California's Healthcare AI Laws: AB 3030, SB 1120 and the Rest of the Family
AB 3030 (Health and Safety Code section 1339.75), SB 1120 (Health and Safety Code section 1367.01 and Insurance Code section 10123.135), AB 489 (Business and Professions Code chapter 15.5), SB 243 (companion chatbots), together with the Confidentiality of Medical Information Act and the California Consumer Privacy Act and its automated decisionmaking regulations
Last updated
Free tool
Twelve factual questions on data access, governance and change capacity.
Need it signed off?
Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.
Book an evaluation callRegulator
Medical Board of California and allied licensing boards, Department of Managed Health Care, Department of Insurance, California Attorney General, and the California Privacy Protection Agency
Who it applies to
- AB 3030: health facilities, clinics, physician's offices and offices of a group practice that use generative AI to produce written or verbal patient communications about clinical information
- SB 1120: health care service plans regulated by the Department of Managed Health Care and disability insurers regulated by the Department of Insurance, when using AI, algorithms or other software tools for utilization review or utilization management
- AB 489: developers and deployers of AI and generative AI systems that use titles or terms implying licensed health care professional status, regardless of sector
- SB 243: operators of companion chatbot platforms, defined by the nature of the interaction rather than by industry
- CMIA: providers of health care, plus businesses offering software or hardware including a mobile application designed to maintain medical information, and businesses offering mental health or reproductive and sexual health digital services
- CCPA and the CPPA regulations: businesses meeting the CCPA thresholds, including for employee and applicant data and for any consumer data that is not PHI already covered by HIPAA or medical information covered by the CMIA
Penalties
There is no single penalty regime, which is the point. AB 3030 is enforced through the existing enforcement provisions for health facilities and clinics, and through the Medical Board of California or the Osteopathic Medical Board for physicians, so exposure is licensing and facility action rather than a fixed fine. AB 489 is enforced by the relevant licensing board and provides that each use of a prohibited term is a separate violation. SB 1120 is enforced by the Department of Managed Health Care and the Department of Insurance through their normal plan and insurer enforcement powers. SB 243 carries a private right of action with damages of at least one thousand dollars per violation plus fees. The CMIA carries administrative fines and a private right of action. CCPA penalties are administrative and set by statute, with a higher tier for intentional violations and violations involving minors. Check the current figures with the agency concerned rather than a secondary summary.
Deadlines
Dates that already bind, and dates still ahead.
| Date | What happens |
|---|---|
| AB 3030 and SB 1120 took effect, along with AB 1008, which confirmed that personal information under the CCPA can exist inside an AI system capable of outputting it. | |
| AB 489 took effect, barring AI systems from using terms implying that care is provided by a licensed health care professional. SB 243 took effect for companion chatbot operators. The California Privacy Protection Agency's regulations on risk assessments, cybersecurity audits and automated decisionmaking technology also took effect. | |
| Businesses using ADMT for a significant decision, which expressly includes health care services, must be in compliance with article 11 of the CCPA regulations. | |
| First annual reports from companion chatbot operators to the Office of Suicide Prevention under SB 243. | |
| Deadline to conduct and document risk assessments for processing activities that started before the CPPA regulations took effect and continue after them. | |
| First risk assessment submissions to the CPPA, covering assessments conducted in 2026 and 2027. The first cybersecurity audit is also due by this date for businesses with 2026 annual gross revenue over one hundred million dollars. | |
| Under SB 306, plans and insurers must stop requiring prior authorization for services on the published high approval list, no later than this date. |
What changed in 2026
Movement by year, newest first. Where nothing in the text moved, that is recorded too.
2026
Two statutes and one regulatory package became operative on January 1, 2026.
AB 489 added chapter 15.5 to the Business and Professions Code. An AI or generative AI system may not use terms, letters or phrases that indicate or imply that care, advice, reports or assessments are being provided by a licensed health care professional when they are not. Each use of a prohibited term is a separate violation, and enforcement sits with the relevant licensing board. This is the provision that turns a chatbot persona called Dr. Something into a licensing matter rather than a marketing question.
