HIPAA Security Rule update

    AI regulation map · Federal, state, and HIPAA

    Every AI rule that touches healthcare, cited and kept current.

    If you need the federal and state AI rules that apply to a healthcare organization, including what HIPAA still requires when a tool touches patient data, this is the cited map. Every entry links to its primary source.

    • Current as of August 20, 2026
    • Checked every morning
    • 59 rules on the board
    • Every entry cited
    • Free, no email

    Watch this page

    A short note by email when a rule changes. Nothing else, ever.

    Federal 15 · State 44 · The date moves when a rule moves

    Already using AI with patient data?

    At a glance

    59 rules, on one board.

    Every rule on this page, with its level, its status, and the date that matters. Filter the board, then read the entry below it.

    Rule or lawLevelStatusKey date
    FDA — Predetermined Change Control Plans (PCCP)Federal · FDAFinal guidanceAug 2025 (rev.)
    FDA — AI device lifecycle management (draft)Federal · FDADraftJan 2025
    FDA — Clinical Decision Support guidance (revised)Federal · FDAFinal guidanceJan 6, 2026
    ONC HTI-1 — Predictive DSI transparencyFederal · ASTP/ONCIn effectCompliance Jan 1, 2025
    ONC HTI-2 — interoperability expansionFederal · ASTP/ONCWithdrawnDec 29, 2025
    ONC HTI-5 — would remove AI "model cards"Federal · ASTP/ONCProposedDec 2025 · final at OMB
    HHS §1557 — patient-care decision-support toolsFederal · OCRIn effectCompliance May 1, 2025
    CMS — Medicare Advantage individualized decisionsFederal · CMSIn effectApplies Jan 1, 2024
    CMS — WISeR Model (AI prior auth, Original Medicare)Federal · CMSIn effect (pilot)Jan 1, 2026
    HIPAA Security Rule overhaul (NPRM, cites AI)Federal · OCRProposedJan 2025
    FTC — Operation AI Comply + health-data actionsFederal · FTCEnforcement2023–2024
    EO 14110 (Biden AI order)Federal · WHRescindedJan 20, 2025
    EO 14179 + America's AI Action PlanFederal · WHIn effect2025
    EO 14365 — preempt "onerous" state AI lawsFederal · WHIn effectDec 11, 2025
    10-year federal moratorium on state AI lawsFederal · Cong.Failed 99–1Jul 1, 2025
    Colorado AI Act — SB 24-205State · CORepealedNever took effect
    Colorado AI Act — SB 26-189 (replacement)State · COEffective soonJan 1, 2027
    Colorado HB 26-1139 (AI in health care / UR)State · COEffective soonJan 1, 2027
    Colorado HB 26-1195 (AI psychotherapy limits)State · COIn effectAug 12, 2026
    Colorado HB 26-1263 (conversational-AI safety)State · COEffective soonJan 1, 2027
    Texas TRAIGA — HB 149State · TXIn effectJan 1, 2026
    Texas SB 1188 (clinician review of AI records)State · TXIn effectSep 1, 2025
    Texas SB 815 (automated system can't make a denial)State · TXIn effectApplies Jan 1, 2026
    Utah AI Policy Act — SB 149 (+ 2025 amendments)State · UTIn effectMay 1, 2024
    Utah HB 452 (mental-health chatbots)State · UTIn effectMay 7, 2025
    California AB 3030 (GenAI patient comms disclaimer)State · CAIn effectJan 1, 2025
    California SB 1120 (Physicians Make Decisions Act)State · CAIn effectJan 1, 2025
    California AB 489 (AI can't pose as a clinician)State · CAIn effectJan 1, 2026
    Illinois WOPR Act — HB 1806 (AI therapy ban)State · ILIn effectAug 1, 2025
    Nevada AB 406 (AI mental/behavioral health)State · NVIn effectJul 1, 2025
    Washington E2SSB 5395 (AI not sole basis for denial)State · WAIn effectJun 11, 2026
    Iowa HF 2635 (no AI-only deny, delay, or downgrade)State · IAIn effectJul 1, 2026
    Maryland HB 820 (AI can't deny, delay, or modify care)State · MDIn effectOct 1, 2025
    Nebraska LB 77 (no AI-only denial; AI use disclosed)State · NEIn effectJan 1, 2026
    Tennessee SB 1580 (AI can't pose as a mental-health professional)State · TNIn effectJul 1, 2026
    Delaware HB 191 (AI can't hold a medical license or title)State · DEIn effectApr 23, 2026
    Oregon HB 2748 (AI agents can't use nursing titles)State · ORIn effectJan 1, 2026
    Rhode Island — AI in mental health care (S 2197A)State · RIIn effectJun 22, 2026
    Rhode Island — AI clinical documentation notice (H 7538A)State · RIIn effectJun 22, 2026
    Rhode Island — chatbot self-harm protocols (S 2195A)State · RIEffective soonJan 1, 2027
    Vermont Act 156 (AI can't provide mental health services)State · VTIn effectJun 17, 2026
    Louisiana Act 649 (disclose AI transcription before recording)State · LAIn effectAug 1, 2026
    Idaho S 1297 (Conversational AI Safety Act)State · IDEffective soonJul 1, 2027
    Nebraska LB 525 (Conversational AI Safety Act)State · NEEffective soonJul 1, 2027
    Maine LD 2082 (AI therapy restrictions)State · MEIn effectJul 29, 2026
    Indiana HEA 1271 (no AI-only downcoding; AI disclosure)State · INIn effectJul 1, 2026
    Alabama SB 63 (human must make the denial)State · ALEffective soonOct 1, 2026
    New York — AI companion crisis protocol (GBS Art. 47)State · NYIn effectNov 5, 2025
    California SB 243 (companion chatbots)State · CAIn effectJan 1, 2026
    Connecticut PA 26-15 (AI companions & mental health)State · CTEffective soonJan 1, 2027
    Oregon SB 1546 (companion chatbots; private right of action)State · OREffective soonJan 1, 2027
    Hawaii SB 3001 (AI disclosure, minor safeguards, crisis protocols)State · HIIn effectJul 14, 2026
    Washington HB 2225 (AI companions — crisis protocol)State · WAEffective soonJan 1, 2027
    Georgia SB 540 (AI companions — crisis protocol)State · GAEffective soonJul 1, 2027
    Georgia SB 444 (clinical peer must review AI denials)State · GAEffective soonJan 1, 2027
    Utah SB 319 (AI disclosure in preauthorization)State · UTEffective soonJan 1, 2027
    Iowa SF 2417 (conversational AI; minors)State · IAAppliesJul 1, 2027
    Illinois SB 3114 (no AI-only downcoding) — PA 104-0568State · ILEffective soonJan 1, 2028
    NAIC AI Model Bulletin (insurers) — ~25 statesState · multiGuidance adopted2024–2026

    Showing 59 of 59

    Note: "Compliance date" is when organizations must comply; it can lag a rule's legal effective date. Future-dated state laws are shown as Effective soon. Each row is detailed and cited below.

    How to trust this page

    Do not take our word for it, or any AI’s.

    Every entry links to its primary source: the statute, the CFR section, the Federal Register notice, the enforcement action. If an AI assistant summarized this landscape for you, check that summary against the operative text before you act on it. This area moves fast enough that answers go stale in weeks. The source links are there for exactly that.

    The big picture

    There is no single "AI in healthcare" law. The same handful of rules keep showing up.

