Healthcare AI regulations, tracked and explained for 2026
The rules that apply when you put AI tools to work in a clinic, tracked and explained in plain language, from HIPAA and the certification programme through to the state AI acts. Each page tells you what the rule requires, who it applies to, what the deadlines are, and what changed this year.
College of Physicians and Surgeons of Alberta for professional standards; Office of the Information and Privacy Commissioner of Alberta for the Health Information Act; Alberta Health as the department responsible for the Act
Alberta AI Scribe Rules: CPSA Advice, the Health Information Act and the OIPC PIA Guidance
What CPSA's AI advice, the Health Information Act and the OIPC's AI scribe PIA guidance require before an Alberta clinic records a visit, and what is approved.
Updated
Arizona Department of Insurance and Financial Institutions for HB 2175; the Arizona Medical Board and other Title 32 licensing boards for clinician conduct; the Arizona Attorney General for breach notification and consumer fraud
Arizona AI Laws for Healthcare Providers: HB 2175 and What Else Applies
Arizona has one AI specific healthcare statute in force: HB 2175 on payer denials, effective July 1, 2026. What clinics, scribes and phone agents must do now.
Updated
College of Physicians and Surgeons of British Columbia for professional standards; Office of the Information and Privacy Commissioner for BC for PIPA and FIPPA; Provincial Health Services Authority and the regional health authorities for the BC Scribe programme
British Columbia AI Scribe Rules: CPSBC, PIPA, FIPPA and the BC Scribe Programme
What CPSBC's AI guideline, PIPA, OIPC guidance and FIPPA require before a BC clinic or health authority uses an AI scribe, and the six BC Scribe tools.
Updated
Florida Attorney General (Department of Legal Affairs) for FDUTPA, the Digital Bill of Rights and FIPA; the Agency for Health Care Administration for licensure and the offshore storage attestation; the Board of Medicine and Department of Health for practitioner discipline; the Office of Insurance Regulation for carriers
Florida's Healthcare AI Laws: What Passed, What Died Twice in 2026, and What Binds a Clinic Anyway
Florida's AI Bill of Rights died twice in 2026. What still binds a clinic: the offshore data storage ban, all party recording consent, FIPA and records rules.
Updated
Georgia Office of the Commissioner of Insurance and Safety Fire for utilization review (SB 444); Georgia Attorney General for AI companion chatbots (SB 540); Georgia Composite Medical Board for physician conduct and records
Georgia AI Laws for Healthcare Providers: SB 444, SB 540 and What Applies Now
Georgia has no general AI act. SB 444 limits AI denials from January 2027, SB 540 covers companion chatbots from July 2027. What a Georgia clinic must do now.
Updated
HHS Office for Civil Rights
HIPAA and AI: What Providers Have to Get Right
What HIPAA requires when an AI vendor handles PHI: BAA clauses, model training, de-identification, minimum necessary, consent, breach duties and state overlays.
Updated
Illinois Department of Financial and Professional Regulation for the Wellness and Oversight for Psychological Resources Act and licensee discipline; Illinois Department of Human Rights for HB 3773; Illinois Department of Insurance for utilization review; Illinois Attorney General under the Consumer Fraud and Deceptive Business Practices Act; private plaintiffs under BIPA, GIPA and the Mental Health and Developmental Disabilities Confidentiality Act
Illinois's Healthcare AI Laws: The AI Therapy Ban, BIPA, HB 3773 and the Clinical Peer Rule
HB 1806's AI therapy ban, BIPA for voiceprints, HB 3773 on AI in hiring and the clinical peer rule for algorithmic utilization review, for Illinois clinics.
Updated
Maryland Insurance Administration for HB 820; Office of the Attorney General, Consumer Protection Division for MODPA; Maryland Board of Physicians and the other health occupations boards for licensee conduct
Maryland AI Laws for Healthcare: HB 820, MODPA and What a Clinic Must Do
Maryland's AI rules for healthcare: HB 820 on AI in utilization review, MODPA consumer health data duties, all party consent for AI scribes, and what to do.
