โ†
AI for Mental & Behavioral Health Clinicians
Aware ยท M2 ยท lesson 2 of 17 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
AI Hallucinations in Clinical Documentation
๐Ÿ“–
now learning

AI Hallucinations in Clinical Documentation

15 min

Somewhere in your EHR right now, or in a colleague's, there is a signed and locked progress note describing a CSSRS score the client never gave, a diagnosis the clinician never made, or a homework assignment that did not happen, and the clinician who signed it does not know it is there. That is what an AI hallucination looks like in clinical documentation: not gibberish, but a fluent, confident, perfectly formatted falsehood sitting inside a legal record under your signature. This lesson takes you through a line-by-line audit of one fictionalized AI-generated note with three planted fabrications, explains exactly why language models invent clinical content (and why the inventions are always plausible), and leaves you with a Three-Item Pre-Signature Protocol you can run in ninety seconds on every AI draft before it becomes a permanent part of someone's medical record. By the end, you will know how to catch the lie before the lock.

The Confident Intern Who Never Says "I Don't Know"

Carry this analogy through the lesson: a generative AI scribe is a brilliant intern with a catastrophic personality flaw. The intern has read every textbook, writes flawless clinical prose, formats a SOAP note better than most supervisors, and works at 2 AM without overtime. But the intern is constitutionally incapable of saying "I don't know." Asked to complete a note from a thin transcript, the intern will not leave a blank. It will fill the blank with the most statistically plausible thing a note like this usually says, and it will do so in the same fluent, confident voice it uses for everything true. The terrifying part is not that the intern lies. It is that the lies are indistinguishable in tone, formatting, and confidence from the truth on either side of them.

This is not a bug a vendor will patch next quarter. It is how the technology works. A large language model is a prediction engine: given the words so far, it produces the most likely next words based on patterns in its training data. It has no concept of "what happened in your session" as a fact to be checked. It has only "what notes like this usually contain." When your transcript covers the content of a session thinly, when audio dropped out, when you spoke in shorthand, when the session went somewhere notes rarely go, the model does what prediction engines do: it predicts. And in behavioral health, the most likely next words are often clinically loaded. Notes about anxious clients usually mention coping skills homework, so the model adds one. Intakes with trauma content usually carry a PTSD code, so the model supplies one. Risk-adjacent sessions usually document a screen, so the model invents a score. The hallucination is never random. It is always the plausible thing, which is exactly why your tired 9:54 PM eyes slide right over it.

One in three psychologists now use AI at least monthly, per the APA Practitioner Pulse Survey's 2026 wave, and the scribe market, Mentalyc, Eleos Health, Upheal, Twofold, Heidi, TherapyNotes' built-in AI, is competing hard on accuracy. The better products hallucinate less than a raw chatbot. None hallucinate never. Your protocol cannot be "pick a good vendor." It has to be "audit every draft as if the intern made something up, because sometimes it did."

The Note Under Audit: A Fictionalized Draft With Three Lies in It

Here is the scenario, fictionalized but assembled from failure modes clinicians report. Maria, our Oakland LCSW, sees a 56-year-old client with C-PTSD (F43.10) for a 90837. The session was heavy: the client processed grief about an estranged sibling, mentioned passively that "some days I wonder what the point is," and Maria followed up clinically, assessed the statement in context, and determined it reflected demoralization without suicidal ideation, plan, or intent. No formal screening instrument was administered; her clinical interview covered it. No homework was assigned; the client was too activated and Maria deliberately closed with grounding instead. The AI scribe, working from session audio, produced a clean draft. Buried in its four tidy paragraphs are these three sentences:

"Columbia Suicide Severity Rating Scale administered; client scored low risk (CSSRS score: 1), denying ideation, plan, or intent." And later: "Client meets criteria for Major Depressive Disorder, recurrent, moderate (F33.1), in addition to PTSD." And in the plan: "Client agreed to complete a daily thought record and practice the 5-4-3-2-1 grounding technique twice daily; homework reviewed and assigned."

