Your Patient Intake Chatbot Is Now a Regulated Product: The 2026 AI Compliance Map for Small Medical Practices

Executive Summary

  • The patient facing chatbot your practice added to its website is no longer governed by HIPAA alone. Three separate layers of law now reach it: HIPAA, the Federal Trade Commission, and a fast growing set of state statutes that regulate conversational AI directly.
  • Tennessee’s restriction on AI systems representing themselves as qualified mental health professionals took effect July 1, 2026, and Hawaii’s Artificial Intelligence Disclosure and Safety Act took effect on approval the same month. These sit alongside disclosure laws in California and Texas, licensure and therapy restrictions in Illinois and Nevada, and consumer protection rules for mental health chatbots in Utah. The obligations differ by state and it is a mistake to treat them as one requirement.
  • Pennsylvania has no comprehensive AI statute and sued an AI chatbot operator anyway. On May 1, 2026 the Commonwealth filed suit in Commonwealth Court under the Medical Practice Act, a statute written long before generative AI existed. The absence of an AI law in your state is not protection.
  • Two failure modes account for most of the exposure. The first is impersonation, where a chatbot implies it is a licensed clinician. The second is silence, where a patient is never told they are talking to software. Both are cheap to fix and expensive to ignore.
  • Physician AI use reached 81 percent in 2026 according to the American Medical Association, more than double the 2023 figure. Adoption has outrun governance at nearly every independent practice, and regulators have noticed.

1. What actually changed, and why July 2026 is the line in the sand

Most small practices did not make a decision to deploy artificial intelligence. They bought a scheduling tool, or a website plugin that answers questions after hours, or an intake form that asks follow up questions based on what the patient types. Somewhere in the vendor’s release notes, the words “AI powered” appeared. Nobody at the practice signed off on anything, because nobody at the practice was asked.

That is the honest starting position for most independent clinics, and it is worth saying out loud because the compliance conversation usually begins by assuming a level of intent that never existed. You did not build an AI system. You bought software that quietly became one.

The American Medical Association’s 2026 physician survey found that 81 percent of physicians now use AI in practice, up from 38 percent in 2023, with the average physician reporting 2.3 distinct use cases compared to 1.1 three years earlier. The same survey found 86 percent of physicians pointing to data privacy as a condition for broader adoption and 85 percent wanting direct involvement in decisions about which tools get adopted. Adoption is running well ahead of governance, and the people closest to the work know it.

July 1, 2026 is a useful marker because that is the date Tennessee’s restriction on AI systems holding themselves out as qualified mental health professionals took effect. It is not the biggest law on this list, and Tennessee is not the biggest state. It matters because it lands in the middle of a cluster of statutes that were already in force, and because it signals what state legislatures have decided to regulate first. They are not regulating model architecture or training data. They are regulating what your chatbot says to a patient at the moment of contact.

2. Three layers of law now apply to one chatbot

The mental model that gets small practices into trouble is treating this as a HIPAA question. HIPAA is one layer. It governs protected health information and the vendors who touch it. It has nothing to say about whether your chatbot tells a patient it is a nurse.

The second layer is the Federal Trade Commission, which reaches deceptive and unfair practices generally and which also administers a breach notification rule that applies specifically to health related technology that falls outside HIPAA. The third layer is state law, and this is the layer that changed most in the last eighteen months.

Each layer has a different trigger, a different enforcer, and a different remedy. A single chatbot on a small clinic’s website can sit inside all three at once. The practical consequence is that you cannot answer “is our chatbot compliant” by checking one box. You have to walk the three layers separately.

Layer What triggers it Who enforces
HIPAA Your chatbot vendor creates, receives, maintains, or transmits protected health information on your behalf HHS Office for Civil Rights, plus state attorneys general
Federal Trade Commission Deceptive or unfair claims about the tool, or a breach at a health technology vendor outside HIPAA’s reach Federal Trade Commission
State AI and licensure law What the chatbot says to a patient, whether AI use is disclosed, and whether the tool implies clinical licensure State attorneys general, professional licensing boards, consumer protection divisions, and in some states private plaintiffs

3. Layer one: HIPAA did not change, but your vendor list did

Nothing in HIPAA was rewritten for artificial intelligence. The Privacy Rule and Security Rule apply the same way they always have. What changed is the number of vendors sitting between your practice and your patients’ information, and how many of those vendors arrived without a formal procurement decision.

