Healthcare Innovation

State Laws on Healthcare AI

Written By:
Josh Spencer
April 15, 2026
State Laws on Healthcare AI

State Healthcare & AI Compliance Laws

Healthcare professionals using AI tools must navigate a growing patchwork of state privacy, data protection, and AI-specific laws. BastionGPT is HIPAA compliant by design, with a Business Associate Agreement (BAA) included on every plan. Learn more about navigating healthcare compliance with BastionGPT. Below is a state-by-state overview of the laws most relevant to healthcare AI assistants and scribes.

Note: Federal laws including HIPAA, the HITECH Act, the FTC Act, COPPA, and Section 1557 of the Affordable Care Act apply in every U.S. state and are not repeated per state below. BastionGPT is built to support compliance with these federal requirements. Last reviewed August 16, 2026. Items marked “pending” have not been enacted, and several 2026 sessions (California, New York, New Jersey, Massachusetts, Pennsylvania, Michigan, Ohio) are still open, so this guide is re-checked quarterly. Updated August 2026: 2026 session outcomes added for 27 states; citations to superseded or never-enacted statutes removed. This page is general information, not legal advice.

If you use AI to document visits, these laws speak to you directly

  • Consent or notice before AI records or transcribes: Colorado (HB 26-1195 — written, revocable consent; in force Aug 12, 2026), Illinois (WOPR Act — written consent), Maine (LD 2082 — written consent; July 29, 2026), Rhode Island (H 7349/S 2197 — written consent; and ch. 23-106 — notify patients that AI documents the visit), Louisiana (Act 649 — tell patients before the visit; Aug 1, 2026), Arizona (Board of Behavioral Health Examiners rule — informed consent; Jan 1, 2027), Utah (SB 226 — prominent disclosure in high-risk generative-AI interactions), Texas (SB 1188 and TRAIGA — disclose AI use).
  • Review what the AI wrote: Nevada (AB 406 — independently review AI-generated notes and billing), Rhode Island (ch. 23-106 — review AI documentation for accuracy), Texas (SB 1188 — review all AI-created records), Indiana (HB 1271 — no AI-prepared claims without human review).
  • AI may not present as, or replace, a licensed clinician: California (AB 489), Delaware (HB 191), Illinois (WOPR), Nevada (AB 406), Missouri (SB 1019, Aug 28, 2026), Tennessee (SB 1580), Vermont (Act 156), Oregon (HB 2748, nursing titles), Nebraska (LB 525, 2027).
  • All-party recording-consent states: California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon (in-person), Pennsylvania, Washington — get and document consent from everyone in the room before an ambient scribe records; Connecticut and Nevada apply all-party rules to phone calls.

Alabama AL

Alabama Personal Data Protection Act (HB 351, eff. May 1, 2027)Data Breach Notification Act (Ala. Code § 8-38-1)SB 63 — AI in health-coverage decisions (eff. Oct 1, 2026)

Alabama enacted its first comprehensive privacy law in 2026. The Alabama Personal Data Protection Act (HB 351, signed April 17, 2026) takes effect May 1, 2027 and gives consumers access, correction, deletion, portability, and opt-out rights; HIPAA covered entities, business associates, and protected health information are exempt. The Data Breach Notification Act requires prompt notice when personal data is compromised. SB 63 (also signed April 17, 2026; effective October 1, 2026) regulates how health plans use AI in coverage determinations: AI cannot be the sole basis for a decision and its use must be disclosed. BastionGPT supports Alabama clinicians with HIPAA-compliant AI that never uses customer data to train models.

Alaska AK

APIPA — breach notification (AS 45.48)HIE Confidentiality & Security (AS 18.23.300–.400)Health Care Services Information & Review Organizations (AS 18.23)Telehealth (AS 08.02.130)

Alaska has no comprehensive consumer privacy law and no AI-specific statute. The Alaska Personal Information Protection Act (AS 45.48) governs breach notification and disposal of personal information. AS 18.23 protects the confidentiality of peer-review records and sets confidentiality and security standards for the state health information exchange (AS 18.23.300–.400). Alaska's telehealth statute (AS 08.02.130) applies when AI-assisted care is delivered remotely. BastionGPT's encryption and access controls support these confidentiality expectations.

Arizona AZ

Medical Claims & Prior Auth — HB 2175 (eff. July 1, 2026)BBHE rule — informed consent for AI used to record or document services (eff. Jan 1, 2027)Breach Notification (A.R.S. § 18-552)Insurance Utilization Review (A.R.S. Title 20)

Arizona has no comprehensive privacy law or general AI statute, but HB 2175 (signed May 12, 2025; effective July 1, 2026) requires a medical director to exercise independent medical judgment on any denial involving medical necessity, so AI cannot be the final decision-maker on claims or prior authorizations. For behavioral-health licensees, the Board of Behavioral Health Examiners' updated rules require, from January 1, 2027, documented informed consent before any service that uses AI or another “human simulation modality” to provide, record, or document clinical services. Arizona's breach law requires notice to affected individuals and the Attorney General. A 2026 chatbot-disclosure bill (HB 2311) was vetoed on June 19, 2026. BastionGPT reinforces this human-in-the-loop model: it drafts and assists while licensed clinicians retain every clinical decision, and BastionGPT's consent guidance helps practices document the required consent.

Arkansas AR

APIPA — breach notification (Ark. Code § 4-110-101)Children & Teens' Online Privacy Protection Act (Act 952 of 2025, eff. July 1, 2026)Deceptive Trade Practices Act

Arkansas has no comprehensive consumer privacy law and no AI-in-healthcare statute. The Personal Information Protection Act (Ark. Code § 4-110-101) requires reasonable security and breach notification, and the Children and Teens' Online Privacy Protection Act (Act 952 of 2025) took effect July 1, 2026. Two 2025 bills on AI in insurer decisions and AI-generated medical records (HB 1297, HB 1816) were withdrawn. BastionGPT operates as a documentation tool under clinician supervision and does not make clinical or coverage decisions.

