Selected 2026 Healthcare AI Regulation Updates: U.S. and Canada

Vero
Jordan Reeves · August 27, 2026 · 26 min read · Published by Vero Scribe Inc.

Healthcare AI regulation in 2026 is a layered system, not one law. In the United States, an AI function can sit under FDA medical-device oversight, HIPAA, ONC certified-health-IT requirements, FTC rules, professional duties, and state laws at the same time. In Canada, Health Canada medical-device rules interact with federal or provincial privacy law, professional obligations, and guidance from provincial privacy regulators.

The practical mistake is to put every development into one “AI regulation” bucket. A final FDA guidance, an active Texas statute, a proposed Canadian bill, and a voluntary NIST framework have different legal status and require different action.

This tracker separates those statuses. It is designed for clinical, compliance, privacy, health-IT, product, and procurement teams that need to answer a harder question than “Is this AI regulated?” The useful question is: Which requirements apply to this function, data flow, decision, user, and jurisdiction right now?

Sources were checked on August 27, 2026. Each tracker entry links to a regulator, legislature, or other primary authority. When a rule's application depends on specific facts, use the linked source and the organization’s jurisdictional review rather than a summary alone.

United States and Canada healthcare AI regulation tracker with 2026 status categories
Vero’s 2026 status map separates active requirements, regulator guidance, proposals, and upcoming dates in the United States and Canada.

Selected 2026 healthcare AI regulation updates

Coverage and maintenance: This is a curated tracker of selected federal, state, and provincial developments that materially affect healthcare AI in the United States and Canada. It is not a complete 50-state or province-by-province inventory, and an omitted jurisdiction does not imply that no law, professional rule, contract, or guidance applies. The page provides legal information, not legal advice. Vero Editorial Team checks FDA, HHS, ASTP/ONC, FTC, official legislatures, Health Canada, Parliament, federal and provincial privacy regulators, and linked primary sources at least quarterly, with an earlier review after a material law, guidance, enforcement, or product change. This version was last verified on August 27, 2026; the next scheduled review is no later than November 27, 2026.

Jordan Reeves is a Vero contributor who prepared this research summary from the linked primary authorities. No separate U.S. or Canadian regulatory reviewer is credited on this version.

The tracker below uses eight status labels:

  • In force: a current legal requirement with an effective date that has passed.
  • Final guidance: a regulator's current interpretation or recommendation. Guidance can strongly shape submissions, inspections, procurement, and enforcement without being a statute.
  • Regulator guidance: a current regulator resource or case note that explains operational expectations without being labelled final rulemaking guidance.
  • Discussion paper / request for feedback: a non-binding regulator publication that asks for input and may inform a future policy approach.
  • Proposed: a bill or rule that has not completed the process required to become binding.
  • Upcoming: enacted or signed requirements with a future effective date.
  • Voluntary: a framework teams may adopt, but which is not binding by itself.
  • Archived: a proposal that did not become law or is no longer active.

That separation prevents two opposite errors. One is waiting for a single “AI Act” while current medical-device, privacy, and professional rules already apply. The other is treating every policy announcement as an enforceable duty.

Material update log

Corrections and additions verified on August 27, 2026

  1. August 27, 2026

    Added FDA GenAI-enabled medical-device discussion paper
    Previous
    Not listed
    Current
    Discussion paper; feedback open through October 19, 2026
    Operational effect
    Review evidence strategy while continuing to apply current requirements.
  2. August 27, 2026

    Corrected Texas SB 1188 effective date
    Previous
    January 1, 2026 shown for the AI row
    Current
    Act effective September 1, 2025; January 1, 2026 applies to specified storage requirements
    Operational effect
    Separate diagnostic-review controls from record-storage controls.
  3. August 27, 2026

    Added Colorado HB 26-1195, Louisiana Act 649, and Rhode Island H 7538A/S 2570A
    Previous
    Not listed
    Current
    In force in 2026
    Operational effect
    Map AI documentation notice, consent, professional review, and accuracy duties by state.
  4. August 27, 2026

    Updated Canada Bill S-5
    Previous
    February 2026 introduction
    Current
    Passed the Senate; at second reading in the House of Commons
    Operational effect
    Continue monitoring. The bill remains proposed, not in force.

Filter selected updates

Showing 20 of 20 entries

Final guidanceUnited States · January 29, 2026
FDA Clinical Decision Support Software guidance

Explains how FDA interprets the four statutory criteria for non-device clinical decision support and which software functions remain device functions.

Verified August 27, 2026

Operational response

Classify each function by intended use and actual output. Do not rely on a product-wide label such as “decision support.”

Discussion paper / request for feedbackUnited States · August 18, 2026; comments due October 19, 2026
FDA considerations for GenAI-enabled medical devices

FDA requested feedback on possible risk assessment, competency-based premarket evaluation, post-market monitoring, foundation models, and agentic AI for GenAI-enabled medical devices. The paper is exploratory and does not replace current device law or final guidance.

Verified August 27, 2026

Operational response

Assess whether the questions affect product evidence and lifecycle plans, consider submitting comments, and continue applying current requirements while the approach develops.

In forceUnited States · January 1, 2026 baseline
ONC HTI-1 algorithm transparency and USCDI v3 baseline

Certified health IT modules that support predictive decision support interventions must provide specified source-attribute and risk-management information.

Verified August 27, 2026

Operational response

Ask certified-health-IT vendors where predictive DSI information appears, who maintains it, and how local users can evaluate updates.

