HIPAA Security Rule Update Get ahead of the rule.

    This page changes when the rules do. Leave your email and we’ll drop you a friendly note whenever we update the map — that’s the only thing we’ll ever send.

    Regulatory reference · Federal & State

    AI in healthcare:
    the rules, in plain English.

    Artificial intelligence is moving faster than any single law can keep up with. So instead of one rulebook, healthcare organizations now face a patchwork — FDA guidance, HHS rules, FTC enforcement, executive orders, and a fast-growing wave of state laws. Here is the whole map, with every claim cited to its primary source.

    Current as of July 17, 2026 · informational, not legal advice

    The big picture

    There is no single "AI in healthcare" law. There's a moving patchwork — and the same handful of rules keep showing up.

    Federal policy turned sharply deregulatory in 2025–26 — the Biden AI executive order was rescinded, a draft ONC rule would actually remove AI transparency requirements, and the White House is now pushing to preempt state AI laws. Into that vacuum, states have stepped hard. Underneath the noise, five principles repeat across almost every rule:

    • 1A human owns the decision. AI can assist, but a licensed person must make any care or coverage denial — it can't be the sole basis.
    • 2Tell people it's AI. Disclosure to patients (and regulators) is the most common new requirement nationwide.
    • 3No algorithmic discrimination. AI tools that touch protected classes must be fair, validated, and monitored.
    • 4Existing law already applies. HIPAA, the FTC Act, and §1557 govern AI today — no "AI exemption" exists.
    • 5Therapy is a red line. A cluster of states now bar AI from delivering mental-health care directly to patients.

    What's inside

    The map.

    Each entry below carries a In effect / Effective soon / Proposed / Guidance / Rescinded / failed status, the citation, what it requires, the healthcare impact, and a link to the primary source.


    At a glance

    Everything on one screen.

    Rule / lawLevelStatusKey date
    FDA — Predetermined Change Control Plans (PCCP)Federal · FDAFinal guidanceDec 2024
    FDA — AI device lifecycle management (draft)Federal · FDADraftJan 2025
    FDA — Clinical Decision Support guidance (revised)Federal · FDAFinal guidanceJan 6, 2026
    ONC HTI-1 — Predictive DSI transparencyFederal · ASTP/ONCIn effectCompliance Jan 1, 2025
    ONC HTI-2 — interoperability expansionFederal · ASTP/ONCWithdrawnDec 29, 2025
    ONC HTI-5 — would remove AI "model cards"Federal · ASTP/ONCProposedDec 2025
    HHS §1557 — patient-care decision-support toolsFederal · OCRIn effectCompliance May 1, 2025
    CMS — Medicare Advantage individualized decisionsFederal · CMSIn effectApplies Jan 1, 2024
    CMS — WISeR Model (AI prior auth, Original Medicare)Federal · CMSIn effect (pilot)Jan 1, 2026
    HIPAA Security Rule overhaul (NPRM, cites AI)Federal · OCRProposedJan 2025
    FTC — Operation AI Comply + health-data actionsFederal · FTCEnforcement2023–2024
    EO 14110 (Biden AI order)Federal · WHRescindedJan 20, 2025
    EO 14179 + America's AI Action PlanFederal · WHIn effect2025
    EO 14365 — preempt "onerous" state AI lawsFederal · WHIn effectDec 11, 2025
    10-year federal moratorium on state AI lawsFederal · Cong.Failed 99–1Jul 1, 2025
    Colorado AI Act — SB 24-205State · CORepealedNever took effect
    Colorado AI Act — SB 26-189 (replacement)State · COEffective soonJan 1, 2027
    Colorado HB 26-1139 (AI in health care / UR)State · COEffective soonJan 1, 2027
    Colorado HB 26-1195 (AI psychotherapy limits)State · COEffective soonAug 12, 2026
    Colorado HB 26-1263 (conversational-AI safety)State · COEffective soonJan 1, 2027
    Texas TRAIGA — HB 149State · TXIn effectJan 1, 2026
    Texas SB 1188 (clinician review of AI records)State · TXIn effectSep 1, 2025
    Utah AI Policy Act — SB 149 (+ 2025 amendments)State · UTIn effectMay 1, 2024
    Utah HB 452 (mental-health chatbots)State · UTIn effectMay 7, 2025
    California AB 3030 (GenAI patient comms disclaimer)State · CAIn effectJan 1, 2025
    California SB 1120 (Physicians Make Decisions Act)State · CAIn effectJan 1, 2025
    California AB 489 (AI can't pose as a clinician)State · CAIn effectJan 1, 2026
    Illinois WOPR Act — HB 1806 (AI therapy ban)State · ILIn effectAug 1, 2025
    Nevada AB 406 (AI mental/behavioral health)State · NVIn effectJul 1, 2025
    Washington E2SSB 5395 (AI not sole basis for denial)State · WAIn effectJun 11, 2026
    Iowa HF 2635 (no AI-only deny, delay, or downgrade)State · IAIn effectJul 1, 2026
    Tennessee SB 1580 (AI can't pose as a mental-health professional)State · TNIn effectJul 1, 2026
    Delaware HB 191 (AI can't hold a medical license or title)State · DEIn effectApr 23, 2026
    Rhode Island — AI in mental health care (S 2197A)State · RIIn effectJun 22, 2026
    Rhode Island — AI clinical documentation notice (H 7538A)State · RIIn effectJun 22, 2026
    Rhode Island — chatbot self-harm protocols (S 2195A)State · RIEffective soonJan 1, 2027
    Idaho S 1297 (Conversational AI Safety Act)State · IDEffective soonJul 1, 2027
    Nebraska LB 525 (Conversational AI Safety Act)State · NEEffective soonJul 1, 2027
    Maine LD 2082 (AI therapy restrictions)State · MEEffective soonJul 29, 2026
    Indiana HEA 1271 (no AI-only downcoding; AI disclosure)State · INIn effectJul 1, 2026
    Alabama SB 63 (human must make the denial)State · ALEffective soonOct 1, 2026
    Connecticut PA 26-15 (AI companions & mental health)State · CTEffective soonJan 1, 2027
    Oregon SB 1546 (companion chatbots; private right of action)State · OREffective soonJan 1, 2027
    Hawaii SB 3001 (AI disclosure, minor safeguards, crisis protocols)State · HIIn effectJul 14, 2026
    Georgia SB 444 (clinical peer must review AI denials)State · GAEffective soonJan 1, 2027
    Utah SB 319 (AI disclosure in preauthorization)State · UTEffective soonJan 1, 2027
    Iowa SF 2417 (conversational AI; minors)State · IAAppliesJul 1, 2027
    Illinois SB 3114 (no AI-only downcoding) — PA 104-0568State · ILEffective soonJan 1, 2028
    NAIC AI Model Bulletin (insurers) — ~25 statesState · multiGuidance adopted2024–2026

