Selected 2026 Healthcare AI Regulation Updates: U.S. and Canada
Healthcare AI regulation in 2026 is a layered system, not one law. In the United States, an AI function can sit under FDA medical-device oversight, HIPAA, ONC certified-health-IT requirements, FTC rules, professional duties, and state laws at the same time. In Canada, Health Canada medical-device rules interact with federal or provincial privacy law, professional obligations, and guidance from provincial privacy regulators.
The practical mistake is to put every development into one “AI regulation” bucket. A final FDA guidance, an active Texas statute, a proposed Canadian bill, and a voluntary NIST framework have different legal status and require different action.
This tracker separates those statuses. It is designed for clinical, compliance, privacy, health-IT, product, and procurement teams that need to answer a harder question than “Is this AI regulated?” The useful question is: Which requirements apply to this function, data flow, decision, user, and jurisdiction right now?
Sources were checked on August 27, 2026. Each tracker entry links to a regulator, legislature, or other primary authority. When a rule's application depends on specific facts, use the linked source and the organization’s jurisdictional review rather than a summary alone.

Selected 2026 healthcare AI regulation updates
Coverage and maintenance: This is a curated tracker of selected federal, state, and provincial developments that materially affect healthcare AI in the United States and Canada. It is not a complete 50-state or province-by-province inventory, and an omitted jurisdiction does not imply that no law, professional rule, contract, or guidance applies. The page provides legal information, not legal advice. Vero Editorial Team checks FDA, HHS, ASTP/ONC, FTC, official legislatures, Health Canada, Parliament, federal and provincial privacy regulators, and linked primary sources at least quarterly, with an earlier review after a material law, guidance, enforcement, or product change. This version was last verified on August 27, 2026; the next scheduled review is no later than November 27, 2026.
Jordan Reeves is a Vero contributor who prepared this research summary from the linked primary authorities. No separate U.S. or Canadian regulatory reviewer is credited on this version.
The tracker below uses eight status labels:
- In force: a current legal requirement with an effective date that has passed.
- Final guidance: a regulator's current interpretation or recommendation. Guidance can strongly shape submissions, inspections, procurement, and enforcement without being a statute.
- Regulator guidance: a current regulator resource or case note that explains operational expectations without being labelled final rulemaking guidance.
- Discussion paper / request for feedback: a non-binding regulator publication that asks for input and may inform a future policy approach.
- Proposed: a bill or rule that has not completed the process required to become binding.
- Upcoming: enacted or signed requirements with a future effective date.
- Voluntary: a framework teams may adopt, but which is not binding by itself.
- Archived: a proposal that did not become law or is no longer active.
That separation prevents two opposite errors. One is waiting for a single “AI Act” while current medical-device, privacy, and professional rules already apply. The other is treating every policy announcement as an enforceable duty.
Material update log
Corrections and additions verified on August 27, 2026
August 27, 2026
Added FDA GenAI-enabled medical-device discussion paper
- Previous
- Not listed
- Current
- Discussion paper; feedback open through October 19, 2026
- Operational effect
- Review evidence strategy while continuing to apply current requirements.
August 27, 2026
Corrected Texas SB 1188 effective date
- Previous
- January 1, 2026 shown for the AI row
- Current
- Act effective September 1, 2025; January 1, 2026 applies to specified storage requirements
- Operational effect
- Separate diagnostic-review controls from record-storage controls.
August 27, 2026
Added Colorado HB 26-1195, Louisiana Act 649, and Rhode Island H 7538A/S 2570A
- Previous
- Not listed
- Current
- In force in 2026
- Operational effect
- Map AI documentation notice, consent, professional review, and accuracy duties by state.
August 27, 2026
Updated Canada Bill S-5
- Previous
- February 2026 introduction
- Current
- Passed the Senate; at second reading in the House of Commons
- Operational effect
- Continue monitoring. The bill remains proposed, not in force.
Filter selected updates
Showing 20 of 20 entries
| Jurisdiction and date | Status | Update and scope | Operational response |
|---|---|---|---|
United States January 29, 2026 Verified August 27, 2026 | Final guidance | FDA Clinical Decision Support Software guidance Explains how FDA interprets the four statutory criteria for non-device clinical decision support and which software functions remain device functions. | Classify each function by intended use and actual output. Do not rely on a product-wide label such as “decision support.” |
United States August 18, 2026; comments due October 19, 2026 Verified August 27, 2026 | Discussion paper / request for feedback | FDA considerations for GenAI-enabled medical devices FDA requested feedback on possible risk assessment, competency-based premarket evaluation, post-market monitoring, foundation models, and agentic AI for GenAI-enabled medical devices. The paper is exploratory and does not replace current device law or final guidance. | Assess whether the questions affect product evidence and lifecycle plans, consider submitting comments, and continue applying current requirements while the approach develops. |
United States January 1, 2026 baseline Verified August 27, 2026 | In force | ONC HTI-1 algorithm transparency and USCDI v3 baseline Certified health IT modules that support predictive decision support interventions must provide specified source-attribute and risk-management information. | Ask certified-health-IT vendors where predictive DSI information appears, who maintains it, and how local users can evaluate updates. |
United States Current in 2026 Verified August 27, 2026 | In force | HIPAA Security Rule remains the current federal security standard Covered entities and business associates must protect electronic protected health information under the current Security Rule while a stronger proposed rule remains pending. | Map AI data flows, execute required business-associate agreements, apply access and audit controls, and keep the proposed rule separate from current obligations. |
United States July 29, 2024 amendments in effect Verified August 27, 2026 | In force | FTC Health Breach Notification Rule Can apply to certain health apps and connected devices that are not covered by HIPAA, including services that draw health information from multiple sources. | Determine whether a consumer health AI product is a personal health record vendor or related entity and prepare breach-notification workflows. |
California January 1, 2025 Verified August 27, 2026 | In force | AB 3030 disclosure for generative AI clinical communications Specified healthcare communications generated by generative AI must disclose that use and provide instructions for reaching a human, unless a licensed or certified provider reviewed the communication. | Inventory patient messages, identify which are generated and which receive qualified review, and test the human-contact path. |
