Regulation

Arizona AI Laws for Healthcare Providers: HB 2175 and What Else Applies

House Bill 2175, Laws 2025, chapter 165, adding Arizona Revised Statutes sections 20-3103 and 20-3407 (denial of claims and prior authorizations; individual review by the medical director), read together with A.R.S. 20-2510, 36-3602, 13-3005, 18-552, 12-2291 and 32-1401

Last updated

Free tool

Healthcare AI Law Checker

This is a starting map, not legal advice.

Need it signed off?

Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.

Book an evaluation call

Regulator

Arizona Department of Insurance and Financial Institutions for HB 2175; the Arizona Medical Board and other Title 32 licensing boards for clinician conduct; the Arizona Attorney General for breach notification and consumer fraud

Who it applies to

  • Health care insurers issuing medical necessity denials of claims or prior authorizations for Arizona plans, whose medical director must individually review each denial from July 1, 2026 under A.R.S. 20-3103 and 20-3407
  • Arizona licensed physicians and other Title 32 licensees, who remain responsible for adequate records under A.R.S. 32-1401 regardless of whether a draft was produced by an ambient scribe
  • Licensees of the Board of Behavioral Health Examiners, who face an AI notice expectation from January 1, 2027 under the Board's published guidance
  • Any health care provider delivering telehealth to a patient in Arizona, who must obtain and document verbal or written informed consent under A.R.S. 36-3602, and out of state providers, who must register under A.R.S. 36-3606
  • Any person or vendor recording or transcribing calls and visits, who needs at least one party's consent under A.R.S. 13-3005
  • Entities conducting business in Arizona that hold unencrypted personal information, under the breach notification statute A.R.S. 18-552, with HIPAA compliant entities exempt

Penalties

HB 2175 carries no penalty schedule of its own. A.R.S. 20-3103 and 20-3407 sit in Title 20, so a health care insurer that denies without individual medical director review is subject to the Department of Insurance and Financial Institutions' general enforcement powers, including examination, corrective orders and civil penalties under the insurance code, and the denial is challengeable through the health care appeals process in A.R.S. 20-3401 onwards. There is no private right of action in the chapter text. On the provider side, failing to maintain adequate records is unprofessional conduct under A.R.S. 32-1401(27)(e), which exposes a physician to the Arizona Medical Board's full disciplinary range from advisory letter to revocation. A security breach involving unencrypted personal information triggers A.R.S. 18-552, enforced exclusively by the Attorney General, with civil penalties of up to the lesser of ten thousand dollars per affected individual or the total economic loss, capped at five hundred thousand dollars per breach or related series; HIPAA covered entities complying with HIPAA are exempt from the state statute. Intentional interception of a wire or electronic communication without the consent of a party is a class 5 felony under A.R.S. 13-3005.

Deadlines

Dates that already bind, and dates still ahead.

DateWhat happens
HB 2175 was signed by the Governor and filed with the Secretary of State as Laws 2025, chapter 165. Final House passage was 53 to 1 and the Senate vote was 29 to 0.
The Arizona Board of Behavioral Health Examiners' amended rules took effect. The Board's published best practice guide states that from January 1, 2027 licensees must give notice of any use of artificial intelligence in the treatment or documentation of services, and recommends doing so sooner.
Governor Hobbs vetoed HB 2311 (conversational AI disclosures and protections for minors) and HB 2592 (AI in state agencies). Neither is law. The date is as reported in the Governor's June 2026 legislative action update; one tracker records June 13.
HB 2175 took effect. A.R.S. 20-3103 and 20-3407 now require individual medical director review, with independent medical judgment, before a health care insurer denies a claim or a prior authorization on medical necessity grounds.
Enforcement date for the Board of Behavioral Health Examiners' AI notice expectation for licensed behavioural health professionals, per the Board's guide.

What changed in 2026

Movement by year, newest first. Where nothing in the text moved, that is recorded too.

  • 2026

    HB 2175 became operative on July 1, 2026. That is the only Arizona AI provision that binds anyone in healthcare this year, and it binds payers, not providers. From that date a health care insurer's medical director must individually review every medical necessity denial of a claim (A.R.S. 20-3103) and every direct denial of a prior authorization (A.R.S. 20-3407), exercising independent medical judgment and not relying solely on recommendations from any other source. The statute as codified does not use the words artificial intelligence; the House engrossed version did, and the final text was narrowed to the individual review duty, which is what an automated denial engine cannot satisfy.

