meilynx

Brief

Healthcare AI compliance in 2026: the five questions and the evidence

A field guide for privacy officers, compliance leaders, and CMIOs: what OCR, state regulators, and surveyors now ask about the AI that reads charts and drafts messages, and the evidence that answers them.

September 5, 2026 · 8 min read

Health systems adopted generative AI faster than any other regulated industry: ambient documentation in the exam room, drafted portal replies, prior-authorization summaries, coding suggestions. The rules did not wait. The Security Rule already reached every information system that uses ePHI; HHS added a decision-support duty in May 2025; ONC made source attributes a certification requirement; and Texas, California, and Colorado wrote disclosure and review duties into statute.

This brief collects the questions we hear from privacy officers, compliance leaders, and clinical informatics teams, grouped by the duty they probe, with notes on what a credible answer looks like. It is not legal advice, and none of the evidence it describes makes an organization compliant with anything. It makes the answer to each question something you can show.

1. "What PHI reaches which model, and under what agreement?"

This is the minimum-necessary question and the business-associate question in one. The Privacy Rule limits each disclosure to what the purpose requires (45 CFR 164.502(b)); the Security Rule requires a business associate agreement with every vendor that receives PHI (164.308(b)(1)). A prompt that carries a whole chart to a provider under standard API terms fails both.

A credible answer names the providers that actually received PHI in the period, the agreements covering them, and what was stripped before each call. Detection with in-flight redaction at the request layer produces that record as the system runs. It is detection and redaction support, not de-identification: no Safe Harbor claim rides on it, and the identifier classes it was benchmarked on are stated.

2. "Which decision support tools use protected-class inputs?"

Since 1 May 2025, 45 CFR 92.210 has required covered entities to make reasonable efforts to identify patient care decision support tools that use race, color, national origin, sex, age, or disability as inputs, and to mitigate the risk of discrimination from each. ONC HTI-1's source attributes tell you what a certified tool uses; the determination is still yours, and it is ongoing.

A credible answer starts from a complete inventory, because a tool that ran cannot be missing from a list drawn from traffic. It records the determination per tool with a date, revisits it when the tool's configuration changes, and names who performs the bias or outcome testing. Nothing about the answer asserts that a tool is nondiscriminatory; it shows what the entity did.

3. "Who reviewed what the AI produced?"

Texas SB 1188 requires a practitioner to review AI-generated diagnostic records. California AB 3030 exempts provider-reviewed communications from its disclaimer. Colorado HB 26-1139 will require a qualified clinician to review AI-involved medical-necessity denials from 1 January 2027. The Joint Commission / CHAI guidance puts human oversight at the center of quality monitoring.

A credible answer is a review record tied to the AI output: who reviewed, when, and what they decided, in the same tamper-evident chain as the request. Approval gates produce the record; the review is a human act, and an honest package classifies it as attested rather than proxy-verified.

4. "Was the patient told?"

Texas HB 149 requires disclosure of AI interaction in health care services no later than the date of service. California AB 3030 requires a disclaimer and human-contact instructions on generative-AI patient communications. Colorado's automated-decision statute adds point-of-interaction notice in 2027.

The disclosure lives in a system prompt or a template. A credible answer shows the approved text, the channels it reaches, and proof that the configuration carrying it did not change without approval. Drift detection against a pinned baseline supplies the last part; the text itself is something you attest.

5. "Show me the records."

Audit controls (164.312(b)), six-year documentation retention (164.316), Texas's medical-records standards, and the breach risk assessment all converge on the same substrate: a record of what the AI was asked, what it returned, which policy applied, and who reviewed it.

Vendor logs and exported spreadsheets read as reconstruction. A hash-chained record with write-once retention under your own key reads as evidence, and it is the first thing an investigator asks for when PHI reaches an unapproved model.

What is not evidence

A vendor's HIPAA page is not a business associate agreement. A policy that says minimum necessary is not a control that operates. A risk analysis that predates the AI program is incomplete on its face. And a draft guidance, FDA's lifecycle recommendations or ONC's HTI-5 proposal, is not an obligation; cite it as a watch item and act on the rules that are in force.

The organizations that pass these reviews are the ones whose evidence produces itself: an inventory drawn from traffic, redaction at the request layer, review records in the audit chain, and a package that says on every row whether the proxy verified it or a person attested it.

Beyond the brief

See it on your own traffic.

A 15-minute walkthrough of inline enforcement, the audit chain, and the examination package.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.