California January 1, 2025 Verified August 27, 2026 | In force | SB 1120 controls on AI-assisted utilization review AI, algorithms, and software tools cannot supplant the judgment of a physician or other qualified healthcare professional in utilization-review decisions. | Document the licensed reviewer, individual clinical context, decision rationale, override path, and appeal route for each affected workflow. |
Texas January 1, 2026 Verified August 27, 2026 | In force | HB 149 healthcare AI disclosure requirement Texas healthcare service providers using AI in relation to healthcare services must provide the disclosure required by the Texas Responsible Artificial Intelligence Governance Act. | Confirm whether each patient-facing or care-related use falls inside the requirement and keep evidence that the disclosure is delivered. |
Texas September 1, 2025 Verified August 27, 2026 | In force | SB 1188: AI used for diagnostic purposes in electronic health records Permits a healthcare practitioner to use AI for diagnostic purposes within the practitioner’s authorized scope, requires disclosure to patients, and requires review of AI-created records consistent with Texas Medical Board records standards. The Act took effect September 1, 2025; a separate storage provision applies on or after January 1, 2026. | Separate diagnostic-AI review and disclosure from data-location controls. Assign review to the qualified practitioner, preserve corrections, and verify storage and access requirements against the enacted text. |
Colorado Effective January 1, 2027 Verified August 27, 2026 | Upcoming | HB 26-1139 healthcare utilization review requirements Creates healthcare-specific controls for automated decision systems used in utilization review, including licensed-clinician review and consideration of individual clinical circumstances. | Use 2026 to map affected decisions, redesign reviewer queues, and test notices, documentation, and appeals before the effective date. |
Colorado August 12, 2026 Verified August 27, 2026 | In force | HB 26-1195 restrictions on AI use in psychotherapy Restricts AI use in psychotherapy, requires regulated professionals to retain responsibility for administrative or supplementary AI outputs, and requires advance disclosure plus written informed consent when an AI system records or transcribes a therapeutic session. | Identify psychotherapy workflows, document the permitted purpose, deliver the required disclosure, obtain written informed consent, and assign the regulated professional to review AI outputs. |
Louisiana August 1, 2026 Verified August 27, 2026 | In force | Act 649 disclosure before AI transcription of a medical visit Requires a healthcare professional licensed under the covered title to verbally disclose the use of a recording device, software, or service before recording any part of an appointment or treatment for transcription by artificial intelligence. | Place the verbal disclosure before recording begins, document the approved workflow, and verify covered professionals and disciplinary provisions against the enacted text. |
Rhode Island June 23, 2026; effective upon passage Verified August 27, 2026 | In force | H 7538A/S 2570A notification and review for AI visit documentation Requires covered healthcare providers and facilities using AI to document in-person or telehealth visits to notify patients of that use and review the AI-generated documentation for accuracy after the visit. | Map covered visit-documentation tools, provide patient notification, assign post-visit accuracy review, and preserve the corrected final record. |
Canada April 1, 2026 Verified August 27, 2026 | Regulator guidance | Health Canada pre-market guidance for machine learning-enabled medical devices Describes expectations for data, testing, clinical validation, transparency, post-market monitoring, and predetermined change control plans for ML-enabled medical devices. | Align submission and procurement evidence with the intended use, relevant populations, locked product version, change plan, and post-market controls. |
Canada Current in 2026 Verified August 27, 2026 | In force | Federal and provincial privacy laws apply by organization and context Private-sector, public-sector, and health-information privacy obligations vary across Canada. AI does not create an exception to existing requirements. | Identify the applicable federal, provincial, and sector-specific law before selecting a consent, data-use, hosting, retention, or breach process. |
Ontario January 28, 2026 Verified August 27, 2026 | Regulator guidance | IPC Ontario guidance on AI scribes in the health sector Sets out privacy, transparency, contracting, consent, accuracy, governance, and human-review considerations for custodians adopting AI scribes. | Approve the use case, map information, verify contracts and retention, inform patients, monitor accuracy, and prevent unsanctioned tools. |
Ontario April 27, 2026 Verified August 27, 2026 | Regulator guidance | IPC case note on unauthorized AI-scribe use Shows how entering personal health information into an unapproved AI scribe can become a privacy breach and exposes failures in policy, training, authorization, and vendor governance. | Block shadow AI, train staff on approved tools, audit access, define incident response, and make managers accountable for enforcement. |
British Columbia January 28, 2026 Verified August 27, 2026 | Regulator guidance | OIPC BC guidance for AI scribes in private practice Explains considerations for private clinics and practices subject to British Columbia’s Personal Information Protection Act. | Confirm organizational scope, necessity, consent, service-provider terms, access controls, accuracy review, and secure deletion. |
Canada Archived after the 44th Parliament Verified August 27, 2026 | Archived | Artificial Intelligence and Data Act proposal in Bill C-27 AIDA was proposed federal legislation, but it did not become an in-force general Canadian AI law. The government’s AIDA page is archived. | Do not cite AIDA as current law. Monitor Parliament for new legislation and continue applying existing medical-device, privacy, consumer, and professional rules. |
Canada Senate passed May 26, 2026; House first reading May 28, 2026 Verified August 27, 2026 | Proposed | Connected Care for Canadians Act, Bill S-5 Would address health-information-technology interoperability and data blocking. As of August 27, 2026, it had passed the Senate and was at second reading in the House of Commons. It is not an in-force general healthcare AI law. | Monitor the House process and assess export, retrieval, exchange, and data-blocking behaviour without treating the bill as current law. |
Explains how FDA interprets the four statutory criteria for non-device clinical decision support and which software functions remain device functions.
Verified August 27, 2026
Operational response
Classify each function by intended use and actual output. Do not rely on a product-wide label such as “decision support.”
FDA requested feedback on possible risk assessment, competency-based premarket evaluation, post-market monitoring, foundation models, and agentic AI for GenAI-enabled medical devices. The paper is exploratory and does not replace current device law or final guidance.
