California Health Care AI Law
California AB 1979 — Health Care Services: Artificial Intelligence
United States
RAI-US-CA-AB19790-2026AB 1979
California Health Care AI Law is Awaiting Entry in United States, according to leginfo.legislature.ca.gov. We have not yet been able to confirm the status.
ActGovernance and OversightTransparency and DisclosureFundamental RightsCalifornia AB 1979 limits AI in clinical care and extends medical privacy rules to health care chatbots.
Summary
California AB 1979 adds AI-specific limits for health care settings and expands CMIA privacy protections to certain health care chatbots. It preserves licensed professional judgment in clinical care, restricts AI from performing licensed clinical functions, and brings covered chatbot businesses under provider-like confidentiality duties.
Full article
Read full text ↗Overview
California AB 1979 is a chaptered statute addressing the use of artificial intelligence in health care services, especially where AI touches clinical judgment, patient communications, and medical information confidentiality. It adds Chapter 25.5, beginning with Section 22758.5, to Division 8 of the Business and Professions Code and amends Civil Code Sections 56.05 and 56.06. The law was approved by the Governor and filed with the Secretary of State on 2026-09-30 as Chapter 854, Statutes of 2026, and it is not an urgency statute. As a result, it takes effect on 2027-01-01. Its structure shows two main regulatory aims: preserving human professional judgment in clinical care and expanding Confidentiality of Medical Information Act coverage to certain AI-based health tools, including health care chatbots. The statute is designed to ensure that AI remains an assistive tool rather than a substitute for licensed decisionmaking in clinical settings, while also extending privacy protections to consumer-facing products that collect and use health-related information.
The statute is notable for linking AI governance with existing California health privacy law rather than creating a wholly separate AI-only regime. Under the amended CMIA provisions, businesses offering certain AI-driven health tools are treated as providers of health care for purposes of confidentiality obligations and penalties under the part. Under the new Business and Professions Code section, health facilities, clinics, physician’s offices, and offices of a group practice must take reasonable steps to preserve a licensed professional’s independent judgment whenever care is informed by a clinical decision support system. The law also bars AI tools from independently performing clinical functions that must by law be performed by a licensed person. It expressly excludes certain documentation and communication functions that do not require professional judgment, such as automated health-record updates and reminders. The statute therefore separates operational automation from clinical authority, and it does so in a way that is intended to protect patients, preserve professional licensing boundaries, and reinforce confidentiality standards in digital health.
Definitions
AB 1979 relies heavily on statutory cross-references and incorporates several definitions that determine the reach of the new requirements. “Artificial intelligence” and “generative artificial intelligence” are given the same meaning as in Health and Safety Code Section 1339.75. A “clinical decision support system” is defined as an artificial intelligence system that produces a prediction, classification, recommendation, evaluation, or analysis that aids clinical decisionmaking related to timing of care, diagnosis, or treatment. The definition excludes appointment management, appointment reminders, patient education and pre-visit materials, and payment processing, so long as the system’s independent performance of those activities does not require a professional license. The statute also defines “automated decision system” broadly as a computational process derived from machine learning, statistical modeling, data analytics, or AI that issues simplified output used to assist or replace human discretionary decisionmaking and materially impacts natural persons; ordinary tools such as spam filters, firewalls, antivirus software, identity and access management tools, calculators, databases, datasets, or other compilations of data are excluded.
The CMIA amendments add an explicit definition of “health care chatbot,” meaning a generative AI system with a natural language interface that provides adaptive, human-like responses, is marketed as facilitating or supporting health services, and uses health care chatbot information to facilitate or support health service to a consumer. “Health care chatbot information” includes health-related information a consumer provides directly or by allowing access, as well as information collected, generated, or inferred by the chatbot. The amended Civil Code also expands the surrounding privacy vocabulary by defining “medical information,” “mental health digital service,” “reproductive or sexual health digital service,” “sensitive services,” “immigration enforcement,” “marketing,” and related terms. These definitions are central because they determine when consumer-facing AI health tools fall within the CMIA’s confidentiality and disclosure limits. The law’s definitional structure is therefore compliance-driven: it identifies the technological systems, the health care settings, and the categories of information to which the new obligations attach.