Read those three sentences again, slowly, the way an auditor would. Every one is plausible. Every one is the kind of sentence that belongs in a note like this. And every one is false. No CSSRS was administered, so there is no score; the model heard risk-adjacent language and supplied the documentation a risk-adjacent session statistically tends to contain. No MDD diagnosis was made; the model heard depressive content and grief and reached for the code that usually accompanies it. No homework was assigned; the model knows CBT-flavored notes end with thought records the way emails end with "best regards." This is the intern filling blanks with the plausible. If Maria signs this draft, three fabrications become legal fact.

Why Each Lie Is Expensive: The Score, the Diagnosis, the Homework

Take the invented CSSRS score first, because it is the most dangerous sentence an AI can write. A documented risk screen that never happened cuts both ways, and both ways are catastrophic. If this client later attempts suicide, the record shows a formal screening instrument administered and scored at the precise session where ideation-adjacent language appeared, and Maria will be asked, in deposition, to produce the instrument, describe the administration, and explain her scoring. She cannot, because it did not happen. The note that was supposed to protect her becomes the exhibit against her. And clinically, an invented "low risk, score 1" in the chart can mislead every future reader, the covering clinician, the psychiatrist, the crisis team, into trusting a risk assessment that was never performed. This is why the rule from the previous lesson is absolute and bears repeating verbatim: AI never scores the CSSRS, never assigns a risk level, never makes the duty-to-protect determination. AI may format risk documentation only after the clinician's own assessment, and it must never originate one. A hallucinated risk score is the worst-case collision of these rules: the AI did not just score the instrument, it invented the administration.

The invented diagnosis is the slow-burn liability. An F33.1 that Maria never formulated, signed into the record, propagates: it flows to the claim, to the payer's records, to any future records request, potentially to life insurance underwriting and custody proceedings the client has not yet imagined. Diagnoses are sticky. Removing one from a chart is far harder than never entering it. A payer audit comparing the diagnosis on the claim against the clinical formulation in the treatment plan will find a mismatch, and mismatches are how recoupment reviews start. And a diagnosis is the most license-weighted judgment a clinician makes; discovering, during a board inquiry, that the diagnosis of record was authored by a language model and ratified by a signature the clinician barely remembers is not a position anyone defends well.

The invented homework looks trivial next to those two, which is exactly why it teaches the most important habit. It is small, it is benign-sounding, and it is still a false statement in a legal record. If the client reads their own note, and clients increasingly do, under information-access rules, through portals, in records requests, they find a homework assignment they never received and a "client agreed" they never said. Now the client doubts everything else in the chart, and the therapeutic alliance absorbs the damage. In a utilization review, documented homework implies a treatment trajectory; a concurrent reviewer may ask about completion of assignments that never existed. The lesson of the homework hallucination is that there is no harmless fabrication in a clinical record. The signature does not distinguish between big lies and small ones. It attests to all of them equally.

A hallucinated note is not wrong the way a typo is wrong; it is wrong the way perjury is wrong. The model invented testimony, and your signature swore to it.

Why the Model Invents Clinical Content: The Mechanics of Plausible Fabrication

To catch hallucinations reliably, you need to predict where they will appear, and for that you need the mechanism, not just the warning. Recall the mental model from Chapter 1: an LLM generates the statistically likely continuation of the text so far. Three properties of that process create the clinical hallucination pattern you just audited.

First, the model completes templates. It has absorbed millions of clinical-adjacent documents, and it knows the shape of a progress note: subjective, objective, assessment, plan; risk addressed; interventions named; homework assigned; follow-up scheduled. When your session's raw material does not fill every slot of the template, the model fills the slot anyway, because incomplete templates are statistically rare in its training data. The homework hallucination is a template completion. So is the invented screen: "risk language appeared, therefore the documentation slot for risk assessment gets filled."

