US Health Care AI Rules carries 14 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-09-09.
What are the duty tiers under US Health Care AI Rules?
Payer AI duties (coverage and utilization management) (42 CFR 422.101(c); Cal. SB 1120; state payer-AI statutes; CMS-0057-F)
Citation: 42 CFR 422.101(c); Cal. SB 1120; state payer-AI statutes; CMS-0057-F — https://www.cms.gov/newsroom/fact-sheets/cms-interoperability-and-prior-authorization-final-rule-cms-0057-f
AI may assist coverage decisions but may not decide them: federal Medicare Advantage rules and at least eleven state laws require individual-circumstance review by a licensed professional. The nH Predict and PxDx class actions show the litigation exposure.
Clinical AI duties (care delivery) (45 CFR §92.210; Cal. Health & Safety Code §1339.75 (AB 3030); Tex. SB 1188; Nev. AB 406 (2025); Iowa HB 475 (2026))
Citation: 45 CFR §92.210; Cal. Health & Safety Code §1339.75 (AB 3030); Tex. SB 1188; Nev. AB 406 (2025); Iowa HB 475 (2026) — https://www.federalregister.gov/documents/2024/05/06/2024-08711/nondiscrimination-in-health-programs-and-activities
AI touches patient care. Federal nondiscrimination and privacy rules apply nationwide; California, Texas, Iowa, and Nevada add disclosure, review, and practice-scope duties, and nine states restrict AI therapy.
Health-technology vendor AI duties (FDA Clinical Decision Support Software guidance (Jan. 2026); 45 CFR 170.315(b)(11) (HTI-1); Cal. AB 489)
Citation: FDA Clinical Decision Support Software guidance (Jan. 2026); 45 CFR 170.315(b)(11) (HTI-1); Cal. AB 489 — https://www.fda.gov/regulatory-information/search-fda-guidance-documents/clinical-decision-support-software
Your product sits at the FDA device boundary, inside the ONC certification program, or makes claims about clinical capability. Accuracy and licensure claims are enforced by the FTC, state attorneys general, and licensing boards.
Health-care baseline (HHS Strategic Plan for the Use of AI in Health, Human Services, and Public Health (Jan. 2025))
Citation: HHS Strategic Plan for the Use of AI in Health, Human Services, and Public Health (Jan. 2025) — https://www.hhs.gov/hipaa/for-professionals/index.html
You are a US health-care organization but reported no AI in care, coverage, or products. The governance baseline below still applies; re-screen when AI enters clinical, coverage, or patient-facing workflows.
What should you do about each obligation?
AI inventory and governance for clinical, coverage, and operational AI (45 CFR §92.210; HHS-OIG Medicare Advantage Compliance Program Guidance; DOJ Evaluation of Corporate Compliance Programs (Sept. 2024))
Keep an inventory of every AI and algorithmic tool used in care, coverage, coding, and operations with an owner, intended use, developer-provided risk information, and the data it uses; put a governance committee and written policy over adoption and monitoring; train staff; and document the evaluation process. This is the record Section 1557 compliance rests on, the HHS-OIG's Medicare Advantage compliance guidance flags AI in risk-adjustment and physician-query practices, and DOJ's False Claims Act working group (July 2025) lists EHR manipulation as a priority — the 2025 and 2026 health-care fraud takedowns included AI-fabricated beneficiary consent recordings.
Section 1557: identify decision-support tools using protected characteristics and mitigate discrimination risk (45 CFR §92.210 (89 FR 37522); HHS Notice of Vacatur, 91 FR (2 June 2026))
Make ongoing reasonable efforts to identify every patient-care decision-support tool that uses race, color, national origin, sex, age, or disability as an input, and for each make reasonable efforts to mitigate the risk of discrimination — an inventory, a governance process, documentation of the developer's risk information, customization records, and staff training. OCR weighs your size and resources, use as intended, and whether an evaluation process exists; each covered entity is independently responsible regardless of who built the tool. The gender-identity provisions of the 2024 rule were vacated in Tennessee v. Kennedy (S.D. Miss., 22 October 2025) and HHS confirmed on 2 June 2026 that the remaining provisions, including §92.210, stay in force. Agency enforcement appetite is low; private claims and state attorneys general can still rely on the rule.