California CA

CCPA / CPRACMIA (Cal. Civil Code § 56)AB 3030 — AI patient-communication disclosuresSB 1120 — Physicians Make Decisions ActAB 489 — AI may not imply a health-care licenseSB 942 / AB 853 — CA AI Transparency Act (operative Aug 2, 2026)SB 243 — Companion ChatbotsAB 2013 — GenAI training-data transparencySB 53 — Transparency in Frontier AI ActAB 45 — consumer health data & geofencingSB 361 — data-broker amendmentsSB 1223 — neural data as sensitive PIAll-party recording consent (Penal Code § 632)CPPA automated-decision-making regulations (phasing in from 2027)

California has the most extensive healthcare AI framework in the country. The CCPA/CPRA and the CMIA establish broad consumer and patient data rights. AB 3030 requires health facilities, clinics, and physician offices to disclose when patient communications about clinical information are generated by AI unless a licensed provider reviews them first. SB 1120 ensures AI cannot independently deny, delay, or modify care based on medical necessity, and AB 489 (effective January 1, 2026) prohibits AI from using terms that imply it holds a healthcare license. SB 243 regulates companion chatbots, the AI Transparency Act became operative on August 2, 2026, and the CPPA's automated-decision-making regulations phase in from 2027. California is also an all-party recording-consent state (Penal Code § 632), so patients must agree before an ambient scribe records a visit. Several 2026 bills on healthcare AI and chatbots are still before the Legislature. BastionGPT supports compliance by operating as a clinician-supervised assistant that never represents itself as a licensed professional, and BastionGPT's consent guidance helps practices meet AB 3030 and recording-consent obligations.

Colorado CO

Colorado Privacy Act (CPA)SB 26-189 — ADMT transparency law (replaces SB 24-205; eff. Jan 1, 2027)HB 26-1195 — Psychotherapy AI restrictions (eff. Aug 12, 2026)HB 26-1139 — AI in utilization review (eff. Jan 1, 2027)Breach Notification (C.R.S. § 6-1-716)

Colorado rewrote its AI framework in 2026. SB 26-189 (signed May 14, 2026; effective January 1, 2027) repeals the 2024 Colorado AI Act and replaces it with transparency duties for automated decision-making technology: notice when ADMT influences a consequential decision, an explanation within 30 days of an adverse decision, and a right to human review. HB 26-1195, effective August 12, 2026, directly governs psychotherapists: AI may be used only for administrative or supplementary tasks under the provider's full responsibility, providers must review any AI-generated recommendations, and clients must give clear, written, revocable consent before AI records or transcribes a session — a refusal cannot affect access to care. HB 26-1139 (effective January 1, 2027) requires individualized, clinician-reviewed decisions when insurers use AI in utilization review. The Colorado Privacy Act adds consumer data rights and profiling opt-outs. BastionGPT is built for the permitted role — a documentation tool under provider supervision — and its consent guidance helps practices document HB 26-1195 consent.

Connecticut CT

CTDPA (Conn. Gen. Stat. § 42-515 et seq.)CTDPA amendments — LLM-training disclosure (SB 1295 / PA 25-113, eff. July 1, 2026)SB 4 / PA 26-64 — data brokers, geolocation, profiling (2026)SB 5 / PA 26-15 — AI companions & employment ADMT (2026)Breach Notification (§ 36a-701b)Safeguards Law (§ 42-471)CUTPA

Connecticut keeps layering AI duties onto its privacy law. Since July 1, 2026 the CTDPA, as amended by SB 1295 (Public Act 25-113), requires businesses to disclose whether personal data is used to train large language models, lowers applicability thresholds, and expands sensitive-data and minor protections; SB 4 (Public Act 26-64, May 2026) adds data-broker, geolocation, and profiling rules. SB 5 (Public Act 26-15, the 2026 online-safety and AI act) regulates AI companion chatbots from January 1, 2027 and automated employment decisions from October 1, 2026; it does not add provider-specific healthcare duties. Because BastionGPT never uses customer or patient data to train models, the CTDPA's core disclosure concern does not arise.

Delaware DE

DPDPA (6 Del. C. ch. 12D)HB 191 — AI may not hold or use medical or nursing titles (2026)Breach Notification (6 Del. C. § 12B-101)Online Privacy & Protection Act (6 Del. C. ch. 12C)

Delaware's Personal Data Privacy Act stands out because it does not include an entity-level exemption for HIPAA covered entities: PHI is exempt at the data level, but HIPAA-regulated organizations must still comply with the DPDPA for data outside PHI. The law grants consumers rights to access, correct, delete, and opt out of advertising and profiling. In April 2026 Delaware enacted HB 191, which bars any nonhuman entity — including AI agents — from being licensed as, or presenting itself as, a physician, physician assistant, or nurse. BastionGPT never represents itself as a licensed professional, and its HIPAA-compliant design and data-minimization practices support Delaware clinicians navigating the DPDPA overlap.

Florida FL

FIPA (Fla. Stat. § 501.171)Florida Digital Bill of Rights (§ 501.701)FDUTPAAll-party recording consent (§ 934.03)

Florida has not enacted an AI-specific healthcare law; the 2026 AI Bill of Rights (SB 482) passed the Senate but died in the House on March 13, 2026, as did bills restricting AI in psychology and counseling. FIPA imposes strict breach notification (a 30-day window, with medical records covered), and the Florida Digital Bill of Rights adds consumer rights for large controllers with a HIPAA covered-entity exemption. Florida is an all-party recording-consent state (§ 934.03), so patients must consent before an ambient scribe records a visit. BastionGPT is a HIPAA-compliant AI assistant operating under licensed provider supervision.

Georgia GA

Personal Identity Protection Act (O.C.G.A. § 10-1-910)Fair Business Practices ActSB 444 — AI in insurance decisions (eff. Jan 1, 2027)SB 540 — conversational-AI disclosure & minor safety (eff. July 1, 2027)

Georgia has no comprehensive consumer privacy statute. Its Personal Identity Protection Act requires breach notice “in the most expedient time possible,” and Bland v. Urology of Greater Atlanta (Ga. Ct. App. 2025) recognized a common-law duty to protect personal information. In 2026 Georgia enacted SB 444 (signed May 5; effective January 1, 2027), which bars insurers from issuing adverse determinations on AI alone, and SB 540 (signed May 11; effective July 1, 2027), which requires conversational-AI operators to disclose AI use and protect minors. BastionGPT operates under provider supervision and does not make coverage determinations.

Hawaii HI

Breach Notification (HRS ch. 487N)Personal Information Protection — SSN rules (ch. 487J)Destruction of Personal Information Records (ch. 487R)Unfair/Deceptive Acts (§ 480-2)SB 3001 / Act 248 — AI companion chatbots (2026)

Hawaii has no comprehensive consumer privacy law and no AI-in-healthcare statute; a 2026 healthcare-AI disclosure bill (SB 2281) did not pass. Its breach law (HRS ch. 487N) requires notice without unreasonable delay, ch. 487J restricts use of Social Security numbers, and ch. 487R governs destruction of personal-information records. In July 2026 Hawaii enacted Act 248 (SB 3001), which requires AI companion chatbots to disclose that users are talking to AI and to follow self-harm protocols. BastionGPT is not a consumer chatbot; it is a HIPAA-compliant documentation tool used by licensed providers.

Idaho ID

Breach Notification (Idaho Code § 28-51-104)Consumer Protection ActConversational AI Safety Act (SB 1297, eff. July 1, 2027)

Idaho has no comprehensive privacy law. In 2026 it enacted SB 1297, the Conversational AI Safety Act (signed March 31, 2026; effective July 1, 2027), which requires conversational-AI operators to disclose that users are interacting with a machine and to maintain protocols for adult and minor users. Idaho's breach statute (§ 28-51-104) and Consumer Protection Act otherwise govern. BastionGPT is not a consumer-facing chatbot; it is a HIPAA-compliant documentation tool used by licensed providers.

Illinois IL

BIPA (740 ILCS 14)WOPR Act (Public Act 104-0054)PIPA / Breach (815 ILCS 530)Consumer Fraud Act (815 ILCS 505)All-party recording consent (720 ILCS 5/14-2)SB 3114 — human review of AI claim downcoding (2026)

Illinois has one of the most active regulatory environments for healthcare AI. The WOPR Act (HB 1806, Public Act 104-0054, effective August 1, 2025) prohibits AI from providing therapy, making therapeutic decisions, or communicating therapeutically with clients, while allowing licensed professionals to use AI for administrative and supplementary support — but recording or transcribing a session with AI requires that the client be informed in writing and give explicit, revocable written consent. BIPA imposes strict consent requirements for biometric identifiers, including voiceprints, with a private right of action, and Illinois is an all-party recording-consent state. In 2026 the Transparency in Downcoding Act (SB 3114) added human-review requirements for payer algorithms. BastionGPT fits within WOPR's permitted categories — drafting notes, transcribing sessions with documented consent, and supporting administrative tasks — without engaging in therapeutic communication.

Indiana IN

INCDPA (Ind. Code art. 24-15, eff. Jan 1, 2026)Breach Notification (IC 24-4.9)HB 1271 — human review of AI in claims and downcoding (eff. July 1, 2026)Deceptive Consumer Sales Act

Indiana's Consumer Data Protection Act (effective January 1, 2026) gives residents access, correction, deletion, and portability rights, requires data protection assessments for sensitive data, exempts HIPAA-regulated data, and has a permanent 30-day cure period. The breach statute allows Attorney General penalties of up to $150,000 per deceptive act. HB 1271 (effective July 1, 2026) bars insurers from using AI as the sole basis for downcoding or medical-necessity denials and requires providers to review any AI-prepared claim before submission. BastionGPT drafts under clinician review and processes clinical data under HIPAA safeguards.

Iowa IA

Iowa CDPA (Iowa Code ch. 715D, eff. Jan 1, 2025)Breach Notification (ch. 715C)Consumer Fraud Act (§ 714.16)HF 2635 — AI in prior authorization (eff. July 1, 2026)

Iowa's Consumer Data Protection Act (effective January 1, 2025) exempts HIPAA-regulated entities and PHI. HF 2635, signed May 13, 2026 and effective July 1, 2026, lets utilization-review organizations use AI for initial prior-authorization review but prohibits AI as the sole basis for denying, delaying, or downgrading a medically necessary service. BastionGPT operates within the HIPAA framework as a provider-supervised documentation tool.

Kansas KS

Breach Notification (K.S.A. § 50-7a01)Consumer Protection ActHealth Information Technology Act

Kansas has no comprehensive consumer privacy law and no AI-specific statute; the 2026 chatbot-safety proposal (HB 2671) died in committee. The breach law requires notice “in the most expedient time possible” and reporting to consumer reporting agencies when more than 1,000 residents are affected. BastionGPT is a clinical documentation tool, not a consumer-facing chatbot.

Kentucky KY

KCDPA (KRS 367.3611–.3629, eff. Jan 1, 2026)Breach Notification (KRS 365.732)Consumer Protection ActTelehealth Laws

Kentucky's Consumer Data Protection Act took effect January 1, 2026 and grants access, correction, deletion, portability, and opt-out rights; HIPAA covered entities' PHI and, after the 2025 amendment (HB 473), health-care providers' HIPAA-governed information are exempt. Kentucky has no AI-specific statute. BastionGPT's privacy-first design supports Kentucky providers in meeting these requirements.

Louisiana LA

Louisiana Data Privacy Act (SB 386 / Act 502, eff. Jan 1, 2027)HB 475 / Act 649 — AI transcription disclosure (R.S. 37:22.1, eff. Aug 1, 2026)Breach Notification (La. R.S. 51:3071)Medical Records Privacy (R.S. 40:1165.1)LUTPA

Louisiana enacted two relevant laws in 2026. Act 649 (HB 475), effective August 1, 2026, requires healthcare professionals to tell patients before an appointment begins if AI-powered recording or transcription software will be used. The Louisiana Data Privacy Act (SB 386, Act 502) takes effect January 1, 2027 with access, deletion, and opt-out rights and consent for sensitive data. Louisiana's breach law and medical-records privacy statute (R.S. 40:1165.1) continue to apply, and LUTPA reaches deceptive claims about what AI tools can do. BastionGPT's consent guidance helps practices meet the Act 649 disclosure duty.

Maine ME

Notice of Risk to Personal Data Act (10 M.R.S. §§ 1346–1350-B)LD 2082 / P.L. 2025 c. 687 — AI in mental-health services (eff. July 29, 2026)Broadband Internet Privacy Law (35-A M.R.S. § 9301)Unfair Trade Practices Act

Maine has no comprehensive consumer privacy law — the Maine Online Data Privacy Act (LD 1822) failed in April 2026 — but its breach-notification statute and broadband privacy law apply. LD 2082, effective July 29, 2026, restricts AI in mental-health care: only licensed professionals may provide therapy, AI may be used for administrative or supplementary support under the licensee's responsibility, and using AI in a recorded or transcribed session requires written notice and the client's written, revocable consent. BastionGPT's consent guidance helps Maine clinicians document that consent.