Updated
Massachusetts Attorney General under General Laws chapter 93A and chapter 93H; the Division of Insurance for carriers; the Board of Registration in Medicine and the other boards under the Division of Occupational Licensure for clinicians; the Health Policy Commission for market oversight
Massachusetts's Healthcare AI Laws: The Attorney General's Advisory, Chapter 93A and the Bills Still in Conference
No Massachusetts AI statute yet. What binds a clinic: the AG's Chapter 93A advisory, the wiretap law, the DOI AI bulletin and the health bills pending.
Updated
Minnesota Attorney General for the Consumer Data Privacy Act and consumer protection; Minnesota Department of Commerce and Department of Health for utilization review organisations under chapter 62M; Minnesota Board of Medical Practice for physician conduct
Minnesota AI Laws for Healthcare: The 2026 Prior Authorization Ban, the MCDPA and the Health Records Act
What Minnesota requires of clinics using AI in 2026: the new ban on AI prior authorization denials, the MCDPA, the Health Records Act and recording consent.
Updated
The professional licensing boards for each mental and behavioral health profession, the Attorney General's Bureau of Consumer Protection for consumer health data, and the Division of Insurance for carrier conduct
Nevada's Healthcare AI Laws: AB 406, SB 370 and the Recording Rules
AB 406 has barred AI from mental and behavioural health care since July 2025. The scribe exception, the split recording consent rule and what SB 370 adds.
Updated
New Jersey Attorney General through the Division on Civil Rights and the Division of Consumer Affairs, the State Board of Medical Examiners and other licensing boards within the Division of Consumer Affairs, and the Department of Banking and Insurance for carriers
New Jersey AI Laws for Healthcare Providers: What Applies in 2026 and What Is Still a Bill
No New Jersey AI in healthcare statute yet. What binds a clinic now: the AG algorithmic discrimination guidance, the NJDPA, the prior authorization act, DOBI.
Updated
New York Attorney General for General Business Law articles 47 and 39-F, the Department of Financial Services for insurers, the State Education Department's Office of the Professions for licensed clinicians, and the NYC Department of Consumer and Worker Protection for Local Law 144
New York's Healthcare AI Laws: The AI Companion Law, the SHIELD Act and What Is Still Pending
The AI companion law, the SHIELD Act, NYC Local Law 144 and the pending bills on AI in utilization review and mental health: what a New York clinic must do now.
Updated
College of Physicians and Surgeons of Ontario for professional conduct; Information and Privacy Commissioner of Ontario for PHIPA; Supply Ontario and OntarioMD for the provincial Vendor of Record programme
Ontario AI Scribe Rules: CPSO Advice, PHIPA and the IPC Guidance in One Place
What CPSO, PHIPA and the IPC Ontario guidance require before a clinic turns on an AI scribe, the Vendor of Record list, and a CPSO aligned AI policy outline.
Updated
Oregon Department of Justice (Attorney General) for consumer protection and privacy; Oregon Medical Board and Oregon State Board of Nursing for licensees; Division of Financial Regulation, Department of Consumer and Business Services, for insurers
Oregon AI Laws for Healthcare Providers: HB 2748, the OCPA and What Applies in 2026
Oregon has no general AI statute. What binds a clinic: HB 2748 on AI nurse titles, the Consumer Privacy Act, Medical Board AI expectations and recording rules.
Updated
Pennsylvania Department of State and its licensing boards, including the State Board of Medicine, under the professional practice acts; the Pennsylvania Insurance Department for carriers; the Department of Health for facilities; the Attorney General under the Unfair Trade Practices and Consumer Protection Law
Pennsylvania's Healthcare AI Laws: The Character.AI Suit, HB 1925 and What Already Applies
No Pennsylvania AI statute for healthcare yet. What applies: the Medical Practice Act, the wiretap law, Act 146 on prior authorization and HB 1925.