HIPAA: business associate agreements, risk analysis, and no training on PHI without authorization (45 CFR Parts 160 and 164; HIPAA Security Rule NPRM, 90 FR 898 (6 Jan. 2025), not final)
Execute a business associate agreement with every AI vendor that touches PHI; apply the minimum-necessary standard to what each tool receives; add AI systems to the security risk analysis and asset inventory; forbid vendor training on PHI unless patients authorize it or the data is de-identified under §164.514; and block staff use of consumer AI tools with PHI. Vendors: you are a business associate with direct liability for the Security Rule and applicable Privacy Rule provisions. The January 2025 Security Rule proposal (asset inventory and network map, mandatory MFA and encryption, 72-hour restoration, annual audits, penetration testing) has not been finalized; the Unified Agenda targets July 2027 and OCR has signaled it may narrow the burdens. Texas SB 1188 separately requires electronic health records to be physically stored in the United States (since 1 January 2026).
Coverage decisions: individual circumstances, physician review, no AI-only denials, 2026 prior-authorization timelines (42 CFR 422.101(c), 422.566(d); CMS HPMS memo of 6 Feb. 2024; CMS-0057-F; state payer-AI statutes (CA, AZ, MD, NE, TX, IL, IN, WA, AL, UT, GA))
Base every medical-necessity determination on the member's individual clinical circumstances and Traditional Medicare coverage criteria where they exist; have a physician or appropriate professional review every denial; and never let an algorithm or prediction be the basis for a denial or a termination — CMS's February 2024 guidance says AI may assist but cannot decide. Since 1 January 2026, decide prior authorizations within 72 hours (expedited) or 7 calendar days (standard), give providers specific denial reasons, and publish annual metrics; FHIR prior-authorization APIs are due 1 January 2027. At least eleven states now require by statute that only a licensed physician or clinical peer make medical-necessity denials, bar sole reliance on AI, and add disclosure or reporting (California SB 1120 since 1 January 2025; Texas SB 815 since 1 September 2025; Maryland, Nebraska, Washington, Indiana, Alabama, Utah, Georgia, Arizona, Illinois on their own dates). The proposed CY2026 Medicare Advantage AI guardrail was dropped; the nH Predict class actions against UnitedHealth and Humana are in discovery with a March 2026 order compelling nine years of algorithm records.
California SB 1120: physicians make medical-necessity decisions; AI tools must use individual history and stay open to audit (Cal. Health & Safety Code §1367.01; Cal. Ins. Code §10123.135(j) (SB 1120, Stats. 2024 ch. 879))
Any AI or algorithmic tool used in utilization review must base determinations on the enrollee's individual clinical history and circumstances, not solely on group datasets; must not supplant provider judgment; may not deny, delay, or modify care on medical-necessity grounds — only a licensed physician or competent professional may; must be applied fairly and equitably; must not use patient data beyond its stated purpose; must be periodically reviewed for accuracy; must be disclosed in written utilization-management policies; and must be open to inspection by the Department of Managed Health Care or the Department of Insurance. The CDI's May 2025 guidance sets out what it will look for.
California AB 3030: disclaimer on AI-generated clinical communications unless a licensed provider reviews them (Cal. Health & Safety Code §1339.75 (AB 3030, Stats. 2024))
When a health facility, clinic, physician's office, or group practice uses generative AI to produce patient communications about clinical information, include a disclaimer that the message was generated by AI plus clear instructions on how to reach a human provider: at the start of written messages, throughout chat or video interactions, and verbally at the start and end of audio. The duty falls away if a licensed or certified health-care provider reads and reviews the communication before it is sent, and it does not apply to administrative messages about scheduling or billing. Licensing and facility regulators enforce.
California AB 489: no titles, terms, or design implying a licensed clinician (Cal. AB 489 (2025))
Remove from AI products any terms, letters, phrases, or design elements that imply the product holds a health-care license or that care is provided by a licensed professional ('Dr.', 'nurse', 'therapist', clinical credentials, white-coat avatars). California licensing boards may enforce and seek injunctions. The same theory underlies the Pennsylvania Attorney General's May 2026 suit against Character.AI over chatbots posing as licensed clinicians and the Nevada and Tennessee bans on representing AI as a mental-health professional.
Texas: review AI-generated records, disclose AI use in diagnosis and treatment, store EHRs in the US (Tex. SB 1188 (89R); Tex. Bus. & Com. Code §552.051(f) (TRAIGA, HB 149))
Practitioners may use AI for diagnosis or treatment recommendations only within their license scope, must review all AI-generated records consistent with Texas Medical Board standards, and must disclose to patients that AI is used in diagnosis (SB 1188, penalties up to $250,000, licensure action, and Attorney General injunctions). Under TRAIGA, give a clear and conspicuous written disclosure that AI is used in relation to the patient's care before or at the time of the interaction, or as soon as reasonably possible in an emergency (§552.051(f); Attorney General enforcement with a 60-day cure). Electronic health records must be physically stored in the United States since 1 January 2026.