    Federal policy turned sharply deregulatory in 2025 and 2026: the Biden AI executive order was rescinded, a draft ONC rule would remove AI transparency requirements, and the White House is pushing to preempt state AI laws. Into that vacuum, states have stepped hard. Underneath the noise, five principles repeat across almost every rule:

    • 1A human owns the decision. AI can assist, but a licensed person must make any care or coverage denial. It cannot be the sole basis.
    • 2Tell people it is AI. Disclosure to patients (and regulators) is the most common new requirement nationwide.
    • 3No algorithmic discrimination. AI tools that touch protected classes must be fair, validated, and monitored.
    • 4Existing law already applies. HIPAA, the FTC Act, and §1557 govern AI today. There is no AI exemption.
    • 5Therapy is a red line. A cluster of states now bar AI from delivering mental-health care directly to patients.

    Federal · 1 of 7

    FDA: AI and machine-learning medical devices

    The FDA is the most mature AI-in-healthcare regulator. It reviews AI/ML-enabled software as a medical device (SaMD) through its existing pathways and has authorized more than 1,000 AI-enabled devices. Its newest work focuses on the hardest problem: how to let a model keep learning after clearance without re-reviewing it every time.

    Premarket review of AI/ML devices (510(k), De Novo, PMA)

    FD&C Act · CDRH Digital Health Center of Excellence
    In effect

    Requires AI/ML-enabled devices that diagnose, treat, or inform clinical decisions are reviewed for safety and effectiveness through the same premarket clearance/approval pathways as other devices. As of January 2025, the FDA reported 1,000+ authorized AI-enabled devices (roughly 97% via the 510(k) pathway). The FDA itself notes its traditional paradigm "was not designed for adaptive" AI.

    Healthcare impact If you deploy an AI diagnostic or clinical tool, check whether it is FDA-authorized for its intended use — and whether your use matches the cleared indication.

    Predetermined Change Control Plans (PCCP)

    Final guidance · FR Dec 4, 2024 · revised Aug 18, 2025 · docket FDA-2022-D-2628 · FD&C Act §515C
    Final guidance

    Requires A PCCP lets a manufacturer pre-specify and get FDA authorization for future model changes as part of the original submission — so pre-approved updates don't each need a new submission. A PCCP must describe three things: the planned modifications, the methodology to develop/validate/implement them safely, and an impact assessment of benefits and risks.

    Healthcare impact The mechanism that finally lets adaptive AI evolve under FDA oversight — relevant to how quickly your vendors can (legitimately) push model updates.

    AI device lifecycle management & postmarket monitoring

    Draft guidance · issued Jan 6, 2025 · docket FDA-2024-D-4488
    Draft

    Proposes The FDA's first comprehensive, total-product-lifecycle recommendations for AI devices — design, development, validation, transparency, and postmarket performance monitoring. It recommends manufacturers maintain a monitoring plan to catch performance drift after deployment. Still a draft as of August 2026 (comment period closed April 7, 2025).

    Healthcare impact A preview of where device oversight is heading: continuous monitoring of real-world AI performance, not just a one-time clearance.

    Clinical Decision Support Software — revised final guidance

    Revised final guidance · issued Jan 6, 2026 · revises the 2022 CDS guidance
    Final guidance

    Clarifies The FDA's January 2026 revision narrows which decision-support software — expressly including AI-enabled CDS — counts as a regulated medical device. Software that informs a clinician who can independently review the basis for its recommendation can qualify as Non-Device CDS, and the FDA now intends enforcement discretion for some single-recommendation tools (such as guideline-based risk scores) that the 2022 guidance pushed toward device status. The FDA walked industry through the changes in a March 11, 2026 town hall.

    Healthcare impact More AI decision-support tools can now reach clinicians without FDA premarket review — shifting the burden of vetting them onto the organizations that deploy them. Note the rhyme with ONC's deregulatory HTI-5 proposal (§2).

    Federal · 2 of 7

    ONC and ASTP: health-IT certification and AI transparency

    The HHS health-IT office (ASTP/ONC) set the first U.S. transparency rules for AI built into certified electronic health records. Important twist: the current direction is deregulatory. A 2025 proposal would strip those AI transparency requirements back out.

    HTI-1 — Predictive Decision Support Intervention (DSI) transparency

    Final rule · 89 FR 1192 · 45 CFR 170.315(b)(11) · effective Mar 11, 2024
    In effect

    Requires The first substantial update to clinical decision-support certification since 2012. It defines "Predictive DSI" (technology using models trained on data to produce a prediction, classification, or recommendation) and requires certified health-IT developers to disclose 31 "source attributes" for predictive tools (and 13 for evidence-based ones) — effectively an AI "nutrition label" covering intended use, training data, validation, and known risks — plus intervention risk-management practices. Compliance date was January 1, 2025.

    Healthcare impact If your EHR is certified, you have a right to standardized transparency disclosures about the predictive/AI tools embedded in it. This is the one binding federal AI-transparency rule in force today.

    HTI-2 — interoperability & payer-API expansion

    Proposed Aug 2024 · largely withdrawn FR Dec 29, 2025 · RIN 0955-AA08
    Withdrawn

    Status Proposed sweeping certification and interoperability changes (new patient/provider/payer FHIR APIs, public-health data exchange, updated standards). A small TEFCA-related slice was finalized in late 2024; the bulk was formally withdrawn December 29, 2025, citing deregulation and "emerging AI technologies."

    Healthcare impact The payer-API and public-health interoperability work many organizations were preparing for is off the table for now — folded into future rulemaking instead.

    HTI-5 — would remove AI "model card" requirements

    Proposed rule · issued Dec 2025 · "ONC Deregulatory Actions"
    Proposed

    Proposes The live ONC AI rulemaking — and it runs the opposite direction. It would remove the HTI-1 AI source-attribute / "model card" and risk-management requirements from the Predictive DSI criterion, arguing there's no published evidence they improved care. Broadly deregulatory (proposes removing 34 of 60 certification criteria). The comment period closed February 27, 2026; the rule is still not finalized as of August 20, 2026, so the HTI-1 model-card requirements remain in force in the meantime. It is close, though. The final rule reached OMB's regulatory-review office (OIRA) on July 28, 2026 and is listed as pending review — the last procedural step before a rule can publish — and the 2026 Unified Agenda projects final action in August 2026 (RIN 0955-AA09).

    Healthcare impact If finalized, the federal mandate for AI transparency in certified EHRs weakens — pushing the burden of vetting embedded AI back onto provider organizations and the market. Given where it sits, plan on that happening rather than on the model-card requirements holding: if your EHR's AI disclosures are the reason you trust a predictive tool, start asking your vendor what they will keep publishing on their own.

    Federal · 3 of 7

    HHS §1557: algorithmic nondiscrimination

    Nondiscrimination in "patient care decision support tools"

    2024 Final Rule · 89 FR 37,522 · 45 CFR 92.210 · effective Jul 5, 2024
    In effect

    Requires HHS OCR's Section 1557 rule (Affordable Care Act) extends nondiscrimination protections to "patient care decision support tools" — defined to include AI and clinical algorithms. Covered providers must make reasonable efforts to (1) identify tools they use that rely on input variables measuring race, color, national origin, sex, age, or disability, and (2) mitigate the resulting discrimination risk. Compliance was required by May 1, 2025.

    Healthcare impact Any covered provider using clinical algorithms or AI needs an inventory of those tools and a documented effort to find and reduce bias — this is an active, enforceable obligation today.

    Federal · 4 of 7

    CMS: AI in Medicare Advantage coverage decisions

    The Medicare Advantage rule below regulates payers, not providers. After reporting that algorithms were being used to deny post-acute care, CMS made clear that coverage decisions must be about the individual patient. And since January 2026, CMS is also piloting AI-assisted review inside Original Medicare itself.

