Several California patients filed a proposed federal class-action lawsuit against Sutter Health and MemorialCare Medical Foundation, alleging the providers used Abridge AI to record, transcribe, and process doctor-patient conversations without informed consent. The complaint, filed in San Francisco, says the ambient clinical documentation tool captured confidential discussions during visits over the past six months, including medical histories, symptoms, diagnoses, medications, and treatment plans, and that patients were not clearly told their conversations would be recorded, transmitted outside the exam room, or handled by third-party systems.
The lawsuit alleges violations of California privacy and medical confidentiality laws, unfair business practices statutes, and federal wiretapping law. Reporting on the case says Abridge’s software converts live speech into text and generates structured clinical notes, and its rapid adoption by major health systems has intensified scrutiny over notice, consent, retention, access controls, HIPAA compliance, Security Rule obligations, patient opt-out rights, and whether providers need business associate agreements when vendors store recordings or transcripts.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
On April 8, 2026, several California patients filed a proposed federal class-action lawsuit in San Francisco alleging that Sutter Health and MemorialCare unlawfully used Abridge AI to record, transcribe, and process doctor-patient encounters without informed consent, in violation of state and federal law.
According to the complaint, medical staff at Sutter Health and MemorialCare used Abridge AI during patient visits over the prior six months, capturing and processing confidential doctor-patient conversations and identifiable medical information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcearstechnica.com
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.