Second, the model escalates fragments into formalities. It heard "some days I wonder what the point is" and Maria's clinical follow-up. It does not know the difference between a clinical interview that addressed risk and a formal instrument administration, but the formal version, named instrument, numeric score, structured denial, is how risk content most often appears in the documents it learned from. So the informal becomes formal in the retelling. The same mechanism turns depressive content into a coded diagnosis: clinical language gravitates, in training data, toward its most official form. Third, the model never flags its own uncertainty in the body of a note. A human intern unsure whether a screen was administered would ask. The model's architecture has no "ask" step inside a generated note; production-grade scribes mitigate this with confidence markers and placeholders, but the failure mode persists wherever the draft reads as finished prose. The practical consequence of all three properties: hallucinations cluster precisely where the stakes are highest, in the risk slot, the diagnosis slot, and the plan slot, because those are the most template-driven, most formalized parts of a behavioral health note. Your audit attention should be distributed accordingly, and that is exactly how the protocol below is built.

The Three-Item Pre-Signature Protocol

Here is the artifact this lesson builds toward, previewed now and assembled in the Applied Problem: a three-item check you run on every AI-drafted note, every time, before signing. It takes about ninety seconds once practiced, and each item targets one of the three hallucination mechanics you just learned.

Item one: verify every instrument, score, and scale. Scan the draft for the names of any measure (CSSRS, PHQ-9, GAD-7, PCL-5), any numeric score, any phrase like "administered," "screened," or "scored." For each one, ask: did I actually administer this, in this session, and is this the actual number? If you did not administer it, the sentence comes out entirely, not softened, deleted. If you did, the number must match your source document, not your memory. This item exists because the model escalates fragments into formal instruments, and because an invented score is the single most dangerous hallucination in behavioral health documentation.

Item two: verify every diagnosis and clinical conclusion. Scan for ICD-10 codes, diagnostic labels, and conclusion verbs: "meets criteria," "presents with," "consistent with," "ruled out." Each one must trace to a determination you actually made and can defend. A diagnosis you are still formulating does not belong in the note as settled; a diagnosis the model added because the content gestured at it comes out. This item exists because diagnoses are sticky, propagate to claims and future records, and are the most license-weighted sentences in the chart. Item three: verify every event and action. Scan the plan and the closing for things that allegedly happened: homework assigned, client agreed, releases signed, referrals made, safety plan reviewed, follow-up scheduled. Each is a factual claim about an event. If the event did not occur, the sentence is a fabrication regardless of how small it seems, and it comes out. This item exists because template completion plants plausible events in the slots your session left empty, and because the signature attests to small lies and large ones identically. Three items, three mechanics, ninety seconds. Scores, conclusions, events. That is the whole protocol, and it is short on purpose: a protocol you will actually run at 9:54 PM beats a comprehensive one you abandon by Thursday.

The Lock Is the Cliff: Why "Before Signing" Is the Whole Game

Every part of this lesson converges on one moment: the instant before you sign and the EHR locks the note. Up to that moment, a hallucination is a draft error, costless to fix, invisible to everyone, a non-event. After that moment, it is a permanent entry in a legal medical record, discoverable in litigation, auditable by payers, readable by the client, and attributable entirely to you. The note does not say "drafted by AI, lightly reviewed." It says your name, your license number, your attestation. SimplePractice, TherapyNotes, and every serious EHR maintain version history precisely because regulators and courts care what the record said and when; an unsigned draft with errors is hygiene, a signed note with fabrications is evidence.

This is why the cardinal rule of this entire program, which gets its full treatment in the next lesson, appears in every documentation lesson including this one: the clinician signs the note, and the signature is a legal attestation, not a formatting step. You read every word before signing. Not skim, read, because hallucinations are engineered by their very mechanics to survive a skim: they are fluent, well-placed, and plausible. You correct identified errors before signing, never after locking with an addendum if a pre-signature read would have caught it. And you never sign a note for a session that was not yours, because attestation requires the one thing the model also lacks: having been there.