The governing requirement is straightforward. Under 45 CFR 164.502(e) and 45 CFR 164.504(e), a covered entity may disclose protected health information to a business associate only if it obtains satisfactory assurances, documented in a written contract, that the business associate will appropriately safeguard the information. The contract has to cover permitted uses and disclosures, safeguards, reporting of security incidents, flow down to subcontractors, support for individual rights, availability of records to HHS, and return or destruction of the information at termination.

A chatbot that collects a patient’s name, reason for visit, symptoms, insurance details, or date of birth is handling protected health information. The vendor operating that chatbot is a business associate. If you do not have a signed business associate agreement with that vendor, every disclosure to it is a problem, and the fix is a contract, not a technical control.

GOVERNANCE INSIGHT

“The vendor never sees the data” is not a defense

HHS guidance on cloud computing is explicit that a service provider storing encrypted protected health information is a business associate even when it holds no decryption key and never views the content. The conduit exception is narrow and fact specific, and it was written for services that merely transmit information without persistent storage. If your chatbot vendor retains conversation logs, and nearly all of them do, the retention makes business associate status considerably clearer rather than less so.

There is a second question most practices skip. Where does the model actually run? If your chatbot vendor calls a third party model provider to generate responses, that provider is a subcontractor handling protected health information, and the business associate agreement has to flow down to it. Ask your vendor, in writing, which model providers process patient conversations and whether the vendor has executed agreements with them.

The third question is retention. Ask what happens to conversation transcripts, how long they are kept, whether they are used to improve the vendor’s models, and how they are deleted when you terminate. A vendor that cannot answer these three questions in writing has not thought about HIPAA, which tells you something useful about the rest of its security posture.

4. Layer two: the FTC reaches where HIPAA does not

Practices tend to assume that if HIPAA does not cover something, nothing does. That assumption is wrong, and the Federal Trade Commission is the reason.

The Health Breach Notification Rule at 16 CFR Part 318 requires vendors of personal health records and related entities that are not covered by HIPAA to notify affected individuals, the Commission, and in some cases the media following a breach of unsecured identifiable health information. In April 2024 the Commission finalized amendments that explicitly brought health applications and similar technologies within the rule’s scope, with the changes taking effect July 29, 2024. The amendments also expanded the definition of a breach so that unauthorized disclosure counts, not only a security incident.

This matters for a small practice in a specific way. A wellness portal, a symptom checker, or a patient engagement application that sits alongside your practice but is not operating as your business associate may fall under this rule instead of HIPAA. If it shares data with advertising platforms without authorization, that is a reportable event under the Commission’s expanded definition, and your patients will hear about it whether or not your practice is the party technically on the hook.

Separately, the Commission continues to pursue deceptive claims about artificial intelligence generally under its Operation AI Comply initiative. In July 2026 it proposed a policy statement titled Suppression of Accuracy in Artificial Intelligence Systems, taking the position that an AI system steered toward undisclosed objectives and away from what users reasonably expect is likely deceiving them under Section 5 of the FTC Act. The comment period closes July 31, 2026. That document is interpretive guidance about existing law rather than a new rule with its own penalties, which is precisely why it matters. It tells you how the Commission reads authority it already has.

The direction of travel is clear enough to act on. Claims about what an AI tool does need to be defensible, and that includes claims your vendor makes that you repeat on your own website.

5. Layer three: the state laws now in force

This is the layer that moved. The table below covers the state requirements most likely to reach a patient facing chatbot at a small practice. It is not a complete map of every AI law in every state, and it deliberately excludes the payer side rules governing prior authorization and claims review, which are a separate topic.

