Regulation is coming to healthcare AI. In several states it has already arrived. The companies that build for compliance now will be the ones still standing when it is mandatory.

Healthcare AI is entering its regulatory era. HIPAA’s audit-control requirements already apply to every system that touches protected health information. ONC’s decision-support transparency and governance criteria already apply to certified health IT. California requires disclosure of generative-AI patient communications today. Texas requires practitioner review and patient disclosure of AI-created diagnostic records today. Beginning January 1, 2027, Colorado requires developers and deployers of automated decision-making technology in healthcare to retain the records that prove compliance for at least three years, and more than a dozen other states are considering similar audit requirements. The FDA issued its final clinical decision support guidance in January 2026, and the EU AI Act makes logging and traceability a legal design requirement. The direction is not in doubt. Only the timetable is.

CONTINUE READING