Healthcare AI regulations, tracked and explained for 2026
The rules that apply when you put AI tools to work in a clinic, tracked and explained in plain language, from HIPAA and the certification programme through to the state AI acts. Each page tells you what the rule requires, who it applies to, what the deadlines are, and what changed this year.
Medical Board of California and allied licensing boards, Department of Managed Health Care, Department of Insurance, California Attorney General, and the California Privacy Protection Agency
California's Healthcare AI Laws: AB 3030, SB 1120 and the Rest of the Family
AB 3030 disclaimers, SB 1120 physician review, AB 489, CMIA and the CCPA rules. What each California law requires of a provider deploying AI agents, and when.
Updated
HHS Office for Civil Rights
HIPAA and AI: What Providers Have to Get Right
What HIPAA requires when an AI vendor handles patient data: business associate agreements, retention, model training, consent and the controls to insist on.
Updated
Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC)
HTI-1: Algorithm Transparency Requirements for Certified Health IT
What HTI-1 requires of predictive AI inside certified EHRs: 31 source attributes, risk management, and the questions providers should be asking vendors.
Updated
Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC)
HTI-2: What Was Finalised, What Was Withdrawn, and What It Means
HTI-2 was finalised as a narrow TEFCA rule. What survived, what became HTI-3 and HTI-4, what was withdrawn, and which parts matter for AI agents.
Updated
Texas Attorney General, with additional sanctions available to state licensing agencies
Texas TRAIGA: What HB 149 Requires of Healthcare Providers
TRAIGA has been in force since January 2026. The patient disclosure duty, the intent based prohibitions, the NIST safe harbour and what SB 1188 adds on top.
Updated
Centers for Medicare and Medicaid Services
The CMS Interoperability and Prior Authorization Rule (CMS-0057-F)
CMS-0057-F in plain terms: which payers are covered, the 72 hour and 7 day decision limits now in force, the January 2027 API deadlines, and what to demand.
Updated
Colorado Attorney General, Colorado Department of Law
The Colorado AI Act, Repealed and Rewritten: What Deployers Owe Now
Colorado repealed SB 24-205 and replaced it with SB 26-189. What a health system deploying AI agents owes patients from January 2027, and what is exempt.
Updated
European Commission AI Office, together with national market surveillance authorities designated by each Member State
The EU AI Act in Healthcare: Deployer Obligations After the Digital Omnibus
How the EU AI Act binds healthcare deployers after the July 2026 Digital Omnibus: revised dates, risk classification, and what US organisations must note.
Updated
Utah Division of Consumer Protection, Department of Commerce, supported by the Office of Artificial Intelligence Policy
The Utah AI Policy Act: Disclosure Duties That Land on Licensed Clinicians
Utah's AI disclosure rules, rewritten in 2025. When a licensed clinician must proactively tell a patient they are talking to generative AI and the safe harbour.
Updated
U.S. Food and Drug Administration, Center for Devices and Radiological Health
When Is a Healthcare AI Tool an FDA-Regulated Medical Device?
Where FDA draws the device line for healthcare AI: the four non-device CDS criteria, why most administrative agents are not devices, and what to ask vendors.
Updated
What changes when
Pulled from the effective-dates table on each rule’s own page, so this list cannot say something the underlying page does not. Each rule’s page also carries the dates before this window: signature, comment period, an earlier version repealed.
| Date | Rule | What changes | Status |
|---|---|---|---|
| Texas TRAIGA | TRAIGA took effect. | In effect | |
| CMS-0057-F | Prior authorisation process policies apply: decision timeframes, specific denial reasons, and the requirement to publish metrics. | In effect | |
| California AI laws | AB 489 took effect, barring AI systems from using terms implying that care is provided by a licensed health care professional. | In effect | |
| HIPAA | Compliance date for the final rule aligning 42 CFR Part 2 substance use disorder records more closely with HIPAA. | In effect | |
| EU AI Act | General date of application of the AI Act, including the Article 50 transparency obligations and Article 6(5), the Commission's duty to publish guidelines on high-risk classification, which the Omnibus deliberately left out of the deferral. | In effect | |
| Colorado AI Act | HB 26-1195, the psychotherapy artificial intelligence restrictions, took effect for Colorado licensed psychotherapy providers. | Ahead | |
| CMS-0057-F | Four FHIR APIs due: Patient Access with prior authorisation information, Provider Access, Payer-to-Payer, and Prior Authorization. | Ahead |
How the layers stack, and who each one binds
Federal rules mostly regulate a function, not an organisation. HIPAA binds covered entities and, since the Omnibus Rule, business associates directly, which is why a vendor’s own posture is your problem too. HTI-1 binds the developer of certified health IT, reaching a provider only indirectly through the certified EHR requirements CMS programs depend on. The CMS prior authorization rule binds payers, not providers, with one exception: the Electronic Prior Authorization measure inside MIPS. And FDA binds the manufacturer of a device, not the organisation using it; FDA does not regulate the practice of medicine.
State AI statutes work differently: most bind the deployer directly, usually the hospital, clinic or practice putting the tool in front of a patient. Colorado is the exception, exempting HIPAA covered entities from most of its sections except employment decisions. Texas and Utah put a disclosure duty directly on the practitioner. The EU AI Act reverses the usual meaning of the word: its “provider” is the vendor, and its “deployer” is the hospital using the tool. A group operating in several states has to satisfy the strictest rule that reaches it, not average across them.
What a rule does not require
The common misreading runs the other way: teams assume a rule reaches further than it does. HIPAA never mentions artificial intelligence and has no separate AI rule, so a vendor calling itself “HIPAA certified AI” is describing nothing in the regulation; ask instead whether it signs a business associate agreement. FDA authorises specific devices for specific indications, not AI in general, so there is no such thing as an FDA-approved AI vendor. The original 2024 Colorado AI Act never actually took effect: its compliance date was pushed back once, then the statute was repealed and rewritten before that date arrived.
Is your tool a regulated device
Most administrative agents are not FDA-regulated devices. A scribe that drafts a note for clinician review or a phone agent that books appointments has no device intended use. The line moves once a vendor claims the software analyses a medical image or diagnostic signal, or gives a specific recommendation the clinician cannot independently review. Decision support that displays a recommendation with time to weigh it can fall inside the statutory exemption; the same logic firing a time-critical alert generally cannot. If you are unsure which side a tool falls on, the healthcare AI law checker walks through the applicable rules for your situation.
Make it a formal evaluation
Everything we publish is free to read and free to argue with. When the decision has to be signed, dated and defended to a board, we run the evaluation against your own estate. We take no vendor commissions.
- A 30 minute evaluation call with an analyst, no pitch deck.
- A read on the vendors and the rules in play, and the use cases we would not touch yet.
- A written proposal with scope, sequence and a fixed fee.
- No obligation
- Direct with an analyst, not a sales rep
- BAA available before any PHI discussion