Verified August 27, 2026
Operational response
Assess whether the questions affect product evidence and lifecycle plans, consider submitting comments, and continue applying current requirements while the approach develops.
Certified health IT modules that support predictive decision support interventions must provide specified source-attribute and risk-management information.
Verified August 27, 2026
Operational response
Ask certified-health-IT vendors where predictive DSI information appears, who maintains it, and how local users can evaluate updates.
Covered entities and business associates must protect electronic protected health information under the current Security Rule while a stronger proposed rule remains pending.
Verified August 27, 2026
Operational response
Map AI data flows, execute required business-associate agreements, apply access and audit controls, and keep the proposed rule separate from current obligations.
Can apply to certain health apps and connected devices that are not covered by HIPAA, including services that draw health information from multiple sources.
Verified August 27, 2026
Operational response
Determine whether a consumer health AI product is a personal health record vendor or related entity and prepare breach-notification workflows.
Specified healthcare communications generated by generative AI must disclose that use and provide instructions for reaching a human, unless a licensed or certified provider reviewed the communication.
Verified August 27, 2026
Operational response
Inventory patient messages, identify which are generated and which receive qualified review, and test the human-contact path.
AI, algorithms, and software tools cannot supplant the judgment of a physician or other qualified healthcare professional in utilization-review decisions.
Verified August 27, 2026
Operational response
Document the licensed reviewer, individual clinical context, decision rationale, override path, and appeal route for each affected workflow.
Texas healthcare service providers using AI in relation to healthcare services must provide the disclosure required by the Texas Responsible Artificial Intelligence Governance Act.
Verified August 27, 2026
Operational response
Confirm whether each patient-facing or care-related use falls inside the requirement and keep evidence that the disclosure is delivered.
Permits a healthcare practitioner to use AI for diagnostic purposes within the practitioner’s authorized scope, requires disclosure to patients, and requires review of AI-created records consistent with Texas Medical Board records standards. The Act took effect September 1, 2025; a separate storage provision applies on or after January 1, 2026.
Verified August 27, 2026
Operational response
Separate diagnostic-AI review and disclosure from data-location controls. Assign review to the qualified practitioner, preserve corrections, and verify storage and access requirements against the enacted text.
Creates healthcare-specific controls for automated decision systems used in utilization review, including licensed-clinician review and consideration of individual clinical circumstances.
Verified August 27, 2026
Operational response
Use 2026 to map affected decisions, redesign reviewer queues, and test notices, documentation, and appeals before the effective date.
Restricts AI use in psychotherapy, requires regulated professionals to retain responsibility for administrative or supplementary AI outputs, and requires advance disclosure plus written informed consent when an AI system records or transcribes a therapeutic session.
Verified August 27, 2026
Operational response
Identify psychotherapy workflows, document the permitted purpose, deliver the required disclosure, obtain written informed consent, and assign the regulated professional to review AI outputs.
Requires a healthcare professional licensed under the covered title to verbally disclose the use of a recording device, software, or service before recording any part of an appointment or treatment for transcription by artificial intelligence.
Verified August 27, 2026
Operational response
Place the verbal disclosure before recording begins, document the approved workflow, and verify covered professionals and disciplinary provisions against the enacted text.
Requires covered healthcare providers and facilities using AI to document in-person or telehealth visits to notify patients of that use and review the AI-generated documentation for accuracy after the visit.
Verified August 27, 2026
Operational response
Map covered visit-documentation tools, provide patient notification, assign post-visit accuracy review, and preserve the corrected final record.
Describes expectations for data, testing, clinical validation, transparency, post-market monitoring, and predetermined change control plans for ML-enabled medical devices.
Verified August 27, 2026
Operational response
Align submission and procurement evidence with the intended use, relevant populations, locked product version, change plan, and post-market controls.
Private-sector, public-sector, and health-information privacy obligations vary across Canada. AI does not create an exception to existing requirements.
Verified August 27, 2026
Operational response
Identify the applicable federal, provincial, and sector-specific law before selecting a consent, data-use, hosting, retention, or breach process.
Sets out privacy, transparency, contracting, consent, accuracy, governance, and human-review considerations for custodians adopting AI scribes.
Verified August 27, 2026
Operational response
Approve the use case, map information, verify contracts and retention, inform patients, monitor accuracy, and prevent unsanctioned tools.
Shows how entering personal health information into an unapproved AI scribe can become a privacy breach and exposes failures in policy, training, authorization, and vendor governance.
Verified August 27, 2026
Operational response
Block shadow AI, train staff on approved tools, audit access, define incident response, and make managers accountable for enforcement.
Explains considerations for private clinics and practices subject to British Columbia’s Personal Information Protection Act.
Verified August 27, 2026
Operational response
Confirm organizational scope, necessity, consent, service-provider terms, access controls, accuracy review, and secure deletion.
AIDA was proposed federal legislation, but it did not become an in-force general Canadian AI law. The government’s AIDA page is archived.
Verified August 27, 2026
Operational response
Do not cite AIDA as current law. Monitor Parliament for new legislation and continue applying existing medical-device, privacy, consumer, and professional rules.
Would address health-information-technology interoperability and data blocking. As of August 27, 2026, it had passed the Senate and was at second reading in the House of Commons. It is not an in-force general healthcare AI law.
Verified August 27, 2026
Operational response
Monitor the House process and assess export, retrieval, exchange, and data-blocking behaviour without treating the bill as current law.
What changed most in 2026?
Five developments deserve immediate attention.
First, the FDA issued final Clinical Decision Support Software guidance on January 29, 2026. The document explains how FDA interprets the statutory criteria for non-device clinical decision support. It does not make all CDS unregulated. A function that does not satisfy the criteria may still be a device software function.
Second, on August 18, 2026, FDA published a discussion paper on GenAI-enabled medical devices. It asks for feedback on possible risk assessment, competency-based premarket evaluation, post-market monitoring, foundation models, and agentic AI. Comments are due October 19, 2026. The paper is exploratory and non-binding; it is not final guidance, a proposed rule, or an authorization.