Maryland MD

MODPA (Com. Law § 14-4601 et seq., eff. Oct 1, 2025)MPIPA — breach (§ 14-3501)Confidentiality of Medical Records Act (Health-Gen. § 4-301)HB 820 — AI in utilization review (2025)All-party recording consent (Cts. & Jud. Proc. § 10-402)HIE Regulations (COMAR 10.25.18)

Maryland's Online Data Privacy Act (effective October 1, 2025) grants access, correction, deletion, and opt-out rights and exempts HIPAA covered entities and PHI. The Confidentiality of Medical Records Act adds state rules on consent, disclosure, and access, and Maryland's wiretap law requires all parties' consent before a conversation is recorded. HB 820 (2025) requires insurers using AI in utilization review to base decisions on the individual patient's clinical record and keep humans responsible for denials. BastionGPT functions as a clinical documentation tool under provider control.

Massachusetts MA

Data Security Regulations (201 CMR 17.00)Breach Notification (M.G.L. c. 93H)Chapter 93A Consumer ProtectionAll-party recording consent (M.G.L. c. 272, § 99)Patients' Rights (M.G.L. c. 111, § 70E)Consumer Data Privacy Act (in conference committee)

Massachusetts has one of the strictest data-security regimes — 201 CMR 17.00 requires a written information security program with encryption, access controls, and training — and an all-party recording-consent law (M.G.L. c. 272, § 99) that matters for any AI scribe. A comprehensive Consumer Data Privacy Act passed both chambers in 2026 and is in conference committee; it is not yet law. Chapter 93A applies to deceptive or unfair AI practices. BastionGPT's security architecture and consent guidance support these requirements.

Michigan MI

Identity Theft Protection Act (MCL 445.61)Consumer Protection ActMedical Records Access Act (MCL 333.26261)

Michigan's Identity Theft Protection Act requires businesses to notify individuals and the Attorney General following a data breach, and the Consumer Protection Act prohibits unfair and deceptive practices. The Medical Records Access Act governs patient access to records. Michigan has no comprehensive consumer privacy statute and no AI-specific law; bills on insurer AI decisions and chatbots remain pending. BastionGPT operates as a secure AI assistant under clinician supervision.

Minnesota MN

MCDPA (Minn. Stat. ch. 325O, eff. July 31, 2025)MGDPA (§ 13.01)Breach Notification (§ 325E.61)Health Records Act (§ 144.291)

Minnesota's Consumer Data Privacy Act (effective July 31, 2025) grants consumers data access, correction, deletion, and opt-out rights and requires data protection assessments for high-risk processing. The state's Health Records Act provides Minnesota-specific rules that apply in addition to HIPAA, making it one of the more protective health privacy frameworks. Minnesota has no AI-in-healthcare statute; bills on AI in psychotherapy and prior authorization remain pending. BastionGPT is purpose-built as a healthcare AI transcriptionist and assistant under clinician control.

Mississippi MS

Breach Notification (§ 75-24-29)Consumer Protection ActMedical Records Confidentiality (§ 41-9-61)

Mississippi maintains a leaner privacy framework, with primary protections from the breach notification statute and Consumer Protection Act; medical records statutes establish patient consent and confidentiality requirements. Mississippi has no comprehensive privacy law and no AI-in-healthcare statute (a 2026 bill to bar AI from mental and behavioral health care, HB 1720, died in committee). BastionGPT keeps Mississippi providers in control of documentation.

Missouri MO

Breach Notification (RSMo § 407.1500)Merchandising Practices ActHealth Information Privacy (§ 191.227)SB 1019 — AI may not be represented as a mental-health professional (eff. Aug 28, 2026)

Missouri has no comprehensive privacy law; its breach statute and Merchandising Practices Act are the main consumer protections, and § 191.227 governs patient access to records. SB 1019, effective August 28, 2026, makes it an unlawful practice to advertise or represent AI as a mental-health professional or as able to provide therapy or a diagnosis, with penalties of $10,000 to $20,000 per violation. BastionGPT is a documentation assistant used under clinician oversight and is never presented as a therapist.

Montana MT

MCDPA (MCA § 30-14-2801; SB 297 amendments eff. Oct 1, 2025)Uniform Health Care Information Act (MCA § 50-16-501)Breach Notification (MCA § 30-14-1704)All-party recording notice (MCA § 45-8-213)Genetic Information Privacy Act (MCA § 30-23-101)

Montana's Consumer Data Privacy Act gives residents rights to access, correct, delete, and port personal data and to opt out of sales, targeted advertising, and profiling; SB 297 (effective October 1, 2025) lowered the applicability threshold to 25,000 consumers, added duties for minors' data, and removed the cure period. Health information held by providers is separately governed by the Uniform Health Care Information Act (MCA § 50-16-501 et seq.). Montana requires that everyone in a conversation know it is being recorded (MCA § 45-8-213), so patients and anyone else present should be told before an ambient AI scribe records a visit. Montana has no statute specific to AI in clinical care or mental health. BastionGPT operates as a clinician-supervised documentation tool within these privacy and consent requirements.

Nebraska NE

NDPA (Neb. Rev. Stat. § 87-1101, eff. Jan 1, 2025)Conversational AI Safety Act (LB 525, eff. July 1, 2027)LB 77 — AI in prior authorization (2025)Breach Notification (§ 87-801)Consumer Protection Act (§ 59-1601)

Nebraska's Data Privacy Act (effective January 1, 2025) gives consumers rights of access, correction, deletion, portability, and opt-out, requires consent before processing sensitive data such as health information, and requires data protection assessments for higher-risk processing. The Conversational AI Safety Act (LB 525, signed April 14, 2026; effective July 1, 2027) prohibits chatbots from presenting themselves as licensed mental-health professionals or holding clinical credentials. LB 77 (2025) bars utilization-review agents from using AI as the sole basis to deny, delay, or modify care and requires disclosure of AI use. Nebraska has no statute specific to AI scribes or AI-generated clinical notes. BastionGPT operates as a clinician-supervised documentation tool within these requirements.