    Coverage decisions must be individualized

    Rule CMS-4201-F · 42 CFR 422.101(c) · applies to coverage from Jan 1, 2024
    In effect

    Requires A Medicare Advantage plan's medical-necessity decision must be based on the individual patient's circumstances — medical history, physician recommendations, and clinical notes — not population data alone. In a February 2024 FAQ, CMS clarified that an algorithm or software tool cannot by itself be the basis to deny admission or terminate post-acute care; a patient-specific reassessment is required first.

    Note The "AI can't be the sole basis" language is CMS's interpretive guidance (the FAQ); the regulation itself requires an individualized determination. Proposed AI "guardrails" in the CY2026 rule were not finalized.

    Healthcare impact Plans may use AI to assist utilization review, but a human, patient-specific clinical judgment must stand behind any denial — a principle now spreading to the states (see §10).

    WISeR Model — AI-assisted prior authorization in Original Medicare

    CMS Innovation Center model · Jan 1, 2026 – Dec 31, 2031 · NJ · OH · OK · TX · AZ · WA
    In effect (pilot)

    Status CMS is testing AI/ML-assisted review of prior-authorization requests in Original Medicare (fee-for-service — it does not apply to Medicare Advantage) across six states. The model targets a pre-selected list of services CMS flags as wasteful or fraud-prone (skin and tissue substitutes, electrical nerve-stimulator implants, and knee arthroscopy for knee osteoarthritis, among others). CMS says WISeR does not change Medicare coverage or payment policy — and any non-payment recommendation must come from an appropriately licensed clinician, not the technology alone.

    Healthcare impact The federal government is no longer just regulating AI in coverage decisions — it now runs an AI-assisted review program of its own, with the same guardrail it imposes on payers: AI can flag, a licensed human must decide. Providers of the targeted services in the six model states face a new prior-authorization step.

    Federal · 5 of 7

    OCR and HIPAA: AI and protected health information

    There is no AI-specific HIPAA rule. But HIPAA is technology-neutral, so its existing Privacy and Security Rules already govern any AI tool that touches PHI. This is where most clinics' real-world exposure lives: the "shadow AI" problem.

    AI vendors as business associates; PHI in model training

    45 CFR 160.103 (BA definition) · 45 CFR 164.504(e) (BAA) · 164.514 (de-identification)
    In effect (existing law)

    Requires An AI vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and needs a BAA. Using consumer AI tools with patient data — with no BAA, no risk analysis, no acceptable-use policy — is a HIPAA exposure under rules that already exist. BAAs should explicitly address whether the vendor may use your PHI to train its models (generally not a permitted use without authorization). De-identified data (per 45 CFR 164.514) falls outside HIPAA and is the cleanest path for AI development.

    Healthcare impact The most common gap isn't a missing AI law — it's staff pasting PHI into ungoverned AI tools. Existing HIPAA already makes that a problem.

    HIPAA Security Rule overhaul (names AI explicitly)

    NPRM · 90 FR 898 · issued Dec 27, 2024 · first update since 2013
    Proposed

    Proposes A major cybersecurity update that would require a technology asset inventory and network map explicitly listing AI software that handles ePHI, and would require the risk analysis to assess — before deploying an AI tool — what ePHI it accesses and where outputs go. Confirms ePHI in AI training data and models is within scope. Not finalized as of August 20, 2026; outcome uncertain amid industry pushback — and the 2026 Unified Agenda carries it as a long-term action with final action projected July 2027 (RIN 0945-AA22), so it is unlikely to bind before then. Note the contrast with HTI-5 above: of the two open federal AI rulemakings, the deregulatory one is at OMB now and the one that would add AI security duties is parked three years out.

    Healthcare impact If finalized, AI tools touching ePHI become mandatory line items in your security inventory and pre-deployment risk analysis.

    If this is you

    Using AI with patient data today?

    The audit-readiness score checks the HIPAA half of the six moves in about ten minutes: BAAs, policies, training, risk analysis, and the officer who owns them. No signup, nothing to install.

    About ten minutes · No signup

    Federal · 6 of 7

    FTC: AI claims and sensitive health data

    The FTC's message: "there is no AI exemption from the laws on the books." It polices two things relevant to health AI: overstated AI claims and misuse of health data, which feeds AI systems.

    Operation AI Comply — deceptive AI claims

    FTC enforcement sweep · announced Sep 25, 2024 · FTC Act §5
    Enforcement

    Prohibits Unsubstantiated or deceptive AI capability claims ("AI washing"). The September 2024 sweep brought five actions (DoNotPay, Rytr, and others) against companies overhyping or misusing AI. Health-tech AI marketing — diagnostic accuracy, "AI clinician," compliance-automation efficacy — is squarely within this standard.

    Healthcare impact Claims about what your (or a vendor's) AI can do must be substantiated and not overstated.

    Health-data enforcement & the Health Breach Notification Rule

    GoodRx (2023) · BetterHelp (2023) · Cerebral (2024) · HBNR amendments eff. Jul 29, 2024
    Enforcement

    Prohibits Sharing sensitive health data with advertisers/third parties without consent. The FTC penalized GoodRx ($1.5M, its first Health Breach Notification Rule action), BetterHelp ($7.8M), and Cerebral for leaking medication, mental-health, and telehealth data via tracking tools. Its 2024 HBNR amendments expressly cover health apps not governed by HIPAA, and treat tracker/pixel leaks as reportable breaches.

    Healthcare impact Non-HIPAA health apps now have a federal breach-notification duty, and the data those apps feed into AI/ad systems is a live enforcement target.

    Federal · 7 of 7

    White House: executive orders, strategy, and preemption

    The federal executive posture flipped in 2025: from precaution to acceleration. The throughline now is "deploy AI, cut rules", including an active effort to preempt state AI laws.

    EO 14110 (Biden AI order) — rescinded

    88 FR 75191 · signed Oct 30, 2023 · revoked by EO 14148 on Jan 20, 2025
    Rescinded

    Was The most sweeping federal AI action to date — directed an HHS AI Task Force, a health-AI assurance strategy, and an AI safety program for clinical errors. Rescinded on Jan 20, 2025; the HHS deliverables it ordered are now superseded.

    EO 14179 + "America's AI Action Plan"

    EO 14179 (90 FR 8741, Jan 23, 2025) · Action Plan released Jul 23, 2025
    In effect

    Directs A national policy to remove barriers to AI leadership; ordered a review/unwinding of EO 14110 actions and mandated the AI Action Plan. The Plan's three pillars — innovation/deregulation, infrastructure, and global influence — promote rapid AI adoption in healthcare and call for regulatory "sandboxes," including for health.

    HHS AI Strategy (the operative health-AI governance posture)

    Released Dec 2025 · OMB memos M-25-21 / M-25-22 (Apr 3, 2025)
    In effect

    Directs A "OneHHS" approach across CMS, FDA, NIH, CDC — deploy AI aggressively while applying OMB's "high-impact AI" risk-management controls (bias mitigation, monitoring, human oversight), with implementation milestones in 2026.

    Federal preemption of state AI laws

    EO 14365 (Dec 11, 2025) · 10-year moratorium failed (Senate 99–1, Jul 1, 2025)
    In effect / contested

    Status A proposed 10-year moratorium barring states from enforcing AI laws was stripped from the 2025 budget bill 99–1. The White House then issued EO 14365 (Dec 11, 2025), directing a DOJ "AI Litigation Task Force" to challenge "onerous" state AI laws, a Commerce evaluation of those laws, and conditioning some broadband funds on state AI policy. A March 2026 White House framework recommended legislative preemption — not yet enacted. In April 2026 the fight reached the courts: xAI sued Colorado over its AI Act (X.AI LLC v. Weiser, D. Colo., No. 1:26-cv-01515, filed Apr 9, 2026), the DOJ intervened on xAI's side April 24 — the first federal court move against a state AI law — and on April 27 the court suspended enforcement of the Colorado AI Act while the challenge proceeds (a pause Colorado's Attorney General extends to the SB 26-189 replacement; see §8).