In forceUnited States · Current in 2026
HIPAA Security Rule remains the current federal security standard

Covered entities and business associates must protect electronic protected health information under the current Security Rule while a stronger proposed rule remains pending.

Verified August 27, 2026

Operational response

Map AI data flows, execute required business-associate agreements, apply access and audit controls, and keep the proposed rule separate from current obligations.

In forceUnited States · July 29, 2024 amendments in effect
FTC Health Breach Notification Rule

Can apply to certain health apps and connected devices that are not covered by HIPAA, including services that draw health information from multiple sources.

Verified August 27, 2026

Operational response

Determine whether a consumer health AI product is a personal health record vendor or related entity and prepare breach-notification workflows.

In forceCalifornia · January 1, 2025
AB 3030 disclosure for generative AI clinical communications

Specified healthcare communications generated by generative AI must disclose that use and provide instructions for reaching a human, unless a licensed or certified provider reviewed the communication.

Verified August 27, 2026

Operational response

Inventory patient messages, identify which are generated and which receive qualified review, and test the human-contact path.

In forceCalifornia · January 1, 2025
SB 1120 controls on AI-assisted utilization review

AI, algorithms, and software tools cannot supplant the judgment of a physician or other qualified healthcare professional in utilization-review decisions.

Verified August 27, 2026

Operational response

Document the licensed reviewer, individual clinical context, decision rationale, override path, and appeal route for each affected workflow.

In forceTexas · January 1, 2026
HB 149 healthcare AI disclosure requirement

Texas healthcare service providers using AI in relation to healthcare services must provide the disclosure required by the Texas Responsible Artificial Intelligence Governance Act.

Verified August 27, 2026

Operational response

Confirm whether each patient-facing or care-related use falls inside the requirement and keep evidence that the disclosure is delivered.

In forceTexas · September 1, 2025
SB 1188: AI used for diagnostic purposes in electronic health records

Permits a healthcare practitioner to use AI for diagnostic purposes within the practitioner’s authorized scope, requires disclosure to patients, and requires review of AI-created records consistent with Texas Medical Board records standards. The Act took effect September 1, 2025; a separate storage provision applies on or after January 1, 2026.

Verified August 27, 2026

Operational response

Separate diagnostic-AI review and disclosure from data-location controls. Assign review to the qualified practitioner, preserve corrections, and verify storage and access requirements against the enacted text.

UpcomingColorado · Effective January 1, 2027
HB 26-1139 healthcare utilization review requirements

Creates healthcare-specific controls for automated decision systems used in utilization review, including licensed-clinician review and consideration of individual clinical circumstances.

Verified August 27, 2026

Operational response

Use 2026 to map affected decisions, redesign reviewer queues, and test notices, documentation, and appeals before the effective date.

In forceColorado · August 12, 2026
HB 26-1195 restrictions on AI use in psychotherapy

Restricts AI use in psychotherapy, requires regulated professionals to retain responsibility for administrative or supplementary AI outputs, and requires advance disclosure plus written informed consent when an AI system records or transcribes a therapeutic session.

Verified August 27, 2026

Operational response

Identify psychotherapy workflows, document the permitted purpose, deliver the required disclosure, obtain written informed consent, and assign the regulated professional to review AI outputs.

In forceLouisiana · August 1, 2026
Act 649 disclosure before AI transcription of a medical visit

Requires a healthcare professional licensed under the covered title to verbally disclose the use of a recording device, software, or service before recording any part of an appointment or treatment for transcription by artificial intelligence.

Verified August 27, 2026

Operational response

Place the verbal disclosure before recording begins, document the approved workflow, and verify covered professionals and disciplinary provisions against the enacted text.

In forceRhode Island · June 23, 2026; effective upon passage
H 7538A/S 2570A notification and review for AI visit documentation

Requires covered healthcare providers and facilities using AI to document in-person or telehealth visits to notify patients of that use and review the AI-generated documentation for accuracy after the visit.

Verified August 27, 2026

Operational response

Map covered visit-documentation tools, provide patient notification, assign post-visit accuracy review, and preserve the corrected final record.

Regulator guidanceCanada · April 1, 2026
Health Canada pre-market guidance for machine learning-enabled medical devices

Describes expectations for data, testing, clinical validation, transparency, post-market monitoring, and predetermined change control plans for ML-enabled medical devices.

Verified August 27, 2026

Operational response

Align submission and procurement evidence with the intended use, relevant populations, locked product version, change plan, and post-market controls.

In forceCanada · Current in 2026
Federal and provincial privacy laws apply by organization and context

Private-sector, public-sector, and health-information privacy obligations vary across Canada. AI does not create an exception to existing requirements.

Verified August 27, 2026

Operational response

Identify the applicable federal, provincial, and sector-specific law before selecting a consent, data-use, hosting, retention, or breach process.

Regulator guidanceOntario · January 28, 2026
IPC Ontario guidance on AI scribes in the health sector

Sets out privacy, transparency, contracting, consent, accuracy, governance, and human-review considerations for custodians adopting AI scribes.

Verified August 27, 2026

Operational response

Approve the use case, map information, verify contracts and retention, inform patients, monitor accuracy, and prevent unsanctioned tools.

Regulator guidanceOntario · April 27, 2026
IPC case note on unauthorized AI-scribe use

Shows how entering personal health information into an unapproved AI scribe can become a privacy breach and exposes failures in policy, training, authorization, and vendor governance.

