🎙 Ambient AI Listening Consent & Privacy Simulator
This simulation allows users to explore the process of obtaining patient consent and maintaining privacy when using an 'listening' AI during a medical consultation.
Disclosing the Ambient AI Scribe
Placeholder lead: patient is told an AI scribe will listen and how it works.
- Always: Disclosure required (before any recording)
- Purpose: Explains (what the AI scribe does)
- Pre-visit: Timing (before conversation starts)
- Verbal + sign: Format (spoken and posted notice)
What disclosure covers
Placeholder: staff state that audio will be captured and processed by AI.
Placeholder: explains transcription, note drafting, and physician review.
Placeholder: clarifies that participation is optional at this stage.
Why disclosure matters
Placeholder: transparency builds trust before any recording occurs.
Placeholder: sets up the explicit consent decision that follows.
Explicit Consent Before Recording Begins
Placeholder lead: patient chooses to allow or decline ambient recording.
- Verbal/written: Consent type (explicit, documented)
- Always offered: Decline option (no penalty for declining)
- Manual notes: Alternate path (used if declined)
- Logged: Documentation (consent recorded in chart)
The consent decision
Placeholder: patient affirmatively opts in or opts out of recording.
Placeholder: decision is timestamped and stored with the visit record.
If consent is declined
Placeholder: physician reverts to manual documentation, no audio captured.
Placeholder: care quality is unaffected by declining the AI scribe.
Audio Capture, Transcription, Note Generation
Placeholder lead: consented audio flows through transcription into a draft note.
- 3: Pipeline steps (capture, transcribe, draft)
- Required: Human review (physician signs off)
- Automated: Processing mode (AI-assisted drafting)
- Skipped: Declined path (manual notes instead)
Processing the conversation
Placeholder: audio is transcribed and summarized into a structured note.
Placeholder: the physician reviews and edits before finalizing.
Keeping the manual alternative live
Placeholder: manual documentation remains fully available at every visit.
Retention, De-Identification, and PHI Protections
Placeholder lead: audio is typically deleted after processing; the note is retained.
- Deleted: Audio default (after transcription completes)
- Kept: Note retention (part of medical record)
- Applied: De-identification (before any secondary use)
- End-to-end: Encryption (in transit and at rest)
What is deleted vs. retained
Placeholder: raw audio is processed then deleted under minimal retention.
Placeholder: extended retention stores audio longer, raising exposure risk.
Safeguards applied throughout
Placeholder: encryption, de-identification, and access control gate each step.
Consent Plus Transparent Handling Resolves the Core Concern
Placeholder lead: informed consent and clear retention policy protect patient privacy.
- Documented: Consent obtained (before recording)
- Disclosed: Retention policy (minimal by default)
- 3 active: Safeguards (encryption, de-ID, access control)
- Preserved: Patient trust (transparent workflow)
Why this resolves the privacy concern
Placeholder: explicit consent removes the core objection to ambient listening.
Placeholder: transparent retention policy limits unnecessary data exposure.
What good practice looks like
Placeholder: disclose, obtain consent, process minimally, protect PHI always.
Placeholder highlight: consent plus minimal retention is the privacy-safe default.
This simulation allows users to explore the process of obtaining patient consent and maintaining privacy when using an 'listening' AI during a medical consultation.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install