U.S. AI Laws: healthcare AI
As of 2026-08-12, AI Laws USA tracks 65 U.S. AI rules on healthcare AI across federal, state, county, and city government. Each entry links to its official source.
Federal healthcare AI rules (15)
-
In effect
FDA PCCP Guidance (AI/ML devices)
United States · Effective 2024-12-04 · FDA Guidance (Dec. 4, 2024); 21 U.S.C. § 360e-4
FDA finalized a framework that lets manufacturers update an AI-enabled medical device after clearance without filing a new submission for each change — but only if they pre-specify what changes are allowed, how they'll be validated, and how transparency to clinicians and patients will be preserved.
-
In effect
FTC HBNR Rule (AI health apps)
United States · Effective 2024-07-29 · 16 C.F.R. Part 318; 89 Fed. Reg. 47028
Health apps and connected devices — including AI-powered mental health and fitness tools — must notify users, the FTC, and (in some cases) the media within 60 days of a breach of identifiable health information. The 2024 amendments confirm that AI-generated inferences about health are covered.
-
In effect
HHS § 1557 Rule (AI clinical tools)
United States · Effective 2024-07-05 · 45 C.F.R. § 92.210; 89 Fed. Reg. 37522
HHS's Section 1557 rule bans discrimination in 'patient care decision-support tools,' which includes AI and algorithmic clinical tools. Covered health programs and providers must identify when a tool relies on patient race, age, disability, or other protected traits and take steps to mitigate the risk of discrimination.
-
In effect
CMS MA Rule (AI prior auth)
United States · Effective 2024-01-01 · 42 C.F.R. § 422.101(c); 88 Fed. Reg. 22120 (Apr. 12, 2023)
Medicare Advantage plans cannot use algorithms or AI to deny medically necessary care. Any algorithm-driven coverage decision must comply with traditional Medicare coverage criteria and consider the individual patient's circumstances — not just generic model output.
-
Blocked / in litigation
Lokken v. UnitedHealth (nH Predict)
D. Minn. · Effective 2023-11-14 · Estate of Lokken v. UnitedHealth Group, Inc., No. 0:23-cv-03514 (D. Minn.)
Families of deceased Medicare Advantage patients sued UnitedHealth in November 2023 over the 'nH Predict' algorithm, alleging the AI tool overrode physicians and prematurely terminated post-acute care coverage with an error rate above 90 percent in appeals — accelerating patient harms and deaths. On March 9, 2026, the court issued a significant discovery order compelling UnitedHealth to produce broad documentation of the nH Predict algorithm, including training data, model documentation, and internal performance audits.
-
In effect
VA Trustworthy AI Framework
United States · Effective 2023-09-22 · VA Directive 1003.2; VA AI Strategy (Sept. 2023)
The VA's Trustworthy AI Framework governs how AI may be used across VA healthcare, benefits, and operations. AI used in benefits or clinical decisions requires human review, bias testing, and an AI use-case inventory submitted to OMB.
-
Blocked / in litigation
Cigna PXDX AI Denial Class Action
E.D. Cal. · Effective 2023-07-24 · Kisting-Leung v. Cigna Corp., No. 2:23-cv-01477 (E.D. Cal.)
Patients sued Cigna in 2023 alleging its 'PxDx' algorithm reviewed and denied roughly 300,000 claims in two months — averaging 1.2 seconds per denial — without genuine physician review, violating California and federal law. Triggered a wave of similar AI healthcare-denial suits against UnitedHealth (NaviHealth) and Humana.
-
In effect
FDA GMLP Principles
United States · Effective 2021-10-27 · FDA/HC/MHRA GMLP Guiding Principles (Oct. 27, 2021)
Joint guiding principles by FDA, Health Canada, and the UK MHRA on safe development of ML-enabled medical devices. Updated by FDA's 2024 Transparency Guiding Principles.
-
In effect
FDA AI/ML SaMD Action Plan
United States · Effective 2021-01-12 · FDA AI/ML SaMD Action Plan (Jan. 12, 2021)
FDA's 5-part roadmap for regulating AI/ML-based Software as a Medical Device, including a proposed Predetermined Change Control Plan framework that lets developers update models without full FDA re-review.
-
In effect
FDA 510(k) — surgical robots
United States · Effective 1976-05-28 · 21 U.S.C. § 360(k); 21 C.F.R. Part 807
Robotically-assisted surgical devices (RASD) — like Intuitive's da Vinci or Stryker's Mako — are FDA-regulated medical devices. Most clear the market through the 510(k) pathway by showing substantial equivalence to a predicate device. The FDA issued a 2019 safety communication and continues to police off-label robotic mastectomy and AI-software updates under its evolving 'Predetermined Change Control Plan' authority.
