AI-Assisted Clinical Documentation Policy
1. Purpose
This policy establishes the conditions under which Social Sense Allied Health (SSAH) may use Heidi Health's AI-assisted scribing functionality to support clinical documentation. It is designed to protect clients, support ethical social work practice, maintain accurate records and demonstrate reasonable privacy, security and governance controls.
The policy provides an operational framework for informed consent, use during appointments, human review, data minimisation, retention and deletion, incident management, complaints, vendor oversight and continuous assurance. It must be read with SSAH's Privacy Policy, consent documentation, record management procedures, Open Disclosure Policy, complaints process and information security controls.
2. Scope
This policy applies to all SSAH clinicians, employees, contractors, students and other persons who access or administer an SSAH Heidi account. It applies to in-person, telephone and telehealth sessions, including individual, family, couple, group and multidisciplinary appointments.
Only the Heidi Scribe functions expressly approved by the Director are within scope. Heidi Evidence, Heidi Comms, translation, automated communications, clinical decision support, file uploads, previous-session context or any new AI feature must not be used with identifiable client information until SSAH has completed and documented a separate privacy, safety and contractual assessment.
Where an applicable law, funding agreement, professional requirement or client contract sets a higher standard than this policy, the higher standard applies. If requirements conflict or are uncertain, use manual documentation and refer the matter to the Director before using Heidi.
3. Governing principles
Human accountability. The treating clinician owns the final note and every clinical decision.
Voluntary informed consent. AI scribing is optional and is never a condition of receiving care.
Transparency. Clients are told what Heidi does, what information is processed, the material risks and their choices.
Data minimisation. Only information reasonably necessary to document the service may be processed.
Privacy and security by design. Approved settings, devices, accounts and retention limits are used from the outset.
Accuracy and fairness. Every output is critically reviewed for errors, omissions, unsupported inferences and bias.
Purpose limitation. Client information is used only to create approved clinical documentation and associated care records.
No disadvantage. A client who declines or withdraws consent receives the same clinical service, with manual notes.
4. Definitions
AI-assisted clinical documentation: the use of an artificial intelligence system to transcribe a consultation and produce a draft note or other document for clinician review.
Heidi: the Heidi Health platform approved by SSAH for the limited purpose described in this policy.
Audio stream: the live sound processed so that speech can be converted to text. Heidi currently states that audio is not saved; SSAH nevertheless treats activation as requiring express consent.
Transcript: the machine-generated text representation of the session. It is sensitive health information while held, whether or not identifiers have been removed.
Draft output: a note, summary, letter, report or other document produced by Heidi that has not yet been reviewed and approved by the clinician.
Final clinical record: the clinician-reviewed and approved record stored in SSAH's authorised practice management or clinical record system.
Informed consent: voluntary, current and specific agreement given after the person has received and understood the information material to the decision.
Authorised representative: a person legally entitled to make the relevant decision for a client who lacks decision-making capacity.
Material change: a change to Heidi's purpose, features, model, data flows, sub-processors, terms, security posture, retention, data location or incident profile that could affect privacy or safety.
5. Legal, ethical and professional framework
SSAH will apply this policy consistently with all obligations that apply to the service and location, including:
Privacy Act 1988 (Cth), the Australian Privacy Principles (particularly APPs 1, 3, 5, 6, 8, 10 and 11) and the Notifiable Data Breaches scheme.
Health Records Act 2001 (Vic) and the Victorian Health Privacy Principles.
Privacy and Data Protection Act 2014 (Vic), where applicable.
Surveillance Devices Act 1999 (Vic), including the requirements relevant to listening devices and private conversations.
Health Records and Information Privacy Act 2002 (NSW) and its Health Privacy Principles, where services or records fall within New South Wales requirements.
Surveillance Devices Act 2007 (NSW), where applicable.
Health Complaints Act 2016 (Vic) and the General Code of Conduct for general health service providers.
Australian Association of Social Workers Code of Ethics 2020 and current AASW Practice Standards.
NDIS Code of Conduct and applicable NDIS Practice Standards, where SSAH provides NDIS supports or services.
Any applicable contractual, funding, insurer, subpoena, court, safeguarding, mandatory reporting and professional indemnity requirements.
Conservative consent rule: SSAH will not rely on whether a particular technology is legally characterised as a recording device. Express consent from every participant is required before Heidi is activated for each session.