SB 243 regulates companion chatbot operators: a clear notification that the user is talking to something artificially generated, a published crisis referral protocol, extra duties for known minors, and a private right of action with damages of at least one thousand dollars per violation. Most clinical deployments are not companion chatbots, but a wellness or check in agent that holds open ended conversations can drift into the definition.
The CPPA regulations on risk assessments, cybersecurity audits and automated decisionmaking took effect on January 1, 2026, having been approved by the Office of Administrative Law on September 22, 2025. The compliance clocks they set run into 2028.
2025
AB 3030 and SB 1120 both took effect on January 1, 2025, and between them defined the shape of California's approach: tell the patient when a machine wrote the clinical message, and do not let a machine deny care.
AB 1008 also took effect, amending the CCPA definition of personal information to cover abstract digital formats including artificial intelligence systems capable of outputting personal information. That is a quiet but consequential change: a fine tuned model can itself be personal information, which affects deletion requests, vendor diligence and what you are actually buying when you buy a custom model.
Later in 2025 the legislature passed AB 489, SB 243 and SB 306. SB 306 was chaptered on October 6, 2025 and reforms prior authorization through reporting and a high approval exemption list rather than through AI rules, with the operative prohibition landing no later than January 1, 2028.
2024
AB 3030 and SB 1120 were both approved on September 28, 2024. AB 3030 was the first US statute to require a disclaimer specifically on generative AI patient communications. SB 1120 was the first to say plainly that an algorithm cannot be the thing that denies care on medical necessity grounds.
Both were drafted before agentic deployments were common, and both have held up better than most 2024 AI legislation because they regulate an act rather than a technology category. That is worth noticing when you read the Colorado experience, where a technology category statute was repealed before it took effect.
Which California laws apply to healthcare AI?
Five, and they do different jobs. There is no California AI Act to comply with, and looking for one is the most common reason buyers arrive at a California deployment underprepared.
| Law | What it governs | In force | Who it binds | The operator duty |
|---|---|---|---|---|
| AB 3030 (HSC 1339.75) | Generative AI patient communications about clinical information | Jan 1, 2025 | Health facilities, clinics, physician's offices, group practices | Disclaimer plus instructions for reaching a human, unless a licensed provider read and reviewed it |
| SB 1120 | AI in utilization review and utilization management | Jan 1, 2025 | Health plans and disability insurers | Medical necessity denials must be made by a licensed physician or competent professional |
| AB 489 (B and P ch. 15.5) | AI implying licensed clinician status | Jan 1, 2026 | Anyone developing or deploying such a system | Do not use protected titles or implying terms; each use is a separate violation |
| SB 243 | Companion chatbots | Jan 1, 2026 | Operators of companion chatbot platforms | Artificial nature notification, crisis protocol, minor protections, annual reporting from 2027 |
| CMIA and CCPA | The data underneath all of it | Ongoing; CPPA ADMT rules by Jan 1, 2027 | Providers and, separately, most businesses | Consent for disclosure of medical information; pre-use notice, opt out and access for ADMT in significant decisions |
Read the table as a stack rather than a menu. A single patient facing agent can touch AB 3030 for what it says, AB 489 for what it calls itself, the CMIA for the record it writes into, and the CCPA regulations for the decision it influences. That is four different regulators looking at one deployment, which is why California rewards a single governance programme over four project plans. The same logic drives our AI governance and compliance work.
What does AB 3030 actually require?
Two things, on every patient communication generated by generative AI that pertains to clinical information: a disclaimer saying the communication was generated by generative AI, and clear instructions describing how the patient can contact a human health care provider or other appropriate person.
The disclaimer's placement is prescribed by medium, and this is where most implementations get sloppy.
- Written communications, including letters and emails: prominently at the beginning of each communication.
- Chat based interactions, including chat based telehealth: prominently displayed throughout the interaction.
- Audio communications: verbally, at the start and again at the end.
- Video communications: prominently displayed throughout the interaction.
Note the audio rule in particular. Start and end, both, spoken. An AI phone agent that discloses once at pickup and then discusses a result is not compliant if the call touched clinical information.
Two boundaries define the whole statute. The first is subject matter: it applies to communications about patient clinical information, meaning information relating to the health status of a patient, and expressly excludes administrative matters including appointment scheduling, billing and other clerical or business matters. The second is the review exception: the requirements do not apply where the communication is generated by generative AI and then read and reviewed by a human licensed or certified health care provider.
