Your healthcare malpractice policy may no longer cover AI.
If your carrier writes an AI exclusion, it can deny claims involving AI. As of January 2026, a pre-drafted exclusion is available to every malpractice insurer in the country — ready to add to your policy, and major carriers have already adopted it.
AI Governance Shield™ certifies your practice against the framework’s controls across seven governance domains — assessed, scored, and signed off by a person, not a checkbox. The documented evidence your carrier, your attorney, and your regulator will ask for.
"You can't opt out of AI. You can only choose whether you govern it — or get governed by it."
Federation of State Medical Boards — May 2024 Guidance
AI Governance Is Now a Certifiable Discipline.
Ours Is Built for You.
In June 2026, the Joint Commission launched an AI governance certification aimed at health systems. If you run a medical practice, a behavioral health practice, or an assisted living community, here is the certification built for organizations your size — and what makes it different.
A Standard-Form AI Exclusion Now Exists — and Any Carrier Can Add It to Your Policy.
In January 2026, the organization that writes the standard policy language used by most U.S. insurers quietly issued a pre-written AI exclusion — a one-page add-on any carrier can attach to your policy at renewal. If yours includes one, an AI-related claim gets denied — and you bear the full cost. This has nothing to do with state law. It's a coverage decision your carrier can make at any renewal.
These Apply to AI Now.
Fines end. Lawsuits settle. A board action follows you for life.
The Profession Has Spoken.
Both Sides Are Exposed.
It's not just your carrier. Medical boards, accreditors, and professional bodies have established that ungoverned AI use falls below the standard of care — and that failing to adopt beneficial AI is equally negligent.
Your Cascade of Liability
You use AI
Scribe, EHR, Chatbot
AI is already in your practice
Carrier exclusion
AI Exclusion
When exclusion fires, you pay everything
State enforcement
$5K–$200K
Stacked across patients and statutes
Plaintiff exposure
Class-action risk
Pattern-of-use across your patient panel
License exposure
Board Action
Letter to suspension, per FSMB
Certified
Chain Broken
Reasonable care, documented
The Laws Are Here.
The Lawsuits Have Started.
Beyond the insurance cliff and the evolving standard of care, 21 states enacted 33 provider-facing AI laws in 2025, with 47 states introducing healthcare AI bills — and every one of them applies to practices outside their borders.
Telehealth Multiplies Your
Regulatory Exposure
The practice of medicine occurs where the patient is physically located during the encounter — not where your office is. 71% of physicians now use telehealth weekly (AMA, 2024). Each cross-state visit can trigger the AI law of the patient's state.
AI Scribes Can Make Errors and Inflate Codes.
The DOJ Noticed.
This is why your carrier is running.
DOJ Formed a Working Group Targeting AI-Driven EHR Manipulation. CMS Is Using AI to Scan Your Claims.
AI documentation inaccuracies meet the False Claims Act’s “reckless disregard” standard. They’re using AI to catch your AI. If your codes were inflated, they’re already looking.
AI code inflation
AI/EHR fraud named priority
CMS CRUSH · Feb 2026
DOJ enforcement priority
The billing patterns are.
The Penalties Stack.
Across Every Jurisdiction.
When your carrier won't cover you, the standard of care exposes you, and the state fines you — the numbers add up fast. Certification is the documented evidence that you took this seriously before any of it hit.
Saucedo v. Sharp HealthCare — First AI Scribe Class Action (Nov 2025)
AI scribe recorded doctor-patient conversations without informed consent, transmitted audio to third-party cloud. Class certification sought for every California patient recorded since April 2025. Every ambient AI scribe — Abridge, DAX, Suki, Freed — carries the same risk.
Update (Apr 2026): a second putative class action followed against Sutter Health and MemorialCare over the same Abridge scribe (N.D. Cal.) — alleging California CMIA, CIPA, and the Federal Wiretap Act. One case has become a pattern.
Your AI scribe could be a crime in about a dozen states
About a dozen states are all-party-consent states — every person has to agree before a conversation is recorded. An ambient scribe records the visit, so without specific patient consent you've crossed that line. And in some of those states it's a crime: in Florida, for example, recording without consent can be a third-degree felony (Fla. Stat. § 934.03). The liability lands on the practice — not the vendor.