    Note: "Compliance date" is when organizations must comply; it can lag a rule's legal effective date. Future-dated state laws are shown as Effective soon. Each row is detailed and cited below.


    Federal · 1 of 7

    FDA — AI & machine-learning medical devices

    The FDA is the most mature AI-in-healthcare regulator. It reviews AI/ML-enabled software as a medical device (SaMD) through its existing pathways and has authorized more than 1,000 AI-enabled devices. Its newest work focuses on the hardest problem: how to let a model keep learning after clearance without re-reviewing it every time.

    Premarket review of AI/ML devices (510(k), De Novo, PMA)

    FD&C Act · CDRH Digital Health Center of Excellence
    In effect

    Requires AI/ML-enabled devices that diagnose, treat, or inform clinical decisions are reviewed for safety and effectiveness through the same premarket clearance/approval pathways as other devices. As of January 2025, the FDA reported 1,000+ authorized AI-enabled devices (roughly 97% via the 510(k) pathway). The FDA itself notes its traditional paradigm "was not designed for adaptive" AI.

    Healthcare impact If you deploy an AI diagnostic or clinical tool, check whether it is FDA-authorized for its intended use — and whether your use matches the cleared indication.

    Predetermined Change Control Plans (PCCP)

    Final guidance · FR Dec 4, 2024 · docket FDA-2022-D-2628 · FD&C Act §515C
    Final guidance

    Requires A PCCP lets a manufacturer pre-specify and get FDA authorization for future model changes as part of the original submission — so pre-approved updates don't each need a new submission. A PCCP must describe three things: the planned modifications, the methodology to develop/validate/implement them safely, and an impact assessment of benefits and risks.

    Healthcare impact The mechanism that finally lets adaptive AI evolve under FDA oversight — relevant to how quickly your vendors can (legitimately) push model updates.

    AI device lifecycle management & postmarket monitoring

    Draft guidance · issued Jan 6, 2025 · docket FDA-2024-D-4488
    Draft

    Proposes The FDA's first comprehensive, total-product-lifecycle recommendations for AI devices — design, development, validation, transparency, and postmarket performance monitoring. It recommends manufacturers maintain a monitoring plan to catch performance drift after deployment. Still a draft as of July 2026 (comment period closed April 7, 2025).

    Healthcare impact A preview of where device oversight is heading: continuous monitoring of real-world AI performance, not just a one-time clearance.

    Clinical Decision Support Software — revised final guidance

    Revised final guidance · issued Jan 6, 2026 · revises the 2022 CDS guidance
    Final guidance

    Clarifies The FDA's January 2026 revision narrows which decision-support software — expressly including AI-enabled CDS — counts as a regulated medical device. Software that informs a clinician who can independently review the basis for its recommendation can qualify as Non-Device CDS, and the FDA now intends enforcement discretion for some single-recommendation tools (such as guideline-based risk scores) that the 2022 guidance pushed toward device status. The FDA walked industry through the changes in a March 11, 2026 town hall.

    Healthcare impact More AI decision-support tools can now reach clinicians without FDA premarket review — shifting the burden of vetting them onto the organizations that deploy them. Note the rhyme with ONC's deregulatory HTI-5 proposal (§2).

    Federal · 2 of 7

    ONC / ASTP — health-IT certification & AI transparency

    The HHS health-IT office (ASTP/ONC) set the first U.S. transparency rules for AI built into certified electronic health records. Important twist: the current direction is deregulatory — a 2025 proposal would strip those AI transparency requirements back out.

    HTI-1 — Predictive Decision Support Intervention (DSI) transparency

    Final rule · 89 FR 1192 · 45 CFR 170.315(b)(11) · effective Mar 11, 2024
    In effect

    Requires The first substantial update to clinical decision-support certification since 2012. It defines "Predictive DSI" (technology using models trained on data to produce a prediction, classification, or recommendation) and requires certified health-IT developers to disclose 31 "source attributes" for predictive tools (and 13 for evidence-based ones) — effectively an AI "nutrition label" covering intended use, training data, validation, and known risks — plus intervention risk-management practices. Compliance date was January 1, 2025.

    Healthcare impact If your EHR is certified, you have a right to standardized transparency disclosures about the predictive/AI tools embedded in it. This is the one binding federal AI-transparency rule in force today.

    HTI-2 — interoperability & payer-API expansion

    Proposed Aug 2024 · largely withdrawn FR Dec 29, 2025 · RIN 0955-AA08
    Withdrawn

    Status Proposed sweeping certification and interoperability changes (new patient/provider/payer FHIR APIs, public-health data exchange, updated standards). A small TEFCA-related slice was finalized in late 2024; the bulk was formally withdrawn December 29, 2025, citing deregulation and "emerging AI technologies."

