AI Scribe (Heidi)
What is an AI scribe?
Ontario MD describes AI scribes as “digital tools designed to automate the administrative tasks of documenting patient consultations. They use artificial intelligence to summarize, or capture spoken conversations with consenting patients into electronic and clinically relevant medical notes for health-care professionals.”
Why Heidi?
Heidi was chosen because it is the only AI scribe which is integrated with Accuro so all Personal Health Information (PHI) and Personally Identifiable Information (PII) stays within Accuro.
Heidi is the only AI scribe that has been approved for use by Campus Wellness providers—no others may be used at this time.
Getting Access
To get access to Heidi in Accuro, send a request to the Tech Team. They will obtain a license for you.
Your Obligations as a Provider
You must read, understand, and abide all of the following in order to use an AI scribe at CW.
Consent
You must obtain explicit informed consent from the patient/client EVERY time you wish to use an AI scribe.
Inform the patient/client, and anyone present during the encounter, about your intended use of AI.
Provide a copy of the Patient Explainer (found in SharePoint) to those attending the encounter and allow them time to read it. Answer any questions they have about your use of AI.
Ask if the patient/client consents to the use of AI. Patients/clients must have the option to decline the use of the tool, and providers must respect any withdrawal of consent without compromising the quality of care.
Consent must be obtained verbally or in written format (electronic or paper-based) as preferred by the patient/client.
If consent is given verbally, turn on the AI scribe and read the script provided in Verbal Patient Consent for Use of AI Scribe (found in SharePoint) so that their consent and understanding of AI use is added to their note for that encounter only.
If consent is given in written format, the document must be uploaded to the patient/client’s medical record as a record of authorization for that encounter only.
Note: Each subsequent encounter will require reconfirmation of consent.
Data Use, Collection, Storage, and Retention
AI scribe tools must not be used to input Personally Identifiable Information (PII), such as patient names, addresses, or other sensitive identifiers.
Providers should only push information from the AI scribe into the Electronic Health Record (EHR) system.
Data should not be saved or stored within the AI scribe tool for longer than 7 days, to minimize data retention risks.
Data should be set to automatically delete according to pre-defined time limits (7 days maximum).
Security
Multi-Factor Authentication (MFA) must be enabled for all accounts associated with the AI scribe tool.
For your AI Scribe account, use a strong password which meets UW’s password standards.
All Campus Wellness providers must complete cybersecurity awareness training before using an AI scribe. Users can self-register on LEARN to complete IST’s training program.
Devices
Providers must use only devices managed by UW, or a personal device with SentinelOne installed and active. Procurement of SentinelOne on a personal device is at the user’s expense and can be acquired by contacting sales@sentinelone.com.
Devices must be running an up-to-date operating system and browser version to mitigate security vulnerabilities.
Do not use mobile applications. If this becomes necessary, please contact the Campus Wellness Tech Team to request a security review of the mobile application.
Decision-Making and Understanding
The AI scribe must not be used for decision-making in diagnosis or treatment.
Providers must understand that the AI scribe should not become a substitute for professional judgment or diligence in documentation.
Providers must balance the use of an AI scribe with their own critical thinking and professional accountability, ensuring that the technology supports but does not replace their expertise.
Do not allow the AI scribe to use contextual thinking (i.e., where it adds context for what it thinks you’re saying instead of just transcribing what you’re actually saying).
Patient/Client Notes
Providers are solely responsible and accountable for all notes entered into the medical record.
Providers must indicate on the note itself if that note was created in part or in whole using an AI scribe. Please use the script found in Verbal Patient Consent for Use of AI Scribe (in SharePoint) to start a note whenever one is created using AI.
Providers should seek clarification from the Campus Wellness Tech Team or UW Legal Services if any terms are unclear or pose potential risks.
Breaches
The AI scribe must be turned off when encounter is finished (to avoid a breach, etc.). This must be done manually by the provider by closing the AI scribe window.
Any data security incidents or suspected breaches involving the AI scribe must be reported immediately to the Health Information Specialist (HIS).
Providers should familiarize themselves with the incident reporting process and response protocols.
Audits
Providers must be aware that Campus Wellness may conduct regular audits to ensure compliance with these guidelines, including checks for:
Proper use of approved tools
Adherence to data privacy protocols
Device security compliance
Training compliance
Reporting Incidents
Auditing
Using Heidi
After you are set up with a license, the Tech Team will meet with you to properly set up and configure Heidi in your Accuro.
Each time you launch Heidi in Accuro, you will be prompted to acknowledge and consent to the following: