Healthcare AI 2026

Last Updated August 05, 2026

USA

Law and Practice

Authors



Jones Walker LLP is among the largest law firms in the United States, with more than 350 lawyers across the Southeast and other strategic locations, including Miami, New York City, and Washington, DC. Led by a core group of veteran healthcare lawyers, the firm’s healthcare industry team includes lawyers from all the firm’s major practice areas, who all have extensive experience in specific practice areas, as well as in-depth knowledge of today’s healthcare marketplace and regulatory environment. The firm’s attorneys have a deep understanding of the technologies that constitute the world of AI, including generative AI, machine learning, natural language processing, large language models (LLMs), and neural networks. This knowledge enables the firm to better help its clients navigate this complex world, mitigate risks, be strategic, and develop approaches to differentiate themselves.

Healthcare artificial intelligence (AI) now spans nearly every corner of US medical practice, and the catalogue of authorised applications grows each year. The US Food and Drug Administration (FDA) maintains a public inventory of AI- and machine learning (ML)-enabled medical devices that, by the agency’s most recent data updates, had surpassed 1,250 cumulative authorisations. The devices authorised in 2025 alone represent the agency’s highest single-year total on record.

Adoption has likewise crossed a threshold: In the American Medical Association’s (AMA) 2026 physician survey, 81% of responding physicians reported using AI tools professionally, more than double the rate the AMA recorded when it first posed the question in 2023.

The principal categories of clinical and operational AI remain the following:

  • Diagnostic Applications: Diagnostics, particularly medical imaging, remain the largest category by a wide margin; radiology has historically accounted for roughly three-quarters of all authorised AI/ML devices. These systems help clinicians interpret X-rays, MRIs, CT scans, and pathology slides, and to triage urgent findings.
  • Clinical Decision Support (CDS): AI-powered CDS tools analyse electronic health records, laboratory values, and clinical guidelines to flag risks, suggest protocols, and surface drug-interaction warnings within existing workflows.
  • Therapeutic and Treatment Planning: ML systems process genetic, historical, and treatment-response data to support individualised dosing, surgical planning, and rehabilitation pathways.
  • Ambient Clinical Documentation: Tools that listen to a patient encounter and draft the clinical note have moved, in barely two years, from niche pilots to mass deployment across major health systems – emerging as the breakout commercial category of healthcare AI.
  • Remote Patient Monitoring (RPM): Wearables, sensors, and connected devices track vital signs, adherence, and disease progression outside traditional settings, enabling earlier intervention.
  • Drug Discovery and Development: Pharmaceutical developers use AI for target identification, molecular modelling, and clinical-trial optimisation.
  • Administrative and Operational Applications: Revenue-cycle management, prior authorisation, coding, scheduling, and resource allocation are increasingly automated, including by generative tools.

Adoption remains uneven, with large health systems and academic medical centres leading and smaller or rural providers following as reimbursement, infrastructure, and governance capacity allow.

The benefits driving adoption are by now well established: improved diagnostic accuracy, greater clinical efficiency, relief for an overstretched workforce, expanded access to specialist-level insight in underserved areas, and cost savings through better resource use. The clearest recent evidence of workforce benefit comes from ambient documentation, where a multi-system study found that clinician burnout among ambulatory users fell from roughly 52% to 39% after thirty days of use.

The countervailing challenges have sharpened over the past year:

  • Data Privacy and Security: AI systems require access to large volumes of sensitive patient information, complicating compliance with the Health Insurance Portability and Accountability Act (HIPAA) and expanding the attack surface for cyber-threats.
  • Consent and Disclosure in Practice: The same ambient tools that reduce burnout have generated the year’s most significant new litigation exposure, with class actions alleging that patient conversations were recorded without the consent that state law requires. The gap is rarely in the vendor contract; it is in consent workflows that exist on paper but fail in the exam room.
  • Algorithmic Bias and Health Equity: AI trained on non-representative data can entrench disparities. A widely cited review of 692 FDA-authorised AI/ML devices found that only 3.6% reported race or ethnicity data, 99.1% reported no socioeconomic data, and 81.6% did not report subject age.
  • Clinical Integration: Interoperability friction, training needs, and change management continue to slow deployment.
  • Regulatory Whiplash: Where 2025 was defined by regulatory uncertainty, 2026 has been defined by collision – aggressive federal deregulation running directly against accelerating state regulation, leaving multi-state organisations to comply with both at once.

Capital has concentrated decisively around AI. US digital health start-ups raised roughly USD14.2 billion in 2025 – the sector’s strongest year since 2022 – with AI-focused companies capturing about 54% of total funding and commanding a premium on deal size. Mega-deals above USD100 million accounted for some 42% of all funding, the highest concentration since 2021, even as roughly a third of rounds were flat or down: a widening divide between AI-native winners and the rest of the field.

The principal market forces are the following:

  • Technology and Foundation-Model Companies: Major platform and foundation-model developers have entered healthcare directly with dedicated clinical and consumer offerings, alongside established players in cloud and enterprise health IT.
  • Health-System and Academic Leadership: Large systems and academic medical centres continue to serve as proving grounds, building internal governance and expertise that smaller providers later adopt.
  • Private Equity Consolidation: PE firms have pursued roll-up strategies pairing legacy healthcare-services businesses with AI-native technology.
  • Industry Standard-Setting Collaborations: The Coalition for Health AI (CHAI) has become a central convener. Its partnership with the Joint Commission, announced in mid-2025, produced the first formal responsible-AI guidance from a US accrediting body in September 2025, followed by a set of governance playbooks in 2026 and a forthcoming voluntary Joint Commission AI certification open to its more than 22,000 accredited organisations.

Ambient documentation has been the breakout commercial category, attracting some of the year’s largest venture rounds – a success that, as noted above, goes hand in hand with its litigation exposure.

No Single Federal Definition

The United States still lacks one comprehensive, cross-agency definition of healthcare AI. Different federal bodies adopt context-specific definitions tied to their own mandates, and AI is generally regulated through existing medical-device, privacy, and consumer-protection frameworks rather than a dedicated AI statute.

FDA Classification

The FDA regulates most clinical AI under its medical-device authority, treating qualifying software as “software as a medical device” (SaMD). The agency’s device paradigm was built for static products, which continues to create friction for adaptive, continuously learning algorithms. Classification turns on intended use: diagnostic and therapeutic systems face device regulation (therapeutic systems most stringently), while purely administrative tools generally fall outside device regulation but remain subject to privacy and other rules.

The Deregulatory Shift and the Generative Frontier

Over the past year the FDA’s posture has moved visibly toward deregulation of lower-risk software (see 2.4 Software as a Medical Device (SaMD)). On the generative frontier, the agency has still not authorised a device built on a purely generative architecture, though the boundary is being actively tested – the FDA cleared its first foundation-model-powered clinical AI in early 2025 and convened its Digital Health Advisory Committee in late 2025 to examine generative AI-enabled mental health devices.

Federal Medical-Device and Cybersecurity Law

The Federal Food, Drug, and Cosmetic Act (FFDCA) supplies the foundational framework for AI that meets the device definition. The 21st Century Cures Act drew the line between regulated device software and exempt low-risk functions, and the Consolidated Appropriations Act of 2023 (Section 524B) requires cybersecurity information in pre-market submissions for connected “cyber devices”.

Health-Information Privacy

HIPAA and the HITECH Act govern protected health information (PHI) used in AI systems; the introduction of AI does not alter the underlying rules on permissible use and disclosure, and vendors processing PHI must operate under business associate agreements (BAAs).

The Federal Pivot to Deregulation and Pre-Emption

The Biden administration’s AI executive order (EO 14110) was rescinded on the first day of the current administration. In its place, the administration issued Winning the Race: America’s AI Action Plan in July 2025 – some ninety recommendations oriented toward accelerating innovation – and, on 11 December 2025, an executive order titled Ensuring a National Policy Framework for Artificial Intelligence. That order seeks to establish a “minimally burdensome” national approach and to push back against state AI regulation through a Department of Justice AI Litigation Task Force, directives to federal agencies to develop potentially pre-emptive standards, and conditions on certain federal funding. Critically, the order does not by itself nullify state law: state statutes remain enforceable while the inevitable constitutional challenges proceed.

State Law

With Congress largely on the sidelines, states have become the primary source of new healthcare AI law. By the AMA’s count, fourteen states enacted health AI legislation in 2025, and dozens of clinical-AI bills have been introduced across roughly two dozen states in 2026. The most consequential enacted measures include the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), effective 1 January 2026, which requires providers to disclose AI use in diagnosis or treatment; California’s AB 489 (also effective 1 January 2026), barring AI tools from implying they hold a healthcare licence, building on the state’s AB 3030 and SB 1120; and Illinois’s Wellness and Oversight for Psychological Resources (WOPR) Act, which bars AI from independently delivering therapy. Colorado’s first-in-the-nation comprehensive AI Act (SB 24-205) was repealed and replaced in 2026 by a narrower, disclosure-focused statute that takes effect on 1 January 2027 – a notable retreat from the original risk-management-and-impact-assessment model.

Anti-Discrimination

The Section 1557 final rule under the Affordable Care Act requires covered entities to identify and mitigate discrimination risks in patient-care decision-support tools, with the relevant obligations effective in 2025; enforcement priorities under the current administration, however, remain uncertain.

Autonomous Prescribing

The Healthy Technology Act of 2025 (H.R. 238), which would let FDA-authorised, state-permitted AI qualify as a prescribing “practitioner”, remains in committee and has not advanced.

FDA Pre-Market Pathways

Developers navigate the established device pathways according to risk: the 510(k) notification (substantial equivalence to a predicate, the route for most AI devices); de novo classification (novel low-to-moderate-risk devices without a predicate); and pre-market approval (PMA, for the highest-risk systems, requiring clinical trials). Breakthrough device designation offers enhanced engagement and expedited review for qualifying technologies.

Predetermined Change Control Plans (PCCPs)

The PCCP mechanism – now operative under finalised guidance – is the agency’s central accommodation for adaptive AI. A cleared PCCP lets a manufacturer pre-specify, validate, and implement defined modifications without a new marketing submission, provided changes stay within the authorised envelope.

Evidence and the Deregulatory Tilt

Evidence requirements scale with risk, with growing emphasis on real-world evidence and post-market monitoring. The FDA’s leadership has signalled a deliberately “deregulatory direction”, including plans to eliminate a substantial share of its software and digital-health guidance documents and to lean more heavily on post-market surveillance than on pre-market review.

The Unfinished Cornerstone Guidance

The FDA’s January 2025 draft guidance on life cycle management and marketing submissions for AI-enabled device software functions – widely expected to anchor AI device regulation – has not been finalised and currently sits on the agency’s lower-priority guidance list for the fiscal year. Its eventual scope and timing remain open questions.

What Has Moved

Several adjacent developments are now settled. The PCCP guidance is final and operative. In January 2026 the FDA issued final guidance on clinical decision support software and on general wellness and low-risk products that narrows active oversight of many lower-risk digital-health tools, pulling certain wearables and decision-support functions out of device regulation. Separately, the Quality Management System Regulation (QMSR), harmonising US device-quality requirements with international standards, took effect on 2 February 2026.

Continuous Learning and Generative Systems

The core technical challenge persists: a framework designed for fixed devices must accommodate systems that evolve after authorisation and, increasingly, systems that generate content. Transparency, explainability, representative training data, and robust post-market surveillance remain the agency’s recurring expectations for AI-based SaMD.

The HIPAA Baseline

HIPAA’s Privacy and Security Rules continue to govern AI systems that touch PHI. Core obligations carry over directly: apply the minimum-necessary standard even though AI models prefer large datasets; meet de-identification standards and guard against re-identification; and bind vendors through BAAs that address AI-specific risks such as algorithm updates, data retention, and ML processing. Data governance is treated in detail in Section 6.

The Stalled Security Rule Overhaul

The most significant proposed change to healthcare data security in two decades – which would mandate encryption of PHI at rest and in transit, multifactor authentication, regular vulnerability scanning and penetration testing, and the incorporation of AI tools into required risk analyses – remains in limbo. It drew roughly 4,745 comments and organised opposition from more than 100 hospital and provider organisations urging withdrawal, and the Office for Civil Rights’ (OCR) spring 2026 target for a final rule passed with nothing published. Prudent organisations are nonetheless treating the proposed controls as a description of reasonable security, because regulators, insurers, and plaintiffs increasingly do. Separately, HIPAA civil monetary penalties were inflation-adjusted in early 2026, with the annual cap for the most serious violation category now approaching USD2.2 million.

Where Privacy Enforcement Actually Moved – the Courts

The year’s decisive privacy developments came not from HIPAA rulemaking but from state-law litigation over ambient documentation tools. Proposed class actions filed against major California health systems allege that AI scribes recorded patient encounters without the all-party consent required under state wiretapping and medical-confidentiality statutes. Because the vendors operate under BAAs, HIPAA compliance is not the gap; the exposure runs through state consent law and through disclosure practices that fail at the bedside. Organisations deploying ambient AI should treat genuine, documented patient consent as a first-order obligation rather than a template setting.

Core Interoperability Standards

The Health Level Seven International (HL7) Fast Healthcare Interoperability Resources (FHIR) standard remains the backbone for exchanging data between AI systems and electronic health records, alongside established API and workflow-integration protocols. The FDA recognises consensus standards from bodies such as ASTM International, IEEE, and ISO addressing AI safety, performance, cybersecurity, and quality-management processes, and the National Institute of Standards and Technology (NIST) publishes widely used AI risk-management and cybersecurity frameworks.

A Renamed, Deregulatory Health-IT Regulator

The Office of the National Coordinator for Health Information Technology now operates as the Assistant Secretary for Technology Policy/ONC (ASTP/ONC). In late 2025, it proposed the HTI-5 rule, a deliberately deregulatory measure that would withdraw unfinished portions of the prior administration’s interoperability proposals, scale back certification burdens, advance FHIR-based APIs, and update definitions to encompass automated and AI-driven data exchange. The proposal reflects the same innovation-first posture visible across the federal government.

Voluntary Frameworks Gaining Weight

Voluntary, consensus-driven standards – most prominently the CHAI/Joint Commission responsible-use guidance and CHAI’s governance playbooks – are increasingly filling the space left by federal deregulation and may, through the Joint Commission’s planned certification, acquire practical force even without the binding effect of regulation.

Federal oversight is shared among several bodies:

  • FDA: Through the Digital Health Center of Excellence and the device, drug, and biologics centres, the FDA regulates AI that meets the device or drug/biologic definitions. Notably, the FDA has itself become a major AI user, deploying a generative assistant and agentic tools across review and inspection functions.
  • HHS and OCR: The Department of Health and Human Services sets healthcare policy and co-ordinates AI governance; its Office for Civil Rights enforces HIPAA and continues its risk-analysis enforcement initiative.
  • CMS: The Centers for Medicare & Medicaid Services sets coverage and reimbursement policy and now describes itself as an “AI-first” agency. CMS has also introduced AI-assisted prior authorisation into traditional Medicare through the WISeR model (see 8.4 Remote Monitoring and Telemedicine).
  • ASTP/ONC: The renamed health-IT office co-ordinates interoperability and certification policy.
  • FTC, CDC, and Others: The Federal Trade Commission polices AI advertising claims and the privacy practices of non-HIPAA entities; the CDC uses AI for surveillance and public-health functions.
  • DOJ: Under the December 2025 executive order, a new Department of Justice AI Litigation Task Force is charged with challenging state AI laws – a co-ordination role aimed at states rather than at developers.

State medical and professional licensing boards and state attorneys general round out the landscape, and their role is growing as federal oversight contracts.

Developers of AI that meets the device definition must generally satisfy the following before authorisation:

  • clinical validation demonstrating safety and effectiveness for the intended use, with study populations representative of the intended-use population so results generalise;
  • technical documentation describing algorithm design, training methodology, validation, and performance characteristics;
  • risk assessment addressing AI-specific hazards, including bias, cybersecurity vulnerabilities, and performance drift over time;
  • transparency sufficient for reviewers and clinicians to understand functionality, limitations, and appropriate use; and
  • cybersecurity information for connected devices under Section 524B of the FFDCA.

Bias testing has historically been an expectation, but its regulatory weight is now less certain given the administration’s retreat from anti-discrimination mandates (see 5.3 Bias and Fairness).

Once a device is on the market, oversight shifts to ongoing performance:

  • continuous monitoring for performance drift, anomalous behaviour, and differences between controlled validation and real-world use.
  • adverse-event reporting through established FDA channels;
  • managed updates under PCCPs, which permit defined changes within pre-authorised parameters while preserving oversight of significant modifications; and
  • real-world evidence collection to confirm continued safety and effectiveness.

The agency’s stated intent to rely more heavily on post-market monitoring – and its own use of AI in post-market surveillance – makes this phase increasingly central to the regulatory bargain.

Traditional levers. FDA enforcement tools include warning letters, recalls, injunctions, civil monetary penalties, and criminal referral. OCR enforces HIPAA through penalties and corrective-action plans, with its risk-analysis initiative focused on entities that fail to conduct adequate security risk analyses.

Areas where the action is shifting. Two trends stand out. First, enforcement energy is migrating from federal agencies toward private litigation and state enforcers – the ambient-scribe class actions and state attorney-general activity are now among the most consequential sources of exposure. Second, the federal government’s December 2025 executive order trains the Department of Justice on state laws rather than on regulated companies, an unusual posture in which a federal enforcement body is directed against state regulation. Meanwhile, payer use of AI is under direct judicial scrutiny; in litigation over a major insurer’s coverage-denial algorithm, a federal court has ordered broad discovery into the tool’s implementation and use, opening AI-assisted utilisation management to adversarial examination for the first time.

The Malpractice Baseline

Healthcare AI liability still operates primarily within established medical-malpractice doctrine, which requires duty, breach, causation, and damages. AI complicates each element, particularly the standard of reasonable care, and typically implicates multiple parties – treating clinician, institution, and the developers of any decision-support software used in the encounter.

Adjacent Theories

Beyond malpractice, AI-enabled devices may face product-liability claims (design defect, manufacturing defect, failure to warn), and the “black box” character of some systems complicates that analysis. Institutions face exposure for AI selection, implementation, training, and oversight, and professional-liability policies may not adequately cover AI-related claims.

From Hypothetical to Discovery

The most important development of the year is that payer-algorithm liability has moved from commentary into active litigation. In the leading case, a federal court allowed breach-of-contract and implied-covenant claims to proceed against a major Medicare Advantage insurer – reasoning that they turned on policy language promising that coverage decisions would be made by clinical personnel – while finding most other claims pre-empted by the Medicare Act, and subsequently ordered broad discovery into the algorithm itself. The durable lesson is that contractual and policy representations that humans will decide become powerful litigation levers when algorithms participate in those decisions, and that federal pre-emption is a strong but incomplete shield against state contract and good-faith theories.

Standard of Care and Human Accountability

Responsibility continues to rest with the humans and institutions deploying AI. The Federation of State Medical Boards has advised that clinicians remain accountable for harm arising from their use of AI tools, and the AMA – which pointedly uses the term “augmented intelligence” – has reinforced through 2026 policy that AI should serve as an assistive tool rather than an autonomous decision-maker, and that physician oversight, transparency, and accountability are essential wherever AI informs patient care. Physicians plainly feel the stakes; in the AMA’s 2026 survey, clear liability frameworks ranked among their top regulatory priorities for trusting clinical AI.

Causation, Documentation, and Proof

Courts must still determine whether an AI recommendation was a proximate cause of harm, weighing the clinician’s independent judgement and other factors. Detailed documentation – the specific recommendation, the clinician’s reasoning for accepting or rejecting it, and any modifications – is increasingly essential to both defence and proof, and AI-related cases will often require expert testimony on both medical practice and the technology’s capabilities and limits.

Doctrine Outrun by Deployment

Novel deployments continue to test the framework faster than doctrine can respond. A company operating in a state regulatory sandbox became, in late 2025, the first authorised to renew prescriptions autonomously using AI – a development that will test supervision, licensure, and liability principles in real time.

Developers, vendors, health systems, and practitioners should:

  • conduct institutional risk assessments covering clinical, cybersecurity, privacy, and liability exposures for each AI application;
  • establish AI governance frameworks led by multidisciplinary committees with clinical, technical, legal, and ethical expertise, with real authority over selection, validation, deployment, monitoring, and updates;
  • invest in staff training and competency, including clear escalation protocols when AI output conflicts with clinical judgement;
  • operate quality-assurance programmes that monitor performance and detect drift or bias in real-world use;
  • audit insurance coverage and close gaps with specialised products where needed; and
  • maintain vendor-management protocols, including due diligence and contractual risk allocation.

Voluntary frameworks now offer a concrete benchmark: the CHAI/Joint Commission responsible-use guidance and governance playbooks, together with the NIST AI Risk Management Framework, increasingly define what diligent governance looks like.

Available defences and limitations include:

  • regulatory-compliance defences based on adherence to applicable law, professional standards, and institutional policy;
  • informed-consent protections where AI use, limitations, and risks were properly disclosed;
  • state-of-the-art arguments where AI use reflected prevailing practice and established guidelines;
  • the learned-intermediary doctrine, which may shield developers where clinicians independently evaluate and apply AI output; and
  • contractual risk allocation through indemnification, limitation-of-liability, and clear scope provisions.

The leading payer-algorithm litigation is a caution; however, where a contract represents that humans or clinicians will decide, that representation can defeat a pre-emption or compliance defence once an algorithm is shown to have driven the decision.

Core Principles and Their Sources

US healthcare-AI ethics continue to rest on beneficence, non-maleficence, autonomy, and justice, expressed through a mostly voluntary set of frameworks. Professional societies – above all, the AMA – articulate principles emphasising physician responsibility, transparency, and informed consent, and institutional ethics committees and review boards increasingly fold AI into their remit.

A New Centre of Gravity

The most significant governance development of the year is the emergence of the first formal responsible-AI framework from a US accrediting body: the Joint Commission’s Responsible Use of AI in Healthcare (RUAIH) guidance, developed with CHAI and released in September 2025, followed by detailed governance playbooks in 2026 and a planned voluntary certification. The guidance is high-level and non-binding for now – addressing AI policy and governance structures, patient privacy and transparency, data security, safety-event reporting, and bias assessment – but it is widely expected to inform future accreditation expectations and to function as a de facto standard.

Federal and International Context

The rescission of the prior administration’s AI executive order removed the principal federal ethical instrument, and US participation in international bodies such as the World Health Organization is constrained; voluntary adherence to international ethical norms nonetheless persists under stakeholder pressure.

The State Disclosure Wave

Patient-facing transparency is now driven primarily by state law. Texas’s TRAIGA requires providers to disclose AI use in diagnosis or treatment at or before the interaction; California’s AB 3030 governs generative AI communications, and AB 489 bars AI tools from implying licensed status; and a growing list of states, including Maine, impose disclosure or consent requirements, particularly for behavioural-health and ambient-listening tools. The trajectory across states runs from disclosure toward, in some cases, outright prohibition of certain uses.

Algorithmic Transparency to Clinicians

Alongside patient disclosure, the FDA’s transparency guiding principles for ML-enabled devices ask that systems provide enough explanation for clinicians to understand recommendations and limitations, balanced against legitimate protection of proprietary detail. Clinicians, in turn, rely on those explanations to communicate with patients.

A Regime in Retreat

The federal anti-discrimination framework for AI rests on the Section 1557 final rule, which requires covered entities to identify and mitigate discrimination risk in patient-care decision-support tools, with relevant obligations effective in 2025. Enforcement under the current administration is uncertain, and commentators widely expect the Section 1557 regulations to be revised or narrowed. At the state level, Colorado’s comprehensive AI Act – which would have imposed duty-of-care and impact-assessment obligations aimed at algorithmic discrimination – was repealed and replaced in 2026 with a narrower disclosure-based statute effective in 2027, eliminating its core anti-discrimination machinery.

Persistent Technical Concerns

The underlying problem is unchanged: non-representative training data can entrench disparities, and demographic reporting in authorised devices remains sparse. Many developers continue, as a matter of good practice rather than clear mandate, to track and represent relevant characteristics in clinical studies and to implement bias testing across the AI life cycle, with particular attention to vulnerable populations including paediatric, elderly, minority, and disabled patients.

In most federal and state schemes, ultimate responsibility for AI rests with the people and organisations that deploy it. Best practices and emerging legal requirements converge on the following:

  • Clinical decision-making authority remains with the provider, even when using decision support.
  • Meaningful human involvement is required rather than fully automated decision-making, a principle now hardening into statute in the behavioural-health context, where states such as Illinois and Maine restrict or prohibit autonomous AI therapy.
  • Override capability must be readily accessible when clinical judgement differs from the algorithm.
  • Competency and training must be maintained through ongoing education.
  • Quality assurance must monitor both system performance and provider use.

Autonomous-prescribing pilots and the stalled federal autonomous-prescribing bill sit in direct tension with these oversight norms and will test their limits.

Training data must meet demanding standards to produce reliable results.

  • Data Quality: Datasets should be complete, accurate, consistent, and representative of the clinical conditions and populations for which the system will be used.
  • Representation and Bias: Datasets should include adequate representation across demographic groups, conditions, and settings, with documented identification and mitigation of potential bias – though, as noted in 5.3 Bias and Fairness, the regulatory force behind these expectations is now less certain.
  • Provenance and Lineage: Comprehensive documentation of sources, collection methods, and processing steps enables proper evaluation of data quality and limitations.

Reusing clinical data for AI development is permissible within specific guardrails:

  • Legal frameworks govern consent, privacy protection, and use limitations for data collected for one purpose and reused for another.
  • Consent requirements vary with data sensitivity and intended use; secondary use frequently requires fresh consideration of patient consent.
  • Research exemptions may apply to certain activities, typically subject to institutional review board approval and appropriate safeguards.
  • Data use agreements should specify permitted uses, protections, and restrictions on further disclosure.

Data-sharing arrangements should address:

  • privacy-preserving collaboration, including federated learning and secure multiparty computation that enable cross-institutional development without centralising raw data.
  • cross-border transfer restrictions under federal, state, and international law;
  • data-sharing agreements specifying access rights, use limitations, IP ownership, compliance, and liability allocation; and
  • industry consortia – CHAI prominent among them – that facilitate shared datasets and common practices.

HIPAA Standards

De-identification proceeds by the safe-harbour method (removing specified identifiers) or expert determination (statistical assurance of low re-identification risk).

Re-Identification Risk

AI’s pattern-recognition capabilities heighten re-identification risk, particularly when datasets are combined, requiring ongoing vigilance.

Synthetic Data

Synthetic-data techniques, including generative methods, can preserve statistical utility while reducing links to identifiable individuals.

Technical Safeguards

Access controls, encryption, audit logging, and secure computing environments should protect against both intentional and accidental re-identification throughout development.

Eligibility Fundamentals

Healthcare AI inventions are patentable when they satisfy novelty, non-obviousness, utility, and subject-matter eligibility; abstract mathematical algorithms, standing alone, are not. Under the prevailing eligibility analysis, AI claims fare better when tied to a specific technical improvement or practical application rather than claimed in the abstract.

Recent USPTO Guidance

The US Patent and Trademark Office has been active. Its 2024 subject-matter eligibility guidance clarified that AI inventions are not categorically abstract, and the agency issued an AI strategy in early 2025. Most importantly, in November 2025 the USPTO issued revised inventorship guidance that rescinded its 2024 approach: AI systems cannot be named inventors, AI tools are treated like any other instrument used by a human inventor, and a natural person must make a significant contribution to the claimed invention – consistent with the federal court holding that only humans can be inventors. International filing strategies remain necessary to address divergent national standards.

Copyright Scope

Software code, interfaces, and documentation may be protected as original works of authorship, but copyright does not reach underlying algorithms or mathematical concepts. The US Copyright Office’s 2025 report on AI and copyright reaffirmed that human authorship is required: purely AI-generated output is not itself protectable, and protection attaches only to the human-authored contributions to a work.

Training-Data and Trade-Secret Considerations

Developers using third-party material for training should secure appropriate licences, an area of active and unsettled litigation. Trade-secret protection often guards algorithms, training datasets, and methodologies – but it sits in tension with regulatory and clinical demands for transparency and explainability, a balance each developer must strike deliberately.

Ownership of AI-generated clinical outputs – diagnostic findings, treatment recommendations – remains largely unsettled, and the human-authorship principle reaffirmed by the Copyright Office means purely machine-generated output may fall outside traditional IP protection entirely.

  • Generated-content ownership is not squarely addressed by existing doctrine.
  • Provider claims may arise where outputs derive from a provider’s patient data and clinical expertise, potentially conflicting with developer rights.
  • Patient interests in outputs derived from their data receive limited protection under current law.
  • Contractual arrangements between developers and institutions therefore do the practical work of allocating rights and should address ownership expressly.

Two models predominate: commercial licensing (subscription software-as-a-service, per-use, and platform licences) and academic–industry collaboration through licences, research partnerships, and joint ventures. Two recurring issues warrant attention: open-source components, which may impose their own licensing obligations, and technology-transfer processes, which must balance public access against commercial incentive. Regulatory status (including any FDA authorisation and associated PCCP) increasingly travels with the licensed product and should be addressed in the commercial terms.

AI-based CDS receives different treatment depending on functionality and the degree of interpretation it provides. The key recent development is the FDA’s January 2026 final guidance on CDS software, which narrows active oversight of certain lower-risk decision-support functions – meaningfully affecting whether a given tool is regulated as a device. Beyond classification, effective CDS deployment depends on appropriate institutional governance, clinical-validity evidence (retrospective, prospective, and real-world), workflow integration that minimises alert fatigue, and clear retention of professional responsibility by the clinician.