    The 2026 regular session produced no new AI law. HB 2311, which would have required conversational AI operators to disclose that a user is talking to AI at the start of each session, every three hours and by persistent notice, banned systems from claiming to provide professional mental or behavioural health care, and added protections for minors, passed both chambers and was vetoed in June 2026. HB 2592 on AI in state agencies was vetoed the same month. HB 4080, an AI and nursing tasks pilot, was introduced on June 13, 2026 and assigned to House Rules; it did not advance and we could not confirm any further action as of September 2026.

    For providers the practical change in 2026 is therefore the appeals leverage HB 2175 gives you, and the countdown to the Board of Behavioral Health Examiners' January 1, 2027 AI notice date.

  • 2025

    Arizona passed HB 2175, prior authorization; claims, sponsored by Representative Willoughby. It cleared the House 58 to 0 on third read, was amended in Senate Finance to the medical director review form, passed the Senate 29 to 0 and the House on final passage 53 to 1, and was signed on May 12, 2025 as chapter 165 with a delayed effective date of July 1, 2026. Arizona already required, under A.R.S. 20-2510, that a direct denial of prior authorization on medical necessity be made in writing by a medical director holding an active unrestricted Arizona licence, with a copy to the requesting provider. HB 2175 adds the word that matters: the review must be individual, with independent judgment, so a signature applied to an algorithm's output is no longer enough.

    Separately, the Arizona Board of Behavioral Health Examiners adopted amended rules effective November 2, 2025 and published a Behavioral Health and Technology Best Practice Guide. The guide states that clinicians retain accountability for any documentation produced by AI and that, beginning January 1, 2027, notice of any AI used in treatment or documentation is required, tailored to the clinician's actual use. That is the only Arizona licensing board text on AI in documentation we could locate on a .gov source. The Arizona Medical Board had published no AI specific substantive policy as of September 2026; its adequate records standard in A.R.S. 32-1401 is what applies.

What AI laws does Arizona actually have for healthcare?

One enacted statute, aimed at payers, and a set of older laws that reach AI without naming it.

HB 2175, Laws 2025 chapter 165, is the only Arizona statute passed specifically because of AI in healthcare. It added A.R.S. 20-3103 for claims and 20-3407 for prior authorizations. Both took effect on July 1, 2026 and both say the same thing: before a health care insurer may deny on the basis of medical necessity, the medical director shall individually review the denial, exercising independent medical judgment and not relying solely on recommendations from any other source. The bill as engrossed in the House stated outright that artificial intelligence may not be used to deny a claim or prior authorization involving medical judgment; the Senate strike everything amendment replaced that with the individual review formulation that was enacted. The effect is similar and the drafting is more durable, because it does not depend on defining AI.

Nothing else on the Arizona books regulates AI in clinical care by name. The 2026 session's attempts, HB 2311 on conversational AI disclosure and HB 2592 on AI in state agencies, were both vetoed in June 2026. Arizona also has no comprehensive consumer privacy statute of the Colorado or Virginia type, and no bill was moving as of September 2026, so the health data provisions that matter in those states have no Arizona equivalent.

What a clinic in Arizona is governed by instead is the existing frame: A.R.S. 32-1401 on adequate records, A.R.S. 36-3602 on telehealth consent, A.R.S. 13-3005 on recording, A.R.S. 12-2291 and 12-2292 on medical records and confidentiality, A.R.S. 18-552 on breach notification, and HIPAA above all of it. That makes Arizona lighter than Texas, which imposes a patient disclosure duty, and far lighter than Colorado. It does not make Arizona empty. Our state by state map places it in the payer only group with a small number of other states.

What does HB 2175 require, and what does it mean for prior authorization?

It requires a person, not a system, to own every medical necessity denial, and it does so at the point where automation had quietly crept in.

Arizona already had A.R.S. 20-2510. Under that section a direct denial of a prior authorization on medical necessity must be made in writing by a medical director who holds an active unrestricted licence to practise medicine in Arizona, must explain why the treatment was denied, and must be copied to the requesting provider. The insurer must keep copies for inspection by the department, and the medical director is responsible for all direct denials on medical necessity grounds. What that section did not say was how much the medical director had to do. A batch of denials generated by a utilization review model and countersigned in bulk met the letter of 20-2510.

HB 2175 closes that. From July 1, 2026, under 20-3407 the medical director shall individually review each direct denial of a prior authorization that involves medical necessity, and under 20-3103 each medical necessity denial of a submitted claim. During each individual review the medical director shall exercise independent medical judgment and may not rely solely on recommendations from any other source. Any other source includes a vendor algorithm, a nurse reviewer's screen and a clinical criteria tool. The House summary of the signed bill puts it in one line: the medical director is prohibited from relying solely on recommendations derived from any other source.