Verified August 27, 2026

Operational response

Block shadow AI, train staff on approved tools, audit access, define incident response, and make managers accountable for enforcement.

Regulator guidanceBritish Columbia · January 28, 2026
OIPC BC guidance for AI scribes in private practice

Explains considerations for private clinics and practices subject to British Columbia’s Personal Information Protection Act.

Verified August 27, 2026

Operational response

Confirm organizational scope, necessity, consent, service-provider terms, access controls, accuracy review, and secure deletion.

ArchivedCanada · Archived after the 44th Parliament
Artificial Intelligence and Data Act proposal in Bill C-27

AIDA was proposed federal legislation, but it did not become an in-force general Canadian AI law. The government’s AIDA page is archived.

Verified August 27, 2026

Operational response

Do not cite AIDA as current law. Monitor Parliament for new legislation and continue applying existing medical-device, privacy, consumer, and professional rules.

ProposedCanada · Senate passed May 26, 2026; House first reading May 28, 2026
Connected Care for Canadians Act, Bill S-5

Would address health-information-technology interoperability and data blocking. As of August 27, 2026, it had passed the Senate and was at second reading in the House of Commons. It is not an in-force general healthcare AI law.

Verified August 27, 2026

Operational response

Monitor the House process and assess export, retrieval, exchange, and data-blocking behaviour without treating the bill as current law.

What changed most in 2026?

Five developments deserve immediate attention.

First, the FDA issued final Clinical Decision Support Software guidance on January 29, 2026. The document explains how FDA interprets the statutory criteria for non-device clinical decision support. It does not make all CDS unregulated. A function that does not satisfy the criteria may still be a device software function.

Second, on August 18, 2026, FDA published a discussion paper on GenAI-enabled medical devices. It asks for feedback on possible risk assessment, competency-based premarket evaluation, post-market monitoring, foundation models, and agentic AI. Comments are due October 19, 2026. The paper is exploratory and non-binding; it is not final guidance, a proposed rule, or an authorization.

Third, Texas requirements are now active, but their dates differ. HB 149 took effect January 1, 2026 and includes disclosure requirements for healthcare service providers using AI in relation to healthcare services. The enacted SB 1188 took effect September 1, 2025 for AI used for diagnostic purposes in electronic health records; the January 1, 2026 date applies to a separate storage provision. A generic website notice is not automatically proof that the actual clinical workflow meets either law.

Fourth, Health Canada published its pre-market guidance for machine learning-enabled medical devices on April 1, 2026. The guidance gives sponsors and buyers a clearer structure for reviewing data, testing, clinical validation, transparency, post-market monitoring, and predetermined change control plans.

Fifth, state and provincial regulators moved from broad AI principles to workflow-specific duties. Colorado, Louisiana, and Rhode Island enacted healthcare AI requirements in 2026. Ontario and British Columbia published AI-scribe guidance, and the Information and Privacy Commissioner of Ontario described an unauthorized AI-scribe incident. Together, these developments make notice, consent, accuracy review, and shadow AI concrete workflow issues.

How healthcare AI regulation works

A regulation inventory should begin with the product's functions, not its marketing category. The same platform might contain:

  • a transcription function that creates a draft;
  • a summarization function that selects clinically relevant content;
  • a prediction function that estimates deterioration;
  • a patient-message generator;
  • a coding suggestion tool;
  • an analytics dashboard for staffing.

Those functions can have different intended uses, data, users, outputs, and regulatory classifications. FDA may review one function while another remains non-device software. A state disclosure law may apply only to the patient-message workflow. HIPAA may apply when a covered provider uses the service, while FTC rules may matter for a related consumer app.

Regulatory stack

One AI function can trigger several layers at once

Start with the function, decision, data, user, and location. The word “AI” does not select the governing rule by itself.

  1. 1

    Medical-device classification

    Does the intended function diagnose, treat, monitor, or otherwise meet the applicable medical-device definition?

    Typical owner: Regulatory affairs with clinical and product leadership

  2. 2

    Health-information privacy and security

    Which health data enters the service, who receives it, and which federal, state, or provincial rules apply?

    Typical owner: Privacy, security, legal, and records leadership

  3. 3

    Clinical and professional accountability

    Which licensed person owns the decision, review, authentication, escalation, and patient communication?

    Typical owner: Clinical leadership and applicable professional bodies

  4. 4

    Health IT and interoperability

    Does the function operate inside certified health IT, use predictive decision support, or exchange regulated records?

    Typical owner: Health IT, informatics, integration, and procurement teams

  5. 5

    State and provincial overlays

    Do location-specific disclosure, consent, utilization review, hosting, records, or breach rules apply?

    Typical owner: Jurisdictional counsel and local compliance owners

  6. 6

    Claims, equity, and consumer protection

    Are accuracy, safety, outcome, bias, cost, and “human oversight” claims supported for the actual product and workflow?

    Typical owner: Evidence, quality, marketing, procurement, and governance teams

Vero operational map for identifying the regulators, professional duties, and internal owners attached to a healthcare AI function.

Step 1: define the intended use and decision boundary

Write one sentence that names the user, input, output, population, setting, and permitted action. For example:

A primary-care physician uses the system to convert encounter audio into a draft SOAP note that the physician reviews, corrects, and authenticates before it enters the legal record.

That sentence is more useful than “AI-powered documentation.” It creates reviewable questions. Does the tool retain audio? Does it infer content that was not spoken? Does it recommend diagnoses? Can administrative staff approve the draft? Does the service train on the encounter? What happens if the audio fails?