Third, Texas requirements are now active, but their dates differ. HB 149 took effect January 1, 2026 and includes disclosure requirements for healthcare service providers using AI in relation to healthcare services. The enacted SB 1188 took effect September 1, 2025 for AI used for diagnostic purposes in electronic health records; the January 1, 2026 date applies to a separate storage provision. A generic website notice is not automatically proof that the actual clinical workflow meets either law.
Fourth, Health Canada published its pre-market guidance for machine learning-enabled medical devices on April 1, 2026. The guidance gives sponsors and buyers a clearer structure for reviewing data, testing, clinical validation, transparency, post-market monitoring, and predetermined change control plans.
Fifth, state and provincial regulators moved from broad AI principles to workflow-specific duties. Colorado, Louisiana, and Rhode Island enacted healthcare AI requirements in 2026. Ontario and British Columbia published AI-scribe guidance, and the Information and Privacy Commissioner of Ontario described an unauthorized AI-scribe incident. Together, these developments make notice, consent, accuracy review, and shadow AI concrete workflow issues.
How healthcare AI regulation works
A regulation inventory should begin with the product's functions, not its marketing category. The same platform might contain:
- a transcription function that creates a draft;
- a summarization function that selects clinically relevant content;
- a prediction function that estimates deterioration;
- a patient-message generator;
- a coding suggestion tool;
- an analytics dashboard for staffing.
Those functions can have different intended uses, data, users, outputs, and regulatory classifications. FDA may review one function while another remains non-device software. A state disclosure law may apply only to the patient-message workflow. HIPAA may apply when a covered provider uses the service, while FTC rules may matter for a related consumer app.
Regulatory stack
One AI function can trigger several layers at once
Start with the function, decision, data, user, and location. The word “AI” does not select the governing rule by itself.
- 1
Medical-device classification
Does the intended function diagnose, treat, monitor, or otherwise meet the applicable medical-device definition?
Typical owner: Regulatory affairs with clinical and product leadership
- 2
Health-information privacy and security
Which health data enters the service, who receives it, and which federal, state, or provincial rules apply?
Typical owner: Privacy, security, legal, and records leadership
- 3
Clinical and professional accountability
Which licensed person owns the decision, review, authentication, escalation, and patient communication?
Typical owner: Clinical leadership and applicable professional bodies
- 4
Health IT and interoperability
Does the function operate inside certified health IT, use predictive decision support, or exchange regulated records?
Typical owner: Health IT, informatics, integration, and procurement teams
- 5
State and provincial overlays
Do location-specific disclosure, consent, utilization review, hosting, records, or breach rules apply?
Typical owner: Jurisdictional counsel and local compliance owners
- 6
Claims, equity, and consumer protection
Are accuracy, safety, outcome, bias, cost, and “human oversight” claims supported for the actual product and workflow?
Typical owner: Evidence, quality, marketing, procurement, and governance teams
Step 1: define the intended use and decision boundary
Write one sentence that names the user, input, output, population, setting, and permitted action. For example:
A primary-care physician uses the system to convert encounter audio into a draft SOAP note that the physician reviews, corrects, and authenticates before it enters the legal record.
That sentence is more useful than “AI-powered documentation.” It creates reviewable questions. Does the tool retain audio? Does it infer content that was not spoken? Does it recommend diagnoses? Can administrative staff approve the draft? Does the service train on the encounter? What happens if the audio fails?
The same discipline applies to prediction. “Sepsis AI” is not an intended use. A useful description names the population, prediction horizon, trigger, reviewer, action, threshold, and fallback. If the organization cannot define the decision boundary, it cannot select the right evidence or regulatory controls.
Step 2: classify function, data, and user separately
Medical-device status and privacy coverage answer different questions. A non-device administrative tool can still process regulated health information. A medical device can operate on de-identified test data during development but receive identifiable data in service. A consumer health app can sit outside HIPAA yet fall under the FTC Health Breach Notification Rule.
Build three linked records:
- Function record: intended use, version, model, prompt, threshold, output, exclusions, and regulatory status.
- Data record: each input, recipient, purpose, subprocessor, storage location, retention period, training use, and deletion path.
- Accountability record: clinical owner, privacy owner, security owner, regulatory owner, operational owner, and the person authorized to pause use.
Our healthcare software evaluation guide explains how to turn these records into procurement requirements rather than accepting a broad security or compliance claim.
Step 3: distinguish authorization from implementation assurance
Regulatory authorization can be necessary and valuable. It is not a substitute for local acceptance testing. The FDA states that its AI-enabled medical-device list is updated periodically and is not necessarily comprehensive. Each entry relates to a particular authorized device and decision record.
Local performance can change with patient mix, devices, clinical prevalence, language, workflow, integration, alert thresholds, and the actions users take after an output. In a well-known external validation of a widely implemented sepsis model, performance and alert burden in the evaluating health system raised concerns that were not visible from adoption alone. The lesson is not that predictive AI always fails. It is that transport must be tested.
United States healthcare AI regulation in 2026
The United States does not have one federal healthcare AI statute. It has a function-based federal structure plus state overlays.
FDA: medical-device function comes first
FDA's question is not whether a vendor uses a large language model, machine learning, rules, or statistics. The question is whether the software function is a device under the Federal Food, Drug, and Cosmetic Act and whether a statutory exclusion applies.
The January 2026 CDS guidance is particularly important for software that supports a healthcare professional. To fit the non-device CDS exclusion, a function must satisfy all four statutory criteria. One criterion concerns whether the healthcare professional can independently review the basis for the recommendation rather than relying primarily on the software.
That makes transparency operational. A tool does not become non-device CDS simply because a clinician clicks “reviewed.” Teams should ask:
- What recommendation is presented?
- What patient-specific information drives it?
- Is the basis understandable to the intended healthcare professional?
- Can the professional independently reach a decision in the available time?
- Does the software produce a specific output, risk score, diagnostic result, or treatment directive that changes the analysis?