AI diagnostic tools are regulated as devices when they analyse patient data to produce diagnostic information, and they generally require clinical validation for specific intended uses. Diagnostic AI remains the largest authorised category, with radiology dominant and pathology, cardiology, and ophthalmology growing. The clearance of the first foundation-model-powered clinical AI in early 2025 signals the category’s evolution toward more general architectures. Speciality-specific validation expectations persist – radiology, pathology, and other fields apply distinct approaches – and successful deployment depends on integration with imaging and laboratory systems.

AI used in treatment planning or therapeutic decision-making faces oversight scaled to risk, with higher-risk applications subject to more demanding validation, potential PMA review, meaningful human oversight, and safety monitoring. The frontier issue is autonomy: a sandbox-authorised system began autonomously renewing prescriptions in late 2025, and the stalled Healthy Technology Act would, if enacted, let AI qualify as a prescribing practitioner where the FDA and the relevant state both permit. These developments will test how much therapeutic decision-making may be delegated to an algorithm and where liability lands when it is.

AI in remote monitoring and telemedicine must satisfy both AI-specific rules and the broader telemedicine framework, and systems operating in the home raise distinct questions of device performance, user training, oversight, and data security outside clinical walls. The FDA’s January 2026 wellness guidance removes many low-risk consumer wearables from active oversight, easing the path for some monitoring tools. Reimbursement remains complex and payer-specific; relatedly, CMS’s WISeR model – a six-year pilot launched on 1 January 2026 – for the first time introduces AI-assisted prior authorisation into traditional Medicare for selected services in a defined set of states, with determination timeframes and contractor-incentive provisions, and it has drawn both political opposition and legislation seeking to prohibit it.

AI in drug development gained its first dedicated federal guidance in January 2025, when the FDA issued draft guidance on the use of AI to support regulatory decision-making for drug and biological products. The guidance proposes a risk-based “credibility assessment” framework keyed to an AI model’s context of use, with a structured, multi-step process for planning and documenting credibility. The guidance expressly excludes pure drug-discovery and operational uses that do not affect patient safety, drug quality, or study reliability. The agency reports having received hundreds of submissions with AI components over the past decade. Developers must still meet good-clinical-practice standards for trial design, validate discovery and screening tools for their intended use, and address the IP questions raised by AI-generated compounds and targets (see 7 Intellectual Property Issues Regarding Healthcare AI).

Several of the open questions from a year ago now have at least partial answers, even as new questions arise:

  • Federal AI policy has resolved toward deregulation and attempted pre-emption rather than revival of the prior administration’s approach, through the July 2025 AI Action Plan and the December 2025 executive order – both of which face anticipated constitutional challenge.
  • The FDA’s cornerstone SaMD guidance remains unfinished, even as the agency finalised narrower CDS and wellness guidance in January 2026 and signalled a broader deregulatory framework.
  • The HIPAA Security Rule overhaul remains unresolved, its final form and timing unknown.
  • Autonomous prescribing (H.R. 238) remains parked in committee.
  • Payer AI faces both litigation and legislation; a bill introduced in December 2025 would prohibit the WISeR prior-authorisation model outright.
  • State activity continues in both directions – 14 states enacted health AI laws in 2025 and dozens more bills are pending in 2026 – even as Colorado’s retreat shows that comprehensive state regimes are not guaranteed to take effect.

The innovation-programme picture has brightened relative to a year ago. The federal AI Action Plan affirmatively encourages regulatory sandboxes and proposes AI Centers of Excellence, including for healthcare. The FDA’s Digital Health Center of Excellence continues to operate. At the state level, sandboxes have produced concrete firsts: a company operating in a state AI-policy sandbox received authorisation in late 2025 to renew prescriptions autonomously, and several additional states have introduced sandbox or regulatory-relief legislation in 2026. These programmes offer participants regulatory engagement and flexibility in exchange for monitoring and guardrails, and they are emerging as a favoured vehicle for testing higher-autonomy applications.

US engagement with international harmonisation is more constrained than in prior years. Constraints on participation in bodies such as the World Health Organization, combined with a deliberately deregulatory domestic posture, create growing divergence from more prescriptive regimes such as the EU AI Act. The AI Action Plan does include an international-diplomacy pillar oriented toward exporting US technology and standards. For developers, the practical consequence is a widening gap between US and foreign requirements – particularly on transparency, bias, and risk management – that cross-border products must bridge through the strictest-common-denominator design (see 10.5 Cross-Border Considerations). International standards from IMDRF and ISO continue to influence US device practice even where formal harmonisation lags.

Several issues are moving from the horizon into active contention:

  • continuous-learning and generative systems, and how a static-device framework accommodates them;
  • agentic and autonomous AI, including autonomous prescribing and regulators’ own use of agentic tools;
  • consumer-facing AI companions and mental-health chatbots, now the target of state prohibition;
  • ambient-documentation consent, the source of the year’s leading privacy litigation;
  • payer-algorithm liability, now in discovery; and
  • federal pre-emption, whose resolution will reshape the state-law landscape.

Effective compliance now rests on a few core disciplines: meticulous documentation of AI selection, validation, implementation, and monitoring; a risk-based approach that concentrates resources on higher-risk applications; and ongoing monitoring and assessment of performance and compliance. The defining practical challenge of 2026 is dual-track compliance – building governance programmes that satisfy the strictest applicable state requirements while the federal government pursues pre-emption that may or may not succeed. The most resilient programmes are principles-based and benchmarked to where regulation is heading, drawing on the NIST AI Risk Management Framework and the CHAI/Joint Commission governance materials rather than to any single, possibly transient, rule.

Healthcare AI contracts must allocate technical, regulatory, and liability risk with precision, addressing system performance, data handling, regulatory compliance, indemnification, limitation of liability, warranties, and service levels.

Two lessons from the past year deserve emphasis. First, representations matter: contract or policy language promising that humans or clinicians will make decisions can become a litigation lever once an algorithm participates, so such language should be drafted with care and matched to operational reality. Second, BAAs are necessary but not sufficient for ambient and other PHI-processing tools – exposure under state consent law runs independently of HIPAA, so contracting should be paired with genuine, documented patient-consent workflows.

Organisations should audit existing coverage for AI-specific gaps, since traditional policies may not address algorithmic error, data breach, or IP infringement. Specialised products – cyber-liability, technology errors-and-omissions, and AI-specific professional liability – are increasingly available, and carriers now evaluate AI deployment, governance, and risk-management practices during underwriting. Organisations with mature governance may secure preferred terms; those without may find coverage narrowed or priced up as insurers absorb the lessons of emerging litigation.

Sound implementation generally includes:

  • an organisational readiness assessment of infrastructure, staffing, compliance, and culture before deployment;
  • multidisciplinary implementation teams with clinical, IT, legal/compliance, and quality expertise and clear authority;
  • a phased approach beginning with lower-risk applications;
  • training and change management to build competency and support adoption;
  • quality assurance that monitors performance and effectiveness over time;
  • patient communication and consent, designed to function reliably at the point of care rather than as a template setting; and
  • AI governance aligned to the NIST framework and the CHAI/Joint Commission materials, with continuous monitoring of performance and bias and clear incident procedures.

Deploying healthcare AI across jurisdictions requires attention to regulatory harmonisation, data-transfer and privacy requirements, professional licensing, IP protection, compliance co-ordination, and risk-management strategy. The widening divergence between a deregulatory US posture and more prescriptive foreign regimes makes a strictest-common-denominator design the most defensible approach for products that must operate in multiple markets.

