Veterinary AI tools may process consultation recordings, client details, medical histories, diagnostic results, and draft medical records. Before choosing one, a clinic should know how that information is used, where it is stored, who can access it, and when it is deleted.
Privacy, security, and record keeping are related but different. Privacy governs how personal information may be collected and used. Security covers the safeguards that protect it. Record-keeping rules determine which information the clinic must preserve.
This guide explains the essential questions to ask a veterinary AI provider and the standards that can help verify its answers. For a broader assessment of features, workflows, and integrations, see our complete veterinary AI scribe buying guide.
Key takeaways
|
Is clinic data used to train AI models?
The answer depends on the provider. Clinics should confirm whether consultation recordings, transcripts, uploaded files, corrections, prompts, or generated documents are used to train or evaluate AI systems.
Privacy, encryption, and model training are separate issues. Information can be encrypted while still being permitted for training under a provider’s terms.
The provider should explain whether training or evaluation occurs, which information is involved, whether people may review it, and whether the same restrictions apply to third-party AI providers.
Avoid relying on a verbal assurance or a broad statement that information is “kept private.” Permitted uses should be clearly stated in the contract or privacy policy.
CoVet states in its Privacy Policy that it does not use customer data to train or fine-tune AI models and that processing by AI providers is limited to delivering the service.
Where are recordings and records stored?
A clinic should know where each type of information is stored and where it may be processed. Information can be stored in one region while support teams, cloud services, or other subprocessors access it from another.
Confirm the arrangements for recordings, transcripts, uploaded files, generated documents, account information, logs, and backups. Clinics should also know whether they can select a hosting region, whether information crosses national borders, and which third parties process it.
Storage location matters because cross-border processing can introduce additional legal and contractual requirements. A provider should maintain a current list of subprocessors and explain what each one does.
CoVet states that it uses Google Cloud Platform and encrypts information in transit and at rest. Current details are available on the CoVet Security page.
Is encryption enough to protect veterinary information?
No. Encryption protects information while it is being transmitted and stored, but it does not control every way information could be exposed or misused.
A complete security programme should also cover individual user accounts, strong authentication, role-based access, removal of former employees, activity logs, vulnerability management, security testing, and incident response.
Access should reflect each person’s role. A veterinarian, technician, student, locum, practice manager, and outside contractor may not need the same permissions.
Under Canada’s PIPEDA safeguards principle, organizations must protect personal information according to its sensitivity. Appropriate safeguards can include limited access, staff training, passwords, encryption, security updates, and regular testing.
Which security standards matter?
Independent certifications and audit reports can show whether a provider has established formal security controls and tested how they operate. They do not eliminate risk, but they provide stronger evidence than a general claim that a platform is secure.
ISO/IEC 27001
ISO/IEC 27001:2022 is the international requirements standard for an information security management system. It covers how an organization establishes, maintains, and continually improves its approach to managing information-security risks.
Confirm that the certification is current, issued by an accredited certification body, and covers the products and services the clinic will use.
SOC 2 Type II
A SOC 2 examination evaluates controls relevant to security, availability, processing integrity, confidentiality, or privacy. A Type II report examines how the specified controls operated over a defined period.
SOC 2 is an examination and report, not a certification. Its Trust Services Criteria are established by the American Institute of Certified Public Accountants.
The full report is usually confidential, but a provider should have a process through which qualified customers can review it.
Penetration testing
Penetration testing looks for technical weaknesses that could be exploited. Ask whether an independent specialist conducts the testing, how often it occurs, what systems are included, and how serious findings are corrected.
Certifications, audit reports, and penetration tests serve different purposes. Together, they provide a more complete view of how a provider manages security.
What should a data-processing agreement cover?
A data-processing agreement should define how a provider may handle personal information on the clinic’s behalf. It should cover permitted uses, confidentiality, security safeguards, subprocessors, incidents, international transfers, and what happens when the service ends.
Under Article 28 of the GDPR, a controller may use only processors that provide sufficient guarantees of appropriate technical and organizational safeguards. The processing must also be governed by a binding contract or other legal act.
At minimum, the agreement should explain:
Why and how information may be processed
Which types of information are involved
Which subprocessors may receive it
How subprocessor changes are communicated
How quickly the provider reports a security incident
How it supports applicable privacy requests
What happens when the contract ends
Which safeguards apply to international transfers
The contract should also make ownership clear. Clinics should retain ownership of the information they submit and the records produced from it.
CoVet’s Terms and Conditions incorporate its Data Processing Agreement where CoVet processes personal data on behalf of a clinic, practice, or organization.
How should retention and deletion work?
A provider should keep personal information only as long as it is needed for its stated purpose, subject to legal and contractual obligations. Consultation audio, transcripts, approved records, logs, and backups may follow different retention schedules.
Clinics should confirm the default retention period for each type of information, whether that period can be changed, who can delete information, how backups are handled, and what happens when the service ends.
The Office of the Privacy Commissioner of Canada advises organizations to retain personal information only as long as needed for its identified purpose and to establish clear retention and destruction procedures.
Deleting a temporary recording is not the same as deleting the approved medical record. The clinic’s professional record-keeping obligations may require the final record to remain in the practice management system for much longer. Our veterinary record-keeping software guide explains how documentation tools and the PMS work together to preserve the clinical record.
A provider should also explain what “delete” means. Removal from the user interface may not immediately remove information from every backup or security log. Any remaining copies should be time-limited, protected from normal use, and governed by a documented process.
Does a clinic need consent to record consultations?
Recording requirements vary by jurisdiction and by how the recording is collected, used, retained, and shared. Clinics should review applicable privacy, recording, employment, contractual, and veterinary-regulatory requirements.