For AI-enabled device software that changes over time, FDA's Predetermined Change Control Plan guidance provides a pathway for describing planned modifications and the methods used to develop, validate, and implement them. Buyers should translate that idea into contracts even when FDA does not directly regulate the function: require version traceability, notice of material changes, regression evidence, pause rights, rollback, and a usable exit.
FDA's August 2026 GenAI discussion paper is a different kind of document. It requests public feedback on a possible regulatory approach for GenAI-enabled medical devices, including competency-based evaluation and lifecycle monitoring. Teams can use its questions to stress-test an evidence plan or submit comments by October 19, 2026, but they should continue applying current law and final guidance while the agency considers the feedback.
ONC HTI-1: transparency inside certified health IT
The HTI-1 Final Rule created transparency requirements for predictive decision support interventions supplied by certified health-IT developers. It also set USCDI v3 as the certification baseline beginning January 1, 2026.
The rule is not a universal approval system for clinical AI. It gives users information about specified predictive DSI, including source attributes and risk-management practices. A healthcare organization still needs to evaluate whether a model fits its population and workflow.
Procurement questions should be concrete:
- Is the function part of the certified module or an external add-on?
- Where can users access the source attributes?
- Which data, exclusions, performance measures, and known limitations are described?
- Who updates the information after a model, threshold, or integration change?
- Can the organization export the record of which model version influenced a decision?
For integration testing, the EHR interoperability guide shows why a vendor's “FHIR compatible” claim is not enough without authorization, status, exception, acknowledgement, and conformance tests.
HIPAA: AI does not create a privacy exception
HIPAA applies based on covered-entity and business-associate relationships and the handling of protected health information. It does not certify an AI product as “HIPAA compliant” in isolation.
The current HIPAA Security Rule remains in effect in 2026. HHS has also published a Security Rule notice of proposed rulemaking, but proposed requirements should not be presented as current law.
An AI review should cover more than encryption. Map whether a vendor uses data to provide the service, improve a shared model, train a customer-specific model, evaluate employees, advertise, or build another product. Examine subprocessors, human access, location, retention, deletion, breach response, audit logs, data return, and the consequences of contract termination.
The same controls matter for a “free” account. A staff member who pastes a patient note into an unapproved tool has still created a data flow even if procurement never signed a contract.
FTC: consumer health AI can fall outside HIPAA and still be regulated
The FTC Health Breach Notification Rule can apply to certain vendors of personal health records, related entities, and service providers that are not covered by HIPAA. The 2024 amendments clarified coverage involving health apps and connected devices.
Teams evaluating an AI symptom app, reproductive-health service, mental-health chatbot, wearable analytics product, or consumer record aggregator should not stop after asking whether HIPAA applies. They should assess what identifiable health information the service draws from multiple sources, how authorization is obtained, whether disclosures match the privacy promise, and how a breach would be investigated and reported.
State laws: workflow details now carry legal consequences
California illustrates why a national policy alone is insufficient. AB 3030 addresses specified clinical communications generated by generative AI. The disclosure and human-contact requirements turn message routing, reviewer credentials, and the state of the recipient into compliance facts.
California's SB 1120 focuses on utilization review. State guidance emphasizes that AI and other software cannot supplant the judgment of a physician or other qualified healthcare professional. A process that sends a denial to a clinician after the system has effectively decided the case may not provide meaningful review.
Texas adds distinct duties through HB 149 and SB 1188. HB 149 took effect January 1, 2026. SB 1188's AI diagnostic provisions took effect September 1, 2025, while its specified storage requirements apply on or after January 1, 2026. Organizations operating across states need a matrix that links each requirement and effective date to the exact function, patient location, provider type, communication, decision, evidence record, and responsible owner.
Colorado's HB 26-1139 belongs in the upcoming column. Its healthcare utilization-review provisions take effect January 1, 2027. The practical 2026 action is to identify affected decisions and redesign the licensed-review, notice, documentation, and appeal workflow before the effective date.
Colorado's HB 26-1195, effective August 12, 2026, restricts AI use in psychotherapy and requires advance disclosure plus written informed consent when an AI system records or transcribes a therapeutic session. The regulated professional remains responsible for permitted administrative or supplementary uses and for reviewing the output.
Louisiana's HB 475 / Act 649, effective August 1, 2026, requires covered licensed healthcare professionals to verbally disclose the use of a recording device, software, or service before recording an appointment or treatment for AI transcription. The disclosure belongs before recording begins, not in a general privacy page discovered later.
Rhode Island's H 7538A/S 2570A, signed June 23, 2026 and effective upon passage, requires covered providers and facilities using AI to document in-person or telehealth visits to notify patients and review the AI-generated documentation for accuracy after the visit.
Canada healthcare AI regulation in 2026
Canada also relies on existing sectoral and jurisdictional rules. The absence of an in-force general AI Act does not mean healthcare AI is unregulated.
Health Canada: regulate the medical purpose, not the label
A machine learning-enabled product with a medical purpose may be a medical device under the Food and Drugs Act and Medical Devices Regulations. Health Canada's April 2026 ML-enabled medical-device guidance describes the evidence expected across the product lifecycle.
The guidance gives procurement teams a useful evidence vocabulary:
- intended use and indications;
- training, tuning, and test data;
- independence and representativeness of evaluation data;
- analytical and clinical validation;
- subgroup and failure analysis;
- human factors and transparency;
- cybersecurity and software lifecycle controls;
- post-market performance monitoring;
- predetermined change control plans.
Health Canada also publishes transparency principles for ML-enabled medical devices. These principles emphasize information that helps users understand the intended use, performance, limitations, inputs, outputs, workflow, and changes. That information should appear where the user makes a decision, not only in a procurement archive.
Privacy: identify the actual Canadian jurisdiction
The Office of the Privacy Commissioner of Canada's AI portal brings together federal privacy guidance, but Canadian healthcare privacy is not a single federal checklist. The applicable law can depend on whether the organization is public or private, the province, the kind of health-information custodian, cross-border processing, and the activity.
A clinic should document why a particular law applies. That classification drives authority or consent, safeguards, access rights, service-provider terms, breach response, retention, and oversight. A vendor statement that it “meets Canadian privacy law” is not enough when the vendor does not know the clinic's province, sector, or data flow.
