Education
5 min read

AI Scribe Consent in Australia

Published on
January 1, 2026
AI Scribe Consent in Australia on a violet Lyrebird Health background
Contributors
Adrian Lee
Subscribe to our newsletter
Read about our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

AI scribes introduce a new way of collecting and processing sensitive information during a consult. Clinicians and practice owners need a consent process that patients understand and staff can follow consistently. A sound Australian workflow explains the tool before capture starts, records the patient's decision and preserves a genuine choice to refuse or withdraw. Privacy, professional and state or territory surveillance rules overlap, so practices should also follow their health service or workplace policy and medical defence organisation (MDO) advice. This is general information, not legal advice.

Reviewed 25 August 2026

What valid AI scribe consent requires

The Office of the Australian Information Commissioner (OAIC) identifies four conditions for valid privacy consent. Each has a practical consequence in an AI scribe consult.

ConditionWhat it means in practice
Adequately informedExplain what the scribe captures, why it is used, what it produces, how information is handled and the material risks and limits. Use plain language and answer questions.
VoluntaryGive the patient a real choice. Declining must not reduce the care available or change how the patient is treated.
Current and specificAsk about this tool and this consult. Revisit the explanation when the vendor, capture method, data use or other material fact changes.
Given with capacityThe person must be able to understand the decision, weigh the effect of agreeing or declining, form a view and communicate it. Provide support where it can help.

The OAIC says withdrawal should be easy and consent cannot be assumed to last indefinitely. These principles apply to spoken, written and electronic consent. OAIC consent guidance sets out the full test.

AHPRA says a generative AI scribe using personal data will generally require informed consent, ideally recorded in the health record. The TGA requires enough information for informed consent before using a digital scribe. RACGP recommends consent at the start of each consultation and recording verbal consent in the consultation note. See AHPRA's AI guidance, TGA digital scribe guidance and RACGP guidance.

What the patient needs to know

A vague statement such as, "I use software for my notes," is insufficient. Explain six things before capture.

  1. The tool and its purpose. Name the AI scribe. Explain that it listens to or captures the consult to produce a draft clinical note or other nominated document.
  2. How capture works. Say whether audio is streamed, recorded or retained. Include any material difference between an in-person consult, telehealth, dictation and another mode.
  3. What the tool produces. Explain that the output is a draft clinical note or document. The clinician reviews, corrects and finalises it, and remains responsible for the patient record.
  4. How information is handled. Cover the processing and storage locations, retention and deletion periods, relevant subprocessors or access, and whether patient or customer data is used for model training, benchmarking or service improvement.
  5. The material risks and limits. Explain that an AI draft can be inaccurate, incomplete, unsupported or affected by bias where relevant. Human review reduces these risks but may not catch every error. Explain material privacy risks for the specific setup, including excessive or unexpected collection, use or disclosure, unauthorised access and security incidents.
  6. The patient's choice. State that the patient can ask questions, decline before capture or withdraw during the consult, without affecting their care. Explain how you will document the consult if they decline.

The OAIC identifies inaccurate output, bias, unexpected data handling and security failures among the risks organisations should assess when using AI. It also says organisations should understand a system's limitations and build in human oversight. OAIC commercial AI guidance provides the risk framework. Use facts for the contracted product and settings. "Secure" or "privacy compliant" does not tell a patient where information goes, how long it remains there or who processes it.

First use and later consultations need different conversations

The first use needs the full explanation. Give the patient enough time to understand the tool, ask questions and decide before capture starts. Appointment messages, website information, waiting-room signs and enrolment material can introduce the subject earlier. They do not record the patient's current decision for the consult. Our pre-appointment consent guide covers that preparation in more detail.

At each later consultation, ask again before capture. If the patient has already received the detailed explanation and nothing material has changed, the confirmation can be short: identify the scribe, ask whether they are comfortable using it today and give them an opportunity to ask questions or decline. This detailed-first-use and brief-later-confirmation pattern is consistent with Avant guidance, the MIPS fact sheet and MDA National guidance.