    Healthcare impact The single biggest uncertainty in the field: as of August 2026 state AI laws generally remain in effect and enforceable — but the federal override effort is now in court, and it has already paused one state's AI act (Colorado, §8). Watch this closely.

    State · 1 of 3

    State comprehensive AI laws

    Broad, cross-industry AI statutes that sweep in healthcare as a "high-risk" or "consequential" use. The headline story: Colorado wrote the first one, then dismantled it, a vivid example of how unsettled this area still is.

    Colorado AI Act — the SB 24-205 → SB 26-189 saga

    SB 24-205 (2024, repealed) → SB 26-189 (signed May 14, 2026)
    Replacement eff. Jan 1, 2027

    What happened SB 24-205 (2024) was the first U.S. comprehensive AI law — a duty of "reasonable care" to prevent algorithmic discrimination in high-risk uses including healthcare services, with impact assessments and consumer notice. Its effective date slipped from Feb 2026 to June 2026 — then it was repealed and replaced by SB 26-189 before it ever took effect.

    The new law SB 26-189 is narrower: it drops the duty-of-care / impact-assessment regime and instead requires notice that you're interacting with AI, disclosure within 30 days of an adverse outcome, data-correction rights, and human review. HIPAA-covered entities are largely exempt except for employment decisions and financial-assistance eligibility. Effective January 1, 2027.

    Enforcement caveat The law is also under a legal cloud: after xAI sued and the DOJ intervened (X.AI LLC v. Weiser, see §7), the court suspended enforcement on April 27, 2026, and the Attorney General has said he will not enforce SB 26-189 until its rulemaking process concludes.

    Healthcare impact The most-watched state AI law is now far lighter on healthcare than the version everyone prepared for — but Colorado pivoted to targeted healthcare AI laws instead (see §9 and §10).

    Texas TRAIGA — Responsible AI Governance Act

    HB 149 · signed Jun 22, 2025 · effective Jan 1, 2026
    In effect

    Requires Prohibits developing/deploying AI with intent to unlawfully discriminate, to manipulate people toward self-harm or crime, for government social scoring, or for unlawful biometric capture. Enforced by the AG (no private lawsuits), with a 60-day cure period and a regulatory sandbox. Healthcare-specific: TRAIGA's disclosure duty is broad (AI used "in relation to a health care service or treatment"); the specific requirement that a provider disclose to patients when AI is used in diagnosis or treatment comes from a separate Texas law, SB 1188 (see below).

    Healthcare impact Texas providers using AI clinically owe patients an up-front disclosure (can be built into intake forms).

    Utah AI Policy Act + 2025 amendments

    SB 149 (eff. May 1, 2024) · narrowed by SB 226 (2025) · extended by SB 332
    In effect

    Requires One of the first provider-facing AI disclosure laws. People in a regulated occupation (including healthcare providers) must disclose generative-AI use to consumers. A 2025 amendment (SB 226) narrowed proactive disclosure to "high-risk" interactions — which still generally captures use of health data for personalized advice. Created Utah's Office of AI Policy and AI "learning lab."

    Healthcare impact Utah providers using generative AI in patient interactions involving health data must disclose it up front.

    State · 2 of 3

    State healthcare-specific AI laws

    Where the real action is. States are targeting three things directly: AI-generated patient communications, AI posing as a clinician, and AI delivering mental-health therapy.

    California AB 3030 — disclaimer on GenAI patient communications

    Ch. 848, Stats. 2024 · Health & Safety Code §1339.75 · effective Jan 1, 2025
    In effect

    Requires A facility, clinic, or physician's office using generative AI to send patients communications about their clinical information must include a disclaimer that it was AI-generated and instructions to reach a human. Exception: messages reviewed by a licensed human before sending are exempt. Doesn't cover scheduling/billing/admin messages.

    Healthcare impact Either add an AI disclaimer + human-contact path to AI-drafted clinical messages, or route them through a licensed reviewer.

    California SB 1120 — "Physicians Make Decisions Act"

    SB 1120 (2024) · Knox-Keene / Insurance Code · effective Jan 1, 2025
    In effect

    Requires When a health plan or insurer uses AI in utilization review, the AI may not deny, delay, or modify care based on medical necessity — the final determination must be made by a licensed physician or competent licensed professional. The tool must use the patient's individual history, be applied fairly and equitably, not supplant the clinician, and be auditable (overseen by DMHC/CDI).

    Healthcare impact The state-level version of the CMS rule — insurers in California can't let AI auto-deny medical-necessity requests.

    California AB 489 — AI can't pose as a licensed clinician

    Ch. 615, Stats. 2025 · effective Jan 1, 2026
    In effect

    Prohibits AI systems from using terms or titles (e.g., "doctor," "nurse," "psychologist") in a way that implies care is being provided by a licensed human. Each prohibited use is a separate violation, enforced by the relevant licensing board.

    Healthcare impact Patient-facing health chatbots in California must not present themselves as licensed professionals.

    Oregon HB 2748 — an AI agent may not use a nursing title

    Oregon Laws 2025, ch. 378 · added to ORS 678.010–678.410 · approved Jun 24, 2025 · effective Jan 1, 2026
    In effect

    Prohibits The whole operative section is one sentence: "A nonhuman entity, including but not limited to an agent powered by artificial intelligence, may not use any of the following titles" — Advanced Practice Registered Nurse (APRN), certified registered nurse anesthetist (CRNA), clinical nurse specialist (CNS), licensed practical nurse (LPN), registered nurse (RN), nurse practitioner (NP), certified medication aide (CMA), or certified nursing assistant (CNA). It sits inside Oregon's Nursing Practice Act, so it is enforced as a title-protection rule.

    Healthcare impact The same red line as California AB 489 and Delaware HB 191, drawn around the nursing titles specifically — and it has been in force since Jan 1, 2026. If a triage chatbot, an on-hold assistant, or a patient-portal agent is named or badged as a "nurse," that is the violation; check what your vendor calls the bot, not just what it does.

    Illinois WOPR Act — AI cannot deliver therapy

    HB 1806 · signed & effective Aug 1, 2025 · enforced by IDFPR
    In effect

    Prohibits Providing therapy/psychotherapy to the public unless by a licensed professional. A licensed clinician may not use AI to make independent therapeutic decisions, interact directly with clients in therapeutic communication, or generate treatment plans without review. Administrative/support uses (notes, scheduling) are allowed. Penalty: up to $10,000 per violation.

    Healthcare impact AI can't run client-facing therapy in Illinois — one of the strictest "AI therapy" bans in the country.

    Nevada AB 406 — AI in mental/behavioral health

    AB 406 · signed Jun 5, 2025 · effective Jul 1, 2025
    In effect

    Prohibits Offering — or claiming — that an AI system can provide professional mental/behavioral health care, and bars providers from using AI to deliver care directly to patients (support uses with provider review allowed). Also restricts AI for these services in public schools. Penalty up to $15,000 per violation.

    Healthcare impact AI cannot be marketed as, or act as, a mental-health professional in Nevada.

    Utah HB 452 — mental-health chatbot rules

    HB 452 · effective May 7, 2025
    In effect

    Requires AI "mental health chatbots" must clearly disclose they are AI (before use, after 7 days of non-use, and on request); in-chat advertising must be labeled; and suppliers may not sell or share users' identifiable health information or inputs (limited exceptions).

    Healthcare impact Behavioral-health chatbot vendors operating in Utah face disclosure, advertising, and data-sharing limits.

    Texas SB 1188 — clinician review of AI-generated records

    SB 1188 · effective Sep 1, 2025
    In effect

    Requires Licensed practitioners may use AI for diagnosis/treatment only within their scope and only if they review all AI-generated records per Texas Medical Board standards; also prohibits offshoring electronic medical records.

