Healthcare AI

Healthcare AI Compliance Briefing

JPM 2026 Healthcare AI Compliance: State AI laws, consent litigation, HIPAA gaps, and what governance committees are asking. Essential for JPM attendees.

15 min read
Joe Braidwood
Joe Braidwood
CEO, GLACIS
15 min read

Executive Summary

Healthcare AI enters late 2026 facing changing regulatory dates, unresolved litigation, and system-specific buyer diligence. This briefing covers several issues relevant to healthcare conversations:

  • State AI laws: Colorado replaced its AI Act with a new ADMT transparency law (SB 26-189); compliance begins January 1, 2027, so the runway to prepare is now
  • Consent litigation: a pending Sharp HealthCare complaint illustrates allegations to investigate, not settled law
  • HIPAA diligence: BAA scope, permitted uses, data flows, safeguards, and model-development terms are deployment-specific
  • Buyer review: some committees ask for operational records alongside policies and assurance reports

Regulatory Timeline: 2025 to 2026

Healthcare AI faces a compressed compliance window. Here’s what’s coming and when:

FDA Lifecycle Guidance Remains Draft

FDA’s January 2025 guidance on AI-enabled device software functions remains draft and not for implementation. Separately, FDA finalized its guidance on predetermined change control plans for AI-enabled device software functions on August 18, 2025. Teams should not treat the broader lifecycle draft as final policy.

January 1, 2027: Colorado ADMT Law Compliance Begins

Colorado’s original AI Act (SB 24-205) was repealed and replaced by SB 26-189, “Automated Decision-Making Technology,” signed May 14, 2026. The earlier “high-risk AI system” framework gives way to transparency and disclosure duties for covered automated decision-making technology used to materially influence a consequential decision, including health-care services. Substantive compliance commences January 1, 2027 (the prior June 30, 2026 date no longer applies).

EU AI Act: Enacted Omnibus Dates

The AI Omnibus entered into force on July 27, 2026. Relevant Annex III high-risk obligations apply from December 2, 2027; relevant Annex I product-embedded obligations apply from August 2, 2028. US organizations whose systems or outputs fall within the Act’s territorial scope should assess the EU obligations separately.

2026 to 2027: State-Law Patchwork

State requirements differ materially and their status changes frequently. Healthcare teams should verify enacted law, effective dates, scope, and agency guidance jurisdiction by jurisdiction rather than assuming other states follow Colorado’s model.

Key Insight for JPM

Implementation time depends on system inventory, operator role, existing controls, evidence gaps, and the obligations that apply. Colorado’s SB 26-189 has substantive compliance beginning January 1, 2027, so teams should establish applicability and map their current controls without relying on a generic program duration.

Ambient AI scribes have become one of healthcare’s most widely-adopted AI categories. They also became a significant liability exposure in 2025.

Sharp HealthCare: pending complaint, not precedent

Saucedo v. Sharp HealthCare is a putative-class complaint filed 26 November 2025. The public court index lists Sharp Rees-Stealy, SharpCare, and Sharp Community Medical Group entities as defendants; Abridge is not listed as a defendant. Secondary reporting describes the following allegations, which are not adjudicated facts:

Hypothetical damages, unresolved case

A multiplication of an alleged encounter count by a cited statutory amount can produce a large hypothetical number, but it is not a judgment or verified exposure. Liability, per-violation treatment, damages, class certification, defenses, and even the underlying facts remain questions for the court. This review did not verify a public merits or class-certification ruling as of August 26, 2026.

The emerging “capability test”

In a 2025 order denying a motion to dismiss in Ambriz v. Google LLC, the Northern District of California applied a “capability test” at the pleading stage. The court found the plaintiffs had adequately alleged that Google was technologically capable of using the call data for an independent purpose. The order did not adjudicate liability.

Google’s terms, as alleged in that case, helped support an inference of technical capability because they contemplated use with a business customer’s permission. That fact pattern does not make a contractual reservation alone an automatic CIPA violation; consent, product operation, the applicable statutory clause, defenses, and later rulings still matter.