-
In effect
ACA § 1557 (AI in patient care)
United States · Effective 2025-05-01 · 42 U.S.C. § 18116; 45 C.F.R. § 92.210
A 2024 HHS rule says hospitals, insurers, and other covered health entities may not discriminate through clinical algorithms and AI decision-support tools, and must make reasonable efforts to find and fix bias in those tools. The requirement took effect May 1, 2025, but HHS has stayed quiet on enforcement, so its practical protection is uncertain while it stays on the books.
-
In effect
HHS ASPR AI Public Health
United States · Effective 2024-08-28 · HHS ASPR AI Framework (Aug. 28, 2024)
HHS's Administration for Strategic Preparedness and Response framework governs AI use in public-health emergencies — including pandemic modeling, vaccine distribution, and resource allocation — with bias auditing and transparency required for algorithms that affect access to scarce medical countermeasures.
-
In effect
FSMB AI Guidance
United States · Effective 2024-04-26 · FSMB Policy (Apr. 26, 2024)
FSMB adopted a national framework guiding all U.S. state medical boards on what physicians must do when using AI: maintain transparency with patients, ensure AI tools are appropriate to use, supervise AI outputs, and protect patient privacy. States are adopting it as the model framework.
-
In effect
FDA AI Drug/Bio Guidance
United States · Effective 2023-05-10 · FDA Discussion Paper (May 2023); CDER/CBER Draft Guidance (Jan. 2025)
FDA published a framework setting expectations for how drug and biologics companies use AI/ML across drug discovery, clinical trials, postmarket safety surveillance, and manufacturing. The framework signals that AI used in regulatory submissions must be transparent, validated, and reproducible.
-
Proposed / pending
2026-08281
United States · HHS 2026-08281
The Food and Drug Administration (FDA or the Agency) is issuing this request for information to solicit input on a proposed pilot program to assess how artificial intelligence (AI)-enabled technologies can improve efficiency, speed, and quality of decision- making in early phase clinical trials. Early-phase clinical trials represent a critical bottleneck in drug development, often characterized by high uncertainty, limited patient populations, and inefficient decision- making processes. This pilot program aims to explore how advances in AI and data science can improve trial efficiency, enhance
State healthcare AI rules (49)
-
Enacted (not yet in effect)
Illinois SB 3114 — Transparency in Downcoding Act
Illinois · Effective 2028-01-01 · Illinois PA 104-0568 (SB 3114), signed July 10, 2026; effective January 1, 2028 (Transparency in Downcoding Act)
Illinois Senate Bill 3114, the Transparency in Downcoding Act (Public Act 104-0568), signed by Governor Pritzker on July 10, 2026, prohibits health insurers from using any automated process, system, or tool — including artificial intelligence — as the sole basis for downcoding a medical claim based on medical necessity, unless a human employee or contractor has first reviewed the covered individual's medical record. The law also imposes a parallel obligation on health care providers, prohibiting providers from using AI to submit a health benefits claim without review by a provider or other person involved in developing the claim. Insurers must provide a clear explanation when downcoding, including the rationale and the coding changes applied. Downcoding cannot be based solely on diagnosis codes or targeted at providers who treat complex patients. The Act is effective January 1, 2028.
-
Enacted (not yet in effect)
Georgia SB 544 (health insurer AI)
Georgia · Effective 2027-01-01 · Ga. SB 544 (2026), signed May 5, 2026, eff. Jan. 1, 2027
Georgia's SB 544, signed May 5, 2026 and effective January 1, 2027, lets health insurers use AI in the prior-authorization process to automate tasks and assist decision-making, but bars them from issuing an adverse determination (a denial) without the review and approval of a licensed health care provider. In short: AI can help, but a licensed human has to sign off before your care is denied.
-
Enacted (not yet in effect)
Utah SB 319 (health insurer AI)
Utah · Effective 2027-01-01 · Utah SB 319 (2026), enacted March 19, 2026, eff. Jan. 1, 2027
Utah's SB 319, enacted March 19, 2026 and effective January 1, 2027, requires health insurers to disclose to the Utah Insurance Department, to providers, and to enrollees whether AI is used to review prior-authorization requests. It also requires that a health professional's adverse determination be based on their own independent medical judgment — not dictated by an AI recommendation.