Give the fuller explanation again when something material changes. Examples include a different vendor, new data location, longer retention, a new training or secondary-use term, a changed capture method, or a new output that goes beyond documentation.

Verbal or written consent

Health information is sensitive information. The OAIC says an entity should generally seek express consent before collecting it under APP 3. For an AI scribe, obtain that consent before capture rather than treating notification, silence or continued participation as agreement. Express consent can be oral or written. Surveillance law, the care setting, employer policy and MDO requirements may affect the appropriate method.

A written notice or form gives the patient time to read. A verbal exchange confirms the information remains current and the patient agrees today. RACGP advises clinicians to ask their MDO whether written consent is required.

A signed form does not remove the need for a current choice. Do not rely on an AI-generated sentence created after capture starts. Record the response before starting the scribe.

A practical AI scribe consent workflow

Separate practice preparation from the decision in each consult:

  1. Set the practice information. Update the privacy policy and patient material with the intended use and current data-handling facts.
  2. Document the vendor facts. Assign an owner to maintain the six answers below, including configured retention and capture settings.
  3. Prepare the patient. Use email, SMS, booking information, signage or enrolment material to let patients read about the tool before the appointment.
  4. Explain before capture. Give a detailed explanation the first time. At a later consult, give a brief confirmation if the information remains current.
  5. Invite a decision. Ask for questions, make refusal easy and resolve uncertainty before starting.
  6. Record the response. Document consent, refusal or withdrawal in the clinical record for that consult.
  7. Start only after consent. If the patient agrees, begin capture. If they refuse or withdraw, do not start or stop capture and use the usual documentation method.
  8. Review and finalise. Check the draft against the consult, correct errors and sign off the final clinical note.

AI scribe consent workflow showing the response recorded before capture, consent leading to capture and draft review, and refusal or withdrawal leading only to no or stopped capture and usual notes

Practice policy, staff training, output review, monitoring and incident response need separate controls. Our AI governance guide covers them.

How to document AI scribe consent

Record the decision in the health record for each consult, including:

  • whether the patient consented, declined or withdrew
  • that the decision preceded capture
  • which AI scribe was proposed
  • whether this was a first-use explanation or a later confirmation
  • material questions, limits or conditions
  • who gave consent where a substitute decision-maker was involved
  • when capture stopped if the patient withdrew.

For example: "Before capture, discussed [vendor/tool], [capture method and purpose], clinician review and relevant data handling. Questions answered. Patient gave verbal consent for this consult."

If the patient declines or withdraws

Accept the decision without pressure. Do not start capture. Stop it if already underway. Continue the same care and use the usual documentation method. Record the decision factually, without suggesting the patient was difficult.

Withdrawal stops future capture and handling that depends on that consent. It may not reverse earlier lawful processing or remove information that another law requires the practice to retain. Route data-rights requests to the privacy owner.

If a patient appears uncertain, pause and clarify the concern. Hesitation, silence or awareness of a sign is a poor basis for capture. The OAIC states that notification alone does not create implied consent. See its commercial AI guidance.

Sensitive consultations, capacity and young people

Mental health, sexual health, family violence, end-of-life care and consults involving an interpreter, carer or family member may need extra care. Treat these as prompts for clinical judgement, rather than an automatic ban.

Consider whether the patient can speak freely and whether everyone whose private conversation may be captured has received an appropriate explanation. The patient can later ask the scribe to stop.

Capacity is specific to the decision and time. Distress, illness, cognitive impairment, medication or communication barriers may affect it temporarily. Provide an interpreter or accessible format where appropriate. If the person still lacks capacity and consent is required, follow the applicable rules for a substitute decision-maker and involve the patient as far as practical.

The Privacy Act does not set one age for every privacy decision. The OAIC calls for a case-by-case assessment of the young person's understanding and maturity. A parent or guardian may need to decide when the young person lacks capacity. Apply the usual confidentiality framework and setting-specific MDO advice.