Governance and Institutional Framework
The governance model in AB 1979 is decentralized but strongly professionalized. The statute does not create a new standalone AI agency. Instead, it places compliance responsibility on health facilities, clinics, physician’s offices, and offices of group practices, while also keeping enforcement within existing professional licensing structures. A physician who violates Section 22758.5 falls within the jurisdiction of the Medical Board of California or the Osteopathic Medical Board of California, as appropriate. More broadly, where a violation constitutes the practice of a health care profession without a license, the appropriate professional licensing board may seek an injunction or restraining order under Section 125.5. This design ties AI governance directly to the bodies that already supervise professional competence and licensure, rather than to a general technology regulator. The law also preserves other available remedies by stating that nothing in the section limits the authority of licensing boards or enforcement agencies to pursue any remedy otherwise authorized by law.
On the privacy side, the governance framework is rooted in the CMIA, which already regulates medical information confidentiality and penalties for improper use or disclosure. By deeming businesses that offer health care chatbots to be providers of health care for CMIA purposes, AB 1979 extends existing oversight and enforcement mechanisms to a new class of digital health operators. The statute thereby uses familiar legal categories—provider of health care, contractor, health care service plan, and medical information—to bring AI-driven consumer products within the same confidentiality regime that applies to traditional health records. This approach matters because it allows regulators, courts, and compliance teams to use established healthcare privacy and licensing doctrines rather than inventing a separate AI-specific taxonomy. The result is a layered governance system: professional boards oversee clinical role boundaries, and the CMIA oversees confidentiality and misuse of medical information. For health organizations, governance therefore depends less on one new regulator and more on internal controls mapped to preexisting California health and professional law.
Key Focus Areas
The first major focus area is clinical decisionmaking. AB 1979 requires covered health care settings to take reasonable steps to ensure that a licensed health care provider retains the ability to exercise independent professional judgment when care is informed by a clinical decision support system. It also prohibits the deployment of AI tools to directly perform clinical functions that state law requires to be performed by a licensed person, and it prohibits AI from directing, guiding, supervising, or instructing unlicensed personnel in performing those licensed clinical functions. In practical terms, the law is aimed at preventing systems from becoming de facto clinical decisionmakers. Its text draws a boundary between AI-generated support and human professional authority, with the licensed provider remaining the accountable decisionmaker.
The second focus area is privacy and confidentiality. The CMIA amendments extend provider-like obligations to businesses that offer health care chatbots for managing information or for the diagnosis, treatment, or management of a medical condition. These businesses must maintain the same confidentiality standards required of a provider of health care and are subject to the CMIA’s penalties for improper use and disclosure of medical information. The law thus addresses direct-to-consumer AI health applications that collect or infer sensitive information, including health data that may be gathered through chat interfaces. The statute also aligns with California’s broader approach to sensitive services by recognizing mental health, sexual and reproductive health, substance use disorder, gender-affirming care, and intimate partner violence as highly sensitive categories. The third focus area is operational clarity. The statute excludes documentation and communication uses that do not involve professional judgment, such as appointment management, reminders, pre-visit materials, payment processing, and automated record-update messages. That carveout helps organizations separate administrative automation from regulated clinical use.
Implementation Framework
Implementation under AB 1979 will require covered entities to build internal controls around AI procurement, workflow design, and clinician supervision. The reasonable-steps requirement is flexible, but it clearly obligates organizations to ensure that licensed professionals can still exercise independent judgment whenever AI output informs care. That implies governance measures such as human-in-the-loop review, escalation pathways, role-based access controls, and written policies clarifying that AI output is advisory rather than determinative in covered clinical functions. Organizations must also avoid using tools that independently perform licensed clinical tasks or that direct unlicensed personnel to do so. The statute does not describe a certification program, a premarket approval process, or a formal registration regime, so implementation rests mainly on institutional compliance programs, documentation, and professional supervision practices.