The same discipline applies to prediction. “Sepsis AI” is not an intended use. A useful description names the population, prediction horizon, trigger, reviewer, action, threshold, and fallback. If the organization cannot define the decision boundary, it cannot select the right evidence or regulatory controls.

Step 2: classify function, data, and user separately

Medical-device status and privacy coverage answer different questions. A non-device administrative tool can still process regulated health information. A medical device can operate on de-identified test data during development but receive identifiable data in service. A consumer health app can sit outside HIPAA yet fall under the FTC Health Breach Notification Rule.

Build three linked records:

  1. Function record: intended use, version, model, prompt, threshold, output, exclusions, and regulatory status.
  2. Data record: each input, recipient, purpose, subprocessor, storage location, retention period, training use, and deletion path.
  3. Accountability record: clinical owner, privacy owner, security owner, regulatory owner, operational owner, and the person authorized to pause use.

Our healthcare software evaluation guide explains how to turn these records into procurement requirements rather than accepting a broad security or compliance claim.

Step 3: distinguish authorization from implementation assurance

Regulatory authorization can be necessary and valuable. It is not a substitute for local acceptance testing. The FDA states that its AI-enabled medical-device list is updated periodically and is not necessarily comprehensive. Each entry relates to a particular authorized device and decision record.

Local performance can change with patient mix, devices, clinical prevalence, language, workflow, integration, alert thresholds, and the actions users take after an output. In a well-known external validation of a widely implemented sepsis model, performance and alert burden in the evaluating health system raised concerns that were not visible from adoption alone. The lesson is not that predictive AI always fails. It is that transport must be tested.

United States healthcare AI regulation in 2026

The United States does not have one federal healthcare AI statute. It has a function-based federal structure plus state overlays.

FDA: medical-device function comes first

FDA's question is not whether a vendor uses a large language model, machine learning, rules, or statistics. The question is whether the software function is a device under the Federal Food, Drug, and Cosmetic Act and whether a statutory exclusion applies.

The January 2026 CDS guidance is particularly important for software that supports a healthcare professional. To fit the non-device CDS exclusion, a function must satisfy all four statutory criteria. One criterion concerns whether the healthcare professional can independently review the basis for the recommendation rather than relying primarily on the software.

That makes transparency operational. A tool does not become non-device CDS simply because a clinician clicks “reviewed.” Teams should ask:

  • What recommendation is presented?
  • What patient-specific information drives it?
  • Is the basis understandable to the intended healthcare professional?
  • Can the professional independently reach a decision in the available time?
  • Does the software produce a specific output, risk score, diagnostic result, or treatment directive that changes the analysis?

For AI-enabled device software that changes over time, FDA's Predetermined Change Control Plan guidance provides a pathway for describing planned modifications and the methods used to develop, validate, and implement them. Buyers should translate that idea into contracts even when FDA does not directly regulate the function: require version traceability, notice of material changes, regression evidence, pause rights, rollback, and a usable exit.

FDA's August 2026 GenAI discussion paper is a different kind of document. It requests public feedback on a possible regulatory approach for GenAI-enabled medical devices, including competency-based evaluation and lifecycle monitoring. Teams can use its questions to stress-test an evidence plan or submit comments by October 19, 2026, but they should continue applying current law and final guidance while the agency considers the feedback.

ONC HTI-1: transparency inside certified health IT

The HTI-1 Final Rule created transparency requirements for predictive decision support interventions supplied by certified health-IT developers. It also set USCDI v3 as the certification baseline beginning January 1, 2026.

The rule is not a universal approval system for clinical AI. It gives users information about specified predictive DSI, including source attributes and risk-management practices. A healthcare organization still needs to evaluate whether a model fits its population and workflow.

Procurement questions should be concrete:

  • Is the function part of the certified module or an external add-on?
  • Where can users access the source attributes?
  • Which data, exclusions, performance measures, and known limitations are described?
  • Who updates the information after a model, threshold, or integration change?
  • Can the organization export the record of which model version influenced a decision?

For integration testing, the EHR interoperability guide shows why a vendor's “FHIR compatible” claim is not enough without authorization, status, exception, acknowledgement, and conformance tests.

HIPAA: AI does not create a privacy exception

HIPAA applies based on covered-entity and business-associate relationships and the handling of protected health information. It does not certify an AI product as “HIPAA compliant” in isolation.

The current HIPAA Security Rule remains in effect in 2026. HHS has also published a Security Rule notice of proposed rulemaking, but proposed requirements should not be presented as current law.

An AI review should cover more than encryption. Map whether a vendor uses data to provide the service, improve a shared model, train a customer-specific model, evaluate employees, advertise, or build another product. Examine subprocessors, human access, location, retention, deletion, breach response, audit logs, data return, and the consequences of contract termination.

The same controls matter for a “free” account. A staff member who pastes a patient note into an unapproved tool has still created a data flow even if procurement never signed a contract.

FTC: consumer health AI can fall outside HIPAA and still be regulated

The FTC Health Breach Notification Rule can apply to certain vendors of personal health records, related entities, and service providers that are not covered by HIPAA. The 2024 amendments clarified coverage involving health apps and connected devices.

Teams evaluating an AI symptom app, reproductive-health service, mental-health chatbot, wearable analytics product, or consumer record aggregator should not stop after asking whether HIPAA applies. They should assess what identifiable health information the service draws from multiple sources, how authorization is obtained, whether disclosures match the privacy promise, and how a breach would be investigated and reported.

