Legal Updates · Reference

AI Healthcare Laws: State-by-State Tracker

A plain-English reference to the enacted and pending laws governing AI use in healthcare — what each one does, when it takes effect, and who enforces it. Because of telehealth, the law that applies to an encounter is generally the law of the state where the patient is physically located.

Facts on this page were verified against primary and secondary sources between July 7 and July 17, 2026, and are reviewed on a recurring weekly schedule.

Educational information only — not legal advice. Sentinel Risk Group is not a law firm and does not provide legal advice or legal opinions. This page summarizes publicly available statutes and regulatory materials for general governance education. Laws change frequently; confirm current requirements with qualified legal counsel in your jurisdiction.

The map at a glance

Hover any state. Colors reflect the entries on this page — re-verified weekly.
AlaskaAlabamaArkansasArizonaCalifornia — AI healthcare law in forceColorado — Enacted — taking effectConnecticutWashington, DCDelawareFlorida — AI healthcare law in forceGeorgiaHawaiiIowaIdaho — Enacted — taking effectIllinois — AI healthcare law in forceIndianaKansasKentuckyLouisianaMassachusettsMarylandMaine — AI healthcare law in forceMichiganMinnesotaMissouri — Enacted — taking effectMississippiMontanaNorth CarolinaNorth DakotaNebraska — Enacted — taking effectNew HampshireNew JerseyNew MexicoNevada — AI healthcare law in forceNew York — Pending — not law yetOhioOklahomaOregonPennsylvaniaRhode Island — Enacted — taking effectSouth CarolinaSouth DakotaTennessee — AI healthcare law in forceTexas — AI healthcare law in forceUtah — AI healthcare law in forceVirginiaVermont — Enacted — taking effectWashingtonWisconsinWest VirginiaWyoming
In force Enacted — taking effect Pending — not law yet No entry on this page
Federal rules (HIPAA, Section 1557, FDA) apply in every state regardless of color. Telehealth note: the law that applies is generally the patient’s state.

Federal framework

These apply nationwide, regardless of state law.
Partial non-enforcement

HHS Section 1557 — Patient Care Decision Support Tools (45 CFR § 92.210)

Federal · Rule effective May 1, 2025 · Enforced by HHS OCR · Private right of action exists under § 1557

Nondiscrimination rules for health programs receiving federal financial assistance. The § 92.210(b)–(c) duty — make reasonable efforts to identify and mitigate discrimination risk from patient-care decision-support tools, including AI — took effect May 1, 2025.

Current posture: HHS OCR announced on May 13, 2025 that it is not currently enforcing § 92.210(b)–(c). Non-enforcement is not repeal: the rule remains in the CFR, the general § 1557 nondiscrimination duty and its private right of action remain, and parallel state-law duties are unaffected.

In force

HIPAA — Privacy, Security & Breach Notification Rules

Federal · Enforced by HHS OCR

Not AI-specific, but HIPAA governs all protected health information processed by AI tools. A Business Associate Agreement is required before any vendor — including an AI vendor — processes PHI, and the Security Rule risk analysis must cover AI systems.

In force

42 CFR Part 2 — Substance Use Disorder Records

Federal · Revised final rule effective April 16, 2024 · Enforcement aligned to HIPAA

Where an AI vendor processes Part 2 substance-use-disorder records, a Qualified Service Organization Agreement and the required consents apply.

In force

FDA — Software as a Medical Device (SaMD)

Federal · Enforced by FDA

Diagnostic or therapeutic AI can be a regulated medical device. More than 1,350 AI-enabled devices have been authorized, and predetermined change control plan (PCCP) guidance governs post-clearance model updates.

Active posture

DOJ / CMS Health-Care-Fraud Enforcement (2026 National Takedown)

Federal · DOJ, HHS-OIG, CMS, state Medicaid Fraud Control Units

The 2026 National Health Care Fraud Takedown (announced June 2026) charged 455 defendants in connection with over $6.5 billion in alleged fraud. DOJ and CMS now use near-real-time data analytics to identify suspect billing and intercept payments — which means sloppy or undocumented AI-assisted coding and billing gets caught faster. AI billing is not itself a charged offense category; the documentation supporting each claim is what matters.

The insurance market

Not a statute — but for most practices this moves first.
In market

ISO Standardized AI Exclusion Endorsements (CG 40 47 / CG 40 48)

Nationwide · Filed for 2026 policy renewals

Standardized AI exclusion endorsements entered the market for 2026 renewals, and major carriers filed through 2026. Malpractice and CGL policies may exclude AI-related claims absent documented governance — which makes documented AI governance a renewal conversation, not a hypothetical.

States with enacted AI healthcare laws

Listed by how directly they reach a healthcare practice. Telehealth note: these laws generally apply when the patient is physically located in the state during the encounter.
In force · Jan 1, 2026

Texas — TRAIGA (HB 149) and SB 1188

Enforced by the Texas Attorney General (TRAIGA) and the Texas Medical Board (SB 1188)

The Texas Responsible Artificial Intelligence Governance Act requires providers using AI in care or treatment to disclose it to patients and prohibits manipulative or discriminatory uses. Enforcement is by the Attorney General only, with tiered civil penalties up to $200,000 per uncurable violation; there is no private right of action. Companion law SB 1188 (effective September 1, 2025) requires disclosure of AI used in a diagnostic capacity and adds health-records data-location provisions.