The law rewards governance: California exempts AI-generated patient communications from its AI-disclaimer mandate when a licensed provider reviews them (Cal. Health & Safety Code § 1339.75).
Consent, provider review, and a BAA defend the tool — but only if you can prove them when a patient, regulator, or carrier asks. An AI Governance Shield™ certification is exactly that proof — a documented, independently verified record of your governance.
See article →Neither should you.
Every bar is a single event.
In addition to the penalties, exclusions, and enforcement actions above — here is what one incident actually costs.
Certification costs a fraction of a single AI-related claim, fine, or coverage exclusion.
Each scenario uses enacted law, published data, or documented market behavior. None are hypothetical.
How Certification Works
No site visits. No IT integration. Minimal disruption to your practice.
Engage
Complete the wizard intake. Structured questions across your governance posture. Supporting documents requested only when needed — most practices upload 3–5, not their entire policy binder.
Assess
Independent scoring across your full governance posture.
Certify
Certification report, governance policies, and implementation tools your carrier, payer, or attorney can rely on.
More than a report. A defensible position.
Every certification delivers the documentation your carrier evaluates at renewal, defense counsel can draw on if your governance is challenged, and you can present to regulators as evidence of good-faith compliance posture.
What Practice Owners Ask Us
The questions we hear most — and the answers that change the conversation.
First, your carrier moved. As of January 2026, standard-form AI exclusion endorsements are available to every malpractice insurer in the country. W.R. Berkley, Hamilton Select, and Philadelphia Indemnity have already adopted them. These exclusions cover AI scribes, EHR algorithms, scheduling chatbots — any AI tool touching patient care. If your policy has one, an AI-related claim gets denied. You bear the full cost.
Second, the laws are already enforceable. Texas TRAIGA carries $200,000 per uncurable violation. Illinois enacted two AI laws — the IHRA AI Amendment (employment discrimination, eff. Jan 2026) and the WOPR Act (HB 1806, $10,000 per violation for AI in therapy without licensed oversight, eff. Aug 2025). Colorado has three AI statutes touching healthcare: SB 26-189 (general AI Act, effective Jan 1, 2027, exempts most HIPAA-covered clinical AI use), HB 26-1139 (AI in health insurance coverage decisions, effective Jan 1, 2027), and HB 26-1195 (AI in psychotherapy, effective Aug 12, 2026). For most general practices Colorado is a monitor-not-trigger; for behavioral health practices HB 26-1195 is directly applicable. If you conduct telehealth follow-ups with patients who have returned to any of these states — and in Florida, with its snowbird population, you almost certainly do — those states\' laws apply to those encounters. Globally, the EU AI Act now classifies healthcare AI as high-risk and requires conformity assessments — U.S. states are building on that model.
Third, the standard of care shifted. The Federation of State Medical Boards established that physicians are liable for AI errors just as for any diagnostic tool — and went further: both reckless use and failure to use beneficial AI can fall below the standard of care. You cannot opt out. You can only govern it or remain exposed on both sides.
Independent third-party certification is the documented evidence that you govern AI properly. It's what carriers evaluate at renewal, what defense counsel can draw on if your governance is challenged, and what you can present to regulators as evidence of good-faith compliance posture. Self-attestation carries zero evidentiary weight. Certification does.
But even if you negotiated the most favorable vendor agreement possible — full indemnification, accuracy guarantees, mandatory model update notifications — that only governs your relationship with the vendor. It does nothing for your liability to patients under malpractice law, to payers under the False Claims Act, to regulators under state AI laws, or to carriers under your insurance policy. Better vendor terms might give you a contribution claim against the vendor after you've already been sued — but they don't prevent the lawsuit, the regulatory fine, the payer recoupment, or the insurance denial.
Contracts are between you and your vendor. Governance is between you and everyone else — patients, payers, regulators, carriers. Our certification optionally includes a vendor governance assessment that identifies where your agreement leaves you exposed.
