System proposed rule, published April 7, 2026, included a request for information on "addressing case-mix upcoding" in the Patient-Driven Payment Model (PDPM) — prompted by a real data anomaly (one MDS item, malnutrition, jumped from 5% of stays before PDPM to 47% of stays by FY2024). A full-text search of that rule for "artificial intelligence" returns nothing. The FY2027 final rule, issued July 29, 2026, confirms CMS is still just taking comments "under advisement" for future rulemaking — no upcoding-detection methodology was finalized this cycle.
As of August 10, 2026, this is a general case-mix-creep concern, not an AI-specific fraud theory. Watch the FY2028 SNF PPS proposed rule, expected around April 2027, for whether that changes.
Is the AI Vendor Federally Regulated as a Medical-Device Maker?
Mostly not — and that’s the vendor-side half of the accountability gap. The 21st Century Cures Act’s device exclusion (FD&C Act §520(o)) and FDA’s 2022 clinical decision support guidance only pull software into device regulation if it recommends a course of action while letting the clinician independently review the basis for that recommendation. A tool that just transcribes and summarizes an encounter arguably never triggers that test at all — it fits more naturally under the separate administrative-support exclusions FDA also recognizes. No major AI scribe vendor has a known FDA clearance or has claimed device status.
In plain terms: if an AI scribe drafts a note that’s simply wrong, that’s not a device malfunction FDA is positioned to regulate. It’s a documentation problem, and it lands back on your facility and your signing clinicians.
Does Any Federal Rule Make AI-Documentation Vendors Show Their Work?
One does, narrowly — and it’s currently proposed for rollback. The Office of the National Coordinator for Health IT’s HTI-1 final rule requires certified health IT developers to publish performance and risk-management disclosures for "Predictive Decision Support Interventions" — a category broad enough to include generative-AI output. But the rule’s own text limits that requirement to a Predictive DSI a developer bundles inside its own certified EHR module; it explicitly doesn’t reach "other-party" tools a customer implements separately. A standalone AI scribe that isn’t packaged into a certified EHR module isn’t covered by HTI-1 at all.
It gets thinner from there: as of August 10, 2026, ONC’s proposed HTI-5 rule (comment period closed February 27, 2026) would remove the source-attribute and risk-management provisions HTI-1 created — no final rule has issued yet, so watch this in 2026 Q4. Combined with the FDA gap above, federal accountability for the vendor side of AI documentation is thin today, and the direction of travel is thinner, not stronger.
Who Does California Law Say Is Accountable for What’s in the Note?
California Code of Regulations, title 22, §72543(f) requires every entry in a resident’s health record to be authenticated with the date, name, and title of the person making the entry. The person — not the drafting tool — is the named accountable party under state regulation. That’s the sharpest, most defensible answer to this post’s own title question: under California law, the human who signs is the "author of record," by design.
California’s Nursing Practice Act (Business & Professions Code §2725) is silent on AI specifically — there’s no explicit documentation-delegation provision for it, and that’s a real gap worth stating plainly rather than glossing over. What can be said honestly is a practical inference, not settled law: the state’s existing delegation principle, already applied to dictation, templates, and unlicensed staff support under Board of Registered Nursing Policy NPR-B-16, holds that the RN retains accountability for documentation outcomes even when the drafting work itself is delegated. Extending that same logic to an AI scribe is a reasonable reading, not a court’s holding — no California court, licensing action, or malpractice case has named AI-drafted-note inaccuracy as a theory of liability as of this writing.
Worth separating clearly: the AI-scribe litigation that does exist in California right now — against Sutter Health/MemorialCare and against Sharp HealthCare — alleges recording a visit without adequate patient consent, a privacy theory under the Confidentiality of Medical Information Act (CMIA) and California’s two-party consent wiretapping law (CIPA). Neither suit claims a note was factually wrong. That’s a different question from the one this post is answering, and it’s easy to conflate the two if you’re skimming trade coverage.
Could Your Facility or Your Vendor Face False Claims Act Exposure?
The legal theory already exists — it just hasn’t been tested against generative AI yet. In United States v. Practice Fusion, Inc., the Department of Justice (DOJ) secured a $145 million resolution in January 2020 against an EHR vendor whose software had been engineered, via a kickback arrangement, to increase opioid prescribing — the first-ever criminal case against an EHR vendor. In November 2025, DOJ reached a $45 million False Claims Act (FCA) settlement with Vohra Wound Physicians Management over documentation and billing software allegedly defaulting to higher-reimbursed codes regardless of what was actually performed — a long-term-care-adjacent example that came with a five-year Corporate Integrity Agreement.
Neither case involves generative AI — both involved software deliberately programmed with specific business logic. But the underlying theory, that software design itself (not just human intent) can create federal liability, is already established, and Bloomberg Law has reported DOJ attorneys are still "formulating a strategy" on open AI/EHR-adjacent subpoenas, with AI-upcoding cases (as opposed to investigations) not expected until 2027-2028. "Not yet, but the theory already exists and DOJ is watching" is the honest version of this risk, as of August 10, 2026 — worth revisiting in 2027 Q1.
Does Your AI-Scribe Process Actually Protect You? A Quick Decision Tree

