Artificial intelligence (AI) is becoming increasingly integrated into healthcare, raising important questions for providers and medical practices about how to adopt these tools responsibly while managing the legal and regulatory risks associated with their use.
At the 2026 Virginia Association of Hematologists and Oncologists (VAHO) Fall Conference, I presented on key regulatory considerations surrounding the use of AI across the clinical workflow, including data privacy and security, consent and patient autonomy, and professional liability. As AI technologies continue to evolve, providers should understand how existing legal requirements apply and remain attentive to emerging AI-specific laws and regulations.
Below are five key takeaways I shared for medical practices evaluating or currently using AI technologies.
1. Know What AI You Are Using, Including What Is Already Built In
AI is being used across a wide range of clinical and operational functions. Managing AI-related risk requires knowing where and how AI is being used within an organization. This means looking beyond stand-alone products, such as AI scribes or clinical decision-support tools, to AI-enabled features that may be embedded in existing software and systems.
Importantly, the legal and compliance considerations vary depending on how AI is used and how a particular tool functions. Healthcare organizations should therefore establish clear responsibility for identifying, evaluating, approving, and monitoring AI tools on an ongoing basis.
2. Understand Where Patient Information Goes and What Vendors Do With It
When patient information enters an AI tool, existing privacy and security obligations, including those under the Health Insurance Portability and Accountability Act (HIPAA), where applicable, continue to apply. AI tools may involve substantial amounts of sensitive patient information flowing through third-party platforms, making it critical to understand where that information goes and how it is used, stored, and protected. This includes evaluating whether vendors have appropriate safeguards in place to protect patient information and address AI-related security risks.
Vendor contracts are a key starting point for this analysis. Healthcare organizations should understand whether vendors may use patient information for purposes beyond providing the service, such as model training, what data they retain, and what happens to that data when the relationship ends. Where a vendor is acting as a business associate, a HIPAA-compliant business associate agreement (BAA) is required. However, a signed BAA should not be viewed as a substitute for understanding the vendor’s data practices, including whether its uses of patient information are permissible.
3. Evaluate What the Patient Needs to Know
There is currently no single, uniform rule requiring disclosure every time AI is used in patient care. Whether disclosure or consent is required or appropriate may depend on several factors, including applicable state law, the function the AI tool performs, the degree to which it affects patient care, and whether the patient has a meaningful choice.
Notably, states are increasingly regulating the use of AI in healthcare, and their approaches vary. For example, a growing number of states have adopted laws requiring patient disclosure when AI is used in certain healthcare settings, including for clinical decision-making and documentation of patient encounters. Separately, existing state recording and wiretapping laws may also apply when tools, such as AI scribes, capture patient conversations. Because these requirements vary by jurisdiction, it is important to evaluate applicable disclosure, consent, and recording requirements on a state-by-state basis.
The analysis should not necessarily end with what the law expressly requires. If patient information will be used beyond the immediate service, such as for model training or product development, providers should also consider whether those uses are consistent with what patients have been told and how they would reasonably expect their information to be used.
4. Maintain Human Oversight
The use of AI does not automatically shift the treating provider’s professional responsibility to the technology or its vendor. AI-generated outputs may be incomplete, inaccurate, or misleading while still appearing plausible, underscoring the importance of appropriate human oversight. AI may support clinical decision-making, but it does not replace the provider’s professional judgment. Providers remain responsible for evaluating AI-generated information and determining whether and how to rely on it when providing patient care.
These principles also intersect with the applicable standard of care. The use of AI may not, by itself, establish compliance with or deviation from the applicable standard. However, expectations surrounding its use may change as AI technologies become more widely adopted and integrated into routine clinical practice. Healthcare providers should continue to monitor developments in professional guidance, clinical practice, and applicable law.
5. Make Sure Your Safeguards Match the Risk
Not every use of AI presents the same level or type of risk. The safeguards surrounding an AI tool should reflect how the technology is being used, the information it handles, and the potential impact on patient care. Higher-risk applications may warrant more robust review, oversight, and controls than tools used for routine administrative functions.
Risk management also requires evaluating what happens if an adverse event occurs in connection with the use of AI in patient care. This includes understanding how existing professional liability insurance policies apply to AI-assisted care, as well as how vendor contracts allocate responsibility and financial risk between the parties.
How Frier Levitt Can Help
Frier Levitt attorneys advise healthcare providers and organizations on the adoption and use of AI technologies, including data privacy and security requirements, patient disclosure and consent obligations, professional liability considerations, AI governance and compliance processes, vendor contracting, and applicable state laws and regulations. Contact Frier Levitt to discuss how your organization can navigate the evolving legal and regulatory landscape as AI becomes increasingly integrated into clinical and administrative workflows.