California illustrates why a national policy alone is insufficient. AB 3030 addresses specified clinical communications generated by generative AI. The disclosure and human-contact requirements turn message routing, reviewer credentials, and the state of the recipient into compliance facts.

California's SB 1120 focuses on utilization review. State guidance emphasizes that AI and other software cannot supplant the judgment of a physician or other qualified healthcare professional. A process that sends a denial to a clinician after the system has effectively decided the case may not provide meaningful review.

Texas adds distinct duties through HB 149 and SB 1188. HB 149 took effect January 1, 2026. SB 1188's AI diagnostic provisions took effect September 1, 2025, while its specified storage requirements apply on or after January 1, 2026. Organizations operating across states need a matrix that links each requirement and effective date to the exact function, patient location, provider type, communication, decision, evidence record, and responsible owner.

Colorado's HB 26-1139 belongs in the upcoming column. Its healthcare utilization-review provisions take effect January 1, 2027. The practical 2026 action is to identify affected decisions and redesign the licensed-review, notice, documentation, and appeal workflow before the effective date.

Colorado's HB 26-1195, effective August 12, 2026, restricts AI use in psychotherapy and requires advance disclosure plus written informed consent when an AI system records or transcribes a therapeutic session. The regulated professional remains responsible for permitted administrative or supplementary uses and for reviewing the output.

Louisiana's HB 475 / Act 649, effective August 1, 2026, requires covered licensed healthcare professionals to verbally disclose the use of a recording device, software, or service before recording an appointment or treatment for AI transcription. The disclosure belongs before recording begins, not in a general privacy page discovered later.

Rhode Island's H 7538A/S 2570A, signed June 23, 2026 and effective upon passage, requires covered providers and facilities using AI to document in-person or telehealth visits to notify patients and review the AI-generated documentation for accuracy after the visit.

Canada healthcare AI regulation in 2026

Canada also relies on existing sectoral and jurisdictional rules. The absence of an in-force general AI Act does not mean healthcare AI is unregulated.

Health Canada: regulate the medical purpose, not the label

A machine learning-enabled product with a medical purpose may be a medical device under the Food and Drugs Act and Medical Devices Regulations. Health Canada's April 2026 ML-enabled medical-device guidance describes the evidence expected across the product lifecycle.

The guidance gives procurement teams a useful evidence vocabulary:

  • intended use and indications;
  • training, tuning, and test data;
  • independence and representativeness of evaluation data;
  • analytical and clinical validation;
  • subgroup and failure analysis;
  • human factors and transparency;
  • cybersecurity and software lifecycle controls;
  • post-market performance monitoring;
  • predetermined change control plans.

Health Canada also publishes transparency principles for ML-enabled medical devices. These principles emphasize information that helps users understand the intended use, performance, limitations, inputs, outputs, workflow, and changes. That information should appear where the user makes a decision, not only in a procurement archive.

Privacy: identify the actual Canadian jurisdiction

The Office of the Privacy Commissioner of Canada's AI portal brings together federal privacy guidance, but Canadian healthcare privacy is not a single federal checklist. The applicable law can depend on whether the organization is public or private, the province, the kind of health-information custodian, cross-border processing, and the activity.

A clinic should document why a particular law applies. That classification drives authority or consent, safeguards, access rights, service-provider terms, breach response, retention, and oversight. A vendor statement that it “meets Canadian privacy law” is not enough when the vendor does not know the clinic's province, sector, or data flow.

Ontario: AI-scribe governance became a concrete enforcement lesson

The IPC Ontario AI-scribe guidance asks health-information custodians to address necessity, transparency, consent or authority, contracts, information flows, retention, accuracy, safeguards, accountability, and patient choice.

The April case note matters because it describes what failure looks like. A clinician used an unauthorized AI scribe and entered personal health information into a service the hospital had not approved. The regulator's lesson was broader than one employee: custodians need governance frameworks, clear policies, training, approved-tool controls, risk assessment, vendor oversight, human review, monitoring, and incident response.

This changes the governance question from “Did we buy a safe AI scribe?” to “Can staff tell which tools are approved, can the organization detect unapproved use, and does the incident process recognize disclosure to an AI service?” Our medical-scribes-for-doctors guide maps the related capture, drafting, clinician-review, and authentication workflow.

British Columbia: scope matters

The OIPC British Columbia guidance addresses AI scribes in private practice under BC's Personal Information Protection Act. It does not automatically describe every public-sector body or every province.

That scope is a feature, not a footnote. A useful regulation tracker records the organizations covered, not merely the province name. Procurement and policy should follow the institution's actual legal position.

AIDA is not current Canadian law

The proposed Artificial Intelligence and Data Act appeared in Bill C-27 during the 44th Parliament. The Parliament of Canada record shows the bill's legislative history, and the government's AIDA information is archived. AIDA did not become an in-force general AI law.

Presenting it as current law makes a tracker less trustworthy. It can still inform policy history, but current decisions should be tied to active medical-device, privacy, consumer, professional, contractual, and provincial requirements.

The proposed Connected Care for Canadians Act, Bill S-5, focuses on interoperability and data blocking rather than creating a general healthcare AI regime. The Senate passed it on May 26, 2026, and the House completed first reading on May 28. As of August 27, the official LEGISinfo record lists it at second reading in the House of Commons. It remains proposed and should not be treated as an active obligation.