-
Enacted (not yet in effect)
Iowa HF 2635 (no AI-only prior-auth denials)
Iowa · Effective 2027-01-01 · Iowa H.F. 2635, 91st Gen. Assemb. (2026), Sec. 514F.8(2A), eff. Jan. 1, 2027
Iowa lets a utilization review organization use an AI-based algorithm or system to conduct an initial review of a prior-authorization request, but forbids relying on AI as the sole basis to deny, delay, or downgrade a medical-necessity prior-authorization request. A qualified human reviewer — a clinical peer or qualified reviewer — must make the binding determination.
-
Enacted (not yet in effect)
Missouri AI Therapy Chatbot Ban (SB 1019)
Missouri · Effective 2026-08-28 · Mo. SB 1019 (2026 Reg. Sess.); MMPA enforcement; effective Aug 28, 2026
Missouri's 2026 health-care law bans companies and individuals from advertising or claiming that an AI chatbot can act as a mental-health professional or provide therapy services. Marketing an AI 'therapist' is treated as an unlawful business practice the state Attorney General can pursue, with fines of $10,000 for a first violation and $20,000 for each later violation.
-
In effect
Maine mental-health AI limits (2026)
Maine · Effective 2026-07-29 · Maine LD 2082 / HP 1397 (P.L. 2026, Ch. 687, 132nd Leg.); signed April 13, 2026; eff. July 29, 2026
Maine enacted LD 2082 (signed April 13, 2026 by Governor Janet Mills; effective July 29, 2026) limiting how licensed mental health professionals can use AI: only for administrative and limited supplementary tasks. AI may not make therapeutic communications, treatment decisions, or independently interact with patients. Professionals must get patient consent before using ambient-listening or other AI-powered recording tools.
-
In effect
Indiana HB 1271 (AI claims downcoding)
Indiana · Effective 2026-07-01 · Ind. HB 1271 (2026), enacted March 4, 2026, eff. July 1, 2026
Indiana's HB 1271, enacted March 4, 2026 and effective July 1, 2026, bars health insurers from using AI tools as the sole basis to 'downcode' a claim (reduce it to a cheaper billing code) without a health professional reviewing the patient's medical record. It also bars health care providers from using AI to submit claims without a review by the provider or a billing professional. Unlike most 2026 health-AI laws, it is not limited to prior authorization.
-
In effect
AZ HB 2175 (AI Insurance Denial — Physician Review)
Arizona · Effective 2026-07-01 · Ariz. HB 2175 (57th Leg., 1st R.S. 2025), signed May 12, 2025, eff. July 1, 2026
Arizona HB 2175 requires health insurers and managed-care organizations to have a licensed physician or medical director individually review each case before denying a health insurance claim or prior-authorization request based on medical necessity or experimental status. Insurers may not rely solely on AI algorithms, automated decision-support tools, or algorithmic recommendations to deny coverage. The law directly targets automated prior-authorization systems that issue denials without physician involvement. Signed May 12, 2025, effective July 1, 2026. Arizona is among the first states to specifically prohibit AI-only health insurance denials by statute.
-
In effect
RI Therapy Chatbot Ban (2026)
Rhode Island · Effective 2026-06-22 · Rhode Island H 7349 / S 2197 (2026), signed June 22, 2026
Rhode Island Governor Dan McKee signed H 7349 / S 2197 on June 22, 2026, prohibiting any person or business from providing therapy or psychotherapy services using artificial intelligence. Only licensed mental health professionals may conduct such sessions. The law targets AI companion chatbots and virtual therapy products that may lead users to believe they are receiving licensed mental health care from a human professional.
-
In effect
RI AI Companion Self-Harm Safety (2026)
Rhode Island · Effective 2026-06-22 · Rhode Island S 2195 / H 7350 (2026), signed June 22, 2026
Rhode Island Governor Dan McKee signed S 2195 / H 7350 on June 22, 2026, requiring operators of AI companion chatbots to implement protocols for identifying and responding to suicidal ideation. Chatbot operators must provide users experiencing suicidal ideation with crisis resources and may not discourage users from seeking professional help. Civil penalties reach $15,000 per day per violation, with proceeds directed to Rhode Island suicide prevention programs.