Nevada NV

AB 406 — AI in mental & behavioral health (NRS ch. 629 & 433, eff. July 1, 2025)Consumer Health Data Privacy (SB 370; NRS § 603A.400)SB 220 online privacy opt-out (NRS § 603A.300)Breach Notification (NRS § 603A.220)

Nevada's AB 406 (effective July 1, 2025) bars licensed mental and behavioral health providers from using AI to deliver care directly to a patient, while expressly allowing AI for administrative support such as scheduling, billing, and organizing session notes — provided the provider independently reviews the accuracy of any AI-generated notes or billing records and complies with HIPAA and state records law; the same act prohibits AI systems from being marketed as therapists or counselors, with civil penalties up to $15,000 per violation. Nevada's Consumer Health Data Privacy Law (SB 370) requires consent for collection and sharing of consumer health data outside HIPAA, bars geofencing of health facilities, and requires opt-in authorization for sales of health data. SB 220 gives consumers a right to opt out of the sale of covered information collected online, and NRS 603A.220 sets breach-notification duties. A 2025 bill limiting insurers' use of AI in prior authorization (SB 128) was vetoed. BastionGPT operates as a clinician-supervised documentation tool consistent with AB 406's administrative-support model, with the clinician reviewing every note.

New Hampshire NH

NH Data Privacy Act (RSA ch. 507-H, eff. Jan 1, 2025)All-party recording consent (RSA 570-A:2)Breach Notification (RSA 359-C:19)Consumer Protection Act (RSA 358-A)Insurance Data Security (RSA 420-P)

New Hampshire's data privacy law (RSA chapter 507-H, effective January 1, 2025) gives consumers rights to access, correct, delete, and port personal data and to opt out of targeted advertising, sales, and profiling; it requires consent to process sensitive data such as health information and data protection assessments for heightened-risk processing. New Hampshire is an all-party-consent state (RSA 570-A:2), so patients and anyone else present must consent before an ambient AI scribe records a visit. Insurers are covered by the Insurance Data Security Law (RSA 420-P), and breaches by RSA 359-C:19. New Hampshire has no statute specific to AI in clinical care; 2026 bills on AI providing licensed professional services (SB 640) and on AI in utilization review (HB 1406) were both rejected. BastionGPT operates as a clinician-supervised documentation tool within these privacy and consent requirements.

New Jersey NJ

NJDPA (N.J.S.A. § 56:8-166.4 et seq., eff. Jan 15, 2025)Identity Theft Prevention Act / breach notice (N.J.S.A. § 56:8-163)Consumer Fraud Act (N.J.S.A. § 56:8-1)A4070 — limits on patient identity data collected by health facilities (eff. Apr 1, 2027)Bills barring AI advertised as a licensed mental-health professional (A799/S735)

New Jersey's Data Privacy Act (effective January 15, 2025) gives consumers rights of access, correction, deletion, portability, and opt-out, requires consent to process sensitive data — expressly including mental or physical health condition, treatment, or diagnosis — and requires data protection assessments for heightened-risk processing. Breach notification is governed by the Identity Theft Prevention Act, and the Consumer Fraud Act underpins Attorney General enforcement. A4070 (signed March 25, 2026; effective April 1, 2027) restricts what identity information health care facilities may collect and disclose about patients. New Jersey has not enacted a law requiring disclosure of AI use in clinical interactions; bills to bar AI from being advertised as a licensed mental-health professional and to have licensing boards set generative-AI rules remain pending. BastionGPT operates as a clinician-supervised documentation tool within these privacy requirements.

New Mexico NM

Breach Notification (NMSA § 57-12C-1)Unfair Practices Act (NMSA § 57-12-1)

New Mexico has no comprehensive consumer data privacy law and no statute specific to AI in health care; every AI bill in the 2025 and 2026 sessions — including the Artificial Intelligence Act (HB 60), the Chatbot Safety Act (HB 174), and the AI Transparency Act (HB 28) — was postponed indefinitely. The Data Breach Notification Act requires notice to affected residents and, for larger breaches, the Attorney General, and the Unfair Practices Act supports enforcement against deceptive practices. New Mexico has not adopted the NAIC Insurance Data Security Model Law; the Office of Superintendent of Insurance has addressed cybersecurity only by bulletin. HIPAA therefore remains the primary framework for clinical documentation. BastionGPT operates as a clinician-supervised documentation tool within these requirements.

New York NY

SHIELD Act (GBL §§ 899-aa / 899-bb)AI Companion Models (GBL Art. 47, eff. Nov 5, 2025)DFS Cybersecurity Reg. (23 NYCRR 500)NYC Local Law 144 (AEDT)RAISE Act (eff. Jan 1, 2027)Health Information Privacy Act (vetoed Dec 19, 2025; S9269 reintroduced)Kids chatbot safety bill (S9051, passed June 2026, awaiting Governor)

New York regulates data security through the SHIELD Act (reasonable safeguards plus breach notification) and, for insurers and other DFS licensees, the Part 500 cybersecurity regulation, whose 2023 amendments were fully phased in by November 2025. General Business Law Article 47 (in force November 5, 2025) requires AI companion operators to disclose that users are not talking to a human — at the start of a session and every three hours — and to maintain self-harm detection and referral protocols. The RAISE Act (signed December 2025; effective January 1, 2027) imposes safety and incident-reporting duties on frontier-model developers, and NYC Local Law 144 requires bias audits of automated employment tools. The New York Health Information Privacy Act passed the Legislature but was vetoed on December 19, 2025 (a revised bill, S9269, is pending), and bills on AI in psychotherapy and AI in utilization review did not pass in 2026; New York currently has no statute requiring clinicians to disclose AI documentation tools. BastionGPT operates as a clinician-supervised documentation tool within New York's data-security requirements.

North Carolina NC

Identity Theft Protection Act (G.S. § 75-60; breach notice § 75-65)UDTPA (G.S. § 75-1.1)Health Information Exchange ActH 565 — AI in Medicaid/commercial insurance decisionsS 963 — AI chatbots

North Carolina has no comprehensive consumer data privacy statute and no law specific to AI in health care; 2025–26 bills to limit AI in Medicaid and commercial insurance decisions (H 565) and to license and regulate AI chatbots (S 963) remain pending. The Identity Theft Protection Act requires reasonable disposal of personal information and breach notification to affected residents and the Attorney General, and the Unfair and Deceptive Trade Practices Act supports enforcement and private treble-damage suits. The Health Information Exchange Act governs provider participation in the state HIE. BastionGPT operates as a clinician-supervised documentation tool within these requirements.