    Healthcare impact A human clinician must review AI-generated clinical records in Texas.

    Colorado HB 26-1139 & HB 26-1195 — targeted healthcare AI

    HB 26-1139 (eff. Jan 1, 2027) · HB 26-1195 (Ch. 358, eff. Aug 12, 2026)
    In effect / rolling in

    Requires After scaling back its broad AI act, Colorado passed two targeted health laws in mid-2026. HB 26-1139 requires AI coverage decisions to use the patient's individual history, requires a licensed clinician to review medical-necessity denials, mandates disclosure of AI use to regulators, and bars payer reimbursement for AI-delivered psychotherapy. HB 26-1195 restricts AI from conducting therapeutic communication except during live sessions with the provider present, and requires consent for AI session recording.

    Healthcare impact Colorado is now regulating AI in healthcare through precise, sector-specific rules rather than one omnibus law — a model other states may follow.

    The 2026 chatbot wave — Tennessee, Delaware, Idaho, Nebraska, Colorado

    TN SB 1580 (Pub. Ch. 647) · DE HB 191 · ID S 1297 · NE LB 525 · CO HB 26-1263
    In effect / rolling in

    Requires Spring 2026 added four more states to the mental-health red line. Tennessee (SB 1580, eff. Jul 1, 2026) bars advertising or representing that an AI system is — or can act as — a qualified mental-health professional, with a private right of action under its consumer-protection law. Delaware (HB 191, eff. Apr 23, 2026) says a nonhuman entity, including an AI agent, cannot be licensed as — or use the title of — a nurse, physician, or physician assistant. Idaho (S 1297) and Nebraska (LB 525) enacted near-identical Conversational AI Safety Acts (both eff. Jul 1, 2027): public-facing chatbots must clearly disclose they are AI, follow crisis-response protocols when a user expresses suicidal ideation, and may not claim to provide professional mental or behavioral health care. Colorado joined on May 29, 2026 (HB 26-1263, operator requirements eff. Jan 1, 2027): conversational-AI operators must disclose that outputs are AI-generated, maintain suicidal-ideation and self-harm response protocols, protect minor users (age estimation, no simulated emotional dependence), report annually to the Attorney General — and may not represent a chatbot's output as equivalent to services from a licensed professional.

    Healthcare impact The therapy red line (Illinois, Nevada, Utah above) is now a national pattern — and Delaware extends it beyond therapy: AI can't hold, or pose under, a medical license at all.

    Maine LD 2082 — AI can't deliver therapy

    P.L. 2026, ch. 687 · 10 MRSA §1500-EE · signed Apr 13, 2026 · effective Jul 29, 2026
    In effect

    Prohibits Providing, advertising, or offering therapy or psychotherapy services to the public — including through Internet-based AI — unless the services are provided by a licensed professional; a violation is an unfair trade practice under Maine law. Licensed clinicians may still use AI for administrative and "supplementary" support (therapy notes, anonymized trend analysis, referral research), but only with the client's explicit written consent — the law says consent can't be collected through a general terms-of-use agreement — after disclosing the tool's purpose and how session data is stored, used for training, and deleted. Even then, the AI may not make independent therapeutic decisions, interact with clients in therapeutic communication, or generate treatment plans without the licensee's review. Clients can't be denied care for refusing consent, and client waivers of these protections are void.

    Healthcare impact Maine joins Illinois and Nevada on the therapy red line — and goes further on consent mechanics: AI consent can't be buried in a terms-of-use agreement, and the disclosure must say whether session data trains the model.

    Rhode Island — AI in mental health care, and AI in the medical record

    S 2197 Sub A as amended / H 7349A (R.I. Gen. Laws ch. 40.1-5.5) · H 7538 Sub A (R.I. Gen. Laws ch. 23-106) · signed Jun 22, 2026 · effective upon passage
    In effect

    Requires Rhode Island enacted two healthcare AI laws that took effect the day they were signed. The Oversight of Artificial Intelligence Technology in Mental Health Care Act bars any person or entity from providing, advertising, or offering therapy or psychotherapy to the public — including through Internet-based AI — unless a licensed professional conducts it. A licensed provider may not let AI make independent therapeutic decisions, determine therapeutic recommendations or treatment plans, or directly engage a client in therapeutic communication without an established relationship. Where AI designed to simulate emotional attachment (or an AI "companion") assists in a recorded or transcribed session, the patient must be told in writing that AI will be used and for what purpose, and must consent — and the statute is explicit that consent cannot be harvested from acceptance of a broad terms-of-use agreement. FDA-cleared AI tools, religious counseling, peer support, and public self-help materials are carved out. Separately, the Use of Artificial Intelligence by Healthcare Providers Notification Act requires any provider or facility that uses AI to document an in-person or telehealth visit to notify the patient and to review the AI-generated documentation for accuracy after the visit.

    Healthcare impact If you run an AI scribe in Rhode Island, patient notice and a post-visit accuracy review are now legal duties, not best practices — the same "a human reviews the AI's output" rule Texas SB 1188 created, now in a second state. Note what the final amendment did to liability: the provider is responsible for clinical judgment and reasonable therapeutic oversight of the patient's use of the system, but not for vendor-controlled system design, algorithms, or outputs.

    Vermont Act 156 — an entity can't offer mental health services through AI

    H.816 (Act 156) · 18 V.S.A. §7115 · signed Jun 17, 2026 · effective on passage
    In effect

    Prohibits A corporation or entity may not provide, advertise, or otherwise offer mental health services to the public — including through the use of artificial intelligence — unless those services are provided by a mental health professional, or delivered as part of a study approved by an IRB or privacy board under 45 CFR 164.512(i)(1)(i)(A)–(B). Vermont's definitions run wide: "therapeutic communication" expressly includes "offering clinical support, including reassurance or empathy in response to emotional or psychological distress," and "mental health professional" reaches nonlicensed psychotherapists and "any other professional who provides mental health services."

    The clinician safe harbor is conditioned on HIPAA This is the provision to know. Under §7115(d) a professional may use AI tools only if they are "compliant with the Health Insurance Portability and Accountability Act of 1996" and the professional reviews and approves the service. FDA-cleared digital therapeutics sit in the same harbor when prescribed or recommended. Vermont has effectively made HIPAA compliance a licensing condition for clinical AI, not just a privacy obligation.

    Enforcement A violation by an entity is a violation of the Vermont Consumer Protection Act (9 V.S.A. ch. 63) — which carries both Attorney General authority and a private right of action. Separately, prohibited AI use is unprofessional conduct under 3 V.S.A. §129a(a)(30) and 26 V.S.A. §1354(a)(3), so it also reaches board discipline.

    Also on the books Vermont Act 101 (H.814, signed May 18, 2026) declares neurological rights — mental and neural data privacy, freedom of thought, and protection from unauthorized access to or manipulation of brain activity (18 V.S.A. ch. 42C §1891). It imposes no duty on a provider today; read it as the signal for Vermont's next round. It also extends the AI Advisory Council to 2030 and orders a January 15, 2027 report that will recommend, among other things, regulating AI in health-insurance utilization review.

    Healthcare impact If your organization offers any AI-assisted mental-health service in Vermont, the tool has to be HIPAA-compliant and a mental health professional has to review and approve what it produces — and the consequence of getting it wrong is consumer-protection exposure, including private suits, not just a licensing complaint.