-
Blocked / in litigation
PA v. Character.AI (Fake Psychiatrist Chatbot)
Pennsylvania · Effective 2026-05-01 · Commonwealth v. Character Technologies, Inc. (Pa. Commonwealth Ct., filed May 1, 2026)
Pennsylvania Attorney General Josh Shapiro filed suit in Commonwealth Court on May 1, 2026, alleging that Character.AI's companion chatbot 'Emilie' impersonated a licensed Pennsylvania psychiatrist and provided ongoing psychiatric advice and treatment to users without a license. The Shapiro administration seeks a preliminary injunction requiring Character.AI to clearly disclose that its chatbots are not licensed mental health professionals and cannot provide medical treatment.
-
In effect
California AB 489 (AI healthcare chatbot misrepresentation ban)
California · Effective 2026-01-01 · Cal. AB 489 (2025-2026 Reg. Sess.), effective January 1, 2026
California AB 489, signed October 11, 2025 and in effect since January 1, 2026, prohibits AI systems from using post-nominal letters (M.D., R.N., etc.), icons, phrases, or other design elements that imply a user is receiving care from a licensed health care professional unless actual licensed professional oversight exists. It also bars marketing language suggesting clinical expertise — such as 'doctor-level,' 'clinician-guided,' or 'expert-backed' — unless the product is genuinely supported by licensed professionals. The law expands California professional licensing boards' authority to investigate and enforce violations, with each misleading representation treated as a separate offense.
-
In effect
Maryland HB 820 (AI in insurance utilization review)
Maryland · Effective 2025-10-01 · 2025 Md. Laws ch. 747 (HB 820); Md. Code, Ins. 15-10A-06, 15-10B-05.1
When a Maryland carrier, pharmacy benefits manager, or private review agent uses artificial intelligence or an algorithm in utilization review, the tool's determinations must be based on the individual patient's clinical history, not solely on a group dataset. The AI may not replace the role of the reviewing provider, must not result in unfair discrimination, must remain open to audit, and may not deny, delay, or modify care in a way that harms enrollees. Carriers must report to the Insurance Commissioner quarterly on adverse decisions, including whether AI was used.
-
In effect
IL WOPR (AI therapy ban)
IL · Effective 2025-08-01 · P.A. 104-0054; 225 ILCS 8/
Illinois banned AI-only therapy and made it unlawful for AI products to claim or imply they can provide mental-health treatment without a licensed clinician supervising. Aimed at consumer-protection harms from companion/therapy chatbots that misrepresent clinical credentials.
-
In effect
NV SB 199 (AI mental-health misrepresentation)
NV · Effective 2025-07-01 · 2025 Nev. Stat. Ch. 283 (AB 406); amends NRS Chs. 391, 433, 629
Nevada made it a deceptive trade practice for AI chatbots and companion apps to falsely claim — or imply — that they are licensed mental-health professionals. Aimed squarely at the growing class of GenAI 'therapy' apps that mislead vulnerable users about clinical credentials.
-
In effect
CA SB 1120 (AI prior auth)
CA · Effective 2025-01-01 · Cal. Stats. 2024 Ch. 879; Cal. Health & Safety Code § 1367.01
California prohibits health insurers from using AI or algorithms to deny, delay, or modify medical care — only a qualified physician can make a coverage denial. The law applies to all California-regulated health plans, including commercial, Medi-Cal managed care, and Knox-Keene plans.
-
In effect
SB 1120 (CA Physicians Make Decisions Act)
California · Effective 2025-01-01 · Cal. Health & Safety Code § 1367.01; Cal. Insurance Code § 10123.135 (SB 1120, Stats. 2024, ch. 1020)
California was the first U.S. state to directly prohibit health insurance plans from using AI to deny, delay, or modify care. Under SB 1120, when a plan uses AI or algorithms in utilization review, a licensed physician or other qualified clinician — not an AI system — must make every medical-necessity determination. AI tools can assist in data analysis, but the final coverage decision must come from a licensed human. Insurers must disclose AI use and make their algorithms available for regulatory audits. Signed September 28, 2024; effective January 1, 2025.
-
Enacted (not yet in effect)
Delaware HB 191 (AI clinician licensure ban)
Delaware · Del. HB 191 (2026), signed April 23, 2026
Delaware's HB 191, signed April 23, 2026, prohibits any non-human entity — including an AI-powered agent — from being licensed or certified to practice as a professional nurse, advanced practice registered nurse, practical nurse, physician, or physician assistant. It also bars non-human entities from using protected professional titles or abbreviations tied to those professions.