Run your own rollout against these four questions before you assume you’re covered:
- Does the treating clinician sign every AI-drafted note personally? If not, you’ve reintroduced exactly the co-signature ambiguity CMS’s single-signer model was designed to avoid.
- Can you produce an individualized identifier, a system timestamp, and proof of immutability for every entry? That’s the F842 bar, and it’s the first thing a surveyor will ask for — AI tool or not.
- If a note is later found to be wrong, can you show who reviewed and signed it, and when? That’s what turns "the AI made a mistake" into a defensible, documented decision instead of an open question.
- Have you separately confirmed resident or patient consent to being recorded? That’s a different legal question — CIPA and CMIA, not documentation accuracy — but it’s the one that’s actually been tested in court so far, and it’s just as easy to get wrong.
If you answered "no" or "not sure" to any of the above, that’s the gap to close before your next survey — not after.
Frequently Asked Questions
Who Is Legally Responsible for an AI-Drafted Nursing Note?
The treating clinician who signs it. CMS’s single-signer model and California’s "author of record" rule both put accountability on the person who authenticates the entry, not the AI tool that drafted it.
Does Medicare Require a Nurse to Co-Sign Every AI-Generated Note?
No. CMS’s MLN905364 fact sheet treats an AI scribe the same as a human scribe: one signature, from the treating clinician, is enough. There’s no federal co-signature mandate for AI-drafted entries.
Can Our Facility Be Sued if an AI Scribe’s Note Turns Out to Be Wrong?
No AI-note-accuracy lawsuit exists yet in California or federally, as of August 10, 2026. But the audit-trail requirements under 42 CFR §483.70(h) and F842 already apply regardless of who or what drafted the note, and a wrong note that isn’t caught is still a survey finding waiting to happen.
Is the AI Vendor Liable Instead of Our Facility?
Not under current federal rules. FDA’s device framework doesn’t clearly reach a pure note-drafting tool, and the one ONC transparency rule that could touch AI documentation is narrow and proposed for rollback. Accountability defaults to your facility and your signing clinicians, not the vendor.
What Should Our Facility Do Before Rolling Out an AI Scribe?
Run the decision tree above: confirm single-clinician sign-off on every note, confirm your F842 audit-trail safeguards, confirm you can show who reviewed a note and when, and separately confirm resident consent to being recorded.
Disclaimer: This post is informational, not legal advice. Confirm any change to your facility’s documentation, signature, or consent process with your own counsel or state association before acting on it.
Sources
- CMS, MLN905364, "Complying with Medicare Signature Requirements" (revised July 2025)
- 42 CFR §483.70(h) — eCFR
- CMS State Operations Manual, Appendix PP (tag F842), Revision 225 (effective August 8, 2024)
- CMS, FY2027 SNF PPS proposed rule — Federal Register 2026-06674 (April 7, 2026)
- CMS, FY2027 SNF PPS final rule fact sheet (CMS-1843-F) (July 29, 2026)
- 21st Century Cures Act §3060(a) / FD&C Act §520(o) — 21 U.S.C. §360j
- FDA, Clinical Decision Support Software guidance notice, Federal Register 2022-20993
- ONC, HTI-1 final rule, 89 FR 1192 (January 9, 2024)
- ONC, HTI-5 proposed rule fact sheet
- California Code of Regulations, title 22, §72543(f)
- California Business & Professions Code §2725
- California Board of Registered Nursing, Policy NPR-B-16
- U.S. Department of Justice / HHS-OIG, Practice Fusion, Inc. resolution summary (January 27, 2020)
- Vohra Wound Physicians Management, LLC — $45 million False Claims Act settlement (DOJ, November 2025; secondary-sourced, direct DOJ release blocked on fetch)
- Bloomberg Law, "DOJ's Healthcare Probes of AI Tools Rooted in Purdue Pharma Case"
Where Relic Care Fits In
If you’re evaluating an AI scribe, or already piloting one, the tool handling your documentation should make the single-signer model above easy to prove: one clear treating-clinician signature per note, an individualized identifier, a system timestamp, and an entry that’s immutable once it’s signed off. See how Notes Scribing handles that audit trail for long-term care documentation.
And if tracking every audit-trail, signature, and consent obligation across everything your facility runs feels like a compliance spreadsheet nobody has time to maintain, that’s what Compliance is built for.
More for the People Running Your Facility

Using AI Scribes - How about Patient Consent?
Planning to roll out an AI scribe at your facility? See what CMIA, CIPA, and the federal Wiretap Act require for patient consent before you go live.

What California's AI Documentation Bill Would Require
AB 2575 would require disclosure and override rights for AI tools in California health facilities — what it could mean for your SNF.