    Healthcare impact The payer-API and public-health interoperability work many organizations were preparing for is off the table for now — folded into future rulemaking instead.

    HTI-5 — would remove AI "model card" requirements

    Proposed rule · issued Dec 2025 · "ONC Deregulatory Actions"
    Proposed

    Proposes The live ONC AI rulemaking — and it runs the opposite direction. It would remove the HTI-1 AI source-attribute / "model card" and risk-management requirements from the Predictive DSI criterion, arguing there's no published evidence they improved care. Broadly deregulatory (proposes removing 34 of 60 certification criteria). The comment period closed February 27, 2026; the rule is still not finalized as of July 2026, so the HTI-1 model-card requirements remain in force in the meantime.

    Healthcare impact If finalized, the federal mandate for AI transparency in certified EHRs weakens — pushing the burden of vetting embedded AI back onto provider organizations and the market.

    Federal · 3 of 7

    HHS §1557 — algorithmic nondiscrimination

    Nondiscrimination in "patient care decision support tools"

    2024 Final Rule · 89 FR 37,522 · 45 CFR 92.210 · effective Jul 5, 2024
    In effect

    Requires HHS OCR's Section 1557 rule (Affordable Care Act) extends nondiscrimination protections to "patient care decision support tools" — defined to include AI and clinical algorithms. Covered providers must make reasonable efforts to (1) identify tools they use that rely on input variables measuring race, color, national origin, sex, age, or disability, and (2) mitigate the resulting discrimination risk. Compliance was required by May 1, 2025.

    Healthcare impact Any covered provider using clinical algorithms or AI needs an inventory of those tools and a documented effort to find and reduce bias — this is an active, enforceable obligation today.

    Federal · 4 of 7

    CMS — AI in Medicare Advantage coverage decisions

    The Medicare Advantage rule below regulates payers, not providers — after reporting that algorithms were being used to deny post-acute care, CMS made clear that coverage decisions must be about the individual patient. And since January 2026, CMS is also piloting AI-assisted review inside Original Medicare itself.

    Coverage decisions must be individualized

    Rule CMS-4201-F · 42 CFR 422.101(c) · applies to coverage from Jan 1, 2024
    In effect

    Requires A Medicare Advantage plan's medical-necessity decision must be based on the individual patient's circumstances — medical history, physician recommendations, and clinical notes — not population data alone. In a February 2024 FAQ, CMS clarified that an algorithm or software tool cannot by itself be the basis to deny admission or terminate post-acute care; a patient-specific reassessment is required first.

    Note The "AI can't be the sole basis" language is CMS's interpretive guidance (the FAQ); the regulation itself requires an individualized determination. Proposed AI "guardrails" in the CY2026 rule were not finalized.

    Healthcare impact Plans may use AI to assist utilization review, but a human, patient-specific clinical judgment must stand behind any denial — a principle now spreading to the states (see §10).

    WISeR Model — AI-assisted prior authorization in Original Medicare

    CMS Innovation Center model · Jan 1, 2026 – Dec 31, 2031 · NJ · OH · OK · TX · AZ · WA
    In effect (pilot)

    Status CMS is testing AI/ML-assisted review of prior-authorization requests in Original Medicare (fee-for-service — it does not apply to Medicare Advantage) across six states. The model targets a pre-selected list of services CMS flags as wasteful or fraud-prone (skin and tissue substitutes, electrical nerve-stimulator implants, and knee arthroscopy for knee osteoarthritis, among others). CMS says WISeR does not change Medicare coverage or payment policy — and any non-payment recommendation must come from an appropriately licensed clinician, not the technology alone.

    Healthcare impact The federal government is no longer just regulating AI in coverage decisions — it now runs an AI-assisted review program of its own, with the same guardrail it imposes on payers: AI can flag, a licensed human must decide. Providers of the targeted services in the six model states face a new prior-authorization step.

    Federal · 5 of 7

    OCR / HIPAA — AI & protected health information

    There is no AI-specific HIPAA rule. But HIPAA is technology-neutral — so its existing Privacy and Security Rules already govern any AI tool that touches PHI. This is where most clinics' real-world exposure lives (the "shadow AI" problem).

    AI vendors as business associates; PHI in model training

    45 CFR 160.103 (BA definition) · 45 CFR 164.504(e) (BAA) · 164.514 (de-identification)
    In effect (existing law)

    Requires An AI vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and needs a BAA. Using consumer AI tools with patient data — with no BAA, no risk analysis, no acceptable-use policy — is a HIPAA exposure under rules that already exist. BAAs should explicitly address whether the vendor may use your PHI to train its models (generally not a permitted use without authorization). De-identified data (per 45 CFR 164.514) falls outside HIPAA and is the cleanest path for AI development.

    Healthcare impact The most common gap isn't a missing AI law — it's staff pasting PHI into ungoverned AI tools. Existing HIPAA already makes that a problem.

    HIPAA Security Rule overhaul (names AI explicitly)

    NPRM · 90 FR 898 · issued Dec 27, 2024 · first update since 2013
    Proposed

    Proposes A major cybersecurity update that would require a technology asset inventory and network map explicitly listing AI software that handles ePHI, and would require the risk analysis to assess — before deploying an AI tool — what ePHI it accesses and where outputs go. Confirms ePHI in AI training data and models is within scope. Not finalized as of July 2026; outcome uncertain amid industry pushback — and the Unified Agenda now carries it as a long-term action with final action projected July 2027 (RIN 0945-AA22), so it is unlikely to bind before then.

    Healthcare impact If finalized, AI tools touching ePHI become mandatory line items in your security inventory and pre-deployment risk analysis.

    Federal · 6 of 7

    FTC — AI claims & sensitive health data

    The FTC's message: "there is no AI exemption from the laws on the books." It polices two things relevant to health AI — overstated AI claims and misuse of health data (which feeds AI systems).

