Plain-English modules on the laws behind healthcare AI — what the rules actually say, how AI tools intersect them, and what regulators look at. Self-paced, built for practice owners and managers. A growing library across three tracks — healthcare, behavioral health, and assisted living — with new modules added regularly.
More than the training bundled with certification. These are topic-deep courses you and your staff can take anytime — certified or not — each ending in a downloadable Certificate of Completion you keep on file. A way to start showing training and compliance today and build the record before you certify.
The full statute, worked: the five elements, SuperValu and Escobar, the 60-day clock — plus the arithmetic showing how a $40-per-claim error becomes $72M, and the FY2025 enforcement data (record $6.8B, 84% healthcare, 1,297 whistleblower suits).
One-party vs. all-party consent, the wiretap/eavesdropping class-action wave against ambient scribes, and written vs. verbal patient recording consent.
When an AI tool is a Business Associate, training-on-PHI limits, subprocessors and data residency, and the risk of staff pasting PHI into consumer chatbots.
Why percentage-of-collections and per-claim AI vendor fees collide with the AKS, the "one purpose" test, and how flat fees + FMV documentation defend you.
How federal nondiscrimination law now reaches clinical AI and decision-support tools — the protected bases, and your duty to identify and mitigate.
The patient-location rule that decides everything, how consent and disclosure laws stack across states, and where prescribing and DEA rules land in 2026.
Who's liable when CDS gets it wrong, the dual-liability squeeze (over-reliance vs. under-use), the learned-intermediary doctrine, and documenting your judgment.
When an AI scribe or summarizer fabricates, inserts, or distorts what's in the chart: accuracy duties, who owns the error once you sign, record-integrity, and the billing and malpractice exposure that follows.
The FTC's "AI washing" crackdown, the substantiation standard, puffery vs. claims you must prove, and the trap of quiet AI where patients expect a human.
The capstone: the six pillars of a program you can defend, the NIST AI RMF backbone, and why independent certification (SRG or another body) turns "we have policies" into proof.
How AI chart-review tools inflate risk scores, the "one-way review" trap, the MEAT documentation standard, RADV audits scaling with their own AI, and why unsupported AI-surfaced codes are a False Claims Act risk.
How ambient AI can turn a patient recording into a regulated voiceprint, how BIPA's consent-and-destruction rules and private right of action actually work (with the 2024–2026 changes), and how one AI scribe can trip BIPA, Texas CUBI, and HIPAA at once.
The new ways AI leaks PHI — staff pasting charts into public chatbots, prompts and outputs stored by vendors, a breached AI subprocessor — and when those leaks become a reportable breach that runs the notification clock to you.
The terms that actually shift risk — model-change notice, AI-specific indemnity, liability-cap carve-outs, data residency, and "no training on our data."
The end of "silent AI," where new exclusions hide, the renewal questions underwriters now ask, and how your governance program becomes an insurability asset.
When an AI tool is a regulated device vs. exempt CDS, the Cures Act's four criteria, the PCCP for AI updates, and why "we just use a vendor" isn't the whole answer.
How payers use AI to deny (nH Predict, PxDx), what CMS and state law now require, how to fight a non-compliant denial, and using AI responsibly in your own UM.
The growing set of state AI-in-healthcare disclosure duties — TX TRAIGA, CA AB 3030 & AB 489, Colorado, Utah — and why multi-state and telehealth practices face layered, sometimes conflicting obligations.
The pixel litigation wave, worked: what trackers actually send, what survived the 2024 OCR vacatur, the wiretap and pen-register theories behind the eight-figure settlements, the FTC's GoodRx/BetterHelp lane, state consumer-health-data laws — and the seven-part defensible posture, with a printable audit checklist.
Why substance-use-disorder records carry stricter consent than HIPAA — the courtroom-use shield, the 2024 rule now in force (Feb 2026), and how AI blending quietly destroys the protection.
Recording psychotherapy with ambient AI — revocable consent and the instant pause, the chilling effect on disclosure, third parties who can't consent, and why the clinician (not the AI) must catch crisis content.
HIPAA's strongest protection has a fragile hinge — the notes must be kept separate from the record. AI scribes file into the chart by design. How you lose the shield without ever deciding to.
The one domain where states banned an AI use outright. Illinois's WOPR Act, Nevada's AB 406, Utah's HB 452 — the three regulatory models, and the administrative-vs-therapeutic line every BH practice must respect.
The camera statutes let families watch staff — they don't authorize you to watch residents. Capacity, surrogates and assent, the least-restrictive ladder, and why audio is the sleeper risk.
The scope-of-practice line AI can erase for unlicensed med aides — and the acuity tool that creates a permanent, timestamped record of exactly what you knew about staffing.
Install AI and you install a witness. It sees (notice + mandatory reporting), it remembers (discoverable — and spoliation if it auto-deletes), and it promises (a safety claim you must substantiate and keep).
Your training opens from a personal link — no password. Lost it? Enter the email you bought with and we'll send it again.