Iowa: verbal disclosure before recording appointments for AI transcription (Iowa HB 475 (2026), signed 2 June 2026)
Before recording a patient encounter for AI transcription or note generation, tell the patient verbally that the appointment is being recorded and why, and document it. Pair this with your state's recording-consent law and HIPAA: the scribe vendor is a business associate, and the recording and transcript are PHI subject to retention and minimum-necessary rules.
Nevada AB 406: no AI delivering care directly; independent review of AI-generated notes (Nev. AB 406 (2025), NRS chs. 433 and 629 (new sections))
Licensed providers may not use AI to provide care directly to patients; AI may be used for administrative support only, and providers must independently review the accuracy of AI-generated records and notes. Violation is unprofessional conduct before the licensing board. The law also bars any AI provider from representing that a system can provide professional mental or behavioral health care (civil penalty up to $15,000 per violation) and bars schools from using AI to perform counselor or psychologist functions.
FDA: keep clinical decision support outside device regulation, or follow the device pathway (FDA, Clinical Decision Support Software — Guidance (Jan. 2026); FDCA §520(o)(1)(E); PCCP guidance (Dec. 2024))
To stay within the non-device clinical decision support criteria, give clinicians clear documentation of the data inputs, the underlying logic, and how recommendations are generated — in labeling, manuals, or in-product — so they can independently review the basis and overcome automation bias; the more the software is a black box, the more likely FDA treats it as a device. The January 2026 revision allows a single recommendation where it is the only clinically appropriate one and no longer excludes time-critical decisions outright, and it applies to AI including certain generative-AI features so long as clinicians can understand and verify the inputs and logic. Software that does not meet the criteria needs marketing authorization: use a predetermined change control plan for models that will be updated, follow the draft lifecycle guidance (still draft as of September 2026) for documentation, subgroup performance, and post-market monitoring, and avoid marketing diagnostic or screening claims without clearance — FDA warning letters in 2025 and 2026 targeted unauthorized AI screening and 'AI agent' claims.
ONC-certified health IT: decision-support source attributes and intervention risk management (HTI-1) (45 CFR 170.315(b)(11) (HTI-1 final rule, 89 FR 1192); HTI-5 proposed rule (90 FR, 29 Dec. 2025))
For certified health IT, enable configuration of and feedback on evidence-based and predictive decision-support interventions, make the required source attributes available to users (thirteen for evidence-based and thirty-one for predictive interventions, including intended use, populations, training data, and fairness and validity testing), and maintain and publicly summarize intervention risk-management practices. HTI-5 (December 2025) proposes to remove the 'AI model card' requirements and broaden information-blocking to automated access, but it has not been finalized; certification bodies advise keeping implementations in place. These attributes are also what providers need for their own Section 1557 tool assessments.
AI therapy and mental-health features: state bans, licensure, and representation limits (Nev. AB 406; Ill. P.A. 104-0054; Utah Code §13-72a; R.I. S 2197; Tenn. SB 1580; Vt. Act 156; Me. LD 2082; Colo. HB 26-1195; Mo. SB 1019)
Do not let AI provide therapy or psychotherapy, make independent therapeutic decisions, or be represented as a therapist, counselor, or mental-health professional in the nine states that restrict it; keep AI to administrative or supplementary roles under a licensed professional's oversight (Illinois), obtain written consent before AI use in recorded sessions (Rhode Island), and use self-help or administrative-support safe harbors where they exist (Nevada, Illinois). Utah's mental-health chatbot chapter adds disclosure, advertising, and data-sharing rules, and Tennessee's law carries a private right of action. Run the full state-by-state screen in the US Conversational AI pack; California SB 243 companion-chatbot duties sit in the California pack.
Substantiate clinical accuracy and hallucination-rate claims; document intended use and known misuses (FTC Act §5; Tex. Bus. & Com. Code ch. 17 (DTPA); Texas AG v. Pieces Technologies (AVC, 18 Sept. 2024))
Hold evidence for every accuracy, error-rate, or 'hallucination rate' claim and explain how the metric is defined and measured; give customers documentation of the model types and training data, intended use, required training, known misuses, and how to monitor accuracy after deployment. The Texas Attorney General's 2024 settlement with Pieces Technologies (a clinical-summarization LLM marketed with a 'less than one per 100,000' hallucination rate) required exactly that. Unauthorized diagnostic claims also draw FDA warning letters; SEC and FTC AI-washing enforcement applies to investor and consumer claims.