    Operation AI Comply — deceptive AI claims

    FTC enforcement sweep · announced Sep 25, 2024 · FTC Act §5
    Enforcement

    Prohibits Unsubstantiated or deceptive AI capability claims ("AI washing"). The September 2024 sweep brought five actions (DoNotPay, Rytr, and others) against companies overhyping or misusing AI. Health-tech AI marketing — diagnostic accuracy, "AI clinician," compliance-automation efficacy — is squarely within this standard.

    Healthcare impact Claims about what your (or a vendor's) AI can do must be substantiated and not overstated.

    Health-data enforcement & the Health Breach Notification Rule

    GoodRx (2023) · BetterHelp (2023) · Cerebral (2024) · HBNR amendments eff. Jul 29, 2024
    Enforcement

    Prohibits Sharing sensitive health data with advertisers/third parties without consent. The FTC penalized GoodRx ($1.5M, its first Health Breach Notification Rule action), BetterHelp ($7.8M), and Cerebral for leaking medication, mental-health, and telehealth data via tracking tools. Its 2024 HBNR amendments expressly cover health apps not governed by HIPAA, and treat tracker/pixel leaks as reportable breaches.

    Healthcare impact Non-HIPAA health apps now have a federal breach-notification duty, and the data those apps feed into AI/ad systems is a live enforcement target.

    Federal · 7 of 7

    White House — executive orders, strategy & preemption

    The federal executive posture flipped in 2025: from precaution to acceleration. The throughline now is "deploy AI, cut rules" — including an active effort to preempt state AI laws.

    EO 14110 (Biden AI order) — rescinded

    88 FR 75191 · signed Oct 30, 2023 · revoked by EO 14148 on Jan 20, 2025
    Rescinded

    Was The most sweeping federal AI action to date — directed an HHS AI Task Force, a health-AI assurance strategy, and an AI safety program for clinical errors. Rescinded on Jan 20, 2025; the HHS deliverables it ordered are now superseded.

    EO 14179 + "America's AI Action Plan"

    EO 14179 (90 FR 8741, Jan 23, 2025) · Action Plan released Jul 23, 2025
    In effect

    Directs A national policy to remove barriers to AI leadership; ordered a review/unwinding of EO 14110 actions and mandated the AI Action Plan. The Plan's three pillars — innovation/deregulation, infrastructure, and global influence — promote rapid AI adoption in healthcare and call for regulatory "sandboxes," including for health.

    HHS AI Strategy (the operative health-AI governance posture)

    Released Dec 2025 · OMB memos M-25-21 / M-25-22 (Apr 3, 2025)
    In effect

    Directs A "OneHHS" approach across CMS, FDA, NIH, CDC — deploy AI aggressively while applying OMB's "high-impact AI" risk-management controls (bias mitigation, monitoring, human oversight), with implementation milestones in 2026.

    Federal preemption of state AI laws

    EO 14365 (Dec 11, 2025) · 10-year moratorium failed (Senate 99–1, Jul 1, 2025)
    In effect / contested

    Status A proposed 10-year moratorium barring states from enforcing AI laws was stripped from the 2025 budget bill 99–1. The White House then issued EO 14365 (Dec 11, 2025), directing a DOJ "AI Litigation Task Force" to challenge "onerous" state AI laws, a Commerce evaluation of those laws, and conditioning some broadband funds on state AI policy. A March 2026 White House framework recommended legislative preemption — not yet enacted. In April 2026 the fight reached the courts: xAI sued Colorado over its AI Act (X.AI LLC v. Weiser, D. Colo., No. 1:26-cv-01515, filed Apr 9, 2026), the DOJ intervened on xAI's side April 24 — the first federal court move against a state AI law — and on April 27 the court suspended enforcement of the Colorado AI Act while the challenge proceeds (a pause Colorado's Attorney General extends to the SB 26-189 replacement; see §8).

    Healthcare impact The single biggest uncertainty in the field: as of July 2026 state AI laws generally remain in effect and enforceable — but the federal override effort is now in court, and it has already paused one state's AI act (Colorado, §8). Watch this closely.

    State · 1 of 3

    State comprehensive AI laws

    Broad, cross-industry AI statutes that sweep in healthcare as a "high-risk" or "consequential" use. The headline story: Colorado wrote the first one, then dismantled it — a vivid example of how unsettled this area still is.

    Colorado AI Act — the SB 24-205 → SB 26-189 saga

    SB 24-205 (2024, repealed) → SB 26-189 (signed May 14, 2026)
    Replacement eff. Jan 1, 2027

    What happened SB 24-205 (2024) was the first U.S. comprehensive AI law — a duty of "reasonable care" to prevent algorithmic discrimination in high-risk uses including healthcare services, with impact assessments and consumer notice. Its effective date slipped from Feb 2026 to June 2026 — then it was repealed and replaced by SB 26-189 before it ever took effect.

    The new law SB 26-189 is narrower: it drops the duty-of-care / impact-assessment regime and instead requires notice that you're interacting with AI, disclosure within 30 days of an adverse outcome, data-correction rights, and human review. HIPAA-covered entities are largely exempt except for employment decisions and financial-assistance eligibility. Effective January 1, 2027.

    Enforcement caveat The law is also under a legal cloud: after xAI sued and the DOJ intervened (X.AI LLC v. Weiser, see §7), the court suspended enforcement on April 27, 2026, and the Attorney General has said he will not enforce SB 26-189 until its rulemaking process concludes.

    Healthcare impact The most-watched state AI law is now far lighter on healthcare than the version everyone prepared for — but Colorado pivoted to targeted healthcare AI laws instead (see §9 and §10).