Within the United States, the unresolved contest between federal pre-emption efforts and an expanding state patchwork adds a domestic cross-border dimension. Organisations should expect, for the near term, to comply with binding state requirements even as federal litigation against some of them proceeds, and should build governance flexible enough to absorb whichever way that contest resolves.

Jones Walker LLP

201 St. Charles Ave
New Orleans, LA 70170-5100
USA

337 593 7634

337 593 7601

ndelahoussaye@joneswalker.com joneswalker.com
Author Business Card

Trends and Developments


Authors



Jones Walker LLP is among the largest law firms in the United States, with more than 350 lawyers across the Southeast and other strategic locations, including Miami, New York City, and Washington, DC. Led by a core group of veteran healthcare lawyers, the firm’s healthcare industry team includes lawyers from all the firm’s major practice areas, who all have extensive experience in specific practice areas, as well as in-depth knowledge of today’s healthcare marketplace and regulatory environment. The firm’s attorneys have a deep understanding of the technologies that constitute the world of AI, including generative AI, machine learning, natural language processing, large language models (LLMs), and neural networks. This knowledge enables the firm to better help its clients navigate this complex world, mitigate risks, be strategic, and develop approaches to differentiate themselves.

From Regulatory Uncertainty to Open Conflict: Deregulation, State Action, and the First Wave of AI Litigation

Artificial intelligence is no longer an emerging presence in American healthcare – it is an ordinary one. According to the American Medical Association’s 2026 Physician Survey on Augmented Intelligence, 81% of US physicians now use AI tools in a professional capacity, more than double the 38% who reported doing so when the AMA first asked the question in 2023. The FDA’s public inventory of authorised AI- and machine-learning-enabled medical devices, which stood at roughly 950 in August 2024, has since climbed well past 1,250. Ambient documentation tools that draft clinical notes from recorded patient encounters, a niche product two years ago, are now deployed across major health systems nationwide.

If 2025 was a year defined by regulatory uncertainty, 2026 has been defined by something sharper: collision. The federal government has moved decisively toward deregulation, culminating in an executive order that seeks to pre-empt state AI laws outright. The states, meanwhile, have accelerated in the opposite direction, enacting disclosure mandates, prior-authorisation guardrails, and, in at least one case, an outright ban on AI-delivered psychotherapy. And the liability questions that practitioners spent 2025 discussing in the conditional tense have arrived in federal courtrooms, where a payer’s coverage algorithm is now in discovery and health systems face class actions over AI tools that listened to patients without their knowledge.

For healthcare providers, AI developers, payers, and the lawyers who advise them, the result is a paradoxical environment: fewer federal guardrails, more sources of legal exposure. This article reviews the year’s most consequential developments and what they suggest for the months ahead.

Federal Policy: Deregulation and the Pre-Emption Offensive

The Trump administration spent 2025 building a comprehensive (and comprehensively deregulatory) national AI policy. In July 2025, the White House released Winning the Race: America’s AI Action Plan, a roadmap of some 90 policy recommendations organised around three pillars: accelerating AI innovation, building American AI infrastructure, and leading in international AI diplomacy and security. Although healthcare appears only intermittently in the plan’s text, its health-relevant provisions are significant. The plan calls for AI Centers of Excellence, including for the healthcare and public-health sectors, to enable real-world testing and validation; supports the development of large, AI-ready scientific datasets; encourages regulatory sandboxes; and recognises healthcare as critical infrastructure requiring strengthened AI-related cybersecurity. Just as significantly, the plan signals that federal AI funding should not flow to states whose regulations are deemed to hinder innovation.

That signal became policy on 11 December 2025, when the president signed an executive order titled Ensuring a National Policy Framework for Artificial Intelligence. The order announces a “minimally burdensome” national standard for AI governance and deploys an array of mechanisms against state regulation: a Department of Justice AI Litigation Task Force charged with challenging state AI laws in court; directives to the Federal Trade Commission and Federal Communications Commission to develop federal standards that could pre-empt conflicting state requirements; and conditions on federal broadband and other discretionary funding tied to states’ willingness to pause enforcement of AI statutes the administration considers inconsistent with federal policy. The order followed failed congressional efforts to enact a statutory moratorium on state AI laws and arrived over the objections of a bipartisan coalition of state attorneys general.

The practical upshot for healthcare organisations must be understood: the executive order does not, by itself, nullify anything. State AI laws remain enforceable while the inevitable constitutional challenges work their way through the courts, and companies that treat pre-emption as accomplished fact do so at their peril. Multistate health systems and AI vendors therefore face a dual-track compliance reality: building governance programmes that satisfy the strictest applicable state regimes while monitoring litigation that could reshape the field at any moment.

The FDA: A Lighter Touch, With Open Questions

The FDA’s posture toward healthcare AI has shifted visibly over the past year, from cautious framework-building toward deliberate deregulation. Several questions left open in 2025 now have answers, though not always the expected ones.

The agency’s January 2025 draft guidance on lifecycle management and marketing submissions for AI-enabled device software functions – widely anticipated as the cornerstone of AI device regulation – has still not been finalised; it appears on the FDA’s “B” list of guidance priorities for fiscal year 2026. The final guidance on predetermined change control plans (PCCPs), by contrast, is now fully operative, giving manufacturers an established pathway to modify AI-enabled devices within pre-authorised parameters without new marketing submissions. And in January 2026, the FDA issued final guidance on clinical decision support software and general wellness products that explicitly reduce oversight of low-risk digital health tools, removing many consumer wearables and certain decision-support functions from active regulation. FDA Commissioner Marty Makary has said publicly that the agency intends to eliminate as many as half of its software and digital health guidance documents and to roll out a new risk-based AI framework oriented in a “deregulatory direction”, with greater reliance on post-market monitoring. Separately, the long-planned Quality Management System Regulation, harmonising US device quality requirements with international standards, took effect on 2 February 2026.

Generative AI remains the unresolved frontier. As of this writing, the FDA has not authorised any medical device built on a purely generative AI architecture, although the boundary is being actively tested. The agency cleared the first foundation-model-powered clinical AI in February 2025 and convened its Digital Health Advisory Committee in November 2025 to examine generative AI-enabled digital mental health devices. How the agency will evaluate adaptive, content-generating systems under a framework built for static devices remains the central regulatory question for AI developers.

A final development would have seemed improbable two years ago: The FDA itself has become a major AI user. In June 2025, the agency launched Elsa, an internal generative AI assistant, across its workforce. By late 2025, the agency reported that a substantial majority of staff were using the tool for tasks such as clinical protocol review, label comparison, and inspection targeting. The agency has since announced the use of agentic AI in premarket reviews and post-market surveillance. Regulated companies should assume that the documents they submit will increasingly be read, summarised, and triaged, at least in part, by machine.

Because the agency’s deregulatory posture has been widely misread, a clarifying note is in order. Nothing about the developments above changes the core premise that software meeting the statutory definition of a medical device – including most AI- and ML-enabled diagnostic, screening, and treatment-recommendation tools – still requires FDA clearance, de novo authorisation, or premarket approval before it may be marketed in the United States. What has shifted is the regulatory perimeter at the low-risk margins: Certain general wellness products, narrowly defined clinical decision support functions that meet the 21st Century Cures Act criteria, and some consumer-facing wearables now fall outside active oversight. The core clearance pathways remain in force, the agency continues to issue warning letters for marketing unauthorised software as a medical device, and the PCCP and QMSR developments described above expand – they do not replace – the existing premarket framework. Developers and the providers who procure their tools should not mistake a lighter touch at the edges for a free-for-all at the centre.