U.S. versus Canada operational comparison

Both countries regulate by function and context, but teams should not copy a U.S. policy into Canada or add “PIPEDA” to a HIPAA checklist and call the work complete.

Operational comparison

United States and Canada are both layered, but not interchangeable

Decision areaUnited StatesCanada
General AI lawNo single federal healthcare AI statute. Federal sector rules and state laws apply by function and context.No in-force general federal AI law. AIDA in former Bill C-27 was proposed but did not become law.
Medical-device routeFDA regulates qualifying device software and publishes function-specific decisions and guidance.Health Canada regulates qualifying medical devices under the Food and Drugs Act and Medical Devices Regulations.
Health-information privacyHIPAA applies to covered entities and business associates. FTC and state rules may cover other health products.Federal, provincial, public-sector, private-sector, and health-information laws vary by organization and province.
Health IT transparencyONC HTI-1 includes predictive decision-support transparency requirements for specified certified health IT.No exact national equivalent. Procurement, medical-device, privacy, interoperability, and provincial requirements interact.
Subnational variationState laws can add disclosure, utilization-review, discrimination, consumer, and professional requirements.Provincial privacy laws, health-information statutes, colleges, and regulators shape local implementation.
Procurement implicationVerify FDA status, certified-health-IT scope, HIPAA roles, state coverage, evidence, and change controls.Verify Health Canada status, applicable privacy jurisdiction, provincial guidance, data location, evidence, and change controls.

One governance system can still support both countries

The shared operational core is strong:

  1. Define the intended use and excluded uses.
  2. Classify medical-device and health-information status.
  3. Identify the local jurisdiction and professional owner.
  4. Map data and vendors.
  5. Audit evidence and claims.
  6. Test the human-AI workflow locally.
  7. Control product changes.
  8. Monitor performance, incidents, and primary regulatory sources.

The artifacts can be shared while legal conclusions remain jurisdiction-specific. One function inventory can feed FDA and Health Canada analysis. One data map can support HIPAA and provincial privacy review. One evidence file can support procurement in both countries. The decision and sign-off columns should identify the applicable authority rather than pretending the standards are identical.

Separate evidence from vendor claims

Healthcare AI regulation news often mixes three kinds of evidence:

  • Regulatory evidence: authorization, licence, certification scope, official guidance, or an enforcement action.
  • Scientific evidence: benchmark, external validation, prospective workflow study, randomized comparison, or post-market outcome.
  • Commercial evidence: a vendor case study, testimonial, demo, press release, or self-reported performance claim.

Each can answer a useful question. None substitutes for the others.

An FDA authorization is not proof that the tool reduces clinician time. A peer-reviewed vignette study is not proof that a product is authorized. A customer quote can describe experience but cannot establish a general error rate. “Used by 10,000 clinicians” describes adoption, not safety or effectiveness.

Use a claim-to-evidence ledger

For every material claim, record the fields below.

Claim-to-evidence ledger fields

FieldWhat to capture
ClaimThe exact accuracy, safety, outcome, workflow, equity, or cost statement
ProductProduct, model, version, prompt, threshold, and integration tested
Intended useUser, population, setting, input, output, and permitted action
EvidenceStudy design, comparator, endpoint, sample, confidence interval, and limitations
IndependenceFunder, product supplier, author employment, conflicts, and replication
Regulatory relevanceAuthorization, licence, certification, guidance, or none
Local resultAcceptance-test result for the intended clinical workflow
DecisionApproved scope, conditions, monitoring, stop criteria, and owner

The ledger prevents evidence drift. A vendor may update a model while the clinic continues quoting results from an earlier version. A claim may move from “drafting accuracy” to “better patient care” without new evidence. A product may inherit the reputation of another product from the same company.

Human-AI trial results do not support a universal conclusion

In a randomized study of 50 physicians, access to GPT-4 did not significantly improve the median diagnostic-reasoning score compared with conventional resources. A separate randomized trial of 92 physicians found improved management-reasoning scores with GPT-4 access, while participants also took more time.

These studies used different tasks and methods. Together, they show why “a clinician remains in the loop” is not a performance guarantee. The system changes what the clinician sees, how they reason, how long the task takes, and which errors look plausible. Evidence must match the decision and workflow.

Failure modes and meaningful human oversight

Human oversight is meaningful only when the reviewer can detect and control the likely failure. A final approval button does not solve missing source information, automation bias, workload overload, or a reviewer who lacks the right scope of practice.

Failure mode 1: the tool performs a different function than the policy describes

A policy may approve “transcription,” while the product also summarizes, infers assessment language, recommends codes, or generates patient instructions. Feature expansion can change medical-device, privacy, and disclosure analysis.

Control: maintain a function-level inventory and require approval after a material model, prompt, threshold, interface, or intended-use change.

Failure mode 2: fluent output hides weak support

Generative text can sound complete while omitting a symptom, reversing negation, merging speakers, inventing a diagnosis, or attaching a statement to the wrong source.

Control: show the reviewer the encounter source or source-linked evidence, identify generated content, and require verification of consequential fields. Measure material additions and omissions, not grammar alone.

Failure mode 3: a correct signal reaches an unusable workflow

A prediction can be technically correct and still fail because no one owns the alert, the queue is too large, escalation is delayed, or the recommended action is unavailable.

Control: name the recipient, response time, acknowledgement, escalation, closure, and downtime path. Test alert volume and response capacity before live reliance.