    Texas TRAIGA — Responsible AI Governance Act

    HB 149 · signed Jun 22, 2025 · effective Jan 1, 2026
    In effect

    Requires Prohibits developing/deploying AI with intent to unlawfully discriminate, to manipulate people toward self-harm or crime, for government social scoring, or for unlawful biometric capture. Enforced by the AG (no private lawsuits), with a 60-day cure period and a regulatory sandbox. Healthcare-specific: TRAIGA's disclosure duty is broad (AI used "in relation to a health care service or treatment"); the specific requirement that a provider disclose to patients when AI is used in diagnosis or treatment comes from a separate Texas law, SB 1188 (see below).

    Healthcare impact Texas providers using AI clinically owe patients an up-front disclosure (can be built into intake forms).

    Utah AI Policy Act + 2025 amendments

    SB 149 (eff. May 1, 2024) · narrowed by SB 226 (2025) · extended by SB 332
    In effect

    Requires One of the first provider-facing AI disclosure laws. People in a regulated occupation (including healthcare providers) must disclose generative-AI use to consumers. A 2025 amendment (SB 226) narrowed proactive disclosure to "high-risk" interactions — which still generally captures use of health data for personalized advice. Created Utah's Office of AI Policy and AI "learning lab."

    Healthcare impact Utah providers using generative AI in patient interactions involving health data must disclose it up front.

    State · 2 of 3

    State healthcare-specific AI laws

    Where the real action is. States are targeting three things directly: AI-generated patient communications, AI posing as a clinician, and AI delivering mental-health therapy.

    California AB 3030 — disclaimer on GenAI patient communications

    Ch. 848, Stats. 2024 · Health & Safety Code §1339.75 · effective Jan 1, 2025
    In effect

    Requires A facility, clinic, or physician's office using generative AI to send patients communications about their clinical information must include a disclaimer that it was AI-generated and instructions to reach a human. Exception: messages reviewed by a licensed human before sending are exempt. Doesn't cover scheduling/billing/admin messages.

    Healthcare impact Either add an AI disclaimer + human-contact path to AI-drafted clinical messages, or route them through a licensed reviewer.

    California SB 1120 — "Physicians Make Decisions Act"

    SB 1120 (2024) · Knox-Keene / Insurance Code · effective Jan 1, 2025
    In effect

    Requires When a health plan or insurer uses AI in utilization review, the AI may not deny, delay, or modify care based on medical necessity — the final determination must be made by a licensed physician or competent licensed professional. The tool must use the patient's individual history, be applied fairly and equitably, not supplant the clinician, and be auditable (overseen by DMHC/CDI).

    Healthcare impact The state-level version of the CMS rule — insurers in California can't let AI auto-deny medical-necessity requests.

    California AB 489 — AI can't pose as a licensed clinician

    Ch. 615, Stats. 2025 · effective Jan 1, 2026
    In effect

    Prohibits AI systems from using terms or titles (e.g., "doctor," "nurse," "psychologist") in a way that implies care is being provided by a licensed human. Each prohibited use is a separate violation, enforced by the relevant licensing board.

    Healthcare impact Patient-facing health chatbots in California must not present themselves as licensed professionals.

    Illinois WOPR Act — AI cannot deliver therapy

    HB 1806 · signed & effective Aug 1, 2025 · enforced by IDFPR
    In effect

    Prohibits Providing therapy/psychotherapy to the public unless by a licensed professional. A licensed clinician may not use AI to make independent therapeutic decisions, interact directly with clients in therapeutic communication, or generate treatment plans without review. Administrative/support uses (notes, scheduling) are allowed. Penalty: up to $10,000 per violation.

    Healthcare impact AI can't run client-facing therapy in Illinois — one of the strictest "AI therapy" bans in the country.

    Nevada AB 406 — AI in mental/behavioral health

    AB 406 · signed Jun 5, 2025 · effective Jul 1, 2025
    In effect

    Prohibits Offering — or claiming — that an AI system can provide professional mental/behavioral health care, and bars providers from using AI to deliver care directly to patients (support uses with provider review allowed). Also restricts AI for these services in public schools. Penalty up to $15,000 per violation.

    Healthcare impact AI cannot be marketed as, or act as, a mental-health professional in Nevada.

    Utah HB 452 — mental-health chatbot rules

    HB 452 · effective May 7, 2025
    In effect

    Requires AI "mental health chatbots" must clearly disclose they are AI (before use, after 7 days of non-use, and on request); in-chat advertising must be labeled; and suppliers may not sell or share users' identifiable health information or inputs (limited exceptions).

    Healthcare impact Behavioral-health chatbot vendors operating in Utah face disclosure, advertising, and data-sharing limits.

    Texas SB 1188 — clinician review of AI-generated records

    SB 1188 · effective Sep 1, 2025
    In effect

    Requires Licensed practitioners may use AI for diagnosis/treatment only within their scope and only if they review all AI-generated records per Texas Medical Board standards; also prohibits offshoring electronic medical records.

    Healthcare impact A human clinician must review AI-generated clinical records in Texas.

    Colorado HB 26-1139 & HB 26-1195 — targeted healthcare AI

    HB 26-1139 (eff. Jan 1, 2027) · HB 26-1195 (eff. Aug 12, 2026)
    Effective soon

    Requires After scaling back its broad AI act, Colorado passed two targeted health laws in mid-2026. HB 26-1139 requires AI coverage decisions to use the patient's individual history, requires a licensed clinician to review medical-necessity denials, mandates disclosure of AI use to regulators, and bars payer reimbursement for AI-delivered psychotherapy. HB 26-1195 restricts AI from conducting therapeutic communication except during live sessions with the provider present, and requires consent for AI session recording.

    Healthcare impact Colorado is now regulating AI in healthcare through precise, sector-specific rules rather than one omnibus law — a model other states may follow.