HIPAA and Data Privacy: Stalemate at the Agency, Action in the Courts

The most significant proposed change to healthcare data security in two decades remains in limbo. The HIPAA Security Rule update proposed in the closing days of the Biden administration – which would mandate encryption of electronic protected health information at rest and in-transit, multifactor authentication, regular vulnerability scanning and penetration testing, and the incorporation of AI tools into required risk analyses – drew roughly 4,745 public comments and organised resistance from a coalition of more than 100 hospital systems and provider associations. The Office for Civil Rights’ target of a spring 2026 final rule has come and gone with nothing published, and the proposal’s ultimate form, scope, and timing remain unknown. Prudent organisations are not waiting; the proposed controls increasingly describe what regulators, insurers, and plaintiffs’ counsel already treat as reasonable security, and OCR’s enforcement priorities (in particular, its risk-analysis initiative) track the same themes. Covered entities should also note that HIPAA civil monetary penalties were inflation-adjusted in January 2026, with the annual cap for the most serious violation category now approaching USD2.2 million.

While the rulemaking stalled, healthcare privacy law moved decisively in the courts, although the vehicle itself was not HIPAA. In November 2025, a patient filed a proposed class action against San Diego-based Sharp HealthCare alleging that an ambient AI documentation tool recorded his clinical encounter without notice or consent, in violation of California’s Invasion of Privacy Act and Confidentiality of Medical Information Act. The complaint included a particularly damaging allegation: that the patient’s chart contained boilerplate language stating he had been “advised” of and “consented” to the recording when no such conversation occurred. In April 2026, a second putative class action was filed in federal court against Sutter Health and MemorialCare, alleging that the same ambient documentation platform intercepted and processed patient conversations without informed consent.

The lesson for health systems is pointed. The AI vendor in these cases operates under business associate agreements with its covered-entity clients; HIPAA compliance, in other words, is not the gap. The exposure runs through state wiretapping and medical-confidentiality statutes (currently, 13 states require all-party consent to recording) and through consent workflows that exist on paper but fail in the exam room. Organisations deploying ambient AI should treat patient-facing disclosure and genuine, documented consent as a first-order compliance obligation, not an EHR template setting.

The States Fill the Vacuum – and Face a Federal Challenge

With Congress still on the sidelines, state legislatures have become the primary source of new healthcare AI law. Health-related AI bills introduced in the states grew from 15 in 2023 to 168 in 2025 and, by early spring 2026, more than 40 bills addressing clinical AI had been introduced across 25 states. Three clusters of enacted law deserve particular attention:

Clinical disclosure and licensure protection. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), effective 1 January 2026, requires healthcare providers to disclose to patients when AI systems are used in their diagnosis or treatment, before or at the time of the clinical interaction. California, building on its 2025-vintage generative AI disclosure law (AB 3030) and utilisation-review statute (SB 1120), added AB 489 (also effective 1 January 2026) prohibiting AI developers and deployers from using terms or design elements that imply an AI system holds a healthcare licence.

Mental health and AI “therapy”. The most aggressive state action of the year targeted AI in behavioural health. Illinois’s Wellness and Oversight for Psychological Resources (WOPR) Act, enacted in August 2025, prohibits the use of AI to independently provide therapy or make therapeutic decisions. Essentially, this stands as an outright ban reaching autonomous chatbots operating in the state, while preserving administrative and supplementary uses under licensed professionals’ oversight. Utah and Nevada enacted disclosure- and supervision-based regimes for mental health chatbots, and, in 2026, Maine barred providers from using AI for therapeutic communications or treatment decisions and required patient consent before ambient listening tools may be used. Arizona’s behavioural health licensing board adopted informed-consent regulations effective in 2027. The trajectory – from disclosure rules toward outright prohibition – reflects mounting legislative alarm over consumer-facing AI companions and chatbots in mental health contexts.

Payer-side AI. A growing number of states now regulate insurers’ use of AI in prior authorisation and claims adjudication, generally requiring transparency about algorithmic involvement and meaningful human review of adverse determinations. This stands as a direct legislative response to the coverage-denial controversies (see discussion below).

Now, every statute described above is a potential target of the December 2025 pre-emption order. Healthcare organisations should expect a period in which state requirements remain binding, federal litigation against some of them proceeds, and legislative activity continues in both directions. This could lead to an environment that rewards flexible, principles-based AI governance over compliance programmes built narrowly around any single regime.

Liability Moves From Hypothetical to Discovery

For years, commentary on healthcare AI liability has been necessarily speculative. That era is ending. In Estate of Lokken v UnitedHealth Group, Medicare Advantage beneficiaries allege that an algorithmic tool was used to cut off coverage for medically necessary post-acute care. In February 2025, the US District Court for the District of Minnesota allowed the case’s breach of contract and implied-covenant claims to proceed, reasoning that they turn on policy language promising that coverage decisions would be made by clinical personnel, while holding most other claims pre-empted by the Medicare Act. In March 2026, the court ordered broad discovery into the implementation and use of the algorithm itself, giving plaintiffs’ counsel an unprecedented look inside a major payer’s AI-assisted utilisation management process.

Lokken offers two durable lessons. First, contract language matters enormously. Representations that humans or clinicians will make decisions become litigation levers when algorithms participate in those decisions. Second, federal pre-emption is a powerful but incomplete shield; state contract and good-faith theories survived where statutory claims did not. Congressional scrutiny of payer AI has intensified in parallel, and legislation has been introduced that would bar AI-driven denial models in Medicare entirely.

On the clinical side, the professional liability framework remains largely as we described it in 2025: responsibility continues to rest with the humans and institutions that deploy AI, malpractice doctrine has not been displaced, and courts have yet to articulate AI-specific standards of care. Physicians appear to understand the stakes; in the AMA’s 2026 survey, clear liability frameworks ranked among respondents’ top regulatory priorities for building trust in clinical AI. Meanwhile, novel deployments continue to outrun doctrine: in late 2025, a company operating within Utah’s regulatory sandbox became the first in the nation authorised to renew prescriptions autonomously using AI, a development that will test supervision, licensure, and liability principles in real time.

Enforcement: AI on Both Sides of the Investigation

The single most underappreciated development of the year may be this: The same AI capabilities that providers are racing to deploy clinically are being deployed against them by the government, and the resulting wave of enforcement activity is unprecedented in both volume and velocity. Healthcare organisations that view AI primarily as a clinical or operational tool are missing what is, for many of them, the larger near-term risk.

CMS reported in May 2026 that its Medicare programme integrity activities generated a record USD41.9 billion in FY 2025 savings, a 59% increase over FY 2024, with a return on investment of USD22.30 for every dollar spent – the highest ROI ever recorded by the agency. Cost-avoidance activities such as automated claim denials and revocations accounted for 68% of those savings. The agency has been explicit that next-generation AI and machine learning are central to the strategy. In July 2025, DOJ and HHS jointly launched a False Claims Act Working Group with stated priority areas that include Medicare Advantage risk adjustment, kickbacks tied to drug and device referrals, materially deficient medical care, and the misuse of electronic health records – all areas where algorithmic data mining is already identifying targets faster than any human review could.

The mechanics of this shift matter for compliance counsel. Investigations are increasingly initiated by algorithmic flags – outlier billing patterns, statistical anomalies in coding distributions, peer-comparison deviations – and providers often receive their first notice of a problem in the form of a civil investigative demand, audit letter, or recoupment demand that was generated before any human investigator reviewed the underlying records. By the time counsel is engaged, the government’s theory of the case has already been shaped by what the algorithm flagged, and the burden of disproving it falls on the provider.