Ontario: AI-scribe governance became a concrete enforcement lesson
The IPC Ontario AI-scribe guidance asks health-information custodians to address necessity, transparency, consent or authority, contracts, information flows, retention, accuracy, safeguards, accountability, and patient choice.
The April case note matters because it describes what failure looks like. A clinician used an unauthorized AI scribe and entered personal health information into a service the hospital had not approved. The regulator's lesson was broader than one employee: custodians need governance frameworks, clear policies, training, approved-tool controls, risk assessment, vendor oversight, human review, monitoring, and incident response.
This changes the governance question from “Did we buy a safe AI scribe?” to “Can staff tell which tools are approved, can the organization detect unapproved use, and does the incident process recognize disclosure to an AI service?” Our medical-scribes-for-doctors guide maps the related capture, drafting, clinician-review, and authentication workflow.
British Columbia: scope matters
The OIPC British Columbia guidance addresses AI scribes in private practice under BC's Personal Information Protection Act. It does not automatically describe every public-sector body or every province.
That scope is a feature, not a footnote. A useful regulation tracker records the organizations covered, not merely the province name. Procurement and policy should follow the institution's actual legal position.
AIDA is not current Canadian law
The proposed Artificial Intelligence and Data Act appeared in Bill C-27 during the 44th Parliament. The Parliament of Canada record shows the bill's legislative history, and the government's AIDA information is archived. AIDA did not become an in-force general AI law.
Presenting it as current law makes a tracker less trustworthy. It can still inform policy history, but current decisions should be tied to active medical-device, privacy, consumer, professional, contractual, and provincial requirements.
The proposed Connected Care for Canadians Act, Bill S-5, focuses on interoperability and data blocking rather than creating a general healthcare AI regime. The Senate passed it on May 26, 2026, and the House completed first reading on May 28. As of August 27, the official LEGISinfo record lists it at second reading in the House of Commons. It remains proposed and should not be treated as an active obligation.
U.S. versus Canada operational comparison
Both countries regulate by function and context, but teams should not copy a U.S. policy into Canada or add “PIPEDA” to a HIPAA checklist and call the work complete.
Operational comparison
United States and Canada are both layered, but not interchangeable
| Decision area | United States | Canada |
|---|---|---|
| General AI law | No single federal healthcare AI statute. Federal sector rules and state laws apply by function and context. | No in-force general federal AI law. AIDA in former Bill C-27 was proposed but did not become law. |
| Medical-device route | FDA regulates qualifying device software and publishes function-specific decisions and guidance. | Health Canada regulates qualifying medical devices under the Food and Drugs Act and Medical Devices Regulations. |
| Health-information privacy | HIPAA applies to covered entities and business associates. FTC and state rules may cover other health products. | Federal, provincial, public-sector, private-sector, and health-information laws vary by organization and province. |
| Health IT transparency | ONC HTI-1 includes predictive decision-support transparency requirements for specified certified health IT. | No exact national equivalent. Procurement, medical-device, privacy, interoperability, and provincial requirements interact. |
| Subnational variation | State laws can add disclosure, utilization-review, discrimination, consumer, and professional requirements. | Provincial privacy laws, health-information statutes, colleges, and regulators shape local implementation. |
| Procurement implication | Verify FDA status, certified-health-IT scope, HIPAA roles, state coverage, evidence, and change controls. | Verify Health Canada status, applicable privacy jurisdiction, provincial guidance, data location, evidence, and change controls. |
One governance system can still support both countries
The shared operational core is strong:
- Define the intended use and excluded uses.
- Classify medical-device and health-information status.
- Identify the local jurisdiction and professional owner.
- Map data and vendors.
- Audit evidence and claims.
- Test the human-AI workflow locally.
- Control product changes.
- Monitor performance, incidents, and primary regulatory sources.
The artifacts can be shared while legal conclusions remain jurisdiction-specific. One function inventory can feed FDA and Health Canada analysis. One data map can support HIPAA and provincial privacy review. One evidence file can support procurement in both countries. The decision and sign-off columns should identify the applicable authority rather than pretending the standards are identical.
Separate evidence from vendor claims
Healthcare AI regulation news often mixes three kinds of evidence:
- Regulatory evidence: authorization, licence, certification scope, official guidance, or an enforcement action.
- Scientific evidence: benchmark, external validation, prospective workflow study, randomized comparison, or post-market outcome.
- Commercial evidence: a vendor case study, testimonial, demo, press release, or self-reported performance claim.
Each can answer a useful question. None substitutes for the others.
An FDA authorization is not proof that the tool reduces clinician time. A peer-reviewed vignette study is not proof that a product is authorized. A customer quote can describe experience but cannot establish a general error rate. “Used by 10,000 clinicians” describes adoption, not safety or effectiveness.
Use a claim-to-evidence ledger
For every material claim, record the fields below.
Claim-to-evidence ledger fields
| Field | What to capture |
|---|---|
| Claim | The exact accuracy, safety, outcome, workflow, equity, or cost statement |
| Product | Product, model, version, prompt, threshold, and integration tested |
| Intended use | User, population, setting, input, output, and permitted action |
| Evidence | Study design, comparator, endpoint, sample, confidence interval, and limitations |
| Independence | Funder, product supplier, author employment, conflicts, and replication |
| Regulatory relevance | Authorization, licence, certification, guidance, or none |
| Local result | Acceptance-test result for the intended clinical workflow |
| Decision | Approved scope, conditions, monitoring, stop criteria, and owner |
The ledger prevents evidence drift. A vendor may update a model while the clinic continues quoting results from an earlier version. A claim may move from “drafting accuracy” to “better patient care” without new evidence. A product may inherit the reputation of another product from the same company.
Human-AI trial results do not support a universal conclusion
In a randomized study of 50 physicians, access to GPT-4 did not significantly improve the median diagnostic-reasoning score compared with conventional resources. A separate randomized trial of 92 physicians found improved management-reasoning scores with GPT-4 access, while participants also took more time.