6. Approval and permitted use
6.1 Conditions of approval
A clinician may use Heidi only when all of the following conditions are met:
the clinician has completed SSAH training and is an authorised user;
the current use is within the approved Scribe configuration and purpose;
all session participants have given informed consent and the consent has been documented;
the clinician remains present, responsible and able to create the record manually if needed;
the environment, device and network satisfy section 13; and
the clinician reviews, edits and approves the output before it becomes part of the clinical record or is shared.
6.2 Prohibited use
Activating Heidi without the knowledge and express consent of every participant.
Treating a privacy policy, intake term, website notice, poster, silence or attendance at an appointment as consent by itself.
Making access to SSAH services conditional on consenting to AI scribing.
Using Heidi to diagnose, make or recommend treatment decisions, undertake autonomous triage, replace risk assessment, determine eligibility, make safeguarding decisions or substitute for professional judgement.
Copying, signing, sending, billing from or filing an output that has not been fully reviewed and corrected by the responsible clinician.
Entering client-identifiable information into Heidi Evidence, a general-purpose chatbot, translation tool or other unapproved AI product.
Using personal Heidi accounts, shared logins, unapproved devices, public computers or accounts not controlled by SSAH.
Using an AI output to fabricate, embellish or retrospectively reconstruct events that the clinician cannot independently verify.
Using client information to test prompts, train models, create demonstrations, conduct marketing or develop templates unless the data is genuinely de-identified and the Director has approved the purpose.
Leaving transcripts or drafts in Heidi for convenience after the verified final record has been saved.
7. Vendor due diligence and change control
Before initial use, at least annually, and after any material change, the Director or delegate must document a privacy and safety assessment. Use must be suspended when SSAH cannot establish that the service remains appropriate for the intended purpose.
Review the current contract, privacy policy, usage policy, data processing terms and allocation of responsibilities.
Map what audio, identifiers, transcripts, prompts, outputs, metadata, support data and audit logs are collected, generated, stored, accessed, disclosed or deleted.
Confirm the approved Australian data region and identify any overseas processing, related companies and sub-processors; assess APP 8 and relevant state privacy obligations.
Verify retention and deletion behaviour, including deleted data, backups, audit logs and account closure; record any limitations.
Confirm whether any client data is used to train, develop or improve models. The approved configuration must not permit patient data to be used for model training.
Review independent security assurance, access controls, encryption, incident response, breach notification timeframes, business continuity and export capability.
Test representative consultations for accuracy, omissions, hallucinations, bias, speaker attribution and suitability for SSAH documentation.
Maintain a register of approved AI systems, features, owners, assessments, decisions, residual risks and review dates.
Plan an orderly exit, including export of required records, verified deletion, access revocation and a manual documentation fallback.
Heidi currently represents that it does not save session audio, does not use patient data to train its AI models, supports Australian data localisation and permits practitioner-controlled retention and deletion of transcripts and notes. Some platform functionality may involve international third-party services. These statements are vendor representations, not guarantees by SSAH, and must be re-verified through the due-diligence process.
8. Client information and informed consent
8.1 Information that must be provided
Before seeking consent, the clinician must explain in plain language:
that SSAH proposes to use Heidi, an AI-assisted scribe, during the session;
that Heidi processes the live conversation to create a transcript and draft documentation;
that the purpose is to assist note-taking so the clinician can focus on the client and create a timely record;
what information may be collected or generated, who may access it, where it may be processed and how long temporary material is kept;
that the clinician - not Heidi - makes all clinical decisions and must review and correct every output;
material risks, including transcription errors, omissions, incorrect speaker attribution, invented content, bias, technical failure and cyber or privacy incidents;
that Heidi currently states no audio recording is saved and patient data is not used to train its AI models, while transcripts and drafts exist until deleted;
that consent is optional, can be refused or withdrawn at any time, and refusal will not affect service quality, eligibility, fees, waiting-list position or the clinician-client relationship;
that manual note-taking will be used if consent is not given; and
how to ask questions, access or correct the final record, make a privacy inquiry or complaint, and obtain the SSAH Privacy Policy and this policy.
8.2 How consent is obtained
SSAH uses a two-stage process: written consent at onboarding or before first use, followed by an express verbal confirmation at the start of every session in which Heidi may be activated. A written form does not remove the need to reconfirm consent each time.