Surveillance-device laws vary by jurisdiction

An AI scribe may listen to, monitor or record a private conversation. The legal analysis depends on the tool's operation and where the consult occurs. State and territory Acts differ in their wording, prohibitions and exceptions.

For example, the NSW Surveillance Devices Act and South Australian Act contain provisions involving the consent of all principal parties in specified circumstances. Queensland's Invasion of Privacy Act includes an exception where the person using the listening device is a party to the conversation, while separate rules govern later communication or publication.

An eight-jurisdiction shortcut is unsafe. Obtain and record informed consent before capture in every consult, then apply advice for the jurisdiction, care setting and capture method. This workflow aligns with AHPRA, RACGP and MDO guidance while avoiding assumptions about one uniform Australian surveillance rule.

How APP 3, 6, 8 and 11 affect the conversation

The Australian Privacy Principles (APPs) shape both the patient explanation and the vendor assessment.

PrincipleConsent-facing implication
APP 3: collectionHealth information is sensitive information. APP 3.3 generally requires consent for its collection unless an exception applies. Collection must also be reasonably necessary for the practice's functions or activities.
APP 6: use and disclosureUse or disclosure is generally limited to the purpose for which the information was collected. For a secondary purpose involving sensitive information, the directly related and reasonably expected test, consent or another exception must support it. Training, benchmarking and service-improvement terms therefore matter.
APP 8: cross-border disclosureSending information to an overseas recipient will often be a disclosure that requires reasonable steps to prevent an APP breach. A tightly controlled overseas contractor may sometimes amount to use, and APP 8 contains exceptions. Australian storage alone does not answer the full data-flow question.
APP 11: security and lifecycleReasonable technical and organisational protections must cover the information lifecycle. When information is no longer needed and no retention exception applies, reasonable steps must be taken to destroy or de-identify it, including relevant copies and backups.

The OAIC's APP 3, APP 6, APP 8 and APP 11 guidelines explain the qualifications and exceptions. State and territory health privacy requirements may also apply.

Six vendor-data questions you need answered

An accurate patient explanation depends on a current data map, the contract and the settings the practice actually uses. Obtain written answers to these six questions:

  1. What is captured, and for what purpose? Separate consultation audio, dictation audio, transcripts, prompts, draft notes, final notes, account data, logs and feedback.
  2. Where is each data type processed and stored? Include every relevant subprocessor, overseas transfer, remote access arrangement, database, backup and disaster-recovery location.
  3. What are the retention and deletion rules? Record defaults and configurable periods for audio, transcripts, notes, logs and backups, plus what happens at contract end.
  4. Who can access the data? Cover practice staff, vendor personnel and subprocessors, together with role controls, support access and audit records.
  5. Is data used beyond providing the service? Ask separately about model training, fine-tuning, benchmarking, product analytics and service improvement, including de-identified data.
  6. How are rights and incidents handled? Define how the practice and vendor record consent and withdrawal, respond to access, correction and deletion requests, and notify and manage incidents.

Our AI scribe data security checklist takes the practice owner and security lead through the wider due-diligence process.

Sample verbal consent script

Use this as a starting framework. Replace every bracketed field with the practice's current facts, keep only statements that apply to the consult and adapt the wording with MDO or legal advice.

"I'd like to use [vendor and tool name] to help document today's consultation. It [streams/records/listens to] our conversation and creates [draft output]. [Explain the material privacy risks for this setup, including any risk of excessive or unexpected collection, use or disclosure, unauthorised access or a security incident, and bias where relevant.] The draft can be inaccurate or incomplete. I will review and correct it, although human review may not catch every error. [State what happens to audio and transcript, retention period, processing and storage locations, relevant access or subprocessors, and any training or secondary use.] You can ask questions, say no or ask me to stop at any time. Your decision will not affect your care. Are you comfortable for me to use it today?"

