Residents are already using AI scribes, with or without a policy — the tools are cheap, the documentation burden is real, and app stores don't check with the GME office. That leaves program directors doing vendor diligence, sometimes retroactively. Here is the checklist we'd want a director to use on any vendor, including us. A serious vendor answers all twelve in writing without a call scheduled first.
Security and data handling
- Where does the audio go, and when is it deleted? Get specifics: on-device vs. cloud transcription, retention windows, deletion on demand. "Enterprise-grade security" is not an answer; a data-flow diagram is.
- Is protected health information used to train models? Yes or no, in the contract, not the marketing site. (tebIQ's answer, for the record: encrypted in transit and at rest (AES). Never used for training. Never sold.)
- Will you sign a BAA, and at what tier? Some vendors gate the BAA behind enterprise pricing, which means residents on personal accounts may be using the product outside any agreement your institution holds. Ask specifically what agreement covers an individual resident's personal subscription.
- What third-party attestations exist? SOC 2 reports, penetration-test summaries, subprocessor lists. Also ask what they don't have yet and when it's expected — the honest answer to that question tells you more about the vendor than the certificate list does.
Supervision and the integrity of training
- Does the tool change who authored the note? The resident must remain the author of record, and attending attestation requirements are unchanged by any drafting tool. Ask the vendor to affirm this in their documentation — and be wary of any feature that auto-finalizes or auto-submits notes.
- Can the draft inflate documentation? Ask directly: can the system generate exam findings, review-of-systems elements, or time attestations that the encounter doesn't support? Every generative system can; the differentiating answer is what the vendor does about it (verbatim transcripts, traceability from note text back to what was said, review-forcing workflows).
- What's the position on trainees using it for notes they haven't learned to write yet? A thoughtful vendor has thought about this. There's a defensible argument that interns should write their first hundred H&Ps largely by hand; a vendor who has never considered the question is selling to your residents without thinking about them as trainees.
Attribution and oversight
- Can the program see usage? If residents use it under a program arrangement, directors need aggregate visibility — who's using it, how much, on what note types — without reading the clinical content of private drafts. Ask what the administrative view actually shows.
- Who is accountable when the note is wrong? The signing physician, always — but ask how the vendor supports error investigation. Can you reconstruct what was transcribed vs. what the model added vs. what the resident edited? That audit trail is the difference between a learnable event and an unanswerable one.
- What happens to a resident's data when they graduate or the program terminates the arrangement? Export, deletion, and portability terms, in writing.
Commercial honesty
- Is pricing public? Vendors who won't publish pricing are telling you how the relationship will go.
- What does the product not do? The most informative question on the list. Every honest vendor has a ready answer; the vendors to avoid claim the product has no meaningful limitations.
---
We're building a director-facing console for exactly the oversight questions above — program-level visibility designed with the supervision chain, not around it. If you'd like to pressure-test these twelve questions against tebIQ's answers, we'll send them in writing, no call required: tebiq.com.