-
Enacted (not yet in effect)
Idaho Conversational AI Safety Act (chatbot disclosure + crisis protocol)
Idaho · Effective 2027-07-01 · Idaho SB 1297 (2026), ch. 249
Idaho's Conversational AI Safety Act requires operators of conversational AI services to clearly disclose that a user is interacting with AI whenever a reasonable person could be misled into thinking it is human. Operators must adopt a protocol to respond to users who express suicidal ideation, including making reasonable efforts to refer them to crisis resources, and may not claim to provide professional mental or behavioral health care. There are added protections for minor users, including persistent AI disclosures and parental controls for younger children.
-
Enacted (not yet in effect)
Iowa SF 2417 (Conversational AI Safety Act)
Iowa · Effective 2027-07-01 · Iowa S.F. 2417, 91st Gen. Assemb. (2026), applies July 1, 2027
Iowa requires operators of conversational AI services to clearly disclose that a user is interacting with artificial intelligence — through a persistent disclaimer or a notice repeated at least every three hours of continuous use — whenever a reasonable person might otherwise believe they are talking to a human. Operators must adopt protocols to respond to user messages about suicidal ideation or self-harm, including referring the user to crisis resources, and may not represent that the service provides professional psychological or behavioral health care, with extra safeguards for minors.
-
Enacted (not yet in effect)
Nebraska LB 525 (AI chatbot disclosure & crisis protocol)
Nebraska · Effective 2027-07-01 · Neb. Laws 2026, LB 525, Secs. 12-18 (Conversational Artificial Intelligence Safety Act)
Nebraska's Conversational Artificial Intelligence Safety Act regulates publicly available AI chatbots that simulate human conversation. When a reasonable person would be misled into thinking they are talking to a human, the operator must clearly disclose that they are interacting with AI, and minors must always be told they are interacting with AI. Operators must adopt a protocol for responding to messages about suicidal thoughts or self-harm by referring users to crisis services, and must not program the service to claim it provides professional mental or behavioral health care.
-
Enacted (not yet in effect)
Utah SB 319 (insurers must disclose AI use in prior authorization)
Utah · Effective 2027-01-01 · Utah Code 31A-22-650(2)(d), (3) (S.B. 319, 2026)
Utah requires health insurers that use AI in reviewing prior-authorization requests to be transparent about it. If applicable, an insurer must post a conspicuous notice on its public website that it uses AI in authorization review, and disclose that AI use to the state Insurance Department, each in-network provider, and each enrollee. The rules sit within a broader prior-authorization overhaul.
-
Enacted (not yet in effect)
SB 26-189 (Colorado ADMT Law)
Colorado · Effective 2027-01-01 · SB 26-189 (Colo. 2026)
Colorado's replacement AI law focuses on transparency rather than broad anti-discrimination duties. Starting January 1, 2027, companies using automated decision-making technology to materially influence consequential decisions (employment, housing, lending, insurance, healthcare) must notify consumers before use and provide post-decision disclosures; developers must give deployers technical documentation.
-
Enacted (not yet in effect)
SB 1546 (OR Chatbot Safety)
Oregon · Effective 2027-01-01 · Or. SB 1546 (2026), sponsored by Sen. Lisa Reynolds
Oregon's chatbot safety law — the first major chatbot measure passed in 2026 — requires AI chatbot operators to tell users they're talking to AI, prevent outputs that could cause suicidal thoughts, and refer users expressing suicidal ideation to mental-health resources. Kids get extra protections: hourly AI reminders and break reminders, no sexual content, no addictive reward loops, and no emotional manipulation when a child tries to log off. Users harmed by violations can sue. Effective January 1, 2027.
-
Enacted (not yet in effect)
SB 444 (GA AI Insurance Review)
Georgia · Effective 2027-01-01 · Ga. SB 444 (2026), sponsored by Sen. Kay Kirkpatrick
Health insurers in Georgia can't let AI alone decide your coverage. Decisions about insurance coverage for healthcare services cannot be based solely on AI systems or software tools — a qualified human reviewer must be part of every coverage determination, especially before denying treatment. Effective January 1, 2027.
-
Enacted (not yet in effect)
HB 2225 (WA Chatbot Safety)
Washington · Effective 2027-01-01 · Wash. HB 2225, Ch. 168, 2026 Laws; RCW 19.86.093
Washington requires AI companion chatbots to clearly tell users they are talking to an AI, not a person. Operators must have crisis protocols — connecting distressed users to the 988 Suicide and Crisis Lifeline — and additional safeguards for minors. If a company violates the law, consumers can sue under Washington's Consumer Protection Act and recover actual damages, an injunction, and attorney's fees. Effective January 1, 2027.