North Dakota ND

Breach Notification (N.D.C.C. § 51-30-01)Consumer Fraud Act (N.D.C.C. § 51-15-01)Insurance Data Security Act (N.D.C.C. ch. 26.1-02.2)

North Dakota has no comprehensive consumer data privacy law and no statute governing AI in clinical care; its only AI enactments (2025) require disclosure of AI-generated political communications and clarify that an AI system is not a “person” under state law. Businesses must notify residents under the breach-notification law (N.D.C.C. ch. 51-30), and the Consumer Fraud Act supports enforcement against deceptive practices. Insurance licensees must maintain information-security programs under the Insurance Data Security Act (N.D.C.C. ch. 26.1-02.2). BastionGPT operates as a clinician-supervised documentation tool within these requirements.

Ohio OH

Data Protection Act / cybersecurity safe harbor (SB 220; ORC § 1354.01)Breach Notification (ORC § 1349.19)Consumer Sales Practices Act (ORC § 1345.01)HB 525 — AI in therapy servicesHB 579 / SB 164 — AI use by health insurers

Ohio has no comprehensive consumer data privacy law and no statute specific to AI in clinical care; bills on AI in therapy services (HB 525) and on insurers' use of AI (HB 579, SB 164) were pending as of August 2026. The Data Protection Act (SB 220, ORC 1354) gives businesses an affirmative defense to data-breach tort claims if they maintain a written cybersecurity program that reasonably conforms to a recognized framework such as the NIST Cybersecurity Framework or HIPAA's Security Rule. Breaches of unencrypted personal information must be disclosed under ORC 1349.19, and the Consumer Sales Practices Act supports Attorney General enforcement. BastionGPT operates as a clinician-supervised documentation tool within these requirements.

Oklahoma OK

Oklahoma Consumer Data Privacy Act (SB 546, eff. Jan 1, 2027)Security Breach Notification Act (24 O.S. § 161; SB 626 amendments eff. Jan 1, 2026)Consumer Protection ActInsurance Data Security Act (36 O.S. § 670)

Oklahoma enacted a comprehensive consumer data privacy law in 2026 (SB 546, signed March 20, 2026; effective January 1, 2027) giving residents access, deletion, correction, and opt-out rights and imposing duties on controllers that process sensitive data such as health information. The Security Breach Notification Act (24 O.S. 161 et seq.), as amended by SB 626 effective January 1, 2026, requires notice to affected residents without unreasonable delay and to the Attorney General within 60 days when more than 500 residents are affected, with a safe harbor for HIPAA-compliant entities. Insurers must maintain information-security programs under the Insurance Data Security Act. Oklahoma has no statute specific to AI in clinical care — a 2026 bill requiring informed consent for AI use by mental-health professionals and other providers (SB 2037) failed — so HIPAA governs AI documentation tools. BastionGPT operates as a clinician-supervised documentation tool within these requirements.

Oregon OR

OCPA (ORS § 646A.570; HB 2008 amendments eff. Jan 1, 2026)AI Companions Act (SB 1546, eff. Jan 1, 2027)HB 2748 — AI barred from nursing titles (2025)In-person recording notice (ORS § 165.540)Consumer Information Protection Act / breach (ORS § 646A.604)Genetic Privacy (ORS § 192.531)

Oregon's Consumer Privacy Act gives consumers rights to access, correct, delete, and port personal data and to opt out of targeted advertising, sales, and profiling, requires consent for sensitive data such as health information and data protection assessments for higher-risk processing; 2025 amendments (HB 2008, effective January 1, 2026) ban selling precise geolocation data and data of consumers under 16. Under ORS 165.540, an in-person conversation may not be recorded unless all participants are specifically informed, so patients and companions must be told before an ambient AI scribe captures a visit. SB 1546 (effective January 1, 2027) requires AI-companion operators to disclose that users are talking to AI and to maintain self-harm response protocols, with a private right of action, and HB 2748 (2025) bars AI and other nonhuman entities from using nursing titles. Oregon has no statute specific to AI-generated clinical notes; a 2026 bill on insurers' AI downcoding (HB 4054) did not pass. BastionGPT operates as a clinician-supervised documentation tool within these privacy and notice requirements.

Pennsylvania PA

Two-party recording consent (18 Pa.C.S. § 5701 et seq.)Breach of Personal Information Notification Act (73 P.S. § 2301; Act 33 of 2024 amendments)UTPCPL (73 P.S. § 201-1)Insurance Data Security Act (40 Pa.C.S. § 4501)Consumer Data Privacy Act (HB 78, passed House Oct 2025)HB 1925 — AI in health care & insurance

Pennsylvania's Wiretap Act (18 Pa.C.S. 5701 et seq.) requires the consent of all parties before a conversation is recorded, so an ambient AI scribe may only capture a visit after the patient — and anyone else present — agrees. Pennsylvania has no comprehensive consumer privacy law: HB 78, the Consumer Data Privacy Act, passed the House on October 1, 2025 and was still before the Senate as of late June 2026. The Breach of Personal Information Notification Act, as amended by Act 33 of 2024, requires notice to affected residents and, in some cases, free credit monitoring; insurers must also comply with the Insurance Data Security Act (40 Pa.C.S. 4501–4536). Bills on AI in health facilities and insurance decisions (HB 1925) and on AI in mental-health therapy (HB 1993, HB 2100) were pending and unenacted as of August 2026. BastionGPT has published guidance on consent practices and operates as a clinician-supervised documentation tool within these consent and data-security requirements.

Rhode Island RI

Use of AI by Healthcare Providers Notification Act (R.I. Gen. Laws ch. 23-106, eff. June 22, 2026)Oversight of AI Technology in Mental Health Care Act (H 7349 / S 2197, signed June 22, 2026)Data Transparency & Privacy Protection Act (§ 6-48.1, eff. Jan 1, 2026)Health Care Confidentiality Act (§ 5-37.3)AI Companion Models (S 2195, eff. Jan 1, 2027)Identity Theft Protection / breach (§ 11-49.3)Insurance Data Security (§ 27-1-46)

Rhode Island now directly regulates clinical AI. The Use of Artificial Intelligence by Healthcare Providers Notification Act (R.I. Gen. Laws ch. 23-106, signed June 22, 2026 and effective immediately) requires providers who use AI to document patient visits to notify patients and to review the AI-generated documentation for accuracy, and the Oversight of Artificial Intelligence Technology in Mental Health Care Act (also signed June 22, 2026) bars AI from making independent therapeutic decisions and requires written consent before AI is used to record or transcribe therapy sessions. The Data Transparency and Privacy Protection Act (effective January 1, 2026) adds consumer data rights and consent for sensitive data, while the Confidentiality of Health Care Communications and Information Act continues to govern health information held by providers. A companion-AI disclosure law (S 2195) takes effect January 1, 2027. BastionGPT operates as a clinician-supervised documentation tool designed for the notify-and-review workflow these laws require, and its consent guidance helps practices document the required notice and consent.

