Skip to content
This feature is in beta. It may behave unexpectedly.

Consent for AI processing

Two consents, not one: the clinic accepts the data-processing agreement, and the patient — separately, and only for recording — agrees to the visit being recorded.

Required permissions:
Clinic AdminPractitioner
Reviewed: 2026-08-24

AI in Heltio rests on two separate consents, and it is worth keeping them apart.

The first — the clinic towards Heltio. Before any AI feature runs, someone with admin rights accepts the AI Sub-processors — Data Processing Agreement. That is a one-off consent, at the level of the whole clinic.

The second — the patient towards the clinic, for recording only. A visit recording is the one piece of material that cannot be de-identified before it is sent. That is why recording needs the patient's separate, documented consent — and why nothing else does.

Open AI settings

How to do it

01

Accept the processing agreement on behalf of the clinic

Settings → AI Features → View disclosure. The document lists every provider separately: who they are, what they are for, which region they operate in and what the retention is. The accept button unlocks only after you scroll to the end — until then it reads "Please scroll to read the full disclosure."

Once saved, the date stays on the page: Data Processing Agreement accepted on.

02

Record the patient's consent to being recorded

The AI Scribe panel in the active session shows Audio-recording consent required until the patient has given it. Click Record patient's consent.

The dialog states plainly what you are confirming: "By recording this consent you confirm the patient has verbally agreed to audio recording of their visits. It is stored durably and can be revoked at any time." Once saved, the panel shows Audio-recording consent on file.

03

Confirm consent before every recording

Consent on the patient card is not enough on its own. Before each recording you also tick The patient has verbally agreed to this recording. — only then does Start recording become active. Two layers instead of one: consent given once does not turn into silent permission for everything that comes later.

04

Show the patient what is on record

In the patient portal, on the privacy tab, the My Consents section lists every consent with a status of Active or Revoked and a date. The recording consent appears there as Visit audio recording (AI transcription). The patient can withdraw it themselves with Revoke.

Consent can be withdrawn by the patient in the portal or by you in the panel — with Revoke consent. The dialog warns that "Revoking removes this patient's audio-recording consent and immediately deletes any un-applied recordings, transcripts and drafts for them. This cannot be undone."

What has already entered the record does not disappear: the content of a note you accepted stays — it is part of the medical record and follows the ordinary retention rules.

Recordings are also deleted without any withdrawal:

  • after a draft is applied — the audio is deleted immediately;
  • unused recordings — after 30 days;
  • transcripts and drafts that were never applied — after 90 days;
  • an interrupted recording (closed browser tab, phone that went to sleep) — marked failed after 24 hours; the audio never left the device.

Each of these events leaves an entry in the audit log — from AI Scribe session started to AI Scribe audio deleted.

When something doesn't work

Warning

Accept the AI data-processing disclosure before using AI Scribe.

What this means: The data-processing agreement has not been accepted in the clinic yet.

What to do: Ask your administrator for step 1. Without it, no AI feature runs at all.
Warning

Audio-recording consent is required before recording.

What this means: The patient has no recorded consent to being recorded.

What to do: Ask the patient, then use **Record patient's consent**. Recording without that step is blocked on the server, not merely hidden in the interface.
Warning

Audio-recording consent was revoked for this patient.

What this means: The patient withdrew consent — themselves in the portal, or through you.

What to do: Recording again needs a fresh conversation with the patient and consent recorded again. Any earlier un-applied recordings are already deleted.
Info

Consent was revoked; this recording was discarded.

What this means: Consent stopped applying while the recording was being processed.

What to do: This behaviour is intentional. Document the visit by hand.

Who has access

Clinic Admin Practitioner

The processing agreement is accepted by the clinic owner or an admin — other roles see "Only clinic owners and admins can manage AI settings." The patient's recording consent is recorded and withdrawn by the practitioner conducting the visit; the patient withdraws it themselves in the portal.

Was this article helpful?

Didn't find an answer? Write to us.

Open the contact form