    The 2026 chatbot wave — Tennessee, Delaware, Idaho, Nebraska, Colorado

    TN SB 1580 (Pub. Ch. 647) · DE HB 191 · ID S 1297 · NE LB 525 · CO HB 26-1263
    In effect / rolling in

    Requires Spring 2026 added four more states to the mental-health red line. Tennessee (SB 1580, eff. Jul 1, 2026) bars advertising or representing that an AI system is — or can act as — a qualified mental-health professional, with a private right of action under its consumer-protection law. Delaware (HB 191, eff. Apr 23, 2026) says a nonhuman entity, including an AI agent, cannot be licensed as — or use the title of — a nurse, physician, or physician assistant. Idaho (S 1297) and Nebraska (LB 525) enacted near-identical Conversational AI Safety Acts (both eff. Jul 1, 2027): public-facing chatbots must clearly disclose they are AI, follow crisis-response protocols when a user expresses suicidal ideation, and may not claim to provide professional mental or behavioral health care. Colorado joined on May 29, 2026 (HB 26-1263, operator requirements eff. Jan 1, 2027): conversational-AI operators must disclose that outputs are AI-generated, maintain suicidal-ideation and self-harm response protocols, protect minor users (age estimation, no simulated emotional dependence), report annually to the Attorney General — and may not represent a chatbot's output as equivalent to services from a licensed professional.

    Healthcare impact The therapy red line (Illinois, Nevada, Utah above) is now a national pattern — and Delaware extends it beyond therapy: AI can't hold, or pose under, a medical license at all.

    Maine LD 2082 — AI can't deliver therapy

    P.L. 2026, ch. 687 · 10 MRSA §1500-EE · signed Apr 13, 2026 · effective Jul 29, 2026
    Effective soon

    Prohibits Providing, advertising, or offering therapy or psychotherapy services to the public — including through Internet-based AI — unless the services are provided by a licensed professional; a violation is an unfair trade practice under Maine law. Licensed clinicians may still use AI for administrative and "supplementary" support (therapy notes, anonymized trend analysis, referral research), but only with the client's explicit written consent — the law says consent can't be collected through a general terms-of-use agreement — after disclosing the tool's purpose and how session data is stored, used for training, and deleted. Even then, the AI may not make independent therapeutic decisions, interact with clients in therapeutic communication, or generate treatment plans without the licensee's review. Clients can't be denied care for refusing consent, and client waivers of these protections are void.

    Healthcare impact Maine joins Illinois and Nevada on the therapy red line — and goes further on consent mechanics: AI consent can't be buried in a terms-of-use agreement, and the disclosure must say whether session data trains the model.

    Rhode Island — AI in mental health care, and AI in the medical record

    S 2197 Sub A as amended / H 7349A (R.I. Gen. Laws ch. 40.1-5.5) · H 7538 Sub A (R.I. Gen. Laws ch. 23-106) · signed Jun 22, 2026 · effective upon passage
    In effect

    Requires Rhode Island enacted two healthcare AI laws that took effect the day they were signed. The Oversight of Artificial Intelligence Technology in Mental Health Care Act bars any person or entity from providing, advertising, or offering therapy or psychotherapy to the public — including through Internet-based AI — unless a licensed professional conducts it. A licensed provider may not let AI make independent therapeutic decisions, determine therapeutic recommendations or treatment plans, or directly engage a client in therapeutic communication without an established relationship. Where AI designed to simulate emotional attachment (or an AI "companion") assists in a recorded or transcribed session, the patient must be told in writing that AI will be used and for what purpose, and must consent — and the statute is explicit that consent cannot be harvested from acceptance of a broad terms-of-use agreement. FDA-cleared AI tools, religious counseling, peer support, and public self-help materials are carved out. Separately, the Use of Artificial Intelligence by Healthcare Providers Notification Act requires any provider or facility that uses AI to document an in-person or telehealth visit to notify the patient and to review the AI-generated documentation for accuracy after the visit.

    Healthcare impact If you run an AI scribe in Rhode Island, patient notice and a post-visit accuracy review are now legal duties, not best practices — the same "a human reviews the AI's output" rule Texas SB 1188 created, now in a second state. Note what the final amendment did to liability: the provider is responsible for clinical judgment and reasonable therapeutic oversight of the patient's use of the system, but not for vendor-controlled system design, algorithms, or outputs.

    Consumer AI-companion laws — Connecticut, Oregon, Iowa, Hawaii

    CT PA 26-15, Secs. 4–6 · OR SB 1546 (Or. Laws 2026 ch. 85) · IA SF 2417 (Iowa Code ch. 554J) · HI SB 3001 CD1 (Artificial Intelligence Disclosure and Safety Act)
    Effective soon

    Requires A separate cluster regulates AI companions — the consumer chatbots people confide in — rather than clinical tools. Connecticut (Public Act 26-15, approved May 27, 2026; the AI-companion sections take effect Jan 1, 2027) requires an evidence-based protocol to detect a user expression indicating risk of suicide, self-harm, or imminent violence and to refer the user to the 988 lifeline and on to treatment "consistent with clinical best practices"; the companion may not claim to be a human being; and for minors it may not offer mental-health services at all unless it is designed to deliver them using clinical best practices and displays, clearly and conspicuously at the start of each interaction, a statement that it is not a licensed mental health professional.

    Oregon and Iowa Oregon (SB 1546, approved Mar 31, 2026, effective Jan 1, 2027) requires a suicidal-ideation detection protocol and a referral carrying contact information and a hyperlink for 988 — or a youthline for a user under 25 — restricts simulated emotional dependence and romantic role-play for minors, and gives users a private right of action for the greater of actual damages or $1,000 per violation. Iowa (SF 2417, approved May 2, 2026; by its own terms the act applies July 1, 2027) requires conspicuous AI disclosure to minor account holders and a protocol referring users to a crisis service, and bars an operator from knowingly programming the service to represent that it provides professional psychology or behavioral-health services that would require a license — enforced by the Attorney General at up to $500,000 per operator, with no private right of action.