State and law What it requires or prohibits In force
California AB 3030 A health facility, clinic, physician’s office, or group practice that uses generative AI to produce written or verbal patient communications about clinical information must include a disclaimer and instructions for reaching a human. Communications read and reviewed by a licensed provider are exempt. January 1, 2025
California AB 489 Prohibits an AI system from using terms, letters, or phrases in its advertising or functionality that imply care or advice is coming from a licensed health care professional. Enforceable by the relevant licensing board. January 1, 2026
Illinois HB 1806, Public Act 104-0054 Therapy and psychotherapy may only be offered by licensed professionals. A licensed professional may not use AI to make independent therapeutic decisions, interact directly with a client in therapeutic communication, or generate treatment recommendations without licensed review. August 1, 2025
Nevada AB 406 Prohibits offering an AI system that provides services constituting the practice of professional mental or behavioral health care, and prohibits representing that an AI system can provide such care. Administrative use is permitted with independent provider review of output. July 1, 2025
Utah HB 452 Regulates mental health chatbots. Requires disclosure of AI use, restricts advertising inside the interaction, prohibits selling or sharing individually identifiable health information collected from users, and requires a documented policy. Enforced by the Division of Consumer Protection. May 7, 2025
Texas HB 149 (TRAIGA) Health care providers must disclose use of an AI system in diagnosis or treatment to the patient or the patient’s representative, before or at the time of the interaction, or as soon as reasonably possible in an emergency. Enforced by the Texas attorney general. January 1, 2026
Tennessee SB 1580 A person who develops or deploys an AI system may not advertise or represent to the public that the system is or can act as a qualified mental health professional. Treated as an unfair or deceptive act under the Tennessee Consumer Protection Act, with a private right of action. July 1, 2026
Hawaii SB 3001, Act 248 Artificial Intelligence Disclosure and Safety Act. Requires an operator to give clear and conspicuous notice that an AI companion is artificial intelligence where a reasonable person would otherwise believe they are interacting with a human, plus crisis response protocols and safeguards for minors. Violations are treated as unfair or deceptive practices. Annual reporting to the Department of Health begins January 1, 2028. On approval, July 14, 2026
Oregon SB 1546 Requires operators of AI companions to disclose that the user is interacting with AI where a reasonable person might think otherwise, with crisis response protocols including referral to the 988 Suicide and Crisis Lifeline and repeated reminders for minors. Enforced only through a private right of action carrying statutory damages of $1,000 per violation plus actual damages and attorney fees. January 1, 2027

One caution on Hawaii. The enrolled text of Act 248 states that the act takes effect upon its approval, which places it in force as of July 14, 2026, while the legislature’s own summary of the measure has described it as taking effect January 1, 2028, the date on which the annual reporting duty begins. The table above follows the enrolled text, which is the controlling document. If Hawaii is a material market for your practice, have counsel confirm the operative date before you rely on either reading.

Two patterns are worth extracting from that table. First, the laws are not symmetric. Some regulate the developer, some regulate the deployer, and several regulate both. Your practice is a deployer, and deployer obligations are the ones that reach you directly. Second, several of these statutes hinge on mental and behavioral health specifically. If your intake chatbot asks about mood, stress, sleep, substance use, or anything that reads as a behavioral health screen, you have moved into the most heavily regulated corner of this map.

6. The impersonation line your chatbot must never cross

Read the statutes side by side and one prohibition appears in nearly all of them. An AI system may not present itself as a licensed clinician. Tennessee bars representing that a system is or can act as a qualified mental health professional. California bars terms and phrases implying licensure. Nevada bars representations that an AI system can provide professional mental or behavioral health care. Illinois restricts therapeutic communication to licensed professionals.

Legislatures converged on this because it is the failure mode with the clearest harm and the easiest proof. A regulator does not need an expert on model behavior to make the case. They need a transcript.

The exposure for a small practice is rarely deliberate. It comes from configuration. Someone in the practice named the chatbot after a person because it felt friendlier. Someone gave it an avatar with a white coat and a stethoscope. Someone wrote a welcome message that says “I’m here to help with your symptoms” and the vendor’s default persona filled in the rest. None of that was a decision to impersonate a clinician, and all of it can read that way in a transcript.

Three concrete controls address most of this. Give the tool a name that is obviously not a person, or if you use a human name, pair it with a persistent label identifying it as an automated assistant. Strip clinical imagery from the avatar and the interface. Then test the system yourself with the questions a worried patient would actually ask, including direct questions like “are you a real doctor” and “are you licensed,” and read what comes back.