Updated
Collège des médecins du Québec for professional obligations; Commission d'accès à l'information for Law 25 and the health information act; Santé Québec's Bureau de certification des produits et services technologiques for certification; Office québécois de la langue française for the Charter
Quebec AI Scribe Rules: the CMQ Position, Law 25, the Health Information Act and French
What the Collège des médecins, Law 25, Quebec's health information act and the Charter of the French language require before a Quebec clinic uses an AI scribe.
Updated
Virginia Attorney General for the Consumer Data Protection Act; State Corporation Commission Bureau of Insurance for carrier prior authorization rules; Department of Health Professions boards for licensee conduct
Virginia AI Laws for Healthcare: What Survived the HB 2094 Veto
Virginia has no general AI statute after the HB 2094 veto. What binds a clinic: HB 481 physician review of denials, the VCDPA and Board of Medicine rules.
Updated
Washington Attorney General under the Consumer Protection Act, the Office of the Insurance Commissioner for carrier conduct, and the Washington Medical Commission for physician discipline
Washington's Healthcare AI Laws: My Health My Data, SB 5395 and HB 2225
My Health My Data, SB 5395 on AI in prior authorization, HB 2225 on companion chatbots and the all party consent rule: what a Washington clinic must do in 2026.
Updated
Medical Board of California and allied licensing boards, Department of Managed Health Care, Department of Insurance, California Attorney General, and the California Privacy Protection Agency
California's Healthcare AI Laws: AB 3030, SB 1120 and the Rest of the Family
AB 3030 disclaimers, SB 1120 physician review, AB 489, CMIA and the CCPA rules. What each California law requires of a provider deploying AI agents, and when.
Updated
Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC)
HTI-1: Algorithm Transparency Requirements for Certified Health IT
What HTI-1 requires of predictive AI inside certified EHRs: 31 source attributes, risk management, and the questions providers should be asking vendors.
Updated
Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC)
HTI-2: What Was Finalised, What Was Withdrawn, and What It Means
HTI-2 was finalised as a narrow TEFCA rule. What survived, what became HTI-3 and HTI-4, what was withdrawn, and which parts matter for AI agents.
Updated
Texas Attorney General, with additional sanctions available to state licensing agencies
Texas TRAIGA: What HB 149 Requires of Healthcare Providers
TRAIGA has been in force since January 2026. The patient disclosure duty, the intent based prohibitions, the NIST safe harbour and what SB 1188 adds on top.
Updated
Centers for Medicare and Medicaid Services
The CMS Interoperability and Prior Authorization Rule (CMS-0057-F)
CMS-0057-F in plain terms: which payers are covered, the 72 hour and 7 day decision limits now in force, the January 2027 API deadlines, and what to demand.
Updated
Colorado Attorney General, Colorado Department of Law
The Colorado AI Act, Repealed and Rewritten: What Deployers Owe Now
Colorado repealed SB 24-205 and replaced it with SB 26-189. What a health system deploying AI agents owes patients from January 2027, and what is exempt.
Updated
European Commission AI Office, together with national market surveillance authorities designated by each Member State
The EU AI Act in Healthcare: Deployer Obligations After the Digital Omnibus
How the EU AI Act binds healthcare deployers after the July 2026 Digital Omnibus: revised dates, risk classification, and what US organisations must note.
Updated
Utah Division of Consumer Protection, Department of Commerce, supported by the Office of Artificial Intelligence Policy
The Utah AI Policy Act: Disclosure Duties That Land on Licensed Clinicians
Utah's AI disclosure rules, rewritten in 2025. When a licensed clinician must proactively tell a patient they are talking to generative AI and the safe harbour.
Updated
U.S. Food and Drug Administration, Center for Devices and Radiological Health
When Is a Healthcare AI Tool an FDA-Regulated Medical Device?