Any earlier SSAH website, intake or policy wording that purports to obtain consent merely because a client engages in therapy must not be relied upon and must be amended or withdrawn. This policy prevails to the extent of any inconsistency about consent for AI-assisted documentation.
The clinician must ask a direct question and receive an affirmative response before activation. Consent must be recorded in the clinical record with the date, method, participants and any limits. The clinician must also record when a client declines or withdraws, without recording judgemental commentary.
Consent must be refreshed in writing after a material change to the system, data handling, purpose, risks or this policy, and whenever there is reason to doubt that earlier consent remains informed or voluntary.
8.3 Withdrawal and refusal
A client may refuse or withdraw consent before or during a session. The clinician must immediately stop Heidi, confirm that manual notes will be used, and delete any unneeded transcript or draft from the current session as soon as safe and practicable. Withdrawal does not generally require deletion of an accurate final clinical record already lawfully created; access and correction requests are managed under the Privacy Policy.
9. Consent in particular circumstances
Multiple participants. Every person whose voice or information may be processed must consent. For couples, families or groups, consent must be unanimous. If anyone declines, Heidi must not be used.
Support people, interpreters and other practitioners. Their consent must be obtained and documented. A new participant joining after activation requires Heidi to be paused and consent obtained before resuming.
Children and young people. Assess the young person's capacity and applicable rights. Obtain consent from the person legally authorised to decide and, wherever possible, the young person's informed assent. Respect dissent and use manual notes where participation is not genuinely voluntary.
Impaired decision-making capacity. Identify and verify the authorised representative and record the basis of authority. Involve the client to the greatest extent possible. Do not use Heidi if authority or the client's wishes are unclear.
Telehealth and telephone services. Confirm who is present at each location, ask whether any undisclosed person can hear, and obtain consent from all participants before activation.
Family violence, safeguarding, crisis or acute distress. Use heightened professional judgement. Prefer manual notes when consent may be coerced, privacy cannot be assured, activation could increase risk or the clinician's attention is needed for immediate safety.
Interpreted or multilingual sessions. AI transcription may be less accurate. Use only when the clinician can independently verify the relevant content or a qualified interpreter supports verification. Unapproved AI translation is prohibited.
10. Required session workflow
10.1 Before activation
Confirm that the clinician, account, device, network and Heidi feature are approved and that no unapproved recording or assistant is running.
Assess whether AI use is appropriate for this client, session purpose, location, capacity, privacy and risk context. If uncertain, use manual notes.
Identify every participant and provide or refresh the required explanation in section 8.1.
Ask each participant for express consent using Appendix A and document the response in the clinical record.
Set a minimally identifying session title and avoid entering identifiers that are not necessary for the documentation task.
Activate Heidi only after the above steps are complete.
10.2 During the session
Keep the client informed that Heidi is active and remain attentive to comfort, distress and non-verbal information that AI may miss.
Collect only information relevant to the service and avoid unnecessarily speaking full names, addresses, identifiers or third-party details.
Pause Heidi when a participant joins, a participant withdraws consent, privacy is interrupted, the discussion moves outside the agreed scope or the technology behaves unexpectedly.
Do not allow the tool to direct the interview, make decisions or replace the clinician's contemporaneous risk and safeguarding processes.
If the service fails or accuracy appears poor, stop using it and complete the note manually.
10.3 After the session
Generate the draft and review it promptly while the consultation is fresh.
Compare the draft with the clinician's recollection, contemporaneous observations and any source material; correct all errors, omissions, unsupported inferences and biased or stigmatising language.
Ensure the note clearly distinguishes client report, third-party report, clinician observation, clinical formulation, risk assessment, actions and agreed plan.
Remove content that is irrelevant, excessive, duplicated or not appropriate for the official record.
Approve the final text personally and transfer it to the authorised clinical record. Do not rely on automatic transfer without checking the destination record.
Confirm the final record is complete, readable, attributed to the clinician and stored with the correct client and date.
Record that AI-assisted drafting was used, that consent was confirmed and that the clinician reviewed and approved the final note.
Delete the transcript and draft from Heidi immediately after verified transfer, with a target of the same day and no later than 24 hours unless a documented legal hold or Director-approved exceptional reason applies.
11. Review, accuracy and professional accountability
Heidi output is always a draft. The responsible clinician must conduct a meaningful line-by-line review and remains accountable even when the output appears plausible, the system provides a verification aid or the text was transferred automatically.