South Carolina SC

Physicians' Patient Records Act (§ 44-115-10)Breach Notification (§ 39-1-90)Insurance Data Security Act (§ 38-99-10)Unfair Trade Practices Act (§ 39-5-10)

South Carolina has no comprehensive consumer data privacy law and no statute governing AI in clinical care; a 2026 bill to restrict AI in therapy and psychotherapy (S 788) and chatbot-regulation bills (S 896, H 5138) did not become law. The Physicians' Patient Records Act governs ownership, confidentiality, and release of medical records, and the breach-notification law requires notice to affected residents. Insurers must maintain information-security programs under the Insurance Data Security Act, modeled on the NAIC model law. BastionGPT operates as a clinician-supervised documentation tool within these requirements.

South Dakota SD

Breach Notification (SDCL § 22-40-19)Deceptive Trade Practices & Consumer Protection (SDCL ch. 37-24)

South Dakota has no comprehensive consumer data privacy law and no statute specific to AI in health care; 2026 bills to restrict AI in therapy (HB 1144), require chatbot disclosures (SB 170), and govern insurers' AI coverage determinations (SB 169) were withdrawn or tabled. The breach-notification law (SDCL 22-40-19 et seq.) requires notice to affected residents, and the Deceptive Trade Practices and Consumer Protection chapter supports Attorney General enforcement. South Dakota has not adopted the NAIC Insurance Data Security Model Law; insurers are subject to Division of Insurance safeguards rules. BastionGPT operates as a clinician-supervised documentation tool within these requirements.

Tennessee TN

TIPA (Tenn. Code Ann. § 47-18-3201)SB 1580 / Pub. Ch. 647 — AI may not pose as a mental-health professional (eff. July 1, 2026)ELVIS Act (§ 47-25-1101)Breach Notification (§ 47-18-2107)Insurance Data Security Act (§ 56-2-1001)HB 1866 / SB 2010 — Regulate AI in Health Care Act

Tennessee's Information Protection Act (TIPA, effective July 1, 2025) gives consumers rights of access, correction, deletion, portability, and opt-out (including profiling), requires consent for sensitive data such as health information, and offers an affirmative defense to businesses that maintain a written privacy program reasonably conforming to the NIST Privacy Framework. Public Chapter 647 (SB 1580, effective July 1, 2026) prohibits anyone who develops or deploys an AI system from representing that it is or can act as a qualified mental health professional, enforceable under the Consumer Protection Act with $5,000-per-violation penalties. The ELVIS Act (2024) bars unauthorized AI replication of a person's voice or likeness. Tennessee has no statute governing AI-generated clinical documentation; a broader Regulate AI in Health Care Act remained pending in 2026. BastionGPT operates as a clinician-supervised documentation tool and does not present itself as a mental health professional.

Texas TX

SB 1188 — AI disclosure & record review by practitioners (Health & Safety Code § 183.005, eff. Sept 1, 2025)TRAIGA (HB 149; Bus. & Com. Code § 552.051 health-care AI disclosure; eff. Jan 1, 2026)TMRPA (Health & Safety § 181.001)TDPSA (Bus. & Com. § 541.001)SB 815 — AI in utilization review (eff. Sept 1, 2025)Breach Notification (Bus. & Com. ch. 521)DTPA

Texas now imposes two provider-level AI duties. SB 1188 (effective September 1, 2025) permits health care practitioners to use AI for diagnostic purposes only if they review all AI-created records consistent with Texas Medical Board standards and disclose their use of AI to patients, and requires electronic health records to be stored in the United States from January 1, 2026. The Texas Responsible Artificial Intelligence Governance Act (HB 149, effective January 1, 2026) adds a general duty for anyone providing licensed health care services to disclose, no later than the first date of service, that an AI system is used in relation to the service, alongside prohibitions on manipulative or discriminatory AI and Attorney General enforcement with a 60-day cure period. The Medical Records Privacy Act applies HIPAA-style duties to a broader set of entities, and the Texas Data Privacy and Security Act grants consumer rights and requires consent for sensitive data; SB 815 (2025) bars insurers from relying solely on AI for adverse utilization-review decisions. BastionGPT operates as a clinician-supervised documentation tool consistent with the disclose-and-review workflow these statutes require.

Utah UT

UCPA (Utah Code § 13-61-101)Generative-AI disclosure in regulated occupations (SB 226; § 13-75-103, eff. May 7, 2025)Mental-health chatbot rules (HB 452; § 13-72a-101, eff. May 7, 2025)AI Policy Act (SB 149; § 13-72-101; sunset July 1, 2027)SB 319 — AI in preauthorization (eff. Jan 1, 2027)Breach Notification (§ 13-44-101)

Utah's Consumer Privacy Act gives consumers access, deletion, portability, and opt-out rights for targeted advertising and sales, with notice-and-opt-out treatment of sensitive data. Since May 7, 2025, SB 226 (Utah Code ch. 13-75) requires anyone providing services in a state-licensed occupation — including physicians and mental-health professionals — to prominently disclose, verbally at the start of a spoken interaction or in writing before a written one, when the person receiving services is interacting with generative AI in a “high-risk” interaction such as one collecting health data or delivering medical or mental-health advice; a clear self-disclosure by the AI is a safe harbor. HB 452 (also effective May 7, 2025) separately regulates mental-health chatbots, requiring non-human disclosure and barring sale of health inputs and targeted ads. The original AI Policy Act (SB 149) remains in force until July 1, 2027, and SB 319 (effective January 1, 2027) restricts insurers' use of AI in preauthorization. BastionGPT operates as a clinician-supervised documentation tool; clinicians remain responsible for any required disclosure to patients.

