Compliance Tool · AI & Emerging Tech

AI Risk Assessment

Ambient scribes, AI coding assistants, chart summarizers, and LLM-backed patient messaging are entering healthcare faster than the controls covering them. This assessment works six angles, from the BAA terms that decide whether your PHI trains someone else's model to the governance controls that make AI a named risk area instead of a shadow one. Open the Introduction tab for how the lanes fit together, or go straight to the Checklist.

Items shown
Checked off
Complete
Current view

Items are grouped into six lanes. Contract and BAA covers what the paper has to say before the vendor touches PHI: training-on-data prohibitions, model retention, subprocessor disclosure, and whether a vendor's de-identification claim would actually survive a look under 45 CFR §164.514. Clinical and patient-facing covers the statutes that reach AI in the care setting, several of which land on the developer rather than the provider. Nondiscrimination covers the Section 1557 duty at 45 CFR §92.210 to keep your own patient care decision support tools, automated and not, from discriminating on race, color, national origin, sex, age, or disability. Fraud and abuse covers what happens when the AI is an arrangement: a tool given free or below cost by a party in a position to refer, or one that steers ordering, tested against the Anti-Kickback Statute and Stark. Research and data covers using patient data to build or fine-tune a model: when that becomes human-subjects research, when an IRB has to see it, and which HIPAA pathway authorizes the secondary use. Program governance maps AI onto the OIG seven elements and the recognized AI frameworks, and now carries the records, retention, and legal-hold duties that reach prompt logs and model outputs. Items badged High exposure carry direct statutory or contractual liability rather than process risk. Items badged Federal or Multi-state reach beyond California, and California flags a state-specific obligation with no federal equivalent.

Contract & BAA

Training-on-data prohibitions, model and prompt retention, subprocessor and foundation-model disclosure, de-identification claims, output ownership, audit rights, and incident clocks that beat the federal 60 days.

Clinical & Patient-Facing

AB 3030 GenAI disclaimers on clinical communications, AB 489 limits on implying a licensed clinician, SB 1120 human review of medical-necessity decisions, and ambient-scribe notice and review workflows.

Nondiscrimination (§1557)

The §92.210 duty to inventory patient care decision support tools, identify those using protected characteristics as inputs, mitigate the risk, plus language access and accessibility for patient-facing AI, and the Colorado AI Act overlay.

Fraud & Abuse

AI given free, below cost, or subsidized by a party in a position to refer, tested against the Anti-Kickback Statute and Stark, fair-market-value documentation, and AI-driven ordering, prescribing, or coding patterns that shift after go-live.

Research & Data

When patient data used to build or fine-tune a model becomes human-subjects research, the IRB review or determination, the HIPAA authorization or waiver pathway for secondary use, and the quality-improvement line.

Program Governance

AI inventory and approval gate, shadow-AI policy, workforce training, AI in the annual risk assessment, HTI-1 and NIST framework mapping, cybersecurity controls, records retention and legal hold over prompt logs, and a reporting channel that captures AI concerns.

Section 1557 §92.210 general nondiscrimination prohibition effectiveJuly 5, 2024
Section 1557 §92.210 identify-and-mitigate obligation compliance dateMay 1, 2025 (300 days after effective date)
AB 3030 GenAI clinical-communication disclaimers effectiveJanuary 1, 2025
SB 1120 human review of medical-necessity determinations effectiveJanuary 1, 2025
AB 489 restriction on implying licensed-clinician status effectiveJanuary 1, 2026
SB 942 California AI Transparency Act operativeAugust 2, 2026 (moved once already, from January 1, 2026)
SB 942 generative AI hosting platformsJanuary 1, 2027
SB 942 large online platformsJanuary 1, 2028
SB 942 covered-provider thresholdMore than 1,000,000 monthly users in California
HIPAA de-identification pathwaysSafe Harbor (18 identifiers) or Expert Determination (45 CFR §164.514(b))
CMS Medicare Advantage rule: services cannot be denied by algorithm alone (42 CFR §422.101(c))Contract year 2024, reinforced in 2025 FAQ
Utah AI Policy Act, regulated-occupation AI disclosure (SB 149, as amended by SB 226 / SB 332)Effective May 1, 2024; healthcare disclosure amendments 2025
Colorado AI Act (SB 205) high-risk-system duties, developer and deployerJune 30, 2026 (delayed from February 1, 2026)
Texas Responsible AI Governance Act (TRAIGA / HB 149)January 1, 2026
Illinois BIPA written-consent rule for biometric identifiers (740 ILCS 14)In force; 2024 amendment limits per-scan accrual

Sources: 45 CFR Part 164 ↗  ·  45 CFR §92.210 ↗  ·  42 CFR §422.101 ↗  ·  Colorado SB 205 ↗  ·  SB 1120 ↗  ·  Compiled as of July 20, 2026

This risk assessment compiles selected federal and state requirements that bear on healthcare organizations adopting artificial intelligence (among them the HIPAA Privacy and Security Rules at 45 CFR Parts 160 and 164, the Section 1557 nondiscrimination rule at 45 CFR Part 92, the CMS Medicare Advantage rule at 42 CFR Part 422, the Anti-Kickback Statute and physician self-referral law, the Common Rule at 45 CFR Part 46, and state AI laws in California, Colorado, Utah, Texas, and Illinois), for general compliance-learning purposes. AI regulation is moving quickly and unevenly, and this is not a complete inventory of the requirements that may apply to any particular AI deployment; the multi-state items flag major laws but do not capture every state, and this tool does not fully address FDA device regulation, employment and workforce AI (see the companion Employment AI Risk Assessment), the EU AI Act, or non-healthcare AI law. This is not legal advice. Brandon Goulter is not an attorney, and using this tool creates no professional advisory relationship. Any contract language suggested here is illustrative and must be reviewed and adapted by your own counsel before use. Verify current requirements against primary sources (ecfr.gov and the relevant state legislatures) and confirm your own program's compliance with a licensed attorney before relying on this tool. Checked items are stored only in your browser's local storage, nothing is transmitted or saved to any server.