For a later consult, where the full explanation is still current:

"You have previously received information about our use of [tool name]. Are you comfortable for me to use it to document today's consultation? You can ask questions, decline or ask me to stop at any time."

Written consent form framework

A written form or patient handout should identify the practice and include:

  • Tool: [vendor, product and version or service]
  • Purpose: [clinical documentation outputs the practice will create]
  • Capture method: [streamed, recorded or other capture; in-person, telehealth and dictation distinctions]
  • Clinician review: [how the draft is checked, corrected and finalised]
  • Data handled: [audio, transcript, draft note, final note, account data and logs]
  • Processing and storage: [countries, regions and relevant subprocessors by data type]
  • Retention and deletion: [default and configured periods, backups and end-of-contract process]
  • Access: [practice, vendor and subprocessor roles and controls]
  • Training and secondary use: [yes/no and exact scope for training, benchmarking, analytics or service improvement]
  • Material risks and limits: [inaccurate, incomplete or unsupported output; the limits of human review; any risk of excessive or unexpected collection, use or disclosure; unauthorised access or security incidents; bias where relevant; and the controls used]
  • Choice: "I can decline or withdraw consent without affecting my care. If I withdraw during a consultation, capture will stop and my clinician will document the consultation another way."
  • Questions and privacy contact: [practice privacy contact and how to request access, correction or deletion]
  • Decision: [consent / do not consent], [patient or substitute decision-maker name], [relationship or authority if applicable], [date and signature or recorded verbal response]

Treat the completed form as supporting information and evidence of the explanation given. Confirm the patient's decision before capture at each consultation and record that response in the clinical record.

Clear consent protects the patient's agency and gives the clinician a repeatable start to every captured consult. If your practice is assessing Lyrebird, Contact us to discuss how the consent step fits your clinical workflow.

More Resources
Continue reading
Posts
The dangers of Copy Paste Scribes
Read More
Posts
How to use an AI medical scribe
Read More
Posts
December Product Updates
Read More
Education
Patient Communication Software: A Buyer’s Guide for Australian Clinics
Read More
Education
Best medical dictation software for Mac in Australia
Read More
Education
New Patient Form Template for Australian Medical Practices
Read More
Post
5 min read

AI Scribe Consent in Australia

Published on
January 1, 2026
AI Scribe Consent in Australia on a violet Lyrebird Health background
Contributors
Adrian Lee
Subscribe to our newsletter
Read about our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

AI scribes introduce a new way of collecting and processing sensitive information during a consult. Clinicians and practice owners need a consent process that patients understand and staff can follow consistently. A sound Australian workflow explains the tool before capture starts, records the patient's decision and preserves a genuine choice to refuse or withdraw. Privacy, professional and state or territory surveillance rules overlap, so practices should also follow their health service or workplace policy and medical defence organisation (MDO) advice. This is general information, not legal advice.

Reviewed 25 August 2026

What valid AI scribe consent requires

The Office of the Australian Information Commissioner (OAIC) identifies four conditions for valid privacy consent. Each has a practical consequence in an AI scribe consult.

ConditionWhat it means in practice
Adequately informedExplain what the scribe captures, why it is used, what it produces, how information is handled and the material risks and limits. Use plain language and answer questions.
VoluntaryGive the patient a real choice. Declining must not reduce the care available or change how the patient is treated.
Current and specificAsk about this tool and this consult. Revisit the explanation when the vendor, capture method, data use or other material fact changes.
Given with capacityThe person must be able to understand the decision, weigh the effect of agreeing or declining, form a view and communicate it. Provide support where it can help.

The OAIC says withdrawal should be easy and consent cannot be assumed to last indefinitely. These principles apply to spoken, written and electronic consent. OAIC consent guidance sets out the full test.

AHPRA says a generative AI scribe using personal data will generally require informed consent, ideally recorded in the health record. The TGA requires enough information for informed consent before using a digital scribe. RACGP recommends consent at the start of each consultation and recording verbal consent in the consultation note. See AHPRA's AI guidance, TGA digital scribe guidance and RACGP guidance.