Vermont VT

Vermont Data Privacy & Online Surveillance Act (S.71 / Act 145, eff. Jan 1, 2028)H.816 / Act 156 — mental-health services by professionals, not AI (eff. June 17, 2026)H.814 / Act 101 — neurological rights & AI Advisory Council (2026)Data Broker Regulation (9 V.S.A. § 2446; 2026 amendments)Security Breach Notice Act (9 V.S.A. § 2435)Insurance Data Security (8 V.S.A. § 4728)

Vermont enacted its first comprehensive privacy law in June 2026: the Vermont Data Privacy and Online Surveillance Act (S.71, Act 145) takes effect January 1, 2028 and will give consumers rights to access, correct, delete, and opt out, require consent for sensitive data such as health information, and require data protection assessments. Act 156 (H.816, effective June 17, 2026) provides that mental health services may not be delivered independently by an AI system — only by mental health professionals — while preserving administrative uses such as scheduling, billing, and transcription that support rather than replace clinical judgment; AI-driven therapeutic decision-making is unprofessional conduct. Act 101 (H.814, 2026) recognizes neurological rights, including neural-data privacy, and extends the state's AI Advisory Council. Vermont's pioneering Data Broker Regulation was tightened in 2026, and breaches are governed by 9 V.S.A. § 2435. BastionGPT operates as a clinician-supervised documentation tool — an administrative-support role consistent with Act 156.

Virginia VA

VCDPA (Va. Code § 59.1-575)Health Records Privacy (Va. Code § 32.1-127.1:03)Breach Notification (§ 18.2-186.6)Insurance Data Security Act (§ 38.2-621)SB 269 — AI in mental-health services (continued to 2027)

Virginia's Consumer Data Protection Act was among the first comprehensive state privacy laws, giving consumers access, correction, deletion, portability, and opt-out rights and requiring opt-in consent to process sensitive data such as mental or physical health diagnoses, with data protection assessments for higher-risk processing. Health records held by providers are separately governed by Va. Code § 32.1-127.1:03, breaches by § 18.2-186.6, and insurers by the Insurance Data Security Act. Virginia has no enacted AI-specific health law: the High-Risk AI Developer and Deployer Act (HB 2094) was vetoed on March 24, 2025, and 2026 bills allowing mental-health providers to use AI in therapy with patient consent (SB 269) and requiring insurers to disclose AI use in claims decisions (SB 586) passed the Senate but were continued to the 2027 session. BastionGPT operates as a clinician-supervised documentation tool within Virginia's privacy and health-records requirements.

Washington WA

My Health My Data Act (RCW 19.373)All-party recording consent (RCW § 9.73.030)Uniform Health Care Information Act (RCW 70.02)AI companion chatbots (HB 2225, eff. Jan 1, 2027)SB 5395 — AI in prior authorization (eff. June 11, 2026)Breach Notification (RCW § 19.255)Consumer Protection Act (RCW 19.86)

Washington's My Health My Data Act applies to consumer health data outside HIPAA, requires consent to collect or share such data beyond what is necessary for a requested service and separate authorization to sell it, bans geofencing of health facilities, and is enforceable through a private right of action under the Consumer Protection Act. Washington is an all-party-consent state: under RCW 9.73.030 a private conversation may not be recorded without the consent of everyone present, which may be obtained by announcing the recording to all parties (and capturing that announcement in the recording) — a rule that directly applies to ambient AI scribes. Provider-held records are governed by the Uniform Health Care Information Act (RCW 70.02). In 2026 the state enacted HB 2225 (effective January 1, 2027), regulating AI companion chatbots, and SB 5395 (effective June 11, 2026), barring insurers from relying solely on AI to deny or limit care in prior authorization; there is still no statute specific to AI-generated clinical documentation. BastionGPT's consent guidance is especially relevant here, and BastionGPT operates as a clinician-supervised documentation tool within these consent and health-data requirements.

West Virginia WV

Breach Notification (W. Va. Code § 46A-2A-101)Consumer Credit & Protection Act (§ 46A-6-101)

West Virginia has no comprehensive consumer data privacy law and no statute governing AI in clinical care; a proposed Consumer Data Protection Act (HB 2987) was never enacted, and a 2026 bill to limit AI in mental-health care to administrative support (HB 4770) did not pass. The state's only AI enactment is HB 3187 (2025), which created a Task Force on Artificial Intelligence. Breaches of unencrypted personal information must be disclosed under W. Va. Code § 46A-2A-101 et seq., and the Consumer Credit and Protection Act supports Attorney General enforcement against unfair or deceptive practices. HIPAA therefore remains the primary framework for AI documentation tools in West Virginia. BastionGPT operates as a clinician-supervised documentation tool within these requirements.

Wisconsin WI

Patient Health Care Records (Wis. Stat. § 146.81)Mental Health Treatment Records (§ 51.30)Breach Notification (§ 134.98)Deceptive Trade Practices (§ 100.18)Wisconsin Consumer ActInsurance Data Security (§ 601.95)

Wisconsin has no comprehensive consumer data privacy law and no statute specific to AI in health care; 2025–26 bills to limit AI-driven prior-authorization denials (AB 1109/SB 1066) and to restrict AI chatbots that simulate relationships with children did not pass. Patient health care records are governed by Wis. Stat. 146.81–146.84, which require informed consent for most disclosures, and mental-health treatment records receive additional protection under Wis. Stat. 51.30. Breaches must be reported under § 134.98, insurers must maintain information-security programs under §§ 601.95–601.956, and § 100.18 prohibits deceptive representations. BastionGPT operates as a clinician-supervised documentation tool within these confidentiality requirements.

Wyoming WY

Breach Notification (W.S. § 40-12-501)Consumer Protection Act (W.S. § 40-12-101)

Wyoming has no comprehensive consumer data privacy law and no statute governing AI in clinical care. The breach-notification law (W.S. 40-12-501 et seq.) requires notice to affected residents when personal identifying information is compromised, and the Consumer Protection Act prohibits deceptive trade practices. Wyoming has not adopted the NAIC insurance data-security model law. HIPAA therefore remains the primary framework for AI documentation tools in Wyoming. BastionGPT operates as a clinician-supervised documentation tool within these requirements.

Try BastionGPT free for 7 days

Draft progress notes, letters, and treatment plans in a HIPAA-compliant AI assistant. A signed BAA is included on every plan, and pricing starts at $20 a month.

Start your free trial