Regulations

Healthcare AI regulations, tracked and explained for 2026

The rules that apply when you put AI tools to work in a clinic, tracked and explained in plain language, from HIPAA and the certification programme through to the state AI acts. Each page tells you what the rule requires, who it applies to, what the deadlines are, and what changed this year.

  • Medical Board of California and allied licensing boards, Department of Managed Health Care, Department of Insurance, California Attorney General, and the California Privacy Protection Agency

    California's Healthcare AI Laws: AB 3030, SB 1120 and the Rest of the Family

    AB 3030 disclaimers, SB 1120 physician review, AB 489, CMIA and the CCPA rules. What each California law requires of a provider deploying AI agents, and when.

    Updated

  • HHS Office for Civil Rights

    HIPAA and AI: What Providers Have to Get Right

    What HIPAA requires when an AI vendor handles patient data: business associate agreements, retention, model training, consent and the controls to insist on.

    Updated

  • Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC)

    HTI-1: Algorithm Transparency Requirements for Certified Health IT

    What HTI-1 requires of predictive AI inside certified EHRs: 31 source attributes, risk management, and the questions providers should be asking vendors.

    Updated

  • Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC)

    HTI-2: What Was Finalised, What Was Withdrawn, and What It Means

    HTI-2 was finalised as a narrow TEFCA rule. What survived, what became HTI-3 and HTI-4, what was withdrawn, and which parts matter for AI agents.

    Updated

  • Texas Attorney General, with additional sanctions available to state licensing agencies

    Texas TRAIGA: What HB 149 Requires of Healthcare Providers

    TRAIGA has been in force since January 2026. The patient disclosure duty, the intent based prohibitions, the NIST safe harbour and what SB 1188 adds on top.

    Updated

  • Centers for Medicare and Medicaid Services

    The CMS Interoperability and Prior Authorization Rule (CMS-0057-F)

    CMS-0057-F in plain terms: which payers are covered, the 72 hour and 7 day decision limits now in force, the January 2027 API deadlines, and what to demand.

    Updated

  • Colorado Attorney General, Colorado Department of Law

    The Colorado AI Act, Repealed and Rewritten: What Deployers Owe Now

    Colorado repealed SB 24-205 and replaced it with SB 26-189. What a health system deploying AI agents owes patients from January 2027, and what is exempt.

    Updated

  • European Commission AI Office, together with national market surveillance authorities designated by each Member State

    The EU AI Act in Healthcare: Deployer Obligations After the Digital Omnibus

    How the EU AI Act binds healthcare deployers after the July 2026 Digital Omnibus: revised dates, risk classification, and what US organisations must note.

    Updated

  • Utah Division of Consumer Protection, Department of Commerce, supported by the Office of Artificial Intelligence Policy

    The Utah AI Policy Act: Disclosure Duties That Land on Licensed Clinicians

    Utah's AI disclosure rules, rewritten in 2025. When a licensed clinician must proactively tell a patient they are talking to generative AI and the safe harbour.

    Updated

  • U.S. Food and Drug Administration, Center for Devices and Radiological Health

    When Is a Healthcare AI Tool an FDA-Regulated Medical Device?

    Where FDA draws the device line for healthcare AI: the four non-device CDS criteria, why most administrative agents are not devices, and what to ask vendors.

    Updated

What changes when

Pulled from the effective-dates table on each rule’s own page, so this list cannot say something the underlying page does not. Each rule’s page also carries the dates before this window: signature, comment period, an earlier version repealed.

DateRuleWhat changesStatus
Texas TRAIGATRAIGA took effect.In effect
CMS-0057-FPrior authorisation process policies apply: decision timeframes, specific denial reasons, and the requirement to publish metrics.In effect
California AI lawsAB 489 took effect, barring AI systems from using terms implying that care is provided by a licensed health care professional.In effect
HIPAACompliance date for the final rule aligning 42 CFR Part 2 substance use disorder records more closely with HIPAA.In effect
EU AI ActGeneral date of application of the AI Act, including the Article 50 transparency obligations and Article 6(5), the Commission's duty to publish guidelines on high-risk classification, which the Omnibus deliberately left out of the deferral.In effect
Colorado AI ActHB 26-1195, the psychotherapy artificial intelligence restrictions, took effect for Colorado licensed psychotherapy providers.Ahead
CMS-0057-FFour FHIR APIs due: Patient Access with prior authorisation information, Provider Access, Payer-to-Payer, and Prior Authorization.Ahead

How the layers stack, and who each one binds

Federal rules mostly regulate a function, not an organisation. HIPAA binds covered entities and, since the Omnibus Rule, business associates directly, which is why a vendor’s own posture is your problem too. HTI-1 binds the developer of certified health IT, reaching a provider only indirectly through the certified EHR requirements CMS programs depend on. The CMS prior authorization rule binds payers, not providers, with one exception: the Electronic Prior Authorization measure inside MIPS. And FDA binds the manufacturer of a device, not the organisation using it; FDA does not regulate the practice of medicine.

State AI statutes work differently: most bind the deployer directly, usually the hospital, clinic or practice putting the tool in front of a patient. Colorado is the exception, exempting HIPAA covered entities from most of its sections except employment decisions. Texas and Utah put a disclosure duty directly on the practitioner. The EU AI Act reverses the usual meaning of the word: its “provider” is the vendor, and its “deployer” is the hospital using the tool. A group operating in several states has to satisfy the strictest rule that reaches it, not average across them.

What a rule does not require

The common misreading runs the other way: teams assume a rule reaches further than it does. HIPAA never mentions artificial intelligence and has no separate AI rule, so a vendor calling itself “HIPAA certified AI” is describing nothing in the regulation; ask instead whether it signs a business associate agreement. FDA authorises specific devices for specific indications, not AI in general, so there is no such thing as an FDA-approved AI vendor. The original 2024 Colorado AI Act never actually took effect: its compliance date was pushed back once, then the statute was repealed and rewritten before that date arrived.

Is your tool a regulated device

Most administrative agents are not FDA-regulated devices. A scribe that drafts a note for clinician review or a phone agent that books appointments has no device intended use. The line moves once a vendor claims the software analyses a medical image or diagnostic signal, or gives a specific recommendation the clinician cannot independently review. Decision support that displays a recommendation with time to weigh it can fall inside the statutory exemption; the same logic firing a time-critical alert generally cannot. If you are unsure which side a tool falls on, the healthcare AI law checker walks through the applicable rules for your situation.