There is also an asymmetry worth naming because it is the economic argument for the protocol. The AI draft saves you, say, ten minutes per note. The ninety-second protocol spends back fifteen percent of that saving. A single signed hallucinated risk score can consume, conservatively, dozens of hours of board response, attorney consultation, and audit defense, and that is the favorable scenario where no client was harmed. The protocol is not a tax on the time savings. It is the insurance premium that makes the time savings keepable. Clinicians who skip it are not saving ninety seconds; they are borrowing them at the worst interest rate in professional life.

The Applied Problem: Your Pre-Signature Protocol Card

Your artifact is the Pre-Signature Protocol Card: a card or half-page that lives where you sign notes, your monitor bezel, your laptop lid, a pinned note inside the EHR dashboard if your system allows it. It is the three-item protocol, personalized to your practice and written in your own imperative voice, because a protocol in your own words is one you actually run.

Step one: draft the card. Open a blank page and write three numbered lines, one per item, in command form. A strong version looks like: "1. SCORES: Every instrument and number, did I administer it, is this the real score? Not administered = delete the sentence. 2. CONCLUSIONS: Every diagnosis and 'meets criteria', did I make this determination and can I defend it? Not mine = delete. 3. EVENTS: Every homework, agreement, referral, safety-plan mention, did it actually happen? Did not happen = delete." Add a header line above all three: "Nothing is signed unread. The signature is my attestation." Add a footer naming your highest-risk zone from this lesson: "Hallucinations cluster in the risk slot, the diagnosis slot, and the plan."

Step two: test the card against the audit note. Go back to the fictionalized Maria draft in this lesson and run your card against its three planted fabrications. Item one must catch the CSSRS score, item two must catch the F33.1, item three must catch the thought-record homework. If your card's wording would let any of the three survive, tighten the wording until it would not. This is your verification pass: the card is not done when it reads well, it is done when it catches all three planted lies. Step three: run it live for one week. For every AI-drafted note you sign this week, run the card and tally, without flattering yourself, how many sentences you deleted or corrected. Most clinicians who do this exercise find at least one correction in the first ten notes, and that discovery, made safely before a signature instead of during an audit, is the moment this lesson becomes permanent. Done looks like: a dated card in your own words, three items mapped to scores, conclusions, and events, validated against all three planted fabrications, with one week of live tallies proving you actually run it.

Key Takeaways

  • An AI hallucination in clinical documentation is a fluent, confident, plausible falsehood, not obvious gibberish. The model is a brilliant intern who never says "I don't know": when the session material leaves a blank, it fills the blank with what notes like this usually say.
  • The three audit fabrications model the field's real failure pattern: an invented CSSRS administration and score, an invented diagnosis (F33.1) the clinician never formulated, and an invented homework assignment. Each is plausible, well-formatted, and false, which is why tired eyes slide over them.
  • A hallucinated risk score is the most dangerous sentence AI can write: it fabricates an assessment that misleads future readers and becomes the exhibit against you in litigation. AI never scores the CSSRS, never assigns a risk level, and never makes the duty-to-protect call; it formats risk documentation only after the clinician's own determination.
  • Invented diagnoses are sticky liabilities: they propagate to claims, payer records, and future records requests, and create the claim-versus-treatment-plan mismatches that start recoupment reviews. Invented homework proves there is no harmless fabrication, the signature attests to small lies and large ones equally.
  • Hallucinations cluster where stakes are highest, the risk slot, the diagnosis slot, and the plan slot, because those are the most template-driven parts of a note. The model completes templates, escalates informal fragments into formal instruments, and never flags its own uncertainty inside finished prose.
  • The Three-Item Pre-Signature Protocol targets each mechanic: verify every score and instrument, verify every diagnosis and conclusion, verify every event and action. Ninety seconds per note, sentences that fail come out entirely, and the protocol is short on purpose so you run it at 9:54 PM.
  • The lock is the cliff: before signing, a hallucination is a free correction; after signing, it is evidence under your legal attestation. Read every word, never skim, correct before locking, and never sign for a session that was not yours.