    Hawaii Hawaii (SB 3001 CD1, the Artificial Intelligence Disclosure and Safety Act) is the cluster's first to be in effect: Governor Green signed it as Act 248 on July 14, 2026 (Gov. Msg. No. 1350), and it takes effect on approval. It requires operators of conversational-AI services to clearly disclose that a user is interacting with AI rather than a human; adds safeguards for minors — limits on manipulative engagement techniques and sexually explicit content, plus tools for parents and guardians to manage screen time and account settings; and requires a protocol to respond to a user expressing suicidal ideation or self-harm by directing them to crisis-intervention resources such as suicide hotlines and crisis text lines. Beginning January 1, 2028, operators must file annual reports with the Department of Health's Behavioral Health Administration. It is enforced as an unfair or deceptive trade practice.

    Read this one carefully These are operator duties, not provider duties. Connecticut and Oregon both expressly carve out software that assists or supports patient or resident care services in a facility. If you run an AI scribe or a clinical decision-support tool, these four laws are not aimed at you — the ones that are aimed at you are Rhode Island's, Texas SB 1188, and the therapy bans above.

    Healthcare impact Mostly a vendor question. But if your organization offers a patient-facing chatbot marketed as a companion rather than as care-support software, you are the operator — and the crisis-response protocol is yours to build.

    State · 3 of 3

    State insurance & utilization-review rules

    The fastest-moving cluster: states stopping insurers from letting AI auto-deny care. The common rule — a qualified human must own any medical-necessity denial — now appears in roughly a dozen states.

    NAIC Model Bulletin on Insurers' Use of AI

    Adopted Dec 4, 2023 · regulator guidance · ~24–25 states adopted
    Guidance adopted

    Requires Insurers (including health insurers) maintain a written AI governance program covering risk management, bias/data-quality controls, consumer notice, vendor oversight, and documentation available to regulators. As of early-to-mid 2026, roughly half the states (~24–25) had adopted it via bulletin. It's guidance, not a binding denial-of-care ban.

    Healthcare impact Health insurers in adopting states must be able to show documented AI governance and tell consumers when AI is used.

    The "human must decide" wave — multi-state

    CA · IL · AL · IN · IA · UT · WA · GA (2024–2028 effective dates) · NY pending
    In effect / rolling in

    Requires A growing set of states require that AI may assist utilization review but a qualified licensed human — not an algorithm alone — must make or own any medical-necessity denial, and that AI be applied fairly and based on the individual patient. Beyond California (SB 1120) and Illinois, 2026 brought laws in Alabama (SB 63, in effect Oct 1, 2026), Indiana (HEA 1271, in effect Jul 1, 2026), Utah (SB 319, Jan 1, 2027), and Georgia (SB 444, Jan 1, 2027) — each detailed below. Washington (E2SSB 5395, in effect Jun 11, 2026) and Iowa (HF 2635, in effect Jul 1, 2026) went furthest. New York has active bills (e.g., S7896 / A11048) pending, not yet enacted.

    Read the bill number, not the tracker Several widely-cited trackers list Georgia's law as "SB 544" (a county property-tax bill) and credit Maryland's HB 1563 (an emergency-room study bill) as an AI law. Neither is true. Every bill on this page is cited to its enacted text.

    Healthcare impact Multi-state payers face a thickening patchwork that all points the same way: AI can recommend, a human must decide.

    Washington E2SSB 5395 — the most prescriptive AI utilization-review law yet

    Ch. 157, Laws of 2026 · amends RCW 48.43.830 · signed Mar 23, 2026 · effective Jun 11, 2026
    In effect

    Requires The core rule is stated flatly: "Artificial intelligence shall not be the sole means used to deny, delay, or modify health care services." Algorithms may be used to process and approve prior-authorization requests, but "may not be used without human review to deny care based on a determination of medical necessity."

    And more A carrier using AI for prior authorization must also ensure the AI bases its determination on the enrollee's own clinical history and individual circumstances and not solely on a group data set; that it does not discriminate; that it is applied fairly and equitably; that its policies and procedures are open to audit by the insurance commissioner; that its performance and outcomes are periodically reviewed; and that patient data is not used beyond its stated purpose (consistent with HIPAA).

    A first "By October 1, 2026, and annually thereafter," large carriers must report to the commissioner — among other prior-authorization data — "the percentage of total denials that were aided by artificial intelligence."

    Healthcare impact Washington doesn't stop at putting a human in the loop — it makes the AI itself auditable and forces carriers to disclose how much of their denial volume AI touched. For providers appealing a Washington denial, that reporting line is new leverage.

    Iowa HF 2635 — AI may screen a request, but can't deny, delay, or downgrade it

    Iowa Acts ch. 1087 · Iowa Code §514F.8(2A) · signed May 13, 2026 · effective Jul 1, 2026
    In effect

    Requires A utilization review organization "may use an artificial intelligence-based algorithm or system to provide an initial review" of a prior-authorization request — but for a request based on medical necessity it "shall not use an artificial intelligence-based algorithm or system as the sole basis for the utilization review organization's decision to deny, delay, or downgrade the prior authorization request."

    The new word Iowa is the first in this wave to name and cover downgrade — defined as converting an expedited or urgent request to a standard determination, or modifying the requested service to a lower-level one. The same act also adds new limits on payer audits of providers (Iowa Code §514F.8C).

    Healthcare impact Iowa closes the gap the other statutes leave open: a payer can't sidestep the "human must decide" rule by quietly downgrading a request instead of denying it outright.