Three things follow for a provider organisation.

  • Ask who reviewed it. Every medical necessity denial dated on or after July 1, 2026 should carry a named Arizona licensed medical director who can say they individually reviewed it. If the denial letter reads like template output, that is now a question for the appeal and for the Department of Insurance and Financial Institutions.
  • HB 2175 does not regulate your side of the transaction. A practice using prior authorization automation to assemble and submit requests is untouched. The statute governs denials by insurers.
  • It stacks with federal rules. The CMS interoperability and prior authorization rule sets timeframes and API requirements for Medicare Advantage, Medicaid and exchange plans; HB 2175 adds the human review floor for Arizona regulated plans. Self funded ERISA plans are outside Arizona's reach, which for a large employer heavy market is a real gap to check before assuming a denial is covered.

Arizona's approach is narrower than California's SB 1120, which regulates the algorithm itself, and closer to Maryland's. It is also easy to enforce, because the question is simply whether a person did the review.

What do Arizona's licensing boards expect when AI writes the note?

The Arizona Medical Board has published no AI specific policy as of September 2026. We checked its Laws and Rules and substantive policy pages and found nothing on artificial intelligence, ambient documentation or clinical decision support. That is not a gap in your obligations, it is a statement that the ordinary standard applies.

The ordinary standard is A.R.S. 32-1401. Adequate records means legible medical records, produced by hand or electronically, containing at a minimum sufficient information to identify the patient, support the diagnosis, justify the treatment, accurately document the results, indicate advice and cautionary warnings provided to the patient and provide sufficient information for another practitioner to assume continuity of care at any point. Failing or refusing to maintain adequate records is unprofessional conduct under 32-1401(27)(e). An ambient scribe note that invents a negative review of systems, drops a cautionary warning that was given, or records a plan that was discussed and rejected fails that definition, and the physician who signed it owns the failure. The vendor is not a licensee and the Board cannot discipline it.

The Board of Behavioral Health Examiners has gone further and said so in writing. Its Behavioral Health and Technology Best Practice Guide, published alongside rules effective November 2, 2025, states that clinicians retain accountability and responsibility for the ethical use of and any documentation produced by AI, and that beginning January 1, 2027 notice of any AI used in the treatment or documentation of services is required, tailored to the clinician's use, with the Board recommending that licensees start now. The guide describes itself as educational rather than a legal directive, but it tells you exactly how a complaint will be assessed. Behavioural health practices using a scribe or a triage chatbot should treat January 1, 2027 as a hard date for adding AI notice to their consent for treatment under A.A.C. R4-6-1101.

For every other profession, borrow the behavioural health standard voluntarily. It costs one paragraph in the consent packet and it is what the Medical Board will consider reasonable if it ever writes its own. Our AI policy template has the paragraph.

Which Arizona privacy laws reach an AI vendor beyond HIPAA?

Fewer than in most large states, and the ones that exist are breach and records statutes rather than consumer data rights.

Arizona has not enacted a comprehensive consumer data privacy law. There is no Arizona equivalent of the Oregon, Maryland, New Jersey, Virginia or Minnesota acts, no consumer health data statute of the Washington My Health My Data type, and as of September 2026 no such bill had passed either chamber. A vendor's obligations to your patients therefore run almost entirely through your business associate agreement under HIPAA, and through three state provisions.

  • A.R.S. 12-2291 to 12-2297, medical records. Medical records are all communications related to a patient's physical or mental health, recorded in any form or medium and maintained for diagnosis or treatment. An audio recording captured by a scribe, and the transcript and draft note derived from it, fall inside that definition once they are kept for treatment purposes, which brings them under the confidentiality rule in 12-2292 and the patient access and retention rules in the article. Decide deliberately whether the vendor retains audio and for how long, because whatever is retained is a medical record.
  • A.R.S. 18-551 and 18-552, breach notification. A person conducting business in Arizona that owns or licenses unencrypted computerised personal information must investigate promptly and notify affected individuals within forty five days of determining a breach. Over one thousand individuals triggers notice to the Attorney General, the Department of Homeland Security and the consumer reporting agencies. Penalties reach ten thousand dollars per individual up to five hundred thousand dollars per breach series. An entity subject to and complying with HIPAA is exempt, so the statute matters mainly where a vendor is not a business associate or where the compromised data is outside HIPAA, such as marketing lists or workforce data.
  • A.R.S. 13-3005, interception. Arizona is a one party consent state. Intentionally intercepting a wire or electronic communication to which one is not a party, without the consent of either a sender or receiver, is a class 5 felony. A clinic recording its own calls or visits has the consent of one party, itself, so the criminal statute is satisfied. It does not settle whether the vendor, a third party to the conversation, has lawful consent when it processes the audio, and it says nothing about calls into states that require all parties to consent. Consent from the patient at the start of the interaction removes both questions.