    Louisiana Act 649 — tell the patient before an AI scribe starts recording

    HB 475 (2026 R.S.) · Act No. 649 · R.S. 37:22.1 · signed Jun 2, 2026 · effective Aug 1, 2026
    In effect

    Requires The operative sentence is short: a healthcare professional licensed under Title 37 "shall verbally disclose the use of any recording device, software, or service to a patient before recording any part of an appointment or treatment to be transcribed by artificial intelligence." Note the two words that decide how you implement it — verbally, and before. A line in the intake paperwork does not satisfy this; the disclosure has to be spoken, and it has to come before the recording starts.

    Disclosure, not consent The bill was introduced as a consent requirement and amended in committee down to disclosure — and Louisiana's own bill-status digest still carries the old "obtain a patient's consent" short title. The enacted text controls, and it requires disclosure. Enforcement runs through the professional licensing board; the statute also limits civil liability absent gross negligence or willful misconduct, so a simple failure to disclose is a board matter rather than a damages claim.

    Healthcare impact If you run an ambient AI scribe in Louisiana, add a spoken line to the start of the visit and document that you say it. This is the third state to put an AI-documentation duty directly on the provider — after Texas SB 1188 (review the output) and Rhode Island's notification act (notify, then review) — and Louisiana's is the easiest to fail by accident, because it turns on how you tell the patient.

    Consumer AI-companion laws — New York, California, Connecticut, Oregon, Iowa, Hawaii, Washington, Georgia

    NY Gen. Bus. Law Art. 47 (§§1700–1704) · CA SB 243 (Ch. 677, Stats. 2025) · CT PA 26-15, Secs. 4–6 · OR SB 1546 (Or. Laws 2026 ch. 85) · IA SF 2417 (Iowa Code ch. 554J) · HI SB 3001 CD1 · WA HB 2225 (Ch. 168, Laws of 2026) · GA SB 540 (O.C.G.A. §39-5-6)
    In effect / rolling in

    Requires A separate cluster regulates AI companions — the consumer chatbots people confide in — rather than clinical tools. Every law in it is built on the same duty: detect a user in crisis, and hand them to a human service.

    The two originals — New York and California New York was first in the nation and has been in effect since Nov 5, 2025. The law arrived as Part U of the FY2026 budget bill (S3008-C) rather than as a standalone act — which is why several trackers still point at A6767, a different bill that died in the Senate — and is codified at Gen. Bus. Law Art. 47. Under §1701 it is unlawful to operate an AI companion unless it runs a protocol to address a user's expression of suicidal ideation or self-harm and refers that user to a crisis service; §1702 requires notice at the start of the interaction and at least every three hours that the user is not talking to a human. The Attorney General enforces it (§1703). California SB 243 (Ch. 677, Stats. 2025, signed Oct 13, 2025) took effect Jan 1, 2026: a crisis-referral protocol, AI disclosure and break reminders for minors, and annual reports to the state's Office of Suicide Prevention beginning Jul 1, 2027 — backed by a private right of action for the greater of actual damages or $1,000 per violation.

    The 2026 wave Connecticut (Public Act 26-15, approved May 27, 2026; the AI-companion sections take effect Jan 1, 2027) requires an evidence-based protocol to detect a user expression indicating risk of suicide, self-harm, or imminent violence and to refer the user to the 988 lifeline and on to treatment "consistent with clinical best practices"; the companion may not claim to be a human being; and for minors it may not offer mental-health services at all unless it is designed to deliver them using clinical best practices and displays, clearly and conspicuously at the start of each interaction, a statement that it is not a licensed mental health professional.

    Oregon and Iowa Oregon (SB 1546, approved Mar 31, 2026, effective Jan 1, 2027) requires a suicidal-ideation detection protocol and a referral carrying contact information and a hyperlink for 988 — or a youthline for a user under 25 — restricts simulated emotional dependence and romantic role-play for minors, and gives users a private right of action for the greater of actual damages or $1,000 per violation. Iowa (SF 2417, approved May 2, 2026; by its own terms the act applies July 1, 2027) requires conspicuous AI disclosure to minor account holders and a protocol referring users to a crisis service, and bars an operator from knowingly programming the service to represent that it provides professional psychology or behavioral-health services that would require a license — enforced by the Attorney General at up to $500,000 per operator, with no private right of action.

    Hawaii Hawaii (SB 3001 CD1, the Artificial Intelligence Disclosure and Safety Act) is the 2026 wave's first to be in effect: Governor Green signed it as Act 248 on July 14, 2026 (Gov. Msg. No. 1350), and it takes effect on approval. It requires operators of conversational-AI services to clearly disclose that a user is interacting with AI rather than a human; adds safeguards for minors — limits on manipulative engagement techniques and sexually explicit content, plus tools for parents and guardians to manage screen time and account settings; and requires a protocol to respond to a user expressing suicidal ideation or self-harm by directing them to crisis-intervention resources such as suicide hotlines and crisis text lines. Beginning January 1, 2028, operators must file annual reports with the Department of Health's Behavioral Health Administration. It is enforced as an unfair or deceptive trade practice.

    Washington and Georgia Two more land in 2027, and both are worth reading for how far the duty now reaches. Washington HB 2225 (Ch. 168, Laws of 2026, approved Mar 24, 2026; effective Jan 1, 2027) conditions deployment itself on the protocol: "An operator may not make available or deploy an AI companion chatbot unless it maintains and implements a protocol for detecting and addressing suicidal ideation or expressions of self-harm by users." The protocol must cover expressions "including eating disorders," refer users to a suicide hotline or crisis text line, and prevent content describing how to self-harm — and the operator must publicly disclose both the protocol and the number of crisis referrals it issued the prior calendar year. Violations are unfair or deceptive acts under ch. 19.86 RCW, which carries a private right of action. Unlike most of this cluster, the duty runs to all users, not only minors. Georgia SB 540 (O.C.G.A. §39-5-6, effective Jul 1, 2027) requires a protocol for "severe harm or related emotional crises" — identification methods, automated or human-mediated referral to the 988 lifeline, prevention of content that encourages or normalizes severe harm, and escalation procedures for repeated or severe indicators — plus a plain-language public summary and an annual crisis-referral count. It also bars programming a companion to represent that it is "licensed, certified, or otherwise authorized to provide professional mental health, behavioral health, medical, or counseling services" unless it lawfully is — the same red line as CA AB 489 and DE HB 191. The Attorney General enforces it at up to $10,000 per knowing violation.

    Read this one carefully These are operator duties, not provider duties. Connecticut and Oregon both expressly carve out software that assists or supports patient or resident care services in a facility. If you run an AI scribe or a clinical decision-support tool, these eight laws are not aimed at you — the ones that are aimed at you are Rhode Island's, Vermont's, Louisiana's, Texas SB 1188, and the therapy bans above.

    Healthcare impact Mostly a vendor question. But if your organization offers a patient-facing chatbot marketed as a companion rather than as care-support software, you are the operator — and the crisis-response protocol is yours to build.

    Ask a specialist

    Which rule are you unsure about?

    Tell us the rule or the situation. A HIPAA specialist answers by email, usually within one business day. No sales pitch, and your question does not go into a sales queue.

    Informational, not legal advice. We reply from a real inbox and keep your address for that reply.

    State · 3 of 3

    State insurance and utilization-review rules

    The fastest-moving cluster: states stopping insurers from letting AI auto-deny care. The common rule, that a qualified human must own any medical-necessity denial, now appears in roughly a dozen states.

    NAIC Model Bulletin on Insurers' Use of AI

    Adopted Dec 4, 2023 · regulator guidance · ~24–25 states adopted
    Guidance adopted

    Requires Insurers (including health insurers) maintain a written AI governance program covering risk management, bias/data-quality controls, consumer notice, vendor oversight, and documentation available to regulators. As of early-to-mid 2026, roughly half the states (~24–25) had adopted it via bulletin. It's guidance, not a binding denial-of-care ban.

    Healthcare impact Health insurers in adopting states must be able to show documented AI governance and tell consumers when AI is used.