Read the full Texas TRAIGA guide →

In force

California — AB 3030, AB 489, SB 1120

Enforced by licensing boards, DMHC / CDI

AB 3030 (effective January 1, 2025): practices using generative AI for patient clinical communications must include a disclaimer that the message was AI-generated plus instructions to reach a human provider — exempt when a licensed provider reviews the message first. AB 489 (effective January 1, 2026): AI systems and chatbots may not imply that care or advice comes from a licensed human — no licensed titles, license numbers, or clinical post-nominals; enforced through licensing boards as unlicensed-practice and discipline matters. SB 1120 (effective January 1, 2025): in health-plan utilization review, a licensed physician — not an algorithm alone — must make medical-necessity determinations.

Effective Aug 2026 – Jan 2027

Colorado — SB 26-189, HB 26-1195, HB 26-1139

Enforced by the Colorado AG, DORA licensing boards, and the CO Division of Insurance

Colorado repealed and reenacted its AI Act as SB 26-189 (signed May 14, 2026; effective January 1, 2027) — an automated-decision-technology disclosure-and-rights framework that largely exempts HIPAA-covered clinical AI use for providers operating from a Colorado location (the exemption has limits and does not cover employment-related AI decisions). The substantive healthcare obligations are HB 26-1195 (AI in psychotherapy; effective August 12, 2026) and HB 26-1139 (AI in health-insurance coverage decisions; effective January 1, 2027).

Read the full Colorado guide →

In force · Aug 4, 2025

Illinois — WOPR Act (HB 1806)

Enforced by IDFPR · Civil penalties up to $10,000 per violation

The Wellness and Oversight for Psychological Resources Act bars AI from providing therapy or making independent therapeutic decisions without oversight by a licensed professional.

In force · Jul 1, 2026

Tennessee — SB 1580 (Tenn. Code Ann. § 33-1-205)

Tennessee Consumer Protection Act · Private right of action · Up to $5,000 per violation, treble damages for willful violations

A developer or deployer may not advertise or represent an AI system as — or as able to act as — a qualified mental-health professional. Notable as the first behavioral-health AI law with a private right of action.

In force · Jul 1, 2025

Nevada — AB 406

Enforced by the Nevada AG and regulators

Prohibits representing AI as able to provide mental or behavioral-health care as a professional, with additional restrictions in school settings.

In force

Utah — AI Policy Act (SB 149) + HB 452

Enforced by the Utah Division of Consumer Protection / Office of AI Policy

Consumer-protection-style AI disclosure obligations (effective May 1, 2024), with HB 452 adding mental-health chatbot rules.

In force

Maine — LD 2082

Maine professional-licensing framework · Enacted April 2026

Licensed mental-health professionals may use AI only for administrative and limited supplementary tasks — AI may not be used for therapeutic communications, treatment decisions, or independent patient interaction. Patient consent is required before using ambient-listening or AI recording tools.

In force

Florida — § 934.03 (All-Party Recording Consent)

Criminal and civil exposure · Private right of action

Not an AI statute, but it reaches every ambient AI scribe: Florida requires all-party consent to record a conversation. An AI scribe records the encounter, so specific patient consent is required before it runs.

Watchlist — enacted-but-future and pending

Nothing below is a binding obligation today. Pending bills fail, change, and come back — this list is what we are tracking, not what is in force.
JurisdictionMeasureStatus
New YorkS7263/S7263A — AI chatbot impersonation of licensed professionalsPending — not passed. Advanced to third reading March 4, 2026; amended May 26, 2026; recommitted to the Senate Rules Committee June 5, 2026. Would bar chatbot impersonation of licensed professionals, with liability not disclaimable via an AI-disclosure notice, and AG civil penalties up to $15,000/day.
New YorkRAISE ActEnacted — frontier-model safety law, effective January 1, 2027. Not the chatbot-impersonation bill.
MissouriSB 1019 — behavioral-health AIEffective August 28, 2026 (signature verification in progress).
VermontAct 156 (H.816)Signed June 17, 2026, effective immediately; operative provisions under review.
Rhode IslandH 7349 / S 2197Enacted June 22, 2026; effective date to confirm.
IdahoSB 1297 — Conversational AI Safety ActEffective July 1, 2027.
NebraskaLB 525 — Conversational AI Safety ActEffective July 1, 2027.
Why this page stays accurate. Every legal fact above comes from a single verified fact file that also feeds our certification deliverables. It is re-verified against primary sources on a weekly schedule, and updates are reviewed by a licensed attorney before publication. If you spot something that has changed, use the Contact Us form below.
Know where your practice stands

See how these laws map to your practice in 7 questions.

Take the Free Risk Assessment → Questions? Contact us with any inquiries.