HIPAA’s AI Blind Spots

HIPAA was written for fax machines and filing cabinets. While its principles apply to AI, significant gaps exist:

BAA Coverage Gaps

Risk Area Standard Cloud BAA AI-Specific BAA
Model training on PHI Not addressed Explicit prohibition or consent requirement
Inference logging Basic access logs only Full input/output audit trail
Subprocessor AI models Generic subprocessor clause Named models, version control
Hallucination liability Not addressed Accuracy disclaimers, liability allocation
Breach definition Standard PHI breach Includes AI-specific incidents (bias, manipulation)

The Audit Trail Problem

HIPAA’s Security Rule requires mechanisms that record and examine activity in information systems containing or using ePHI. It does not prescribe one universal AI log. A system-specific risk analysis may support events such as:

Whether native service logs are sufficient depends on the approved oversight purpose, complete data path, and risk analysis. Copying prompts or outputs into a log can expand the PHI footprint; no log by itself proves compliance.

What Governance Committees Are Asking

Health-system review practices vary by organization and use case. Policies and independent assurance reports remain relevant; some reviewers also request system-specific operational records.

The New Questions

Questions worth preparing for include:

  1. “Can you demonstrate that PHI was not used to train your model?” Reviewers want technical evidence, not a policy statement.
  2. “What happens if your AI hallucinates clinical information?” Committees are looking for incident response, not just disclaimers.
  3. “What records show what a configured content filter reported for a specific patient interaction?” This is the operational evidence question.
  4. “What’s your consent workflow for AI-assisted documentation?” Requirements depend on jurisdiction, technology, and workflow.
  5. “How will you comply with state AI disclosure requirements?” The question points at regimes like Colorado’s new ADMT transparency law.

From Attestation to Evidence

A strong diligence package connects policy and system design to records from operation without claiming that one artifact is sufficient. Depending on the reviewer, useful material may include:

Operational records can help close a diligence gap, but a valid signature only preserves the presented claim and signer attribution. It does not establish complete coverage, source truth, control effectiveness, safety, or compliance.

Ambient AI Scribe: The 2025 Flashpoint

Ambient AI clinical documentation is a prominent healthcare use case with material privacy, consent, clinical, procurement, and operational questions. Adoption and risk posture vary across organizations.

The Consent Challenge

In California and other “all-party consent” states, recording a conversation without all parties’ consent is illegal. Doctor-patient conversations have heightened protection as “confidential communications.”

Yet many ambient AI deployments rely on:

The Sharp complaint illustrates why teams should analyze consent, notice, documentation, and vendor data flows for the actual jurisdiction and workflow. It does not establish a universal per-encounter consent rule or an adjudicated standard.

Best Practice Framework

Ambient AI Consent Checklist

  • ☐ Written consent form specific to AI recording (not general treatment consent)
  • ☐ Consent obtained before recording begins, not retrospectively
  • ☐ Consent captured in EHR with timestamp
  • ☐ Patient can review and request deletion of recordings
  • ☐ Clear disclosure of what AI does with the recording
  • ☐ Opt-out doesn’t affect care quality

Talk to us about one healthcare AI workflow

We help healthcare AI vendors and health systems connect intended supervision to bounded, independently verifiable operational evidence.

Recommendations for 2026

For Healthcare AI Vendors

  1. Upgrade your BAA. Standard cloud BAAs don’t cover AI-specific risks. Work with counsel to add model training prohibitions, inference logging requirements, and AI incident definitions.
  2. Build bounded operational evidence. For in-scope interactions, preserve signed records of the configured control outcomes reported so a reviewer can check integrity and key attribution for covered fields. Do not present those checks as proof of effectiveness, complete capture, or compliance.
  3. Prepare for state AI laws. Map your products against Colorado’s new ADMT transparency framework (SB 26-189) and other emerging state regimes. Identify where your technology could materially influence a consequential decision, and stand up the notice, disclosure, and human-review workflows those laws expect.
  4. Document consent workflows. For ambient AI, create auditable consent capture that can withstand litigation discovery.

For Health Systems

  1. Audit existing AI deployments. Particularly ambient scribes. Verify consent procedures meet CIPA/CMIA requirements.
  2. Strengthen vendor diligence. Add AI-specific questions to security questionnaires. Require evidence, not just attestations.
  3. Establish AI governance. If you don’t have a formal AI governance committee, create one. If you do, update its charter for 2026 requirements.
  4. Plan for state law compliance. Colorado’s new ADMT law (SB 26-189) reaches technology used to materially influence consequential decisions, including health-care services. Map your exposure ahead of the January 1, 2027 compliance date.

Related Resources