Are AI scribes like Lyrebird Health safe to use in general practice?
AI scribes such as Lyrebird Health can be used safely in Australian general practice, but the safety is configured, not bought. It rests on four things: informed patient consent, a documented answer on where recordings are processed and stored, control over which staff and devices use the tool, and a doctor reviewing every note before it enters the record.
A scribe listens to the consultation and drafts the clinical note, which the doctor edits and files. The appeal is not mysterious: documentation is a major time cost in general practice, and note-taking competes directly with the patient for the doctor's attention. Communication coaches make the same point about any professional conversation: presence, eye contact, voice and attention, is most of what the other person actually experiences. Understood that way, the scribe's real product is not the note; it is giving the doctor back the room.
Safe adoption comes down to four questions, settled before the first consult is recorded. First, consent: patients must be told what the tool does and asked before recording starts, in plain words a receptionist could deliver, with signage and a privacy policy to match. Under the Privacy Act, a recorded consultation is a collection of sensitive health information, and the consent must be real, informed and refusable. Verbal consent noted in the record is the common pattern, but the practice should decide its own standard and apply it every time, including in telehealth consults, where recording is even easier to forget to mention.
Second, the data path. Where is audio processed, where do drafts and transcripts live, how long is anything retained, and can the vendor answer those questions in writing? Ask for the answers before signing, put them in the privacy policy, and revisit them when the vendor updates terms. This is not exotic diligence; it is the same question a practice should ask of any system that touches patient data, applied to a new category.
Third, access control. The scribe should run only on practice-managed devices, enrolled in Intune, with access granted per role through Entra ID rather than shared logins, and it belongs inside the same security baseline as everything else, multi-factor authentication included. The principle is the one we keep returning to with Microsoft Copilot: permissions and governance first, rollout second, because an AI tool inherits whatever access sloppiness already exists. It also belongs in the offboarding checklist, so a departing doctor's scribe access ends the day they leave, along with everything else.
Fourth, review. The AI's note is a draft, always. The treating doctor reads, corrects and owns every note before it is filed, and the practice should say so in writing as policy. Accuracy is good and improving, but it degrades in exactly the situations that matter clinically: heavy accents, noisy rooms, interrupted consults, complex multi-issue presentations. A review habit costs seconds; an unreviewed error in a record can cost far more. The review habit is also where the tool earns trust properly: doctors who correct drafts for a few weeks learn precisely where it is strong and where it stumbles, which is far safer than either blanket faith or blanket refusal.
The honest caveats. Some patients will decline, and the workflow must make that easy rather than awkward. Subscriptions are per doctor, so the economics depend on how much documentation time each doctor actually loses today; a practice with light documentation burden may gain little. And a scribe fixes note-taking, not a struggling appointment book or an ageing server; it deserves to be adoption decision number three or four, not a distraction from foundations. None of these caveats is a reason to avoid scribes; they are the difference between adopting a tool and absorbing a risk.
The sensible path is a contained pilot: one or two doctors, managed devices, an agreed consent script, a review checklist, and a decision date. Run it for a defined period, ask patients and doctors what changed, then expand or stop on evidence. If you want help setting up the governance, the device controls or the pilot itself, call us on 1800 456 567, or start with our free Essential Eight Cyber Security Scorecard to check the foundations first.
Get the governance right before the rollout.
Identity, permissions and managed devices first, AI second. We set up the foundations that make tools like scribes and Copilot safe to adopt.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business