Because the state layer is thin, the contract is where Arizona practices win or lose. Ask every AI vendor for its data retention schedule, its subcontractor list, whether it trains on your data, and how it supports a 45 day breach investigation. Our healthcare AI law checker lists the questions by state.

They mean consent is already a documented event in Arizona, so adding AI to it is an edit, not a new process.

A.R.S. 36-3602 requires a health care provider to obtain verbal or written informed consent before delivering health care through telehealth, and where consent is verbal to document it in the medical record. There are exceptions for interactions that would not have been in person anyway, for emergencies, and for the transmission of diagnostic images and test results. Telehealth is broadly defined in 36-3601 and includes audio only encounters, so a clinical conversation conducted through an AI phone agent that goes beyond scheduling and into symptoms or advice is a telehealth encounter for a licensee's purposes and needs the consent 36-3602 describes. All telehealth reports become part of the medical record under 12-2291, and providers must follow their scope of practice and the guidelines of the telehealth advisory committee under 36-3607.

Two further points. First, A.R.S. 36-3606 requires an out of state provider to register with the relevant Arizona board before delivering telehealth to Arizona patients, with narrow exceptions including fewer than ten encounters a year. An AI vendor's remote clinical oversight staff, or a national telehealth partner fronted by an AI intake agent, needs to be on the right side of that. Second, the Medical Board's unprofessional conduct list at 32-1401(27)(tt) permits prescribing through telehealth only with a clinical evaluation appropriate to the patient, which an automated intake cannot supply on its own.

For scribes, the combination of 36-3602, 13-3005 and the behavioural health board's 2027 notice date points to one design: a short verbal disclosure at the start of every recorded visit or call, documented in the note, and a written statement in the consent for treatment. Arizona does not yet prescribe wording. Texas and California do, and a disclosure drafted to satisfy them will satisfy an Arizona board.

What was vetoed or left pending in Arizona in 2026?

Three AI bills reached the Governor in June 2026 and none became law. One nursing AI bill was filed and went nowhere.

BillSubjectStatus as of September 2026
HB 2311Conversational AI: disclosure at session start, every three hours and by persistent notice; no claiming to provide professional mental or behavioural health care; self harm protocols; protections and parental tools for minors; Attorney General enforcement; effective date would have been September 30, 2027Passed House and Senate, vetoed June 2026
HB 2592AI implementation in state agenciesVetoed June 2026
HB 2133Synthetic intimate imagesVetoed June 2026
HB 4080Artificial intelligence and nursing tasks pilot programmeIntroduced June 13, 2026, assigned to House Rules, no further action confirmed

The Governor's stated objection to HB 2311, as reported in the press, was that its penalty cap was too small for large companies and that it barred families from bringing their own suits. That is an objection to the remedy, not to the disclosure duty, so expect a version with a private right of action to return in the 2027 session. A practice that already discloses AI at the start of every interaction will not need to change anything if it does.

We also checked the Department of Insurance and Financial Institutions for an AI bulletin. Arizona had not adopted the NAIC model bulletin on insurers' use of AI systems as of September 2026, and DIFI's 2025 legislative bulletin summarises HB 2175 without adding rules. Payer AI governance in Arizona is therefore HB 2175 and nothing more.

What must an Arizona clinic do this year, concretely?

Seven items, in the order they will bite.

  1. Put a named clinician attestation gate in front of every AI drafted note. A.R.S. 32-1401 defines adequate records and makes the licensee responsible. Configure the scribe so nothing files without a signature and a review timestamp, and audit a sample monthly.
  2. Add AI notice to the consent for treatment now, not in December. Behavioural health licensees must give it from January 1, 2027. Everyone else should, because it is the standard a board will borrow.
  3. Open every recorded call and visit with a verbal disclosure and log it. That satisfies 13-3005 for the vendor as well as the clinic, satisfies 36-3602 for verbal telehealth consent, and covers patients calling from all party consent states.
  4. Rewrite the denial appeal template for July 1, 2026. Ask the insurer to identify the medical director who individually reviewed the medical necessity denial under A.R.S. 20-3103 or 20-3407 and to confirm they did not rely solely on any other source. Escalate template denials to DIFI.
  5. Confirm which of your payers are outside HB 2175. Self funded plans and out of state plans are not Arizona health care insurers. Note it on the payer matrix so staff do not cite the statute where it does not apply.
  6. Fix the contract, because the state privacy layer will not. Retention of audio and transcripts, no training on your data without written consent, subcontractor disclosure, 45 day breach cooperation, and an exit clause returning or destroying the medical records the vendor holds under 12-2291.
  7. Check out of state telehealth registration. Any remote clinician behind an AI agent who touches Arizona patients more than nine times a year needs to be registered under 36-3606.