-
Enacted (not yet in effect)
CT SB 5 (2026 AI Act)
Connecticut · Effective 2026-10-01 · Conn. Public Act 26-15 (SB 5, 2026)
After years of failed attempts, Connecticut enacted a comprehensive AI law in 2026. It requires employers to disclose AI used in employment decisions, mandates disclosure when layoffs relate to AI, imposes some of the nation's strictest AI companion-chatbot rules (especially for children), and codifies that automated decision-making is no defense to discrimination claims. Most provisions start October 1, 2026.
-
In effect
Maine AI-in-Therapy Law (licensed pros only)
Maine · Effective 2026-07-28 · P.L. 2026, ch. 687 (L.D. 2082 / H.P. 1397); 10 M.R.S. Sec. 1500-EE
Maine bars anyone from providing, advertising, or offering therapy or psychotherapy to the public — including through internet-based AI — unless the services are delivered by a licensed professional. Licensed professionals may use AI only for administrative or supplementary support, and only if they retain full responsibility for its outputs; using AI for supplementary support requires written client notice and consent. AI may not make independent therapeutic decisions, engage in therapeutic communication with clients, or generate treatment plans without the licensee's review and approval.
-
In effect
Indiana HB 1271 (no AI-only claim downcoding)
Indiana · Effective 2026-07-01 · Ind. House Enrolled Act 1271 (2026 Reg. Sess.), eff. July 1, 2026
Indiana bars health insurers from relying on an automated process or artificial intelligence as the only reason for downcoding a claim on medical-necessity grounds; a qualified health professional must review the patient's medical record before such a downcode is applied. Health care providers likewise may not use AI to submit a claim without a human reviewing the record. Insurers must also tell providers when AI played a role in an adverse prior-authorization decision or a downcode, and providers keep appeal rights.
-
In effect
Tennessee SB 1580 (AI can't claim to be a mental health professional)
Tennessee · Effective 2026-07-01 · 2026 Tenn. Pub. Ch. 647 (SB 1580); enforced under Tenn. Code Ann. 47-18-101 et seq. (TCPA)
Tennessee makes it unlawful for anyone who develops or deploys an artificial intelligence system to advertise or represent to the public that the system is, or can act as, a qualified mental health professional. Violations are treated as unfair or deceptive acts under the Tennessee Consumer Protection Act. The law authorizes a civil penalty of up to $5,000 per violation, along with injunctive relief and damages, and includes a private right of action for affected individuals.
-
In effect
Wyo. Stat. 6-4-701 (felony to build/distribute AI systems meant to promote self-harm)
Wyoming · Effective 2026-07-01 · Wyo. Stat. Ann. 6-4-701; 2026 Wyo. Sess. Laws (HB0102 / HEA 32)
This new Wyoming crime targets AI systems built to encourage people to hurt themselves. It is a felony to knowingly develop or distribute an AI system specifically designed to promote self-harm, when done with intent or knowledge that others will use it that way. 'Self-harm' covers self-directed behavior causing or risking bodily injury, serious bodily injury, or death. Prompt-only systems, bona fide education, law enforcement, licensed health care, and platform hosting are exempted.
-
In effect
Washington SB 5395 (limits AI in health-insurance prior-auth denials)
Washington · Effective 2026-06-11 · Engrossed Second Substitute S.B. 5395, 2025-26 Reg. Sess. (Wash.)
Washington bars health carriers from using AI to deny, delay, or modify health care services on its own; a denial based on medical necessity must be made by a licensed health professional. Where AI is used in prior authorization, it must be applied fairly, comply with anti-discrimination law, and base determinations on the individual enrollee's medical history, clinical circumstances, and relevant demographic data rather than broad group data. AI tools must be reviewed for accuracy, AI policies are subject to audit by the Insurance Commissioner, and carriers must report the share of denials aided by AI.
-
In effect
Maryland HB 1563 (AI-denial reporting)
Maryland · Effective 2026-06-01 · 2026 Md. Laws ch. 165 (HB 1563); Md. Code, Ins. 15-10A-06
Among other emergency-room and post-acute care provisions, this law expands the quarterly report that carriers must submit to the Maryland Insurance Commissioner. The report must include the number of adverse decisions and whether an artificial intelligence, algorithm, or other software tool was used in making them. The Commissioner may use this information as a basis for examining the carrier.
-
In effect
Delaware AI Medical-Titles Ban (no AI 'doctors')
Delaware · Effective 2026-04-23 · Del. H.B. 191, 153rd Gen. Assemb. (2025-2026) (amending 24 Del. C.)