What the patient needs to know

A vague statement such as, "I use software for my notes," is insufficient. Explain six things before capture.

  1. The tool and its purpose. Name the AI scribe. Explain that it listens to or captures the consult to produce a draft clinical note or other nominated document.
  2. How capture works. Say whether audio is streamed, recorded or retained. Include any material difference between an in-person consult, telehealth, dictation and another mode.
  3. What the tool produces. Explain that the output is a draft clinical note or document. The clinician reviews, corrects and finalises it, and remains responsible for the patient record.
  4. How information is handled. Cover the processing and storage locations, retention and deletion periods, relevant subprocessors or access, and whether patient or customer data is used for model training, benchmarking or service improvement.
  5. The material risks and limits. Explain that an AI draft can be inaccurate, incomplete, unsupported or affected by bias where relevant. Human review reduces these risks but may not catch every error. Explain material privacy risks for the specific setup, including excessive or unexpected collection, use or disclosure, unauthorised access and security incidents.
  6. The patient's choice. State that the patient can ask questions, decline before capture or withdraw during the consult, without affecting their care. Explain how you will document the consult if they decline.

The OAIC identifies inaccurate output, bias, unexpected data handling and security failures among the risks organisations should assess when using AI. It also says organisations should understand a system's limitations and build in human oversight. OAIC commercial AI guidance provides the risk framework. Use facts for the contracted product and settings. "Secure" or "privacy compliant" does not tell a patient where information goes, how long it remains there or who processes it.

First use and later consultations need different conversations

The first use needs the full explanation. Give the patient enough time to understand the tool, ask questions and decide before capture starts. Appointment messages, website information, waiting-room signs and enrolment material can introduce the subject earlier. They do not record the patient's current decision for the consult. Our pre-appointment consent guide covers that preparation in more detail.

At each later consultation, ask again before capture. If the patient has already received the detailed explanation and nothing material has changed, the confirmation can be short: identify the scribe, ask whether they are comfortable using it today and give them an opportunity to ask questions or decline. This detailed-first-use and brief-later-confirmation pattern is consistent with Avant guidance, the MIPS fact sheet and MDA National guidance.

Give the fuller explanation again when something material changes. Examples include a different vendor, new data location, longer retention, a new training or secondary-use term, a changed capture method, or a new output that goes beyond documentation.

Verbal or written consent

Health information is sensitive information. The OAIC says an entity should generally seek express consent before collecting it under APP 3. For an AI scribe, obtain that consent before capture rather than treating notification, silence or continued participation as agreement. Express consent can be oral or written. Surveillance law, the care setting, employer policy and MDO requirements may affect the appropriate method.

A written notice or form gives the patient time to read. A verbal exchange confirms the information remains current and the patient agrees today. RACGP advises clinicians to ask their MDO whether written consent is required.

A signed form does not remove the need for a current choice. Do not rely on an AI-generated sentence created after capture starts. Record the response before starting the scribe.

A practical AI scribe consent workflow

Separate practice preparation from the decision in each consult:

  1. Set the practice information. Update the privacy policy and patient material with the intended use and current data-handling facts.
  2. Document the vendor facts. Assign an owner to maintain the six answers below, including configured retention and capture settings.
  3. Prepare the patient. Use email, SMS, booking information, signage or enrolment material to let patients read about the tool before the appointment.
  4. Explain before capture. Give a detailed explanation the first time. At a later consult, give a brief confirmation if the information remains current.
  5. Invite a decision. Ask for questions, make refusal easy and resolve uncertainty before starting.
  6. Record the response. Document consent, refusal or withdrawal in the clinical record for that consult.
  7. Start only after consent. If the patient agrees, begin capture. If they refuse or withdraw, do not start or stop capture and use the usual documentation method.
  8. Review and finalise. Check the draft against the consult, correct errors and sign off the final clinical note.

