Most AI-powered medical record summarization tools on the market today—EvenUp, Supio, Wisedocs, Precedent, Superinsight, and the rest—operate the same way. You upload your client's protected health information to a shared cloud. Their AI processes it on pooled infrastructure, often through third-party model providers. Then you download the result.
This workflow has become so normalized that most firms never pause to consider what they are actually doing: transmitting the most sensitive category of personally identifiable information across the internet to servers they do not control, cannot audit, and have no physical access to.
There is a better way. And as both HIPAA enforcement and state bar ethics opinions tighten around cloud-stored client data, the argument for keeping records in a dedicated, auditable environment under your own Business Associate Agreement is becoming harder to ignore.
What Happens When You Upload Medical Records to the Cloud
When you send a PDF of medical records to a cloud-based AI platform, the following things occur:
- The file is transmitted over the internet, typically encrypted in transit via TLS.
- It is received by the vendor's servers—usually hosted on AWS, Google Cloud, or Azure.
- The records are processed by one or more AI models, often including third-party models from OpenAI, Anthropic, or Google.
- Extracted text and structured data may be stored temporarily or permanently on the vendor's infrastructure.
- In some cases, your data may be used to improve the vendor's AI models, unless you have explicitly opted out.
Each step in this chain introduces a point of risk. Not theoretical risk—the kind of risk that has already resulted in data breaches affecting millions of healthcare records.
The HIPAA Question
HIPAA's Security Rule requires covered entities and their business associates to implement safeguards protecting the confidentiality, integrity, and availability of electronic protected health information (ePHI). Law firms processing medical records typically fall under the business associate umbrella.
Cloud-based AI vendors generally address HIPAA compliance by executing Business Associate Agreements (BAAs) with their customers. However, a BAA is a contractual instrument, not a technical one. It does not prevent a breach. It merely establishes liability after one occurs.
Key HIPAA Consideration
Under the HIPAA Security Rule (45 CFR 164.312), entities must implement access controls, audit controls, integrity controls, and transmission security. When data resides on a third-party cloud platform, the law firm is relying entirely on the vendor's implementation of these controls—controls they cannot independently verify.
The Sub-Processor Problem
Most cloud AI platforms do not run their own AI models. They call APIs from providers like OpenAI, Anthropic, or Google. This means your client's medical records may traverse multiple third-party systems, each with its own data handling policies, retention schedules, and security posture.
When you signed a BAA with your medical chronology vendor, did that BAA extend to every sub-processor in the chain? In many cases, the answer is unclear. And "unclear" is not a comfortable position when a state bar disciplinary committee is reviewing your data handling practices.
State Bar Ethics and Cloud Storage of Client Data
The American Bar Association's Formal Opinion 477R (revised 2017) addresses a lawyer's duty to protect client communications and data. While it acknowledges that cloud computing is permissible, it imposes a duty of competence that requires lawyers to understand the technology they use and its associated risks.
"A lawyer generally may transmit information relating to the representation of a client over the internet without violating the Model Rules of Professional Conduct where the lawyer has undertaken reasonable efforts to prevent inadvertent or unauthorized access."
The phrase "reasonable efforts" is the operative standard. What constitutes "reasonable" is evolving, and it is evolving toward more stringent requirements. Several state bar associations have issued opinions expanding on this duty:
- California Formal Opinion 2010-179 requires lawyers to consider the sensitivity of the data when choosing technology solutions. Medical records containing PHI fall into the highest sensitivity category.
- New York State Bar Association Opinion 842 permits cloud storage but requires lawyers to ensure they can access the data, know where it is stored, and understand how it is protected.
- Florida Bar Opinion 12-3 states that attorneys must exercise due diligence before using cloud services, including understanding the provider's security practices.
The direction of these opinions is clear: the more sensitive the data, the greater the burden on the attorney to justify the chosen method of storage and processing. Medical records—containing diagnoses, treatments, mental health history, substance abuse records, and other deeply personal information—represent the highest tier of sensitivity.
The Dedicated-Enclave Alternative
The risk chain above comes from pooling. One vendor, many firms, shared infrastructure, sub-processors nobody named in the BAA. The alternative is a single-tenant environment that exists for your firm, with a contract and a named person behind it. That is how CaseBridge processes records:
- A dedicated HIPAA-eligible enclave—your records are processed and stored in an environment segregated by firm, operated under a Business Associate Agreement with you, not in a multi-tenant pool.
- No model training on your records—your clients' files are used to produce your deliverables and nothing else.
- A fixed retention schedule—records are purged 30 days after delivery unless your firm gives written retention instructions.
- Named access—access is limited to your firm and your assigned CaseBridge reviewer, and every deliverable carries that reviewer's signature and an attestation record.
- An audit trail you can ask for—who touched the file, when, and what they signed.
- Private deployment when you need it—for larger firms, the engine can be quoted to run inside the firm's own cloud account under the firm's own agreements.
Why Most Vendors Pool Everyone's Records
You may be wondering: if a dedicated environment is clearly the more defensible option, why do most medical record AI vendors run one shared cloud for every customer?
The answer is business model, not technology. Pooled delivery allows vendors to:
- Charge per-case or per-page fees at software margins, with no person accountable for any one file
- Aggregate data from all customers to train and improve their models
- Avoid the cost of segregating environments and retention schedules by client
These are advantages for the vendor, not the customer. The pooled model exists because it is more profitable for the company selling the service, not because it is better or safer for the firm using it.
What to Ask Any Vendor
Whatever you buy, get written answers to six questions before PHI moves: Where exactly are my records stored, and is that environment shared with other customers? Who can access them, by name or role? How long are they kept, and what triggers deletion? Are they used to train any model? Which sub-processors see them, and does my BAA reach each one? Who signs the work, and what record exists of that review?
CaseBridge answers them this way: a single-tenant HIPAA-eligible enclave under a BAA with your firm; access limited to your firm and your assigned reviewer; purge 30 days after delivery, or your written instructions; no model training; no sub-processor outside the enclave sees your records; and a named paralegal or legal nurse consultant signs every deliverable, with the attestation kept on file. There is nothing for your office to install, and the cost of processing is inside the per-case price rather than a separate line you have to track.
The Trajectory of Enforcement
HIPAA enforcement has intensified steadily over the past five years. The HHS Office for Civil Rights collected over $4 million in penalties in 2024 alone for violations related to inadequate ePHI protections. State attorneys general have also begun pursuing independent actions under state health privacy laws.
Simultaneously, AI-specific data privacy regulations are emerging at both the state and federal level. The intersection of AI processing and healthcare data is receiving particular scrutiny. Firms that proactively adopt architectures that keep PHI under their direct control will be better positioned as this regulatory landscape continues to develop.
The Bottom Line
Pooled cloud AI is convenient. It requires no setup and no thought about where the data goes. But convenience has a cost, and in this case, that cost is measured in regulatory risk, ethical exposure, and the loss of control over your clients' most sensitive information.
Keeping records in a dedicated environment, under your own agreement, with a named person accountable for every file, is not merely a privacy-conscious choice. It is increasingly the professionally responsible one.
Records in a Dedicated Enclave, Signed by a Person
Every CaseBridge case is processed in a single-tenant HIPAA enclave under a BAA with your firm, purged 30 days after delivery, and signed by a named reviewer. Case reviews from $695.
See Case Review and Package Pricing