None of this requires a new committee. It requires one policy, one consent paragraph, one contract schedule and one appeal template, all of which are reusable in every other state you operate in.

What does an independent review add in a light touch state?

Discipline, because a light statute book is where organisations relax and then find out that HIPAA, the Medical Board and the plaintiff's bar were never light.

Arizona's AI exposure for a provider sits in three places that a vendor's compliance page does not cover: the accuracy of what the licensee signs, the consent trail behind every recording, and the contract terms that decide what happens to audio when the relationship ends. Vendors selling scribes and phone agents in Arizona will tell you, correctly, that no state AI act applies to them. They will not volunteer that their retention default makes them a custodian of your medical records under 12-2291, or that their onshore clinical reviewers may need 36-3606 registration.

An independent review maps each deployed system to the Arizona statutes above and to the stricter states you also serve, so the same disclosure, attestation and contract artefacts work across Arizona, Texas, Colorado and California. It also builds the denial appeal playbook that turns HB 2175 into recovered revenue rather than a headline. That is the scope of our AI governance and compliance engagement, which is vendor neutral and paid by you, not by the vendor. If you are about to sign a scribe, phone agent or prior authorization contract for an Arizona practice, book a conversation before you do, and bring the contract.

Official sources

Primary documents from the issuing authority. Where a summary and the source disagree, the source is right.

Questions we get asked

Does Arizona have an AI law for healthcare?

One. HB 2175, Laws 2025 chapter 165, added A.R.S. 20-3103 and 20-3407, effective July 1, 2026. They require a health care insurer's medical director to individually review any medical necessity denial of a claim or prior authorization, exercising independent medical judgment and not relying solely on recommendations from any other source. There is no Arizona statute regulating provider side AI use by name; existing records, consent, recording and breach laws apply instead. Our state map shows how that compares.

When did Arizona HB 2175 take effect?

July 1, 2026. The act was signed on May 12, 2025 and section 3 provided that it is effective from and after June 30, 2026. Denials dated on or after July 1, 2026 must carry individual medical director review.

Does HB 2175 ban AI in prior authorization?

Not in those words. The House engrossed version said artificial intelligence may not be used to deny a claim or prior authorization involving medical judgment. The enacted text instead requires the medical director to individually review each medical necessity denial and not rely solely on any other source. An insurer may still use AI to approve requests, to triage, or to draft a recommendation, but a person must independently make every medical necessity denial.

Do Arizona doctors have to tell patients an AI scribe is being used?

No statute requires it for physicians as of September 2026. The Board of Behavioral Health Examiners' guide states that its licensees must give notice of AI use in treatment or documentation from January 1, 2027. For everyone else, A.R.S. 36-3602 telehealth consent and A.R.S. 13-3005 one party consent make a short verbal disclosure the safe default, and HIPAA governs the vendor's handling of the recording.

Is Arizona a one party or two party consent state for recording?

One party. Under A.R.S. 13-3005 it is a class 5 felony to intentionally intercept a wire or electronic communication to which one is not a party without the consent of either a sender or receiver. A clinic recording its own calls has that consent. Patients calling from all party states, and the position of a third party vendor, are the reasons to disclose anyway.

Does Arizona have a consumer data privacy law that covers health data?

No. Arizona has not enacted a comprehensive consumer privacy act and none was pending as of September 2026. The relevant state laws are the medical records article at A.R.S. 12-2291 onwards, the breach notification statute at A.R.S. 18-552, which exempts HIPAA compliant entities, and the genetic information privacy provisions. Vendor obligations therefore run mainly through your business associate agreement.

What happened to Arizona's AI chatbot bill, HB 2311?

It passed both chambers in 2026 and was vetoed by the Governor in June 2026. It would have required conversational AI to disclose its nature at the start of each session, every three hours and by persistent notice, and would have barred systems from claiming to provide professional mental or behavioural health care. Expect a revised version in 2027; a persistent disclosure design already satisfies it.