Failure mode 4: the reviewer becomes a rubber stamp

Repeated exposure to plausible outputs can create automation bias. Time pressure can turn “human review” into superficial acceptance.

Control: sample corrections and overrides, test known failure cases, train reviewers to disagree, and monitor review time and error recurrence. Give reviewers authority to reject the output and pause the system.

Failure mode 5: the model or integration changes silently

A vendor may update a model, prompt, subprocessor, user interface, or integration without calling it a new product. Output quality and regulatory analysis can change even when the product name stays the same.

Control: contract for change notice and traceability. Record versions at the time of use. Run regression tests after material changes and keep rollback and export tested.

Failure mode 6: shadow AI bypasses every formal control

An employee can use an unapproved chatbot, transcription app, or browser extension because the approved route is slow or unclear. The organization may discover the tool only after a complaint or breach.

Control: publish an approved-tool pathway, make prohibited uses specific, train with realistic examples, monitor access where lawful, provide a rapid evaluation route, and include AI services in incident-response playbooks.

A 90-day implementation plan

The goal is not to create a binder called “AI policy.” It is to make each live function traceable from legal status to workflow evidence.

Days 1 to 30: inventory and classify

  • Find AI functions in purchased software, EHR modules, pilots, free accounts, browser extensions, research tools, and patient apps.
  • Record version, owner, user, intended use, data, output, locations, vendor, and current status.
  • Stop unapproved use involving patient information while it is assessed.
  • Classify medical-device, privacy, certified-health-IT, state, provincial, and professional layers.
  • Mark every source as in force, final guidance, proposed, upcoming, voluntary, or archived.

Days 31 to 60: prove evidence and controls

  • Build the claim-to-evidence ledger.
  • Review contracts, subprocessors, training rights, retention, deletion, change notice, incidents, export, and exit.
  • Write the human-review and fallback workflow.
  • Define acceptance thresholds for clinically material errors, failed inputs, correction burden, latency, subgroup results, alert volume, and privacy events.
  • Test representative and adversarial cases before users rely on the output.

Days 61 to 90: approve, monitor, and prepare for change

  • Approve a narrow scope with named owners and stop criteria.
  • Train users on the tool's limits, disclosure duties, correction workflow, and prohibited uses.
  • Capture version and configuration evidence.
  • Monitor corrections, overrides, incidents, complaints, drift, and workflow burden.
  • Set a quarterly primary-source review and event-driven review after a law, guidance, enforcement action, incident, or product change.

Governance control check

Can the team prove operational readiness?

Progress stays in this browser session. The checklist does not collect patient or product data.

0/12

How to keep the tracker current

Healthcare AI regulation news moves quickly, but speed does not excuse weak sourcing. Use a source hierarchy:

  1. enacted statutory or regulatory text and official effective dates;
  2. regulator decisions, final guidance, enforcement, and official databases;
  3. proposed-rule and legislative records;
  4. professional-college or privacy-regulator guidance for the applicable jurisdiction;
  5. peer-reviewed evidence for performance and human factors;
  6. vendor documentation for product-specific facts;
  7. news or commentary as a pointer to a primary source, not the final authority.

For every change, record the previous status, new status, source, effective date, affected functions, owner, decision, and implementation deadline. Keep the evidence snapshot that supported the decision. A link alone can change over time.

Watch items for the rest of 2026

  • FDA feedback and any follow-up to the August 2026 GenAI-enabled medical-device discussion paper; comments are due October 19, 2026.
  • HHS action on the proposed HIPAA Security Rule changes while the current rule remains effective.
  • Implementation and enforcement of state healthcare AI duties, including the 2026 Colorado, Louisiana, and Rhode Island requirements.
  • Preparation for Colorado HB 26-1139's January 1, 2027 effective date.
  • Health Canada implementation experience under the April 2026 MLMD guidance.
  • Bill S-5's House of Commons progress and any new Canadian federal AI legislation, without assuming archived AIDA language will return unchanged.
  • Provincial privacy-regulator and professional-college guidance on AI scribes and clinical decision support.
  • Product changes that alter intended use, output, data sharing, training, or reviewer workload.

The practical standard for 2026

A defensible healthcare AI program can answer five questions without relying on a vendor slogan:

  1. What exact function is live, and which version produced the output?
  2. Which current requirements and guidance apply in this jurisdiction?
  3. What independent and product-specific evidence supports the intended use?
  4. How can a qualified person detect, correct, reject, and escalate a failure?
  5. What evidence would trigger a pause, rollback, regulatory reassessment, or exit?

The central 2026 lesson is straightforward. Regulation follows the clinical function, data, decision, user, and location. Teams that keep those elements visible can adapt when the law or product changes. Teams that reduce governance to “AI approved” cannot.

For a wider evidence and implementation framework, see Medical AI: Use Cases, Risks, Evidence, and Implementation and AI in Healthcare: Use Cases, Risks, Evidence, and Implementation. For data-access and patient communication controls, use the patient portal guide and HIPAA forms routing checklist.

Plain-language answers

Frequently asked questions about healthcare AI regulation

Current answers about FDA, Health Canada, HIPAA, ONC, state and provincial requirements, human oversight, vendor evidence, and 2026 implementation dates.

What is healthcare AI regulation?

Healthcare AI regulation is the set of medical-device, privacy, security, professional, health-IT, consumer-protection, and jurisdiction-specific rules that apply to an AI function. The applicable requirements depend on what the system does, which data it uses, who relies on it, and where it operates.

Where can I find current healthcare AI regulation news?

