Patient concerns and new regulations are set to affect HIPAA compliance procedures
As the use of AI becomes prevalent across the healthcare industry, States are moving quickly to establish new rules around transparency, patient consent, and the use of AI during clinical treatments. In 2026, this dynamic accelerated, with several States introducing laws governing the way that healthcare providers use and disclose AI interventions.
In April 2026, the State of Maine enacted law LD 2082 on Regulating the Use of Artificial Intelligence (AI) in Providing Certain Mental Health Services. It was the first of several State laws to pass in a matter of a few months. Rhode Island’s governor signed House Bill 7538 on June 22 requiring healthcare providers and healthcare facilities to inform patients of the use of AI to memorialize patient visits. Louisiana’s Act 649, requires providers to disclose AI-recording at medical visits.
These developments have precedents beginning with the States of Illinois and Nevada in 2025. Texas has required practitioners to disclose the use of AI to patients since September of that year, with a broader duty added in January 2026.
While the precise text of state laws are different, their consequences are the same for mental health practitioners and practices. In short, before an AI tool records, transcribes, or writes up a therapy session, staff must alert the patient. Under certain mental health statutes, the patient must also agree in writing.
Why practices elsewhere should care
Many therapists do not practice in Maine, Rhode Island, or Louisiana. Nevertheless, but there are three reasons why the laws might still affect them.
The first applies to telehealth consultations. Maine law covers a patient in Maine, irrespective of who the therapist is or where they are licensed. The same applies in Illinois and Rhode Island. That means a multi-State, telehealth practice falls under these statutes, whether they are aware of it or not.
The second reason is due to the court actions. In California, patients have filed class action suits against Sutter Health, MemorialCare and Sharp HealthCare over the use of “AI scribes.” They claim that these systems recorded clinical conversations without the patient’s consent. The cases are being fought under wiretap and State privacy laws rather than something AI-specific. However, once State legislatures define “adequate consent” as affirmative, written, and not buried in a terms document, that will open an additional pathway to litigation.
The third reason is about “who carries the duty?” In every one of these statutes, licensed professionals or their facilities have an obligation to inform their patients. Their procedures must also include steps to obtain consent, and to review consultation notes. A HIPAA business associate agreement with an AI software vendor does not discharge their obligation. Legal experts commenting on the 2026 laws have made the same point – when something goes wrong, the exposure rests with whoever deployed the tool, not the organisation selling it.
How can mental health practices prepare for these AI regulatory changes?
Our advice is to treat AI regulations as a workforce compliance training issue first and foremost. HIPAA policies, consent forms, and vendor contracts are all necessary. However, vulnerabilities can arise in conversations with staff members at the front desk, or at the start of a therapy session. If the therapist cannot explain what the AI tool does and cannot obtain valid consent from the patient, the practice is exposed regardless of what supporting compliance documents are designed to achieve.
Standard HIPAA training is insufficient where the content is outdated because it usually addresses only the privacy and security rules, and breach notifications. We recommend that practices add the following to their workforce compliance training now, ahead of legislation in their own State.
- Disclosure. Staff should state plainly that the session is recorded, that a transcript is produced, where it is held, and for how long.
- Consent. Staff should obtain a specific written agreement before the first recorded session. This is separate from intake documentation and includes an option to decline, without affecting care.
- Accountability. A business associate agreement governs the vendor’s handling of PHI. It does not transfer the practice’s duty to inform, to obtain consent, or to review output.
- Review. Treat AI-generated notes as drafts until a clinician has read, corrected, and approved them.
- Jurisdiction. For telehealth consultations, the applicable law is the client’s State, not that of the practice.
ComplianceJunction’s HIPAA + AI Guardrails course covers each of these important points. We have designed this training to sit alongside our core HIPAA training course. More than half of the programmes we train currently include this new and evolving HIPAA training extension.
Signposts about the use of AI in healthcare point in a clear direction. Several states have shown the way, and the regulatory bar is rising quickly. Rather than waiting for a patchwork of State requirements to emerge, healthcare practices should prepare now by training staff to the live up to strongest standards already in force thereby creating a consistent approach to AI use, patient transparency, and privacy across their organization.