AI scribe consent workflow showing the response recorded before capture, consent leading to capture and draft review, and refusal or withdrawal leading only to no or stopped capture and usual notes

Practice policy, staff training, output review, monitoring and incident response need separate controls. Our AI governance guide covers them.

How to document AI scribe consent

Record the decision in the health record for each consult, including:

  • whether the patient consented, declined or withdrew
  • that the decision preceded capture
  • which AI scribe was proposed
  • whether this was a first-use explanation or a later confirmation
  • material questions, limits or conditions
  • who gave consent where a substitute decision-maker was involved
  • when capture stopped if the patient withdrew.

For example: "Before capture, discussed [vendor/tool], [capture method and purpose], clinician review and relevant data handling. Questions answered. Patient gave verbal consent for this consult."

If the patient declines or withdraws

Accept the decision without pressure. Do not start capture. Stop it if already underway. Continue the same care and use the usual documentation method. Record the decision factually, without suggesting the patient was difficult.

Withdrawal stops future capture and handling that depends on that consent. It may not reverse earlier lawful processing or remove information that another law requires the practice to retain. Route data-rights requests to the privacy owner.

If a patient appears uncertain, pause and clarify the concern. Hesitation, silence or awareness of a sign is a poor basis for capture. The OAIC states that notification alone does not create implied consent. See its commercial AI guidance.

Sensitive consultations, capacity and young people

Mental health, sexual health, family violence, end-of-life care and consults involving an interpreter, carer or family member may need extra care. Treat these as prompts for clinical judgement, rather than an automatic ban.

Consider whether the patient can speak freely and whether everyone whose private conversation may be captured has received an appropriate explanation. The patient can later ask the scribe to stop.

Capacity is specific to the decision and time. Distress, illness, cognitive impairment, medication or communication barriers may affect it temporarily. Provide an interpreter or accessible format where appropriate. If the person still lacks capacity and consent is required, follow the applicable rules for a substitute decision-maker and involve the patient as far as practical.

The Privacy Act does not set one age for every privacy decision. The OAIC calls for a case-by-case assessment of the young person's understanding and maturity. A parent or guardian may need to decide when the young person lacks capacity. Apply the usual confidentiality framework and setting-specific MDO advice.

Surveillance-device laws vary by jurisdiction

An AI scribe may listen to, monitor or record a private conversation. The legal analysis depends on the tool's operation and where the consult occurs. State and territory Acts differ in their wording, prohibitions and exceptions.

For example, the NSW Surveillance Devices Act and South Australian Act contain provisions involving the consent of all principal parties in specified circumstances. Queensland's Invasion of Privacy Act includes an exception where the person using the listening device is a party to the conversation, while separate rules govern later communication or publication.

An eight-jurisdiction shortcut is unsafe. Obtain and record informed consent before capture in every consult, then apply advice for the jurisdiction, care setting and capture method. This workflow aligns with AHPRA, RACGP and MDO guidance while avoiding assumptions about one uniform Australian surveillance rule.

How APP 3, 6, 8 and 11 affect the conversation

The Australian Privacy Principles (APPs) shape both the patient explanation and the vendor assessment.

PrincipleConsent-facing implication
APP 3: collectionHealth information is sensitive information. APP 3.3 generally requires consent for its collection unless an exception applies. Collection must also be reasonably necessary for the practice's functions or activities.
APP 6: use and disclosureUse or disclosure is generally limited to the purpose for which the information was collected. For a secondary purpose involving sensitive information, the directly related and reasonably expected test, consent or another exception must support it. Training, benchmarking and service-improvement terms therefore matter.
APP 8: cross-border disclosureSending information to an overseas recipient will often be a disclosure that requires reasonable steps to prevent an APP breach. A tightly controlled overseas contractor may sometimes amount to use, and APP 8 contains exceptions. Australian storage alone does not answer the full data-flow question.
APP 11: security and lifecycleReasonable technical and organisational protections must cover the information lifecycle. When information is no longer needed and no retention exception applies, reasonable steps must be taken to destroy or de-identify it, including relevant copies and backups.