This is not hypothetical. 71% of physicians now use telehealth weekly (AMA, 2024). If you conduct telehealth follow-ups with patients who have returned to states with enacted AI laws, those laws apply to those visits. Each cross-state telehealth encounter potentially triggers disclosure requirements, documentation obligations, and penalty exposure in the patient's state. As more states enact AI laws (47 states have introduced bills, 17 enacted in 2025 and counting), the compliance footprint for every telehealth-enabled practice expands with every out-of-state follow-up.
17 states have already enacted AI healthcare laws. Texas TRAIGA is in effect. Colorado has three AI statutes touching healthcare — SB 26-189 (general AI Act with broad HIPAA carveout), HB 26-1139 (health-insurance utilization review), and HB 26-1195 (psychotherapy AI). Illinois, California, New York — all enforceable. These laws don't pause because Washington is drafting a framework. Your practice is subject to them today, through every telehealth visit that crosses state lines.
The federal executive order signed in December 2025 signals intent to establish a national AI standard — but an executive order does not preempt state law. Only Congress can do that through legislation, and the current legislative draft still requires governance obligations, risk assessments, and duty of care for high-risk AI in healthcare. The question isn't whether governance will be required — it's whether the framework is state, federal, or both.
Meanwhile, your malpractice carrier isn't waiting. Carrier exclusion decisions are private market decisions that no federal framework changes. The DOJ False Claims Act applies regardless. Common law negligence applies regardless. The standard of care applies regardless. None of these depend on AI-specific statutes.
Practices that certify now are governed before any mandate — state or federal — requires it. When the framework arrives, you're already compliant. Practices that wait will certify under pressure, at higher cost, with less favorable terms.
In the past 12 months alone: multiple states passed new AI transparency and liability laws, CMS updated billing guidance for AI-assisted documentation, the ONC finalized new rules on AI in health IT, and major malpractice carriers introduced AI-specific exclusion endorsements. A certification based on last year's regulatory landscape does not protect you from this year's enforcement actions.
The parallel is HIPAA Security Risk Assessments — HHS recommends annual reviews, and OCR has fined practices for stale assessments. AI governance moves faster than HIPAA ever did. A two-year-old governance framework would miss entire categories of risk that didn't exist when it was written.
Annual recertification ensures your practice stays current with the law — not just current with the technology. Each renewal is a full reassessment against the current year's legal landscape. The governance foundation you've built carries forward — but the laws it's measured against are re-verified from scratch, because that's what makes the certification worth relying on.
Most practices have items requiring remediation on their first assessment — that's the entire point of an independent evaluation. If your practice doesn't meet the criteria for full certification, you receive a Conditional outcome: an AI Governance Shield™ Gap Assessment & Remediation Roadmap that lists each finding with required remediation and a 30 / 60 / 90-day timeline.
Here's the key: one re-assessment is included at no additional cost. You complete the remediation items at your own pace, we re-review, and if you meet the criteria, you're certified. You will have a defined remediation window to complete the work while your assessment stays current. Within that window, a re-review is included; beyond it, a fresh engagement applies.
The Gap Assessment itself is a valuable deliverable. It tells you exactly where governance stands, what to address, and the operative authority behind each item. None of the findings represent a finding of failure — they represent a defined and closeable list. The goal is certification — the assessment just gets you there safely.
What may not apply (only if your practice receives no federal financial assistance — no Medicare, no Medicaid, no TRICARE, no FEHB, no ACA marketplace billing, no HHS grant funding):
- HHS Section 1557 § 92.210 algorithmic-discrimination obligations
- OIG and Medicare Advantage coding-fraud scrutiny
- 21st Century Cures Act ONC Information Blocking (only triggers with certified EHR use)
What still applies — universally, regardless of payer mix:
- HIPAA Privacy, Security, and Breach Notification Rules
- Every state AI healthcare law in your operating jurisdictions (TX HB 149, CA AB 3030/489, CO HB 26-1195 + HB 26-1139, TN SB 1580, IL WOPR, and the rest) — these reach providers based on where you practice, not how you get paid
- FTC Act § 5 truth-in-AI obligations
- State medical board AI guidance
- 42 CFR Part 2, if any patient is treated for substance use disorder
Why concierge practices certify anyway:
- Malpractice carrier renewals. Coverys, MAG Mutual, MedMal Direct and others increasingly request AI governance documentation regardless of payer mix
- Patient trust. Concierge patients are sophisticated. They ask. Certification is a clean answer
- Practice sale or affiliation. Buyers and concierge networks (MDVIP, SignatureMD, equity-backed groups) require governance documentation in due diligence
- State law obligations are unchanged by payer model
- Future-proofing if the practice ever adds Medicare, joins a federally-funded program, or merges into a covered entity
How the engagement adapts: the scope statement explicitly notes the payer model. Domain 6 (Insurance & Coding Defensibility) is reviewed at reduced scope — focused on patient-facing financial disclosure and direct-pay medical-necessity documentation rather than CMS billing posture. Domains 1–5 are evaluated in full because they're triggered by clinical AI use, not by payer model. Same certificate, scope-adjusted report.