These studies used different tasks and methods. Together, they show why “a clinician remains in the loop” is not a performance guarantee. The system changes what the clinician sees, how they reason, how long the task takes, and which errors look plausible. Evidence must match the decision and workflow.
Failure modes and meaningful human oversight
Human oversight is meaningful only when the reviewer can detect and control the likely failure. A final approval button does not solve missing source information, automation bias, workload overload, or a reviewer who lacks the right scope of practice.
Failure mode 1: the tool performs a different function than the policy describes
A policy may approve “transcription,” while the product also summarizes, infers assessment language, recommends codes, or generates patient instructions. Feature expansion can change medical-device, privacy, and disclosure analysis.
Control: maintain a function-level inventory and require approval after a material model, prompt, threshold, interface, or intended-use change.
Failure mode 2: fluent output hides weak support
Generative text can sound complete while omitting a symptom, reversing negation, merging speakers, inventing a diagnosis, or attaching a statement to the wrong source.
Control: show the reviewer the encounter source or source-linked evidence, identify generated content, and require verification of consequential fields. Measure material additions and omissions, not grammar alone.
Failure mode 3: a correct signal reaches an unusable workflow
A prediction can be technically correct and still fail because no one owns the alert, the queue is too large, escalation is delayed, or the recommended action is unavailable.
Control: name the recipient, response time, acknowledgement, escalation, closure, and downtime path. Test alert volume and response capacity before live reliance.
Failure mode 4: the reviewer becomes a rubber stamp
Repeated exposure to plausible outputs can create automation bias. Time pressure can turn “human review” into superficial acceptance.
Control: sample corrections and overrides, test known failure cases, train reviewers to disagree, and monitor review time and error recurrence. Give reviewers authority to reject the output and pause the system.
Failure mode 5: the model or integration changes silently
A vendor may update a model, prompt, subprocessor, user interface, or integration without calling it a new product. Output quality and regulatory analysis can change even when the product name stays the same.
Control: contract for change notice and traceability. Record versions at the time of use. Run regression tests after material changes and keep rollback and export tested.
Failure mode 6: shadow AI bypasses every formal control
An employee can use an unapproved chatbot, transcription app, or browser extension because the approved route is slow or unclear. The organization may discover the tool only after a complaint or breach.
Control: publish an approved-tool pathway, make prohibited uses specific, train with realistic examples, monitor access where lawful, provide a rapid evaluation route, and include AI services in incident-response playbooks.
A 90-day implementation plan
The goal is not to create a binder called “AI policy.” It is to make each live function traceable from legal status to workflow evidence.
Days 1 to 30: inventory and classify
- Find AI functions in purchased software, EHR modules, pilots, free accounts, browser extensions, research tools, and patient apps.
- Record version, owner, user, intended use, data, output, locations, vendor, and current status.
- Stop unapproved use involving patient information while it is assessed.
- Classify medical-device, privacy, certified-health-IT, state, provincial, and professional layers.
- Mark every source as in force, final guidance, proposed, upcoming, voluntary, or archived.
Days 31 to 60: prove evidence and controls
- Build the claim-to-evidence ledger.
- Review contracts, subprocessors, training rights, retention, deletion, change notice, incidents, export, and exit.
- Write the human-review and fallback workflow.
- Define acceptance thresholds for clinically material errors, failed inputs, correction burden, latency, subgroup results, alert volume, and privacy events.
- Test representative and adversarial cases before users rely on the output.
Days 61 to 90: approve, monitor, and prepare for change
- Approve a narrow scope with named owners and stop criteria.
- Train users on the tool's limits, disclosure duties, correction workflow, and prohibited uses.
- Capture version and configuration evidence.
- Monitor corrections, overrides, incidents, complaints, drift, and workflow burden.
- Set a quarterly primary-source review and event-driven review after a law, guidance, enforcement action, incident, or product change.
Governance control check
Can the team prove operational readiness?
Progress stays in this browser session. The checklist does not collect patient or product data.
How to keep the tracker current
Healthcare AI regulation news moves quickly, but speed does not excuse weak sourcing. Use a source hierarchy:
- enacted statutory or regulatory text and official effective dates;
- regulator decisions, final guidance, enforcement, and official databases;
- proposed-rule and legislative records;
- professional-college or privacy-regulator guidance for the applicable jurisdiction;
- peer-reviewed evidence for performance and human factors;
- vendor documentation for product-specific facts;
- news or commentary as a pointer to a primary source, not the final authority.
For every change, record the previous status, new status, source, effective date, affected functions, owner, decision, and implementation deadline. Keep the evidence snapshot that supported the decision. A link alone can change over time.
Watch items for the rest of 2026
- FDA feedback and any follow-up to the August 2026 GenAI-enabled medical-device discussion paper; comments are due October 19, 2026.
- HHS action on the proposed HIPAA Security Rule changes while the current rule remains effective.
- Implementation and enforcement of state healthcare AI duties, including the 2026 Colorado, Louisiana, and Rhode Island requirements.
- Preparation for Colorado HB 26-1139's January 1, 2027 effective date.
- Health Canada implementation experience under the April 2026 MLMD guidance.
- Bill S-5's House of Commons progress and any new Canadian federal AI legislation, without assuming archived AIDA language will return unchanged.
- Provincial privacy-regulator and professional-college guidance on AI scribes and clinical decision support.
- Product changes that alter intended use, output, data sharing, training, or reviewer workload.
The practical standard for 2026
A defensible healthcare AI program can answer five questions without relying on a vendor slogan:
- What exact function is live, and which version produced the output?
- Which current requirements and guidance apply in this jurisdiction?
- What independent and product-specific evidence supports the intended use?
- How can a qualified person detect, correct, reject, and escalate a failure?
- What evidence would trigger a pause, rollback, regulatory reassessment, or exit?
The central 2026 lesson is straightforward. Regulation follows the clinical function, data, decision, user, and location. Teams that keep those elements visible can adapt when the law or product changes. Teams that reduce governance to “AI approved” cannot.