Consent should be clear enough that a client understands:
That the consultation may be recorded
Why the recording is being made
How it will be used
How long it may be retained
What happens if they decline
The clinic also needs a practical alternative for clients who do not consent.
Because recording laws differ significantly between jurisdictions, clinics should obtain advice based on where they operate rather than relying only on a vendor’s standard consent language.
How do GDPR, PIPEDA, and HIPAA differ?
These frameworks do not apply in the same way, and none should be treated as a generic security certification.
GDPR
Under the GDPR, a clinic may act as the controller when it decides why and how personal information is processed. An AI provider may act as a processor when it handles that information according to the clinic’s instructions.
The clinic should identify its lawful basis for processing, establish the required controller-processor agreement, review subprocessors, manage applicable privacy rights, and assess international transfers. The full requirements are set out in the General Data Protection Regulation.
PIPEDA
Canada’s PIPEDA fair information principles cover accountability, consent, limited collection and use, safeguards, access, and retention. Provincial private-sector privacy laws may apply instead of or alongside PIPEDA, depending on the clinic’s location and activities.
Safeguards must reflect the sensitivity, amount, format, distribution, and storage of the information involved. Personal information should also be kept only as long as it serves the purpose for which it was collected.
HIPAA
HIPAA applies to defined covered entities and business associates in the US human healthcare system. An organization that does not meet either definition does not have to comply with the HIPAA Rules, according to the US Department of Health and Human Services.
Veterinary records are therefore not automatically governed by HIPAA simply because they are medical records. Other state privacy, recording, breach-notification, consumer-protection, employment, and professional record-keeping requirements may still apply.
There is also no official HIPAA certification. Providers should explain the safeguards and contractual measures behind their compliance claims rather than relying on an unsupported badge.
Veterinary AI security checklist
Before adopting a veterinary AI tool, get clear written answers to these questions:
Is clinic information used to train or evaluate AI models?
Do the same restrictions apply to third-party AI providers?
Where are recordings, transcripts, documents, and backups stored?
Is information processed or accessed from another country?
Is information encrypted in transit and at rest?
Does the platform support individual accounts, role-based access, and SSO?
Does the provider hold a current ISO/IEC 27001 certification and a SOC 2 Type II report?
Is a data-processing agreement available?
How long is each type of information retained, and how does deletion work?
Does every generated medical record remain subject to clinical review and approval?
A provider should be able to answer these questions directly and support the answers through contracts, security documentation, certifications, audit reports, and controls inside the product.
For a wider evaluation framework covering accuracy, workflows, integrations, and security, read our guide to choosing a veterinary AI scribe.
How does CoVet protect clinic information?
CoVet states that clinic information is encrypted in transit and at rest and that users retain ownership and control of their data. Its security programme includes:
ISO/IEC 27001 certification
SOC 2 Type II
Single sign-on
Google Cloud infrastructure
Regular penetration testing
Vulnerability assessments
DDoS protection
Clinics can review CoVet’s current safeguards and supporting resources on the CoVet Security page.
CoVet’s Privacy Policy states that customer data is not used to train or fine-tune AI models and is not sold or shared for marketing purposes. Its Terms and Conditions explain data ownership and how its Data Processing Agreement applies when CoVet processes personal data on behalf of a clinic or organization.
CoVet also keeps every generated medical record subject to review and approval by the clinical team. For more on how approved documentation moves into the patient file, see How Veterinary AI Works with Your Existing Practice Management Software.
Keep the clinic in control
The right veterinary AI tool should reduce documentation work while leaving the clinic in control of its information.
Before recording the first consultation, know what the tool collects, why it needs it, where the information goes, who can access it, and when it is deleted. Then verify those answers through the provider’s contract, DPA, certifications, audit evidence, and product controls.
Security should be clear before adoption, not something the clinic has to piece together afterward.
Frequently asked questions
Is veterinary clinic data used to train AI models?
It depends on the provider. Confirm whether recordings, transcripts, files, corrections, prompts, or generated records are used for training or evaluation, and ensure the answer appears in the provider’s contract or privacy policy.
CoVet states that it does not use customer data to train or fine-tune AI models.
Does HIPAA apply to veterinary records?
Not automatically. HIPAA applies to defined covered entities and business associates in the US human healthcare system. Veterinary clinics may still be subject to state, contractual, privacy, recording, and professional requirements.
What is the difference between ISO/IEC 27001 and SOC 2 Type II?
ISO/IEC 27001 is a certifiable international standard for information security management systems. SOC 2 Type II is an independent examination and report on how specified controls operated over a defined period.
How long should consultation recordings be retained?
There is no universal period. Recordings should generally be retained only as long as needed for their stated purpose, subject to legal and contractual requirements. The approved veterinary record may need to be kept for longer than the temporary audio used to prepare it.
Sources
ISO/IEC 27001:2022: Information security management systems, International Organization for Standardization
Trust Services Criteria, American Institute of Certified Public Accountants
General Data Protection Regulation, European Union
PIPEDA fair information principles, Office of the Privacy Commissioner of Canada
Covered Entities and Business Associates, US Department of Health and Human Services
This article provides general information and is not legal advice. Privacy, recording, and veterinary record requirements vary by jurisdiction. Clinics should obtain advice based on their location and circumstances.
About the Author

Iain MacNeil
Iain MacNeil is the Content Manager at CoVet. He's the one behind most of what you read here (the copy, the guides, the launch emails, the brand voice) and he's spent the last ten-plus years turning complicated things into stuff people actually want to read. He studied Creative Writing at Concordia, lives in Montreal, and can still land a kickflip despite being in his mid-30s.
)
)
)
)
)