Every engagement — whether it ends in certification, conditional pass, or non-certification — is governed by the confidentiality terms of the engagement letter. Sentinel Risk Group does not disclose the existence or outcome of any assessment to third parties absent your written authorization or valid legal process.
If you achieve certification, your practice is listed in the public Certification Directory at sentinelriskgrp.com. The Directory listing is limited to: practice name, city, state, certification reference number, certification dates, and current status. Findings, scores, gap analyses, and remediation recommendations are never published. The Directory is the verification tool insurers, regulators, and patients use to confirm certified status. You may opt out of public listing in writing at any time.
If you do not achieve certification — including conditional pass, unable to certify, or engagements closed without issuance — your practice is never publicly identified in any Sentinel Risk Group communication. The outcome is yours; we do not advertise it, infer it, or list you as having taken the assessment. The engagement closes confidentially.
Our assessment methodology and supporting materials are proprietary and protected as trade secrets under the Florida Uniform Trade Secrets Act. Sentinel responds to legal process only after providing reasonable advance notice to allow you to seek a protective order.
What we are not, in plain terms:
- Not a law firm. We do not provide legal advice. Engagement summaries, regulatory mappings, and findings are governance guidance, not legal counsel. Practices should consult qualified attorneys for legal questions.
- Not an insurance company. We do not underwrite policies, settle claims, or provide insurance coverage. We evaluate AI exclusion exposure in your existing malpractice and cyber policies; we do not provide the policies themselves.
- Not a healthcare provider. We do not provide clinical care, diagnose patients, or make treatment recommendations. The AI Governance Shield™ assessment evaluates governance posture; it is not clinical guidance.
- Not a government regulatory authority. We are not affiliated with HHS, OIG, FDA, CMS, the FTC, state medical boards, or any federal or state agency. AI Governance Shield™ certification is not a regulatory ruling and confers no governmental status.
- Does not certify HIPAA, FDA, or state-law compliance. AI Governance Shield™ certification is an independent governance evaluation against our published Framework. It is not a HIPAA compliance audit, an FDA premarket review, a state-board determination, or any other regulatory certification. Compliance with HIPAA, state AI laws, FDA regulation, and other authorities remains the Practice's responsibility.
- No PHI collected. Our intake and evidence workflows are engineered so Protected Health Information (PHI) does not flow to Sentinel in the ordinary course of the Services. See Master Terms § H.8 for details.
What we do: evaluate governance across seven structured domains, deliver a written assessment with findings + remediation roadmap, and issue a certification outcome (Certified / Conditional / Not Certifiable). See Master Terms for full scope.
Assessment Packages
Certify your practice — priced to your practice size.
One certification covering your AI systems, jurisdictional scope, and regulatory risk — governance policies and staff training included.
Independent Evaluation Authority
Sentinel Risk Group is an independent governance evaluation firm with no vendor affiliations, no product endorsements, and a rigorous independence screening process.
Led by a healthcare attorney with over 20 years of in-house experience across hospital systems, medical groups, specialty practices, and managed care organizations — spanning compliance program design, risk management, regulatory affairs, and health information governance. Our assessment methodology draws on direct experience navigating the complex regulatory frameworks we evaluate against.
Our extended team includes a clinical expert witness and practicing physician who reviews AI workflow integration from the provider's perspective, enterprise consulting alumni who bring institutional-grade audit methodology, and health IT specialists who evaluate the technical architecture of AI systems in clinical environments. Certification decisions are evidence-based and methodology-driven. We certify governance structure — not technology.