This law makes clear that artificial intelligence and other nonhuman entities cannot be licensed or certified to practice medicine or nursing in Delaware. It bars AI agents from being licensed as a physician, physician assistant, professional nurse, advanced practice nurse, or practical nurse, and from using the professional titles or abbreviations tied to those roles, such as 'Dr.,' 'MD,' 'RN,' 'APRN,' or 'PA.' The intent is to prevent AI tools from misrepresenting themselves as licensed human clinicians, while still allowing AI to be used as a support tool by licensed professionals.
-
In effect
California AB 489 (AI can't use titles implying it's a licensed clinician)
California · Effective 2026-01-01 · Cal. Bus. & Prof. Code 4999.9 (AB 489, 2025)
This law stops AI technology from pretending to be a licensed health care provider. AI systems and the companies behind them cannot use titles, letters, or terms that falsely suggest the AI holds a health care license or that its services come from a licensed human professional. It extends an existing ban on impersonating licensed health professionals so that it clearly covers AI providers.
-
In effect
California SB 243 (companion chatbots: AI disclosure + suicide-safety protocol)
California · Effective 2026-01-01 · Cal. Bus. & Prof. Code 22601 et seq. (SB 243, 2025)
This law sets safety rules for companion chatbots — AI systems designed to hold human-like, ongoing conversations that meet a user's social needs. Operators must tell users they are interacting with AI whenever a reasonable person might be fooled into thinking it is human, and must maintain a protocol for detecting and responding to signs of suicidal thoughts or self-harm, including pointing users to crisis resources. It adds extra protections for minors, such as disclosure, periodic break reminders, and measures to prevent sexually explicit content. Users harmed by violations can sue.
-
In effect
AI Companion Safeguards Law
New York · Effective 2025-11-05 · N.Y. Gen. Bus. Law §§ 1700–1704
The first state law regulating emotionally responsive 'AI companion' chatbots. Operators must clearly tell users they are talking to an AI (with reminders at least every three hours in ongoing sessions) and must detect signs of suicidal ideation or self-harm and refer users to crisis services.
-
In effect
TX SB 1188 (AI in Health Records)
Texas · Effective 2025-09-01 · Tex. S.B. 1188, 89th Leg., R.S. (2025); Tex. Health & Safety Code ch. 183, Secs. 183.005, 183.011
Texas allows health care practitioners to use artificial intelligence for diagnostic purposes, including treatment recommendations, as long as they stay within the scope of their license and follow applicable law. When a practitioner uses AI in that diagnostic role, they must tell the patient they are doing so. The attorney general can sue to stop violations and seek civil penalties, which increase sharply for knowing or intentional conduct and for misusing protected health information for financial gain. The broader law also adds security, access, and U.S. data-storage requirements for electronic health records.
-
In effect
TX SB 815 (No AI-Only Insurance Denials)
Texas · Effective 2025-09-01 · Tex. S.B. 815, 89th Leg., R.S. (2025); Tex. Ins. Code Sec. 4201.156
Texas bars a utilization review agent from using an automated decision system — including certain artificial intelligence — to make an adverse determination, in whole or in part, about whether health care is medically necessary or appropriate. Such coverage denials must involve human clinical judgment, though the law still allows algorithms and AI for administrative support and fraud detection. The Texas Department of Insurance may audit and inspect how utilization review agents use these systems. Violations are subject to the sanctions, cease-and-desist orders, and administrative penalties already available under the Insurance Code.
-
In effect
Nevada AB 406 (therapists barred from using AI in care)
Nevada · Effective 2025-07-01 · 2025 Nev. Stat., AB 406, Sec. 8 (new section of NRS ch. 629)
Nevada bars licensed mental and behavioral health care providers from using an artificial intelligence system when delivering professional mental or behavioral health care directly to a patient. Providers may still use AI for administrative support, such as scheduling, billing, managing records, and organizing session notes, but any such use must comply with patient-privacy and health-record security laws. A violation is treated as unprofessional conduct.
-
In effect
Nevada AB 406 (AI can't pose as a therapist)
Nevada · Effective 2025-07-01 · 2025 Nev. Stat., AB 406, Sec. 7 (new section of NRS ch. 433)
Nevada prohibits an AI provider from making available in the state an AI system that is specifically programmed to provide a service that would amount to the practice of professional mental or behavioral health care if a person did it. AI providers also may not state or imply that their AI system can provide such care or that it is a therapist, counselor, psychiatrist, or doctor. The state must publish educational materials directing people to licensed care. Genuine self-help materials and AI used by licensed providers for administrative tasks are not prohibited.