This environment makes the 60-day overpayment rule and the reverse False Claims Act it backstops more dangerous than ever. Under Section 1128J(d) of the Social Security Act, an identified Medicare or Medicaid overpayment must be reported and returned within 60 days; an overpayment knowingly retained beyond that deadline becomes an “obligation” under 31 U.S.C. § 3729(a)(1)(G), giving rise to reverse False Claims Act liability with treble damages, per-claim civil penalties, and potential exclusion. CMS’s November 2024 final rule, now fully operative, aligned the “identified” trigger with the FCA’s “knowingly” standard – actual knowledge, deliberate ignorance, or reckless disregard – and replaced the prior “reasonable diligence” formulation with a 180-day suspension for good-faith investigations into related overpayments. The window for protective action is real but narrow, and it is measured against a knowledge standard that AI-assisted analytics make easier, not harder, for the government to satisfy.

Self-disclosure, accordingly, has moved from a strategic option to, in many cases, the only defensible path. Both the OIG Self-Disclosure Protocol and the CMS Voluntary Self-Referral Disclosure Protocol toll the 60-day clock during good-faith negotiation, and both routinely produce settlements at meaningful multiples below FCA exposure. The calculus is straightforward: a known overpayment that is timely self-disclosed becomes a negotiation; the same overpayment retained past 60 days becomes a federal fraud case with treble damages, daily penalties, exclusion exposure, and, where individual knowledge is provable, criminal risk under 18 U.S.C. § 1347 and related statutes.

In this same vein, on 1 January 2026, the Centers for Medicare & Medicaid Services (CMS) launched the Wasteful and Inappropriate Service Reduction (WISeR) Model, a six-year pilot that, for the first time at scale, introduces prior authorisation into traditional Medicare and uses AI-assisted review for a defined set of Part B services considered vulnerable to fraud, waste, and abuse. The model operates in six states, with determinations promised within 72 hours (48 for expedited requests) and contractor incentives that CMS says are designed to reward accurate determinations rather than denials. The model is politically contested: Critics argue it imports Medicare Advantage’s most-criticised practice into original Medicare, and a bill introduced in December 2025 would prohibit it outright.

The practical message for hospitals, physician practices, pharmacies, and the boards and executives who govern them is unwelcome but unavoidable. Algorithmic enforcement is faster, cheaper, and more pattern-sensitive than the human review it is replacing, and the government’s ROI on it gives the programme durable bipartisan support. Compliance programmes built for a slower era – programmes that rely on annual audits, voluntary reporting up the chain, and the time-honoured assumption that small anomalies will not be noticed – are no longer fit for purpose. Providers and developers should internalise the shift: Compliance now means responding to government AI, not merely deploying one’s own. The organisations that will fare best are those that treat continuous monitoring, prompt internal investigation of credible information, and timely use of the self-disclosure protocols as core operational disciplines rather than as last resorts.

Market Dynamics: Capital Concentrates Around AI

The investment market validated AI’s centrality in 2025. US digital health start-ups raised USD14.2 billion – the sector’s strongest year since 2022 and a 35% increase over 2024 – with AI-focused companies capturing 54% of all funding and commanding meaningful premiums on deal size. The market’s character changed as well as its size: megadeals above USD100 million accounted for 42% of total funding, the highest concentration since 2021, even as roughly a third of all rounds were flat or down. This reflects a widening divide between AI-native winners and the rest of the field. Private equity has pursued roll-up strategies pairing legacy healthcare services businesses with AI-native technology, and the major foundation-model developers have entered healthcare directly with dedicated clinical and consumer offerings.

Commercially, ambient clinical documentation has emerged as healthcare AI’s breakout category, attracting some of the year’s largest venture rounds and demonstrating measurable returns. One multi-system study found clinician burnout dropped from roughly 52% to 39% after 30 days of ambient scribe use. The category’s commercial success and its litigation exposure, discussed above, are two sides of the same rapid deployment and serve as a reminder that adoption curves and governance maturity do not automatically rise together.

Conclusion: Governance Becomes the Differentiator

The defining irony of 2026 is that as federal regulators have loosened their grip on healthcare AI, legal risk has not receded. Instead, it has migrated. It now resides in state statutes that remain enforceable despite federal hostility, in plaintiffs’ creative use of decades-old privacy and contract law, in discovery orders that expose algorithmic decision-making to adversarial scrutiny, and in the gap between consent policies as written and as practised. In this environment, the risk-controlling disciplines are internal: AI governance committees with real authority; documented human oversight of clinical and coverage decisions; patient-facing disclosure and consent workflows that function in the exam room; rigorous vendor diligence and contractual risk allocation; continuous billing and coding surveillance with documented investigation protocols; disciplined use of the OIG and CMS self-disclosure pathways when credible information of overpayment surfaces; and security programmes benchmarked to where regulation is heading rather than where it currently sits.

The year ahead will answer questions this one has only posed. Will the pre-emption order survive constitutional challenge, and will any state laws fall with it? Will OCR finalise, narrow, or abandon the Security Rule overhaul? Will the FDA authorise its first generative AI device – and under what framework? Will WISeR’s results vindicate or indict AI-assisted utilisation review? Will the FY 2025 programme integrity ROI figures sustain the political momentum behind AI-driven enforcement, and will Congress or the courts impose any meaningful procedural guardrails on algorithm-initiated investigations?

Whatever the answers, the organisations best positioned to benefit from healthcare AI will be those that treat trustworthiness – toward patients, regulators, and courts alike – as a design requirement rather than a compliance afterthought. The technology has become ordinary; the obligation to use it responsibly has become anything but.

Jones Walker LLP

201 St. Charles Ave
New Orleans, LA 70170-5100
USA

337 593 7634

337 593 7601

ndelahoussaye@joneswalker.com joneswalker.com
Author Business Card

Law and Practice

Authors



Jones Walker LLP is among the largest law firms in the United States, with more than 350 lawyers across the Southeast and other strategic locations, including Miami, New York City, and Washington, DC. Led by a core group of veteran healthcare lawyers, the firm’s healthcare industry team includes lawyers from all the firm’s major practice areas, who all have extensive experience in specific practice areas, as well as in-depth knowledge of today’s healthcare marketplace and regulatory environment. The firm’s attorneys have a deep understanding of the technologies that constitute the world of AI, including generative AI, machine learning, natural language processing, large language models (LLMs), and neural networks. This knowledge enables the firm to better help its clients navigate this complex world, mitigate risks, be strategic, and develop approaches to differentiate themselves.

Trends and Developments

Authors



Jones Walker LLP is among the largest law firms in the United States, with more than 350 lawyers across the Southeast and other strategic locations, including Miami, New York City, and Washington, DC. Led by a core group of veteran healthcare lawyers, the firm’s healthcare industry team includes lawyers from all the firm’s major practice areas, who all have extensive experience in specific practice areas, as well as in-depth knowledge of today’s healthcare marketplace and regulatory environment. The firm’s attorneys have a deep understanding of the technologies that constitute the world of AI, including generative AI, machine learning, natural language processing, large language models (LLMs), and neural networks. This knowledge enables the firm to better help its clients navigate this complex world, mitigate risks, be strategic, and develop approaches to differentiate themselves.

Compare law and practice by selecting locations and topic(s)

{{searchBoxHeader}}

Select Topic(s)

loading ...
{{topic.title}}

Please select at least one chapter and one topic to use the compare functionality.