Those two boundaries do more work than the disclaimer rules. Between them they mean a large share of real deployments fall outside AB 3030 entirely, and the compliance question becomes a design question: can you prove which messages went out unreviewed?
Does an AI scribe or intake agent need an AB 3030 disclaimer?
Usually not, for different reasons in each case, and the reasoning is worth being able to state to a surveyor.
An ambient scribe produces a note that a clinician reviews and signs. Where the output reaching the patient has been read and reviewed by a licensed provider, the exception applies. That places the compliance burden exactly where the clinical burden already is: on attestation. If your workflow allows a draft to reach a patient portal without a signature, the exception has not been earned, whatever the policy says.
A patient intake agent collecting demographic and insurance details is dealing in administrative matters, which are excluded. The moment it starts summarising symptoms back to the patient or answering a question about their condition, it is dealing in clinical information and the exclusion stops helping.
A scheduling agent is administrative and therefore outside AB 3030. It is not outside AB 489, which does not care about the subject matter and only cares what the system calls itself.
The practical control is a log, not a policy. For every automated outbound message, record whether it contained clinical information and whether a licensed provider reviewed it before it left. Without that record, you cannot demonstrate the exception applies, and the disclaimer becomes the cheaper default. Many organisations conclude it is easier to disclaim everything than to prove the boundary, which is a defensible answer as long as it is a decision rather than a drift.
What does SB 1120 require, and does it bind providers?
SB 1120 binds payers, not providers. It amends Health and Safety Code section 1367.01 for health care service plans and Insurance Code section 10123.135 for disability insurers.
Where a plan or insurer uses AI, an algorithm or another software tool for utilization review or utilization management, the tool must base its determination on the enrollee's medical or other clinical history, individual clinical circumstances and other relevant records, and must not base its determination solely on a group dataset. Its criteria and guidelines must comply with the chapter, it must be fairly and equitably applied, it must not discriminate directly or indirectly, it must be open to inspection for audit or compliance review, and disclosures about its use and oversight must appear in written policies and procedures.
The provision that changes conduct is the one about who decides. A tool may not deny, delay or modify health care services based in whole or in part on medical necessity. That determination must be made by a licensed physician or a licensed health care professional competent to evaluate the specific clinical issues, after reviewing the requesting provider's recommendation and the enrollee's individual circumstances.
For a provider organisation, the operational value is leverage. If a denial arrives with reasoning that reads as machine generated and no evidence of individualised clinical review, SB 1120 gives you a named statutory hook for the appeal rather than a general complaint. Teams running prior authorization automation and denial management should be capturing that pattern rather than only capturing outcomes. Colorado followed with a broadly similar rule in HB 26-1139, effective January 1, 2027, which we cover on the Colorado page.
Separately, SB 306 attacks the same problem from the volume side. Plans must report prior authorization approval rates by December 31, 2026, the departments publish a list of services approved at ninety percent or above by July 1, 2027, and prior authorization for those services must stop no later than January 1, 2028. That is a real change to the workload your automation is sized for.
What does AB 489 prohibit, and why does it catch agent branding?
AB 489 added chapter 15.5 to the Business and Professions Code, effective January 1, 2026. It makes the existing prohibitions on holding yourself out as a licensed professional enforceable against the developers and deployers of AI systems, and it bars an AI or generative AI system from using terms, letters or phrases that indicate or imply that care, advice, reports or assessments are provided by a person licensed or certified to provide health care.
Each use of a prohibited term, letter or phrase is a separate violation. Enforcement sits with the appropriate health care professional licensing board or enforcement agency.
This is the least discussed and most easily tripped of the California statutes, because it is triggered by product design rather than by clinical function. Names, avatars, honorifics and credential styled suffixes are all in scope. So is copy that says an assistant will review your symptoms in language that reads as clinical assessment. A triage agent branded with a clinician persona is a licensing exposure in California even if every clinical output is safe and every disclaimer is present.