At a minimum, the review must check:
client identity, session date, modality and all speakers;
names, pronouns, relationships, dates, numbers, medications, services and appointments;
accuracy of direct quotes, reported events, allegations and third-party information;
risk, safeguarding, consent, capacity, mandatory reporting and action-plan details;
omitted non-verbal information, contextual nuance, uncertainty and dissent;
unsupported diagnosis, causal statements, certainty, recommendations or invented facts;
cultural, disability, gender, sexuality, racial or other biased, stigmatising or deficit-based language;
consistency between assessment, intervention, outcomes and plan; and
whether the amount and sensitivity of information is necessary for a defensible clinical record.
Letters, reports, referrals, funding documents, statutory reports and medico-legal material require the same independent verification as if written from scratch. High-risk or externally consequential documents should receive a second review by an appropriately qualified colleague or supervisor where required by SSAH procedure, professional judgement, contract or law.
12. Information handling and record management
12.1 Data categories and status
The audio stream, transcript, prompts, draft output, system metadata, support material and audit logs may contain personal, sensitive and health information. Temporary status or pseudonymisation does not remove the obligation to protect that information. De-identified information must not be treated as anonymous unless re-identification is not reasonably possible in the circumstances.
12.2 Collection, use and disclosure
SSAH may process client information through Heidi only for the primary purpose explained to and agreed by the client: assisting the clinician to prepare accurate and timely documentation of the service. Any new purpose requires a documented legal basis, privacy assessment and, where required, fresh consent.
Outputs must not be disclosed outside SSAH except as part of a lawful clinical record disclosure under the Privacy Policy, with valid consent, or where authorised or required by law. No transcript or draft may be used for marketing, performance surveillance, unrelated analytics or model training.
12.3 Data location and third parties
SSAH will configure approved Scribe use for Australian data localisation where available and will assess all relevant sub-processors and cross-border disclosures. Optional features involving international processing are disabled until separately approved. Client collection notices and the SSAH Privacy Policy must accurately describe material overseas processing and the classes of likely recipients.
12.4 Retention and deletion
Temporary Heidi transcripts and drafts are not a substitute for the final clinical record. After verified transfer, they must be deleted immediately, with a target of the same day and no later than 24 hours. The clinician must resolve failed deletion promptly and notify the Director if deletion cannot be confirmed.
Final clinical records are retained in SSAH's authorised record system in accordance with the Privacy Policy and applicable law. For Victorian health records, SSAH will not delete adult records until more than seven years after the last occasion on which SSAH provided a health service. Information collected while a person was a child will not be deleted until the later of the person attaining 25 years of age or more than seven years after the last service. A longer period applies where required by law, contract, professional indemnity advice, complaint, incident, investigation, subpoena, litigation or legal hold.
When health information is destroyed, SSAH will document the destruction as required by applicable law. Deletion from Heidi does not authorise alteration or destruction of the final clinical record.
12.5 Access, correction and legal process
Client requests to access or correct the final record are managed under the SSAH Privacy Policy. Corrections must preserve the integrity and audit trail of the original record. If SSAH receives or reasonably anticipates a subpoena, complaint, investigation, legal claim or other hold, relevant material must not be destroyed; the Director must obtain appropriate legal or insurer advice before ordinary deletion resumes.
13. Information security and access control
Use only an SSAH-controlled account with a unique user identity, strong password and multi-factor authentication.
Apply least-privilege access. Shared accounts and credential sharing are prohibited. Access must be revoked promptly when a role changes or ends.
Use an approved, encrypted and supported device with current security updates, screen lock, anti-malware controls and secure backups where relevant.
Do not use public or shared computers. Avoid public Wi-Fi; where remote access is necessary, use an approved secure connection.
Position the device and microphone to minimise collection of conversations outside the appointment. Do not use Heidi in public or acoustically insecure spaces.
Disable unapproved browser extensions, meeting bots, cloud transcription, recording, clipboard synchronisation or other tools that could capture client information.
Store final documentation only in the approved clinical record. Downloads, screenshots and local copies are prohibited unless required for an approved workflow and must then be secured and deleted promptly.
Use de-identified test data for training and troubleshooting. If vendor support access to identifiable information is unavoidable, obtain Director approval, use the minimum necessary information, document the purpose and obtain client consent unless a lawful exception applies.