For a wider evidence and implementation framework, see Medical AI: Use Cases, Risks, Evidence, and Implementation and AI in Healthcare: Use Cases, Risks, Evidence, and Implementation. For data-access and patient communication controls, use the patient portal guide and HIPAA forms routing checklist.
Plain-language answers
Frequently asked questions about healthcare AI regulation
Current answers about FDA, Health Canada, HIPAA, ONC, state and provincial requirements, human oversight, vendor evidence, and 2026 implementation dates.
What is healthcare AI regulation?
Healthcare AI regulation is the set of medical-device, privacy, security, professional, health-IT, consumer-protection, and jurisdiction-specific rules that apply to an AI function. The applicable requirements depend on what the system does, which data it uses, who relies on it, and where it operates.
Where can I find current healthcare AI regulation news?
Start with primary sources: FDA, HHS, FTC, ONC, NIST, Health Canada, the Office of the Privacy Commissioner of Canada, provincial privacy regulators, and official state or provincial legislatures. Record whether each item is binding law, final guidance, a proposal, or a voluntary framework.
Is there one federal healthcare AI law in the United States?
No. U.S. healthcare AI oversight is layered. FDA may regulate a medical-device function; HHS rules protect regulated health information; ONC rules apply to specified certified health IT; the FTC covers certain consumer and health-app practices; and state laws can add disclosure or review duties.
How does FDA regulate AI in healthcare?
FDA regulates AI when the software function meets the medical-device definition and is not excluded from it. The intended use and actual function matter. FDA authorization supports the specific reviewed function and conditions, not every feature or every future model version from the same vendor.
What changed in FDA clinical decision support guidance in 2026?
FDA issued final Clinical Decision Support Software guidance on January 29, 2026. Separately, on August 18, FDA published a non-binding discussion paper and requested feedback on GenAI-enabled medical devices. The paper is not final guidance, a proposed rule, authorization, or a binding requirement.
Does FDA authorization prove that a healthcare AI tool will work in my clinic?
No. Authorization is important evidence for a specific intended use, product, and regulatory pathway. Local workflow, patient mix, equipment, language, prevalence, integrations, thresholds, and reviewer behaviour can change performance. A clinic still needs fit-for-purpose acceptance testing and monitoring.
Does HIPAA regulate artificial intelligence?
HIPAA does not create a separate AI category. Its Privacy, Security, and Breach Notification requirements apply when covered entities and business associates use or disclose protected health information through AI. The current Security Rule remains in effect while HHS considers proposed changes.
Can the FTC Health Breach Notification Rule apply to an AI health app?
Yes, depending on the product and data flows. The rule can cover certain personal health record vendors and related entities outside HIPAA. An AI health app that draws identifiable health information from multiple sources should evaluate coverage and prepare notification procedures before an incident.
What does ONC HTI-1 require for predictive decision support?
HTI-1 establishes transparency requirements for specified predictive decision support interventions in certified health IT. Users should be able to access source attributes and risk-management information. The rule does not make every predictive model safe or clinically appropriate; it improves the information available for evaluation.
Which U.S. state healthcare AI laws matter in 2026?
Selected examples include California clinical-communication and utilization-review requirements, Texas disclosure and practitioner-review provisions, Colorado psychotherapy restrictions, Louisiana disclosure before AI transcription, and Rhode Island notice and accuracy review for AI visit documentation. This tracker is curated, not a complete 50-state inventory.
What does California AB 3030 require?
AB 3030 requires specified healthcare communications generated by generative AI to disclose that fact and explain how a patient can reach a human, unless the communication was reviewed by a licensed or certified healthcare provider. The exact statutory scope and exceptions should be checked for the workflow.
What does Texas HB 149 mean for healthcare providers?
Texas HB 149 includes an AI disclosure requirement for healthcare service providers using AI in relation to healthcare services, effective January 1, 2026. Providers should determine which uses are covered and retain evidence that the required disclosure was delivered through the actual patient workflow.
Is Colorado HB 26-1139 already in force?
No. The healthcare utilization-review requirements in Colorado HB 26-1139 are scheduled to take effect January 1, 2027. It belongs in a 2026 implementation watchlist, not in a list of current obligations.
Is there one healthcare AI law in Canada?
No. Canada applies existing medical-device, privacy, consumer, professional, contractual, and provincial health-information rules to AI. Health Canada regulates qualifying medical-device functions, while privacy obligations vary by organization, sector, province, and the data involved.
Is Canada’s Artificial Intelligence and Data Act in force?
No. AIDA was proposed in Bill C-27 during the 44th Parliament but did not become an in-force general AI law. Its government information page is archived. Healthcare organizations should not cite AIDA as current law and should continue applying existing requirements.
What did Health Canada publish for machine learning-enabled medical devices in 2026?
Health Canada published pre-market guidance on April 1, 2026. It covers topics including data, testing, clinical validation, transparency, post-market monitoring, and predetermined change control plans. It is regulator guidance for ML-enabled medical devices, not a rule for every administrative AI tool.
What do Ontario and British Columbia say about AI scribes?
Ontario and British Columbia privacy regulators published AI-scribe guidance in January 2026. Their jurisdictional scope differs, but both emphasize approved use, necessity, transparent patient communication, vendor and data-flow review, accuracy, human verification, safeguards, and accountable governance.
What is meaningful human oversight for healthcare AI?
Meaningful oversight gives a qualified person the source information, time, competence, authority, interface, and fallback needed to detect and act on an error. A name on a workflow or a final click is not enough when the reviewer cannot independently assess the output.
How should a clinic evaluate healthcare AI vendor claims?
Match each claim to evidence for the same product version, intended use, population, setting, comparator, and endpoint. Separate regulatory authorization, technical benchmarks, independent validation, prospective workflow studies, patient outcomes, and vendor testimonials. Record funding, conflicts, limitations, and local test results.
How often should a healthcare AI regulation tracker be updated?
High-risk programs should monitor primary sources continuously and perform a documented review at least quarterly, plus event-driven review after a new law, guidance, enforcement action, product change, incident, or expansion into a new jurisdiction. Vero last verified this curated set on August 27, 2026.