The remedy is cheap and best done before launch: name the agent as software, avoid protected titles and their near neighbours, and put the naming decision through the same review as the clinical content. It belongs in staff training too, because front line teams routinely give agents nicknames that undo careful branding decisions.
How do the CMIA and the CCPA apply to an AI vendor?
The CMIA is the reason California is stricter than HIPAA on the vendor question. Civil Code section 56.06 deems several kinds of business to be providers of health care in their own right, including any business organised for the purpose of maintaining medical information to make it available to an individual or a provider, and any business offering software or hardware to consumers, including a mobile application or related device, designed to maintain medical information. Businesses offering a mental health digital service or a reproductive or sexual health digital service are covered too.
The practical consequence is that a vendor which is a business associate under HIPAA may also be a provider of health care under the CMIA, with its own direct duties and its own exposure, including a private right of action. A business associate agreement does not dispose of the CMIA question, and vendor questionnaires written to a HIPAA template frequently do not ask it. Our tooling comparison notes where vendors publicly address California specifically, and where they do not.
The CCPA reaches the parts a health system tends to forget. PHI under HIPAA and medical information under the CMIA are exempted, but employee and job applicant data is not, and neither is consumer data collected outside the treatment relationship: marketing sites, appointment request forms before a relationship exists, patient acquisition campaigns. AB 1008 confirmed that personal information can exist inside an AI system capable of outputting it, which pulls fine tuned models into the analysis.
Then there are the CPPA regulations, effective January 1, 2026. They define a significant decision to include the provision or denial of healthcare services, where healthcare services means services related to the diagnosis, prevention or treatment of human disease or impairment, or the assessment or care of an individual's health. A business using ADMT to make a significant decision must be in compliance with article 11, including pre-use notice and the rights to opt out of and access ADMT, no later than January 1, 2027. Risk assessments for pre-existing processing must be conducted by December 31, 2027 and submitted by April 1, 2028, and the first cybersecurity audits fall due on April 1, 2028 for larger businesses.
Those dates line up almost exactly with Colorado's. If you are building one automated decision notice and one human review path, build it once for both.
What does California enforcement look like?
Distributed, which makes it harder to plan for than a single regulator with a single penalty schedule.
AB 3030 has no bespoke penalty. It routes into the existing enforcement provisions for health facilities and clinics, and to the Medical Board of California or the Osteopathic Medical Board where the conduct is a physician's. So the realistic exposure is a licensing or facility matter, arriving through a complaint, discovered during an unrelated survey. AB 489 works the same way and adds that each use of a prohibited term counts separately, which turns a badly named product into an arithmetic problem.
SB 1120 is enforced by the Department of Managed Health Care and the Department of Insurance against plans and insurers. SB 243 gives injured users a direct right to sue. The CMIA gives patients a private right of action alongside administrative fines. The CCPA is enforced administratively by the CPPA and by the Attorney General.
The pattern to take from this: California will not send you a single notice of violation with a sixty day cure period the way Texas and Colorado will. It will surface as a board complaint, a plan audit, a patient lawsuit or an agency inquiry, each with its own timeline. That argues for evidence that is retrievable on demand rather than a compliance binder that is assembled when asked.
If you deploy agents in California, do these things
Seven items. Most are a day of work each, and the first two prevent the majority of the realistic exposure.
- Classify every outbound automated message as clinical or administrative. AB 3030 only reaches clinical information. Scheduling, billing and clerical matters are excluded by statute. Write the classification down, because you will be asked to defend it.
- Prove the human review exception, or disclaim. If a licensed or certified provider reads and reviews the communication, no disclaimer is needed. If your workflow cannot evidence that review per message, disclaim by default and stop arguing about it.
- Fix the audio path. Verbal disclaimers at the start and the end of the call, not just at pickup. This is the most commonly failed requirement in voice deployments.
- Audit the agent's name and persona against AB 489. No protected titles, no implied credentials, no clinician styled avatars. Each use is a separate violation, so this scales badly if you get it wrong.
- Ask vendors the CMIA question, not just the HIPAA question. A vendor can be a provider of health care under Civil Code 56.06 in its own right. A signed business associate agreement does not answer this.
- Map the non PHI data. Employee data, applicant data and pre relationship consumer data sit under the CCPA, not under the HIPAA exemption. That is where the CPPA's ADMT rules will find you.