    The "human must decide" wave — multi-state

    CA · MD · TX · NE · IL · AL · IN · IA · UT · WA · GA (2024–2028 effective dates) · NY pending
    In effect / rolling in

    Requires A growing set of states require that AI may assist utilization review but a qualified licensed human — not an algorithm alone — must make or own any medical-necessity denial, and that AI be applied fairly and based on the individual patient. Maryland (HB 820, in effect Oct 1, 2025) got there earliest — a flat prohibition rather than a "sole basis" rule — and is detailed below. Two more states legislated in 2025 and their duties switched on in January 2026 — Texas (SB 815) and Nebraska (LB 77) — also detailed below. Beyond those, California (SB 1120) and Illinois, 2026 brought laws in Alabama (SB 63, in effect Oct 1, 2026), Indiana (HEA 1271, in effect Jul 1, 2026), Utah (SB 319, Jan 1, 2027), and Georgia (SB 444, Jan 1, 2027) — each detailed below. Washington (E2SSB 5395, in effect Jun 11, 2026) and Iowa (HF 2635, in effect Jul 1, 2026) went furthest of the 2026 laws. New York has active bills (e.g., S7896 / A11048) pending, not yet enacted.

    Read the bill number, not the tracker Several widely-cited trackers list Georgia's law as "SB 544" (a county property-tax bill), and credit Maryland's HB 1563 (an emergency-room study bill) as an AI law rather than Maryland's actual AI utilization-review law, HB 820. Neither is true. Every bill on this page is cited to its enacted text.

    Healthcare impact Multi-state payers face a thickening patchwork that all points the same way: AI can recommend, a human must decide.

    Maryland HB 820 — the flat ban, and the earliest in force

    2025 Md. Laws ch. 747 · Md. Ins. Art. §15-10B-05.1 & §15-10A-06 · signed May 20, 2025 · effective Oct 1, 2025
    In effect

    Prohibits Maryland's rule is the bluntest in the wave, and it is a prohibition rather than a "sole basis" qualifier: "An artificial intelligence, algorithm, or other software tool may not deny, delay or modify health care services." (§15-10B-05.1(D))

    And requires Any carrier, pharmacy benefits manager, or private review agent that uses AI in utilization review must ensure the tool bases determinations on the enrollee's own medical and clinical history and individual circumstances and not solely on a group data set; does not replace the role of a health care provider in the determination; does not unfairly discriminate; is fairly and equitably applied; is open to audit by the Insurance Commissioner; is described in written policies in the utilization review plan; has its performance reviewed and revised at least quarterly; keeps patient data to its stated purpose; and does not cause harm to an enrollee.

    And counts them The amendment to §15-10A-06 makes AI denials visible: a carrier's quarterly report to the Commissioner must state whether an AI, algorithm, or other software tool was used in making each adverse decision. Washington reached the same denial-transparency idea a year later, effective Oct 1, 2026 — Maryland got there first.

    Healthcare impact If you appeal Maryland denials, this is the strongest text in the country to appeal against: the tool is not permitted to deny, delay, or modify at all, and the carrier has to tell the regulator quarterly whether AI touched the decision.

    Texas SB 815 and Nebraska LB 77 — the 2025 laws that switched on in January 2026

    TX SB 815 (89th Leg., R.S.) · Tex. Ins. Code §4201.156 · signed Jun 20, 2025 — NE LB 77 · Ensuring Transparency in Prior Authorization Act · approved Jun 4, 2025
    In effect

    Texas prohibits Texas legislated a year before the 2026 wave, and its rule is stricter than a "sole basis" test: "A utilization review agent may not use an automated decision system to make, wholly or partly, an adverse determination." (§4201.156(a)) The statute defines the terms it regulates — an "artificial intelligence system" is a machine-learning-based system that infers from its inputs how to generate outputs including decisions, predictions and recommendations, and an "automated decision system" is an algorithm, including one incorporating an AI system, that uses data-based analytics to make, suggest, or recommend determinations. AI remains permitted for administrative support and fraud detection (§4201.156(c)), and the commissioner "may audit and inspect at any time" a UR agent's use of one (§4201.156(b)). Separately, notice of an adverse determination must now include "a description of and the source of the screening criteria and review procedures used" (§4201.303(a)(3)).

    Read the dates carefully The act itself took effect Sep 1, 2025, but it "applies only to utilization review conducted for a health benefit plan delivered, issued for delivery, or renewed on or after January 1, 2026." Trackers usually print only one of those two dates.

    Nebraska requires Nebraska put its AI rule inside a prior-authorization reform act, which is why it rarely appears on AI trackers. Section 12: "An artificial intelligence-based algorithm shall not be the sole basis of a utilization review agent's decision to deny, delay, or modify health care services based, in whole or in part, on medical necessity." A UR agent must disclose — to the department, to each provider in its network, to each enrollee, and on its public website — whether AI-based algorithms are used or will be used in utilization review. The department may audit the automated utilization-management system at any time, and may hire a third party to do it. Section 12 became operative Jan 1, 2026.

    Healthcare impact Two more states were already regulating payer AI before the 2026 wave began, and both reach a Texas- or Nebraska-licensed plan today. Texas closes the gap a "sole basis" rule leaves open — "wholly or partly" removes the defense that a human rubber-stamped the algorithm's output — and Nebraska's four-way disclosure duty means a provider can check a plan's own website to see whether AI touches its reviews before appealing a denial.

    Washington E2SSB 5395 — the most prescriptive of the 2026 wave

    Ch. 157, Laws of 2026 · amends RCW 48.43.830 · signed Mar 23, 2026 · effective Jun 11, 2026
    In effect

    Requires The core rule is stated flatly: "Artificial intelligence shall not be the sole means used to deny, delay, or modify health care services." Algorithms may be used to process and approve prior-authorization requests, but "may not be used without human review to deny care based on a determination of medical necessity."

    And more A carrier using AI for prior authorization must also ensure the AI bases its determination on the enrollee's own clinical history and individual circumstances and not solely on a group data set; that it does not discriminate; that it is applied fairly and equitably; that its policies and procedures are open to audit by the insurance commissioner; that its performance and outcomes are periodically reviewed; and that patient data is not used beyond its stated purpose (consistent with HIPAA).

    The reporting line "By October 1, 2026, and annually thereafter," large carriers must report to the commissioner — among other prior-authorization data — "the percentage of total denials that were aided by artificial intelligence."

    Healthcare impact Washington doesn't stop at putting a human in the loop — it makes the AI itself auditable and forces carriers to disclose how much of their denial volume AI touched. For providers appealing a Washington denial, that reporting line is new leverage.

    Iowa HF 2635 — AI may screen a request, but can't deny, delay, or downgrade it

    Iowa Acts ch. 1087 · Iowa Code §514F.8(2A) · signed May 13, 2026 · effective Jul 1, 2026
    In effect

    Requires A utilization review organization "may use an artificial intelligence-based algorithm or system to provide an initial review" of a prior-authorization request — but for a request based on medical necessity it "shall not use an artificial intelligence-based algorithm or system as the sole basis for the utilization review organization's decision to deny, delay, or downgrade the prior authorization request."

    The new word Iowa is the first in this wave to name and cover downgrade — defined as converting an expedited or urgent request to a standard determination, or modifying the requested service to a lower-level one. The same act also adds new limits on payer audits of providers (Iowa Code §514F.8C).

    Healthcare impact Iowa closes the gap the other statutes leave open: a payer can't sidestep the "human must decide" rule by quietly downgrading a request instead of denying it outright.