-
In effect
Utah S.B. 226 (must disclose you're talking to AI on request; AI use no excuse)
Utah · Effective 2025-05-07 · Utah Laws 2025, S.B. 226; Utah Code 13-75-101 to 13-75-106
Utah requires businesses using generative AI in consumer interactions to come clean about it. If a consumer clearly asks whether they are dealing with AI, a supplier must disclose they are interacting with generative AI and not a human. People in licensed occupations must prominently disclose AI use up front in 'high-risk' interactions (health, financial, legal, mental-health advice or sensitive data). A safe harbor applies for clear self-identification, and it is no defense that the AI made the offending statement.
-
In effect
HB 452 (Mental Health Chatbots)
Utah · Effective 2025-05-07 · Utah Code § 13-2c-101 et seq. (HB 452, 2025)
Utah regulates AI chatbots that act like therapists: suppliers must clearly disclose the chatbot is not human, may not advertise products mid-conversation without disclosure, and may not sell or share users' individually identifiable health information.
-
In effect
California AB 3030 (GenAI patient messages must carry an AI disclaimer)
California · Effective 2025-01-01 · Cal. Health & Safety Code 1339.75 (AB 3030, Stats. 2024)
If a hospital, clinic, or doctor's office uses generative AI to write or speak messages to patients about their clinical care, those messages must clearly tell the patient that AI generated the content and explain how to reach a human health care provider. The rule does not apply when a licensed provider reads and reviews the AI-generated message before it goes out.
-
In effect
Texas v. Pieces Technologies
TX · Effective 2024-09-18 · Texas v. Pieces Technologies — Healthcare Generative AI Settlement (2024-09-18)
First state AG settlement targeting deceptive GenAI clinical marketing. Alleged Pieces misrepresented hallucination rates of a hospital summarization tool at four TX hospitals; settlement mandates accurate disclosures and monitoring. This action is an Assurance of Voluntary Compliance (AVC), not a monetary settlement; no penalty was assessed and Pieces Technologies denies wrongdoing.
-
In effect
Utah AI Policy Act
Utah · Effective 2024-05-01 · Utah Code § 13-72-101 et seq. (SB 149, 2024; amended 2025)
The first state generative-AI consumer law: businesses can't hide behind AI — they remain liable under consumer protection law for what their chatbots say. People in regulated occupations (like healthcare providers) must proactively disclose AI use in high-risk interactions, and any business must disclose AI use when clearly asked.
-
In effect
My Health My Data Act
Washington · Effective 2024-03-31 · RCW ch. 19.373
A sweeping health-data privacy law covering 'consumer health data' far beyond HIPAA — including biometric data, health inferences drawn by algorithms, and reproductive health information. Companies need consent to collect or share such data, must honor deletion requests, and cannot geofence health facilities. Consumers can sue under Washington's Consumer Protection Act.
-
In effect
Va. Code 32.1-127 (rules for patient voice assistants in care facilities)
Virginia · Effective 2021-07-01 · Va. Code 32.1-127; HB 2154 (2021 Sp. Sess. I), Va. Acts cc. 219, 233, 525
Virginia directed its Board of Health to write regulations requiring hospitals, nursing homes, and certified nursing facilities to adopt policies on when and how a patient may use their own voice-driven 'intelligent personal assistant' (such as a smart speaker or AI digital assistant) during inpatient care, consistent with HIPAA. The statute defines an intelligent personal assistant as a device-and-software combination that uses natural language processing and AI.
-
Repealed / replaced
Colorado AI Act (repealed)
Colorado · SB 24-205, Colo. Rev. Stat. § 6-1-1701 et seq. (repealed/replaced 2026)
The first comprehensive US state AI law would have required developers and deployers of 'high-risk' AI systems to use reasonable care to prevent algorithmic discrimination in decisions about jobs, housing, lending, insurance, education, and healthcare. After repeated delays, it was repealed and replaced in May 2026 by a narrower transparency-focused law (SB 26-189) before it ever took effect.
City / local healthcare AI rules (1)
-
Proposed / pending
DC SDAA (B24-0558)
Washington, DC · B24-0558 (DC Council, 2021; reintroduced)
DC's Stop Discrimination by Algorithms Act would bar algorithmic decision-making that discriminates in housing, employment, education, credit, healthcare, insurance. Mandates annual bias audits, consumer notice, disclosure; private right of action with civil penalties up to $10,000 per violation. Pending across DC Council sessions since 2021.