    The downcoding rules — Indiana and Illinois

    IN HEA 1271 (IC 27-1-52) · signed Mar 4, 2026 · effective Jul 1, 2026 — IL SB 3114 (PA 104-0568) · signed Jul 10, 2026 · effective Jan 1, 2028
    IN in effect

    Requires Two states now regulate the quieter cousin of the outright denial: downcoding — paying a claim at a lower level than the clinician billed. Indiana (in effect since Jul 1, 2026) says an insurer "may not use an automated: (1) process; (2) system; or (3) tool, including artificial intelligence; as the sole basis to downcode a claim based on medical necessity without the review of the covered individual's medical record by an employee or contractor of the insurer" — and must disclose, "in an easily accessible and readable manner," when AI is used to make an adverse determination on a prior-authorization request or to downcode a claim. Indiana also bars providers from using AI to submit a claim without human review.

    Illinois goes further The Transparency in Downcoding Act bars a payor from using "any algorithm or other automated process, system, or tool that bypasses the evaluation of information included by the billing health care professional." AI may flag claims that may justify downcoding, but "all downcoding determinations must be made or reviewed by a natural person"; the payor must give the clinician the specific reason (including the original and revised codes) and a dispute process with a submission window of no less than 90 days, in which every dispute is reviewed by a natural person who was not involved in the original decision.

    Scope Illinois reaches group health plan sponsors, insurance issuers, and Medicaid managed-care organizations — but not ERISA self-insured plans, workers' compensation, or excepted benefits.

    Healthcare impact If you bill in Indiana, a downcoded claim that no human checked against the record is already unlawful — and the payer has to tell you when AI touched it. That is appealable leverage today, not in 2028.

    Prior-authorization rules — Alabama, Georgia, Utah

    AL SB 63 (Act 2026-589) · GA SB 444 (O.C.G.A. §33-46-7.1) · UT SB 319 (Utah Code §31A-22-650)
    Effective soon

    Requires Three more states put a licensed human between AI and a denial. Alabama (SB 63, signed Apr 16, 2026, effective Oct 1, 2026): a decision to "deny, delay, or modify" a prior-authorization request based on medical necessity "shall always be made by a licensed physician or other health care professional who is competent to evaluate any recommendation or conclusion of artificial intelligence." The plan must also certify annually to the department that its AI does not rely on a group dataset, is applied fairly and equitably, and does not discriminate — and must make prominent written disclosure of its AI use in its utilization-review policies and procedures.

    Georgia (SB 444, effective Jan 1, 2027): AI may automate tasks and participate in decision-making, but such systems "shall not issue an adverse determination to a patient until a natural person qualifying as a private review agent or a utilization review entity conducts a utilization review in which a clinical peer participates. In no event shall artificial intelligence … supersede the judgment of such clinical peer."

    Utah (SB 319, effective Jan 1, 2027): an insurer must disclose — to the department, to each health care provider in its network, and to each enrollee — if it uses AI to review authorization requests. And an adverse preauthorization determination on clinical or medical necessity must be made by an individual who "exercises independent medical judgment" and "does not rely solely on recommendations from any other source."

    Healthcare impact Utah is the one providers should watch: you are entitled to be told that your patients' authorizations are being screened by AI. That disclosure is what you appeal against.

    The broader landscape — by the numbers

    NCSL · MultiState · Manatt Health AI Policy Tracker
    Active legislating

    Context In 2025, legislators in 36 states introduced 168 AI-and-health bills, part of a record year for AI legislation generally. There is no single clean count of states with enacted healthcare-AI statutes — the honest summary is "dozens of states are legislating; a smaller subset have enacted binding health-AI or insurer-AI laws," and the pace is accelerating.

    Healthcare impact Expect your state's rules to change. The safe posture is to build to the strictest common denominator now.

    Action · what this means for you

    Six moves that satisfy almost every rule above.

    The patchwork is sprawling, but the obligations converge. If you do these six things, you're aligned with the direction of travel across nearly every federal and state requirement on this page.

    1 · Inventory your AI

    Know every AI tool touching patients or PHI — including the consumer ones staff use unofficially. §1557 and the proposed HIPAA Security Rule both assume you have this list.

    2 · Get BAAs that cover model training

    Any AI vendor handling PHI is a business associate. The BAA should state plainly whether your data can train their models — usually, it shouldn't.

    3 · Keep a human in the loop

    For any care or coverage decision, a licensed person must make the call. CMS, California, Illinois, Colorado, and the multi-state UR wave all require it.

    4 · Disclose AI to patients

    Disclosure is the single most common new requirement. If AI writes to patients or interacts with them, say so — and give a path to a human.

    5 · Write an AI acceptable-use policy

    Put guardrails in writing: which tools are approved, what data may never be entered, who reviews AI output. It's the artifact regulators and insurers ask for.

    6 · Monitor & revisit

    Rules and tools both shift monthly. Bias testing, performance monitoring, and a policy review cadence turn a one-time scramble into living compliance.

    The honest caveat

    This is a fast-moving, contested area. Effective dates slip, rules get withdrawn (see HTI-2), laws get repealed before they start (see Colorado), and a federal push to preempt state AI laws is underway. Treat this brief as a map for orientation and verify any specific obligation against the linked primary source and your counsel before you act on it.

    From map to ready

    Where does AI quietly touch your compliance today?

    Live Compliance helps healthcare organizations turn this patchwork into a living program — AI inventories, acceptable-use policies, BAAs, training, and monitoring that update as the rules do. Start with the free 10-minute gap scan: no forms, no pressure, just your score and where you stand.

    livecompliance.com/gap-scan

    Compliance was never a binder. It's a living thing — and with AI, the ground keeps moving.


    Citations · 12

    Sources & further reading

    Primary government sources are listed first in each group, followed by established legal/policy analyses used to confirm dates and details. All links verified accessible at time of writing.

    Disclaimer. This document is an informational summary prepared by Live Compliance for educational purposes. It is current as of July 17, 2026 and reflects a rapidly changing legal landscape — effective dates, rule statuses, and pending legislation change frequently. It is not legal advice and does not create an attorney–client relationship. Verify any specific requirement against the linked primary source and consult qualified counsel before acting.