That last step is the one practices skip, and it is the one that produces evidence. Run the test, save the transcripts, and keep them. If a regulator ever asks what you did to prevent impersonation, a dated file of test conversations is a far better answer than a policy document nobody executed.

7. The disclosure line: telling patients they are talking to software

The second recurring requirement is disclosure, and the statutes differ on scope in ways that matter operationally.

Texas takes the broadest position among the laws in force. Under TRAIGA, a health care provider using an AI system in the diagnosis or treatment of a patient must disclose that use to the patient or the patient’s representative before or at the time of the interaction, with an emergency exception allowing disclosure as soon as reasonably possible afterward. The obligation sits on the provider, not the vendor.

California takes a narrower but more prescriptive position. AB 3030 applies when generative AI produces patient communications about clinical information, and it specifies the mechanics: a disclaimer plus clear instructions for how the patient can reach a human. The exemption for communications read and reviewed by a licensed provider is the practical escape hatch, and it is worth designing your workflow around it. If a clinician reviews the draft before it goes out, you are outside the requirement.

GOVERNANCE INSIGHT

Disclose once at the top and you will still fail California

AB 3030 sets placement rules, not just a duty to disclose. For a continuous chat interaction the disclaimer must be displayed throughout, not only in the opening message. Audio requires a verbal disclaimer at the start and again at the end. A single line buried in a welcome screen satisfies the instinct and misses the requirement.

For a practice operating in a single state, follow that state’s rule. For a practice that serves patients across state lines, and telehealth means most practices now do, build to the strictest requirement you are exposed to and apply it everywhere. Maintaining separate chatbot behavior by patient location is technically possible and operationally miserable, and it fails the first time someone updates the vendor configuration without checking the geography logic.

Write the disclosure in plain language. “You are chatting with an automated assistant, not a member of our clinical staff. To speak with a person, call us at [number] or reply with the word STAFF.” That sentence carries the core of what the disclosure laws are asking for, and a patient in distress can act on it.

It is a floor, not a finish line. The newer statutes layer additional duties on top of the notice itself. Hawaii and Oregon both require crisis response protocols and specific handling for minors, Oregon requires repeated reminders during a minor’s conversation, and California specifies where the disclaimer has to appear rather than merely that it must exist. Getting the sentence right is the first step. Confirming the timing, repetition, and crisis behavior in each state you serve is the rest of the work.

Getting your AI governance in order

Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001, before regulation forces the issue.

Start the free AI maturity self assessment

8. Pennsylvania proved you do not need an AI law to get sued

If you practice in a state with no AI statute, the reasonable assumption is that none of this applies to you yet. Pennsylvania spent this spring demonstrating why that assumption is expensive.

On May 1, 2026, the Pennsylvania Department of State filed suit in Commonwealth Court against Character Technologies, Inc., the operator of the Character.ai platform. According to the Commonwealth, an investigator from the Bureau of Enforcement and Investigation interacted with a chatbot character presenting itself as a licensed psychiatrist, which supplied a fabricated Pennsylvania medical license number and offered mental health guidance. The Commonwealth alleges the unlawful practice of medicine and surgery and is seeking injunctive relief.

The statute the Commonwealth used is the Medical Practice Act, a licensure law that predates generative AI by decades. Governor Shapiro’s office framed the filing as the first action of its kind announced by a governor and described a broader investigation into AI companion bots, along with a complaint reporting process through the Department of State. The allegations have not been adjudicated and Character Technologies has not been found liable.

The lesson generalizes cleanly. Every state has a medical practice act. Every state has consumer protection law. Every state has professional licensing boards with investigative authority and an interest in defending the scope of licensure. A state does not need to pass an AI statute to reach a chatbot that claims clinical credentials. It needs an investigator with a browser.

For a small practice, the implication is not that enforcement is imminent against you. Regulators are going after platforms first. The implication is that your compliance posture cannot rest on the argument that your state has not legislated. The tools regulators are using are the ones that have been on the books all along.

9. A compliance review you can run in one afternoon

You do not need a consultant to do the first pass. You need an office manager, a list of the tools in use, and about three hours. Work through the following in order and write down what you find, because the written record is itself part of what governance means.