Where FDA draws the device line for healthcare AI: the four non-device CDS criteria, why most administrative agents are not devices, and what to ask vendors.
Updated
What changes when
Pulled from the effective-dates table on each rule’s own page, so this list cannot say something the underlying page does not. Each rule’s page also carries the dates before this window: signature, comment period, an earlier version repealed.
| Date | Rule | What changes | Status |
|---|---|---|---|
| Texas TRAIGA | TRAIGA took effect. | In effect | |
| CMS-0057-F | Prior authorisation process policies apply: decision timeframes, specific denial reasons, and the requirement to publish metrics. | In effect | |
| California AI laws | AB 489 took effect, barring AI systems from using terms implying that care is provided by a licensed health care professional. | In effect | |
| HIPAA | Compliance date for the final rule aligning 42 CFR Part 2 substance use disorder records more closely with HIPAA. | In effect | |
| EU AI Act | General date of application of the AI Act, including the Article 50 transparency obligations and Article 6(5), the Commission's duty to publish guidelines on high-risk classification, which the Omnibus deliberately left out of the deferral. | In effect | |
| Colorado AI Act | HB 26-1195, the psychotherapy artificial intelligence restrictions, took effect for Colorado licensed psychotherapy providers. | In effect | |
| CMS-0057-F | Four FHIR APIs due: Patient Access with prior authorisation information, Provider Access, Payer-to-Payer, and Prior Authorization. | Ahead |
How the layers stack, and who each one binds
Federal rules mostly regulate a function, not an organisation. HIPAA binds covered entities and, since the Omnibus Rule, business associates directly, which is why a vendor’s own posture is your problem too. HTI-1 binds the developer of certified health IT, reaching a provider only indirectly through the certified EHR requirements CMS programs depend on. The CMS prior authorization rule binds payers, not providers, with one exception: the Electronic Prior Authorization measure inside MIPS. And FDA binds the manufacturer of a device, not the organisation using it; FDA does not regulate the practice of medicine.
State AI statutes work differently: most bind the deployer directly, usually the hospital, clinic or practice putting the tool in front of a patient. Colorado is the exception, exempting HIPAA covered entities from most of its sections except employment decisions. Texas and Utah put a disclosure duty directly on the practitioner. The EU AI Act reverses the usual meaning of the word: its “provider” is the vendor, and its “deployer” is the hospital using the tool. A group operating in several states has to satisfy the strictest rule that reaches it, not average across them.
What a rule does not require
The common misreading runs the other way: teams assume a rule reaches further than it does. HIPAA never mentions artificial intelligence and has no separate AI rule, so a vendor calling itself “HIPAA certified AI” is describing nothing in the regulation; ask instead whether it signs a business associate agreement. FDA authorises specific devices for specific indications, not AI in general, so there is no such thing as an FDA-approved AI vendor. The original 2024 Colorado AI Act never actually took effect: its compliance date was pushed back once, then the statute was repealed and rewritten before that date arrived.
Is your tool a regulated device
Most administrative agents are not FDA-regulated devices. A scribe that drafts a note for clinician review or a phone agent that books appointments has no device intended use. The line moves once a vendor claims the software analyses a medical image or diagnostic signal, or gives a specific recommendation the clinician cannot independently review. Decision support that displays a recommendation with time to weigh it can fall inside the statutory exemption; the same logic firing a time-critical alert generally cannot. If you are unsure which side a tool falls on, the healthcare AI law checker walks through the applicable rules for your situation.
Make it a formal evaluation
Everything we publish is free to read and free to argue with. When the decision has to be signed, dated and defended to a board, we run the evaluation against your own estate. We take no vendor commissions.
- A 30 minute evaluation call with an analyst, no pitch deck.
- A read on the vendors and the rules in play, and the use cases we would not touch yet.
- A written proposal with scope, sequence and a fixed fee.
- No obligation
- Direct with an analyst, not a sales rep
- BAA available before any PHI discussion