The OAIC's APP 3, APP 6, APP 8 and APP 11 guidelines explain the qualifications and exceptions. State and territory health privacy requirements may also apply.

Six vendor-data questions you need answered

An accurate patient explanation depends on a current data map, the contract and the settings the practice actually uses. Obtain written answers to these six questions:

  1. What is captured, and for what purpose? Separate consultation audio, dictation audio, transcripts, prompts, draft notes, final notes, account data, logs and feedback.
  2. Where is each data type processed and stored? Include every relevant subprocessor, overseas transfer, remote access arrangement, database, backup and disaster-recovery location.
  3. What are the retention and deletion rules? Record defaults and configurable periods for audio, transcripts, notes, logs and backups, plus what happens at contract end.
  4. Who can access the data? Cover practice staff, vendor personnel and subprocessors, together with role controls, support access and audit records.
  5. Is data used beyond providing the service? Ask separately about model training, fine-tuning, benchmarking, product analytics and service improvement, including de-identified data.
  6. How are rights and incidents handled? Define how the practice and vendor record consent and withdrawal, respond to access, correction and deletion requests, and notify and manage incidents.

Our AI scribe data security checklist takes the practice owner and security lead through the wider due-diligence process.

Sample verbal consent script

Use this as a starting framework. Replace every bracketed field with the practice's current facts, keep only statements that apply to the consult and adapt the wording with MDO or legal advice.

"I'd like to use [vendor and tool name] to help document today's consultation. It [streams/records/listens to] our conversation and creates [draft output]. [Explain the material privacy risks for this setup, including any risk of excessive or unexpected collection, use or disclosure, unauthorised access or a security incident, and bias where relevant.] The draft can be inaccurate or incomplete. I will review and correct it, although human review may not catch every error. [State what happens to audio and transcript, retention period, processing and storage locations, relevant access or subprocessors, and any training or secondary use.] You can ask questions, say no or ask me to stop at any time. Your decision will not affect your care. Are you comfortable for me to use it today?"

For a later consult, where the full explanation is still current:

"You have previously received information about our use of [tool name]. Are you comfortable for me to use it to document today's consultation? You can ask questions, decline or ask me to stop at any time."

Written consent form framework

A written form or patient handout should identify the practice and include:

  • Tool: [vendor, product and version or service]
  • Purpose: [clinical documentation outputs the practice will create]
  • Capture method: [streamed, recorded or other capture; in-person, telehealth and dictation distinctions]
  • Clinician review: [how the draft is checked, corrected and finalised]
  • Data handled: [audio, transcript, draft note, final note, account data and logs]
  • Processing and storage: [countries, regions and relevant subprocessors by data type]
  • Retention and deletion: [default and configured periods, backups and end-of-contract process]
  • Access: [practice, vendor and subprocessor roles and controls]
  • Training and secondary use: [yes/no and exact scope for training, benchmarking, analytics or service improvement]
  • Material risks and limits: [inaccurate, incomplete or unsupported output; the limits of human review; any risk of excessive or unexpected collection, use or disclosure; unauthorised access or security incidents; bias where relevant; and the controls used]
  • Choice: "I can decline or withdraw consent without affecting my care. If I withdraw during a consultation, capture will stop and my clinician will document the consultation another way."
  • Questions and privacy contact: [practice privacy contact and how to request access, correction or deletion]
  • Decision: [consent / do not consent], [patient or substitute decision-maker name], [relationship or authority if applicable], [date and signature or recorded verbal response]

Treat the completed form as supporting information and evidence of the explanation given. Confirm the patient's decision before capture at each consultation and record that response in the clinical record.

Clear consent protects the patient's agency and gives the clinician a repeatable start to every captured consult. If your practice is assessing Lyrebird, Contact us to discuss how the consent step fits your clinical workflow.

Keep reading

All posts
Questions about compliance?