Skip to main content

Stanford Physician Advocate

Healthcare AI Governance Gains Regulatory Attention

Healthcare AI is becoming an increasingly important regulatory issue for California physicians as state laws establish new requirements around patient communications, professional representations, insurer utilization decisions, and clinical accountability. The state’s approach is not centered on a single comprehensive AI law for medicine. Instead, several laws address specific ways artificial intelligence can affect healthcare delivery and the physician-patient relationship.

For medical practices, the expanding Healthcare AI framework means that technology adoption increasingly has to be considered alongside professional obligations, patient communication requirements, privacy protections, and existing standards of medical practice. California’s Medical Board has specifically highlighted new laws governing AI-generated patient communications, AI systems that misrepresent themselves as licensed healthcare professionals, and the use of AI by health plans in utilization review.

Patient Communication Becomes a Key Healthcare AI Issue

One of California’s most direct physician-facing requirements comes from Assembly Bill 3030. The law applies to health facilities, clinics, physician offices, and group practices that use generative AI to create written or verbal communications concerning patient clinical information.

Under the law, covered communications generally must tell patients that the communication was generated by generative AI and provide clear instructions for contacting a human healthcare provider or another appropriate person. The requirements vary depending on the communication format. Written communications must display the notification prominently, while continuous online interactions, audio communications, and video communications have corresponding disclosure requirements. A communication that is generated by AI but read and reviewed by a licensed or certified human healthcare provider is exempt from the disclosure requirement.

This creates a practical compliance issue for physicians using Healthcare AI tools for patient messaging. A practice may use generative AI to improve efficiency, draft patient responses, or support communications, but the workflow must account for when the technology is communicating clinical information directly to patients.

The law also distinguishes clinical information from routine administrative communications. Appointment scheduling, billing, and other clerical or business matters are not included within the statutory definition of patient clinical information. That distinction can be important when practices determine which AI-assisted communications require additional safeguards.

Physician Oversight Remains Central

California’s developing Healthcare AI framework also addresses the boundary between technological assistance and the practice of medicine. The Medical Board has stated that physicians may use AI tools in their work, but the physician remains responsible for practicing according to the applicable standard of care. The Board has also emphasized that AI systems cannot represent themselves as licensed healthcare professionals or practice medicine independently.

Assembly Bill 489, which became effective January 1, 2026, extends existing professional title protections to AI and generative AI systems. The law prohibits AI systems and similar technologies from using terms or representations that imply that the system itself is a licensed healthcare professional. It also gives the appropriate licensing board or enforcement agency authority to pursue violations.

For physician practices, this aspect of Healthcare AI governance is relevant when evaluating patient-facing chatbots, virtual assistants, symptom tools, clinical applications, and other systems that interact directly with patients. Product descriptions, interface language, advertising, and generated responses can all influence whether patients understand that they are interacting with technology rather than a licensed clinician.

The issue is particularly important when an AI tool provides health advice. California’s framework seeks to preserve the distinction between technological assistance and licensed professional care, while allowing physicians to continue using AI as a tool within appropriate clinical workflows.

Insurer Algorithms Face Separate Requirements

Another major component of California’s Healthcare AI policy involves health plans and insurers rather than physician practices directly. Senate Bill 1120 established requirements governing the use of AI, algorithms, and other software tools for utilization review and utilization management.

Under the law, covered tools must consider individual clinical information and relevant medical records rather than relying solely on group datasets. The framework also requires safeguards against unlawful discrimination, provides for auditing and oversight, and restricts the use of these technologies in ways that would replace healthcare provider decision-making. Most significantly for physicians, medical-necessity determinations cannot be made by AI or software alone. Those determinations must be made by a licensed physician or another appropriately licensed healthcare professional competent to evaluate the clinical issues involved.

This part of Healthcare AI governance has implications for physicians who interact with health plans regarding authorization, utilization review, and treatment decisions. When an insurer uses an algorithmic tool as part of its review process, California law establishes limits on how that technology can influence decisions involving medical necessity.

The framework does not prohibit insurers from using technology. Instead, it establishes requirements concerning the information considered, human oversight, discrimination, auditing, privacy, and the role of licensed healthcare professionals in medical-necessity decisions.

Documentation and Clinical Accountability

As Healthcare AI becomes more integrated into medical practices, documentation is likely to remain an important operational consideration. California’s laws do not create a blanket rule requiring physicians to disclose every use of AI in every clinical setting. Instead, specific disclosure obligations depend on the type of AI use and the circumstances involved.

For example, AB 3030 specifically addresses AI-generated communications involving patient clinical information. Separately, the Medical Board has explained that physicians using AI remain subject to existing professional standards and other applicable laws, including privacy requirements.

This means practices should distinguish between different categories of AI use rather than treating all Healthcare AI applications identically. A documentation-assistance tool used internally, a patient-facing chatbot, a clinical decision-support application, and an insurer’s utilization-management algorithm can fall under different legal and operational requirements.

Physicians and practice administrators may therefore need to establish internal policies describing how AI tools are selected, reviewed, used, and monitored. Vendor contracts, data-handling procedures, patient communications, human review processes, and escalation pathways can all become relevant depending on the technology.

Patient Protection Shapes California’s Approach

The expanding Healthcare AI framework reflects a broader concern about maintaining patient protections as healthcare organizations adopt increasingly sophisticated technologies. California’s laws emphasize transparency in certain patient communications, protection against misleading representations, and human involvement in medical-necessity decisions.

The state’s approach also recognizes that AI can be used in healthcare without automatically replacing physicians. The Medical Board has stated that AI can be used as a tool in professional work when the physician continues to meet the applicable standard of care.

For physicians, that distinction is important. Healthcare AI adoption does not remove professional responsibility simply because an output was generated by software. Clinical judgment, patient-specific information, documentation, and applicable professional standards remain relevant when physicians incorporate AI into care delivery.

Healthcare organizations may therefore need governance structures that identify which AI applications are being used, what functions they perform, what information they access, and where human review is required. Such policies can help distinguish appropriate technological assistance from functions that may create additional regulatory or clinical concerns.

California Physicians Monitor the Next Stage of AI Governance

The development of Healthcare AI regulation is continuing as California agencies, licensing boards, health plans, technology developers, and medical organizations adapt to the growing use of artificial intelligence. The laws already in effect provide a framework for several specific situations, but technology continues to develop faster than many traditional healthcare regulatory structures.

For physician practices, the immediate priority is understanding which requirements apply to the tools already being used. Practices can review patient-facing AI communications, confirm appropriate disclosures, evaluate whether AI systems make representations about professional credentials, and examine how clinical staff oversee AI-generated information.

The regulatory environment also reinforces the importance of maintaining clear lines of responsibility. Healthcare AI can assist with communication, documentation, analysis, and other functions, but California’s current framework continues to place significant emphasis on human oversight where patient care and medical necessity are involved.

As additional technologies enter clinical workflows, physicians will need to monitor both new legislation and guidance from California licensing and healthcare agencies. The state’s current framework suggests that future Healthcare AI policy will continue addressing specific risks while attempting to preserve opportunities for responsible technological adoption.

For California physicians, the central issue is therefore not simply whether AI can be used in healthcare. It is how the technology is deployed, how patients are informed, how clinical decisions remain accountable, and how practices comply with the laws governing specific AI applications.

For current physician-facing information on California’s AI requirements, visit the Medical Board of California’s Generative Artificial Intelligence Notification Requirements.

Subscribe to StanfordPhysicianAdvocate.org for continued coverage of California physician policy, healthcare regulation, artificial intelligence, reimbursement, workforce issues, and emerging developments affecting medical practices.