- Put January 1, 2027 in the plan. Pre-use notice, opt out and access rights for ADMT used in significant decisions, which expressly include healthcare services. Colorado's deadline is the same day, so design the notice and the human review path once.
The pattern across all seven is that California punishes ambiguity about what your system did, more than it punishes the system itself. Organisations that can answer which message went to which patient, generated by what, reviewed by whom, tend to have short conversations with regulators. Organisations that cannot tend to have long ones. Building that evidence layer, and reusing it across Utah, Texas and Colorado, is the substance of our AI governance and compliance engagement, and it sits alongside the federal baseline set out in HIPAA and AI.
Official sources
Primary documents from the issuing authority. Where a summary and the source disagree, the source is right.
- StateAB 3030, health care services and artificial intelligence, California Legislative Information (opens in a new tab)
- StateSB 1120, health care coverage and utilization review, California Legislative Information (opens in a new tab)
- StateAB 489, health care professions and deceptive terms, California Legislative Information (opens in a new tab)
- StateCivil Code section 56.06, Confidentiality of Medical Information Act (opens in a new tab)
- StateCCPA updates, cybersecurity audits, risk assessments and ADMT regulations, California Privacy Protection Agency (opens in a new tab)
- StateCalifornia Department of Managed Health Care (opens in a new tab)
- StateMedical Board of California (opens in a new tab)
Questions we get asked
Does California require AI disclaimers on patient messages?
Yes, where the message was generated by generative AI and pertains to patient clinical information. AB 3030 requires a disclaimer and clear instructions for contacting a human health care provider. It does not apply to administrative matters such as appointment scheduling or billing, and it does not apply where a licensed or certified health care provider read and reviewed the communication.
Is an AI medical scribe covered by AB 3030?
Generally not, because the clinician reads and reviews the note before it is signed, which is the statutory exception. The exception depends on the review actually happening, so if your workflow can release an unreviewed draft to a patient portal, the exception has not been earned for that message. Keep a per message record of review.
Can an AI tool deny a prior authorization in California?
No. Under SB 1120, a plan or insurer may not use AI, an algorithm or a software tool to deny, delay or modify services based in whole or in part on medical necessity. That determination must be made by a licensed physician or a licensed health care professional competent to evaluate the specific clinical issues, after reviewing the requesting provider's recommendation and the enrollee's own circumstances.
What does AB 489 mean for naming an AI agent?
An AI system may not use terms, letters or phrases indicating or implying that care, advice, reports or assessments come from a licensed health care professional. Titles, credential styled suffixes and clinician personas are all in scope. Each use of a prohibited term is a separate violation, and enforcement runs through the relevant licensing board.
Does the CCPA apply to a hospital using AI?
Partly. PHI under HIPAA and medical information under the CMIA are exempt, but employee and applicant data is not, and neither is consumer data collected outside a treatment relationship. The CPPA's automated decisionmaking regulations treat the provision or denial of healthcare services as a significant decision, with compliance required by January 1, 2027.
Is a HIPAA business associate agreement enough for a California AI vendor?
No. Civil Code section 56.06 deems certain businesses to be providers of health care under the CMIA in their own right, including businesses offering software designed to maintain medical information and businesses offering mental health digital services. Those duties sit alongside HIPAA and carry a private right of action, so ask the CMIA question separately during diligence.
What is the deadline for the California ADMT rules?
A business using automated decisionmaking technology for a significant decision before January 1, 2027 must be in compliance with article 11 of the CPPA regulations no later than that date. Risk assessments for pre-existing processing are due by December 31, 2027 and must be submitted to the Agency by April 1, 2028, with the first cybersecurity audits due on the same day for larger businesses.
Make it a formal evaluation
Everything we publish is free to read and free to argue with. When the decision has to be signed, dated and defended to a board, we run the evaluation against your own estate. We take no vendor commissions.
- A 30 minute evaluation call with an analyst, no pitch deck.
- A read on the vendors and the rules in play, and the use cases we would not touch yet.
- A written proposal with scope, sequence and a fixed fee.
- No obligation
- Direct with an analyst, not a sales rep
- BAA available before any PHI discussion