/3 min read/doctorstudio editorial
AI avatars for doctors: consent, privacy and what to ask before you record
What doctors should know before creating an AI avatar of themselves: how likeness and voice data are used, consent and verification, deletion rights, retention, and questions to ask any provider.
An AI avatar lets you publish patient-education videos without filming each one. You record a short video once, and software generates new videos of you speaking new scripts, in your own voice.
That convenience rests on something sensitive: a model of your face and voice. Before you record, it is worth understanding what you are handing over and what control you keep.
What an avatar is made from
Creating a digital-twin avatar usually needs:
- A source video of you speaking to camera, often 30 seconds to two minutes long.
- A face model derived from that video, used to render new footage.
- A voice model cloned from the audio, used to speak new scripts.
Your face and voice identify you. Many privacy laws treat this kind of data with extra care, and you should expect a provider to do the same.
Consent: proving it is really you
The biggest risk with avatars is impersonation: someone building an avatar of a doctor from a clip they found online. Responsible services prevent this with an identity check. You record a short consent statement or complete a live verification that matches the person in the source video.
Ask any provider:
- Is there a verification step before an avatar can be used?
- Can an avatar be created from someone else's footage?
- What happens if verification fails?
On DoctorStudio, every avatar goes through a verification step with our video-generation provider before it can render anything.
Where your data goes
An avatar platform usually relies on several providers, known as subprocessors: one generates the video, another stores files, another writes scripts. You should be able to see a list of them.
DoctorStudio, for example, uses HeyGen for avatars and voice, OpenAI for scripts, Replicate for illustrations, Cloudflare for file storage, MongoDB for account data and Resend for login emails. The full list and the purpose of each is in our privacy policy.
Deletion and retention
Two questions matter most:
- Can I delete my avatar, and what exactly is deleted? Deleting an avatar should remove it from the video provider and stop it being used, not just hide it in your dashboard.
- How long are my recordings and videos kept? Keeping a source video indefinitely has no benefit to you once the avatar exists.
DoctorStudio deletes your source recording 30 days after your avatar is ready, deletes finished reels 90 days after they are generated, and lets you delete an avatar at any time.
Your avatar, your words
An avatar speaks whatever script it is given. Treat it as you would your signature:
- Review every script before rendering. You are responsible for what the avatar says.
- Keep content educational, and avoid anything that reads as advertising or a personal diagnosis.
- Add a short disclaimer at the end of each video.
- Do not let anyone else use your account.
Should you tell viewers it is an avatar?
Transparency builds trust. Many doctors add a line to the caption such as "Presented with my AI avatar; script written and reviewed by me." Platforms are also introducing labels for AI-generated content, and it is sensible to follow them.
Questions to ask before you record
- Is there identity verification before an avatar can be used?
- Who are the subprocessors, and where is data stored?
- Can I delete my avatar and source video at any time?
- How long are generated videos kept?
- Is my likeness used to train other models?
- Who can see my videos before I share them?
If a provider cannot answer these clearly, do not upload your face.