Step one: inventory what is actually running

List every patient facing tool that generates text or holds a conversation. Website chat widget, appointment reminder system, after hours answering service, patient portal messaging, symptom checker, intake forms with conditional logic, translation features. For each one, write the vendor name and what patient information it touches. Most practices find between three and seven tools, and are surprised by at least two of them.

Step two: confirm the paperwork

For every tool on that list that touches protected health information, locate the signed business associate agreement. Not the vendor’s marketing page claiming HIPAA compliance. The executed agreement. If you cannot find it, request it in writing today and note the date you asked.

Step three: ask the three vendor questions

Send each vendor the same short email. Which model providers process our patient conversations, and do you have agreements in place with them? How long do you retain conversation transcripts, and are they used to train or improve models? What is your deletion process when we terminate? Keep the replies. If a vendor will not answer in writing, that is your answer.

Step four: run the impersonation test

Open each tool as a patient would and ask directly whether it is a doctor, whether it is licensed, and whether it can tell you what is wrong with you. Then ask a mental health question, because that is where the statutes bite hardest. Save the transcripts with the date.

Step five: check the disclosure and the exit

Confirm that each tool tells the patient it is automated, that the notice persists through the conversation rather than appearing once, and that there is an obvious path to a human being. Then use that path yourself and time how long it takes to reach a person.

Step six: fix the crisis path

Type a message indicating distress and see what happens. A patient facing tool at a medical practice that responds to a statement about self harm with a scheduling prompt is a serious problem regardless of which state you are in, and several of the newer statutes address exactly this scenario. Confirm the tool escalates, provides crisis resources, and does not attempt to counsel.

Step seven: write it down and set a review date

Two pages is enough. What tools you use, what each one does, what you verified, what you fixed, who owns it, and when you will look again. Ninety days is a reasonable review interval given how fast vendors ship changes. This document is what turns a good afternoon into a governance program.

10. What lands in 2027, and what to do before then

The obligations already on the calendar are worth planning around rather than reacting to. Oregon’s requirements take effect January 1, 2027, and Oregon is the outlier worth watching closely. It is enforced through a private right of action rather than by the attorney general, with statutory damages of $1,000 per violation plus actual damages and attorney fees. That changes the enforcement dynamic considerably, because a plaintiff does not need a regulator to act first and does not need to prove financial loss. Hawaii’s annual reporting duty to the Department of Health begins January 1, 2028, though the substantive disclosure and crisis protocol requirements are already operative under the enrolled text.

Holland and Knight’s review of 2026 state health AI legislation identifies conversational AI safety acts in Idaho and Nebraska taking effect July 1, 2027, along with an Arizona behavioral health board requirement for informed consent before providing AI involved services, also effective January 1, 2027. The same review documents a parallel wave of payer side rules constraining how insurers use AI in prior authorization and claims decisions, including an Indiana measure effective July 1, 2026. Those payer rules do not regulate your chatbot, but they will change how your denials arrive, and practices should watch them for that reason.

The through line across all of it is that the disclosure and impersonation requirements are converging. Different states, different drafting, same two obligations. That is unusually good news for a small practice, because it means the work is not fifty separate compliance projects. Build a patient facing AI standard that satisfies the strictest version of both requirements, apply it uniformly, document that you did, and you will be substantially compliant across the map without tracking every bill.

What you should not do is wait for your state to legislate. Pennsylvania settled that question. The licensure statutes and consumer protection laws already on the books are sufficient, and the practices that get caught out will not be the ones that read a new AI law too slowly. They will be the ones that never looked at what their chatbot was saying.

Talk to Ross about your AI governance needs

Every business has different AI governance requirements. Let us talk about yours.

Contact Dynamic Comply

About the author

Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.

Related articles

  • The HIPAA and AI Scribe Compliance Gap: What Independent Medical Practices Need to Know
  • Medical Practice AI Vendor Due Diligence: A 12 Point Checklist When You Have No IT Department
  • AI Use Policy for a 10 Person Medical Practice: What to Include and What to Skip
  • Illinois SB 315 Explained: The First State AI Audit Law and What It Means for Your Business

This article is provided for general informational purposes and reflects the state of the law as of July 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.

Leave a Reply

Your email address will not be published. Required fields are marked *