Start with primary sources: FDA, HHS, FTC, ONC, NIST, Health Canada, the Office of the Privacy Commissioner of Canada, provincial privacy regulators, and official state or provincial legislatures. Record whether each item is binding law, final guidance, a proposal, or a voluntary framework.

Is there one federal healthcare AI law in the United States?

No. U.S. healthcare AI oversight is layered. FDA may regulate a medical-device function; HHS rules protect regulated health information; ONC rules apply to specified certified health IT; the FTC covers certain consumer and health-app practices; and state laws can add disclosure or review duties.

How does FDA regulate AI in healthcare?

FDA regulates AI when the software function meets the medical-device definition and is not excluded from it. The intended use and actual function matter. FDA authorization supports the specific reviewed function and conditions, not every feature or every future model version from the same vendor.

What changed in FDA clinical decision support guidance in 2026?

FDA issued final Clinical Decision Support Software guidance on January 29, 2026. Separately, on August 18, FDA published a non-binding discussion paper and requested feedback on GenAI-enabled medical devices. The paper is not final guidance, a proposed rule, authorization, or a binding requirement.

Does FDA authorization prove that a healthcare AI tool will work in my clinic?

No. Authorization is important evidence for a specific intended use, product, and regulatory pathway. Local workflow, patient mix, equipment, language, prevalence, integrations, thresholds, and reviewer behaviour can change performance. A clinic still needs fit-for-purpose acceptance testing and monitoring.

Does HIPAA regulate artificial intelligence?

HIPAA does not create a separate AI category. Its Privacy, Security, and Breach Notification requirements apply when covered entities and business associates use or disclose protected health information through AI. The current Security Rule remains in effect while HHS considers proposed changes.

Can the FTC Health Breach Notification Rule apply to an AI health app?

Yes, depending on the product and data flows. The rule can cover certain personal health record vendors and related entities outside HIPAA. An AI health app that draws identifiable health information from multiple sources should evaluate coverage and prepare notification procedures before an incident.

What does ONC HTI-1 require for predictive decision support?

HTI-1 establishes transparency requirements for specified predictive decision support interventions in certified health IT. Users should be able to access source attributes and risk-management information. The rule does not make every predictive model safe or clinically appropriate; it improves the information available for evaluation.

Which U.S. state healthcare AI laws matter in 2026?

Selected examples include California clinical-communication and utilization-review requirements, Texas disclosure and practitioner-review provisions, Colorado psychotherapy restrictions, Louisiana disclosure before AI transcription, and Rhode Island notice and accuracy review for AI visit documentation. This tracker is curated, not a complete 50-state inventory.

What does California AB 3030 require?

AB 3030 requires specified healthcare communications generated by generative AI to disclose that fact and explain how a patient can reach a human, unless the communication was reviewed by a licensed or certified healthcare provider. The exact statutory scope and exceptions should be checked for the workflow.

What does Texas HB 149 mean for healthcare providers?

Texas HB 149 includes an AI disclosure requirement for healthcare service providers using AI in relation to healthcare services, effective January 1, 2026. Providers should determine which uses are covered and retain evidence that the required disclosure was delivered through the actual patient workflow.

Is Colorado HB 26-1139 already in force?

No. The healthcare utilization-review requirements in Colorado HB 26-1139 are scheduled to take effect January 1, 2027. It belongs in a 2026 implementation watchlist, not in a list of current obligations.

Is there one healthcare AI law in Canada?

No. Canada applies existing medical-device, privacy, consumer, professional, contractual, and provincial health-information rules to AI. Health Canada regulates qualifying medical-device functions, while privacy obligations vary by organization, sector, province, and the data involved.

Is Canada’s Artificial Intelligence and Data Act in force?

No. AIDA was proposed in Bill C-27 during the 44th Parliament but did not become an in-force general AI law. Its government information page is archived. Healthcare organizations should not cite AIDA as current law and should continue applying existing requirements.

What did Health Canada publish for machine learning-enabled medical devices in 2026?

Health Canada published pre-market guidance on April 1, 2026. It covers topics including data, testing, clinical validation, transparency, post-market monitoring, and predetermined change control plans. It is regulator guidance for ML-enabled medical devices, not a rule for every administrative AI tool.

What do Ontario and British Columbia say about AI scribes?

Ontario and British Columbia privacy regulators published AI-scribe guidance in January 2026. Their jurisdictional scope differs, but both emphasize approved use, necessity, transparent patient communication, vendor and data-flow review, accuracy, human verification, safeguards, and accountable governance.

What is meaningful human oversight for healthcare AI?

Meaningful oversight gives a qualified person the source information, time, competence, authority, interface, and fallback needed to detect and act on an error. A name on a workflow or a final click is not enough when the reviewer cannot independently assess the output.

How should a clinic evaluate healthcare AI vendor claims?

Match each claim to evidence for the same product version, intended use, population, setting, comparator, and endpoint. Separate regulatory authorization, technical benchmarks, independent validation, prospective workflow studies, patient outcomes, and vendor testimonials. Record funding, conflicts, limitations, and local test results.

How often should a healthcare AI regulation tracker be updated?

High-risk programs should monitor primary sources continuously and perform a documented review at least quarterly, plus event-driven review after a new law, guidance, enforcement action, product change, incident, or expansion into a new jurisdiction. Vero last verified this curated set on August 27, 2026.

Evaluating AI-assisted clinical documentation?

See how Vero turns permitted encounter information into a note draft for clinician review.