Review account access, active sessions, exports, retention settings and audit logs at least quarterly and after any suspected compromise.
14. Incidents, errors, breaches and downtime
14.1 Immediate response
A user who identifies an error, privacy concern, security incident or unsafe output must:
stop or suspend the affected use and move to manual documentation;
protect the client from immediate clinical or privacy harm and correct any inaccurate final record using the approved correction process;
preserve relevant evidence, logs, timestamps and communications without making unnecessary copies of client information;
notify the Director / Privacy Officer on the same business day, or immediately for urgent risk;
record the event in the incident register and, where appropriate, notify Heidi through the approved support channel; and
avoid contacting affected persons, regulators or media independently unless necessary for immediate safety or directed by the incident response process.
14.2 Assessment and notification
The Director will assess clinical harm, privacy impact, affected information, likely access or disclosure, serious-harm risk, containment, remediation and notification obligations. This includes considering the Privacy Act Notifiable Data Breaches scheme, state privacy or health complaints requirements, NDIS reportable incident obligations, professional indemnity notification, contractual duties and open disclosure.
Where an AI error or incident affects care or the integrity of the record, SSAH will communicate openly and compassionately with the client in accordance with the Open Disclosure Policy, explain corrective action and offer an accessible complaints pathway.
14.3 Downtime
AI availability is not required to deliver SSAH services. If Heidi, the internet, the device or the clinical record system is unavailable or unreliable, the clinician must use the approved manual documentation process and enter the final record when systems are restored. No client should experience delayed or lower-quality care because AI is unavailable.
15. Complaints and client rights
Clients may raise a concern, withdraw consent, request access or correction, or make a complaint without adverse treatment. Complaints are managed promptly, fairly, confidentially and without retaliation under the SSAH complaints and privacy procedures.
The primary contact is Don Mackenzie, Director / Privacy Officer, on 0435 005 669 or don@socialsense.com.au. Clients may also contact the Office of the Australian Information Commissioner, the Victorian Health Complaints Commissioner, the NSW Health Care Complaints Commission, the NDIS Quality and Safeguards Commission or another applicable regulator. SSAH will provide the appropriate details on request.
16. Roles and responsibilities
Director / Privacy Officer: approves the system and configuration; owns the risk assessment and AI register; monitors legal and vendor changes; manages incidents, complaints, contracts, audits, training and suspension decisions.
Treating clinician: obtains and records consent; decides whether use is appropriate; operates the system securely; reviews and approves every output; transfers the final record; deletes temporary data; and reports concerns.
Authorised administrator: provisions and revokes accounts, applies approved settings, maintains access records and assists with audit and incident response without accessing clinical content beyond what is authorised.
Contractors and students: must comply with this policy and may use Heidi only when their contract, supervision arrangements, training and access have been expressly approved.
All personnel: must protect client confidentiality, complete required training, use only approved AI tools and report suspected non-compliance or incidents promptly.
17. Training, monitoring and assurance
Before access and at least annually, authorised users must complete training covering:
this policy, the SSAH Privacy Policy and relevant consent, record and incident procedures;
how Heidi processes a session, the distinction between audio, transcript, draft and final record, and current vendor settings;
informed consent, capacity, multi-party sessions, telehealth and withdrawal;
hallucinations, omissions, speaker errors, automation bias, cultural safety and fair language;
manual fallback, secure device use, data minimisation, deletion and support access; and
reporting clinical errors, privacy incidents, security concerns and complaints.
SSAH will conduct quarterly spot checks of consent documentation, final-note approval, deletion compliance and account access; an annual review of sample output quality and vendor controls; and additional review after incidents, complaints, material changes or relevant regulatory guidance. Audits must minimise access to client content and be recorded in the AI governance register.
18. Non-compliance
Non-compliance may result in immediate suspension of AI access, retraining, increased supervision, corrective action, contract or employment action, notification to an insurer or regulator, and any other response required to protect clients and SSAH. A person must not be disadvantaged for reporting a concern in good faith.
19. Policy review and publication
The Director will review this policy at least annually and earlier after a material vendor change, legal or professional update, new use case, incident, complaint, audit finding or evidence of changed risk. The current client-facing policy or summary must be available on the SSAH website and on request. Material changes require updated notices and, where necessary, fresh consent.