    The downcoding rules — Indiana and Illinois

    IN HEA 1271 (IC 27-1-52) · signed Mar 4, 2026 · effective Jul 1, 2026 — IL SB 3114 (PA 104-0568) · signed Jul 10, 2026 · effective Jan 1, 2028
    IN in effect

    Requires Two states now regulate the quieter cousin of the outright denial: downcoding — paying a claim at a lower level than the clinician billed. Indiana (in effect since Jul 1, 2026) says an insurer "may not use an automated: (1) process; (2) system; or (3) tool, including artificial intelligence; as the sole basis to downcode a claim based on medical necessity without the review of the covered individual's medical record by an employee or contractor of the insurer" — and must disclose, "in an easily accessible and readable manner," when AI is used to make an adverse determination on a prior-authorization request or to downcode a claim. Indiana also bars providers from using AI to submit a claim without human review.

    Illinois goes further The Transparency in Downcoding Act bars a payor from using "any algorithm or other automated process, system, or tool that bypasses the evaluation of information included by the billing health care professional." AI may flag claims that may justify downcoding, but "all downcoding determinations must be made or reviewed by a natural person"; the payor must give the clinician the specific reason (including the original and revised codes) and a dispute process with a submission window of no less than 90 days, in which every dispute is reviewed by a natural person who was not involved in the original decision.

    Scope Illinois reaches group health plan sponsors, insurance issuers, and Medicaid managed-care organizations — but not ERISA self-insured plans, workers' compensation, or excepted benefits.

    Healthcare impact If you bill in Indiana, a downcoded claim that no human checked against the record is already unlawful — and the payer has to tell you when AI touched it. That is appealable leverage today, not in 2028.

    Prior-authorization rules — Alabama, Georgia, Utah

    AL SB 63 (Act 2026-589) · GA SB 444 (O.C.G.A. §33-46-7.1) · UT SB 319 (Utah Code §31A-22-650)
    Effective soon

    Requires Three more states put a licensed human between AI and a denial. Alabama (SB 63, signed Apr 16, 2026, effective Oct 1, 2026): a decision to "deny, delay, or modify" a prior-authorization request based on medical necessity "shall always be made by a licensed physician or other health care professional who is competent to evaluate any recommendation or conclusion of artificial intelligence." The plan must also certify annually to the department that its AI does not rely on a group dataset, is applied fairly and equitably, and does not discriminate — and must make prominent written disclosure of its AI use in its utilization-review policies and procedures.

    Georgia (SB 444, effective Jan 1, 2027): AI may automate tasks and participate in decision-making, but such systems "shall not issue an adverse determination to a patient until a natural person qualifying as a private review agent or a utilization review entity conducts a utilization review in which a clinical peer participates. In no event shall artificial intelligence … supersede the judgment of such clinical peer."

    Utah (SB 319, effective Jan 1, 2027): an insurer must disclose — to the department, to each health care provider in its network, and to each enrollee — if it uses AI to review authorization requests. And an adverse preauthorization determination on clinical or medical necessity must be made by an individual who "exercises independent medical judgment" and "does not rely solely on recommendations from any other source."

    Healthcare impact Utah is the one providers should watch: you are entitled to be told that your patients' authorizations are being screened by AI. That disclosure is what you appeal against.

    The broader landscape — by the numbers

    NCSL · MultiState · Manatt Health AI Policy Tracker
    Active legislating

    Context In 2025, legislators in 36 states introduced 168 AI-and-health bills, part of a record year for AI legislation generally. There is no single clean count of states with enacted healthcare-AI statutes — the honest summary is "dozens of states are legislating; a smaller subset have enacted binding health-AI or insurer-AI laws," and the pace is accelerating.

    Healthcare impact Expect your state's rules to change. The safe posture is to build to the strictest common denominator now.

    Action · what this means for you

    Six moves that satisfy almost every rule above.

    The patchwork is sprawling, but the obligations converge. If you do these six things, you are aligned with the direction of travel across nearly every federal and state requirement on this page.

    1. 01

      Inventory your AI

      Know every AI tool touching patients or PHI, including the consumer ones staff use unofficially. §1557 and the proposed HIPAA Security Rule both assume you have this list.

    2. 02

      Get BAAs that cover model training

      Any AI vendor handling PHI is a business associate. The BAA should state plainly whether your data can train their models. Usually, it should not.

    3. 03

      Keep a human in the loop

      For any care or coverage decision, a licensed person must make the call. CMS, California, Illinois, Colorado, and the multi-state UR wave all require it.

    4. 04

      Disclose AI to patients

      Disclosure is the single most common new requirement. If AI writes to patients or interacts with them, say so, and give a path to a human.

    5. 05

      Write an AI acceptable-use policy

      Put guardrails in writing: which tools are approved, what data may never be entered, who reviews AI output. It is the artifact regulators and insurers ask for.

    6. 06

      Monitor and revisit

      Rules and tools both shift monthly. Bias testing, performance monitoring, and a policy review cadence turn a one-time scramble into living compliance.

    The honest caveat

    This is a fast-moving, contested area. Effective dates slip, rules get withdrawn (see HTI-2), laws get repealed before they start (see Colorado), and a federal push to preempt state AI laws is underway. Treat this brief as a map for orientation and verify any specific obligation against the linked primary source and your counsel before you act on it.

    Straight answers

    Five questions, answered from the map.

    There is no single law governing AI in healthcare. A handful of federal rules and a growing set of state laws apply, and HIPAA still governs any tool that touches patient data.

    These are the five questions readers and AI assistants ask most. Each answer comes from the entries above, and every entry links to its primary source.

    • Current as of August 20, 2026
    • 59 rules
    • Every entry cited
    • Checked every morning
    Ask a specialist about a rule

    No. There is no single 'AI in healthcare' law. Instead there is a patchwork of FDA guidance, HHS rules (including HIPAA and Section 1557), FTC enforcement, federal executive orders, and a fast-growing set of state laws. The same handful of principles repeat across almost all of them.

    Yes. HIPAA is technology-neutral, so its existing Privacy and Security Rules already govern any AI tool that touches protected health information. An AI vendor that creates, receives, maintains, or transmits PHI is a business associate and needs a Business Associate Agreement (BAA).

    No. CMS, California (SB 1120), and a growing number of states require that a qualified licensed human, not an algorithm alone, make or own any medical-necessity denial. AI can assist; a human must decide.

    Increasingly, yes. Disclosure is the most common new requirement. For example, California's AB 3030 requires a disclaimer on generative-AI clinical communications to patients, with a path to reach a human.

    A growing list of states bar it. Illinois (the WOPR Act), Nevada (AB 406), and Maine (LD 2082, effective July 29, 2026) prohibit AI from delivering therapy or professional mental-health care directly to the public; Tennessee (SB 1580) bars representing an AI system as a qualified mental-health professional; Delaware (HB 191) bars AI from holding or using a medical license or title; and Utah, Idaho, Nebraska, and Colorado regulate mental-health and conversational chatbots.

    The map says what the rules demand. The score says where you stand.

    Most organizations already have two or three of the six moves in place. The audit-readiness score checks the HIPAA half in about ten minutes: BAAs, policies, training, risk analysis, and the officer who owns them. No signup, nothing to install.

    Or talk to a specialist

    About ten minutes · No signup · No call required

    500+
    healthcare organizations
    100%
    audit success rate
    2010
    protecting healthcare since

    Citations · 12

    Sources & further reading

    Primary government sources are listed first in each group, followed by established legal/policy analyses used to confirm dates and details. All links verified accessible at time of writing.

    Disclaimer. This document is an informational summary prepared by Live Compliance for educational purposes. It is current as of August 20, 2026 and reflects a rapidly changing legal landscape: effective dates, rule statuses, and pending legislation change frequently. It is not legal advice and does not create an attorney-client relationship. Verify any specific requirement against the linked primary source and consult qualified counsel before acting.