For privacy compliance, businesses newly deemed providers of health care for CMIA purposes must align data handling practices with confidentiality obligations under Civil Code Part 2.6. That includes limiting uses and disclosures of medical information to those authorized by law, maintaining safeguards, and ensuring that health care chatbot information is treated with the same protections as other medical information. Because the statute also defines “marketing” and contains detailed rules for remunerated communications in the CMIA text, entities will need to review both product design and communications practices to avoid impermissible uses of health-related consumer data. The law’s explicit exclusion for non-clinical documentation and communication systems suggests that implementation should distinguish clearly between administrative AI features and functions that materially affect diagnosis or treatment. The operative date of 2027-01-01 means organizations have a compliance window to review contracts, policies, vendor terms, and training materials before the statute becomes active. The key implementation challenge will be mapping AI use cases to the statutory definitions and ensuring that clinicians, compliance teams, and vendors share the same understanding of where human judgment must remain in control.
Monitoring and Evaluation
AB 1979 does not set out a dedicated state reporting system, audit regime, or periodic review cycle, but it embeds monitoring through existing professional and enforcement structures. In clinical settings, the main monitoring obligation is organizational: covered entities must take reasonable steps to preserve independent professional judgment and prevent AI from crossing into prohibited functions. This is the kind of rule that will likely be evaluated through internal policies, incident review, professional oversight, and board complaints rather than through routine state submissions. Because physician violations are subject to the Medical Board of California or Osteopathic Medical Board of California, professional discipline can function as the primary ex post monitoring mechanism. Likewise, if a use case amounts to the unlicensed practice of a health care profession, boards may seek injunctive relief or restraining orders. The design encourages ongoing supervision, not just one-time compliance.
For the privacy component, monitoring will be anchored in the CMIA’s established rules on improper use and disclosure of medical information. Businesses offering health care chatbots must be able to demonstrate that they maintain the same confidentiality standards as other providers of health care for the medical information they handle. In practice, this suggests monitoring of data flows, retention practices, vendor processing, and user-facing disclosures. The statute itself does not prescribe metrics, testing intervals, or public transparency reports. Instead, it depends on ordinary enforcement channels and the evidentiary record generated when a privacy complaint, licensing matter, or civil action arises. The statute’s carveout for documentation and communications that do not involve professional judgment also creates an implicit evaluation task: organizations must distinguish permissible automation from regulated clinical support. Over time, evaluation will likely focus on whether AI systems are being used as aids to human professionals or as substitutes for licensed clinical functions.
Penalties, Liability, and Appeals
AB 1979 carries enforcement consequences through existing California health law structures rather than through a bespoke penalty schedule. A physician who violates Section 22758.5 is subject to the jurisdiction of the Medical Board of California or the Osteopathic Medical Board of California, which means professional discipline may follow under the applicable licensing framework. Where conduct amounts to the practice of a health care profession without a license, the appropriate licensing board may seek an injunction or restraining order to enforce the section. The statute also preserves all other remedies otherwise authorized by law, so liability is not limited to the measures expressly mentioned in the section. For AI vendors and institutions, this means the practical consequences may include licensing discipline, civil injunctive relief, and any additional remedies available under other statutes or common law if their conduct also violates those laws.
On the privacy side, the CMIA amendments provide that businesses covered by the new AI chatbot provision are subject to the penalties for improper use and disclosure of medical information prescribed in that part. The underlying CMIA framework already treats certain violations that result in economic loss or personal injury as misdemeanors, and AB 1979 extends the provider-like confidentiality obligations to the newly covered businesses. The statute does not create a separate appeals process or specialized administrative review route. Appeals therefore depend on the forum in which enforcement occurs, whether professional discipline, injunction proceedings, or a civil/privacy proceeding under the existing CMIA framework. The law’s penalty structure reinforces its policy objective: compliance is not merely a best practice but a legally enforceable duty. Its deterrent effect comes from the combination of professional oversight, privacy liability, and the possibility of injunctive relief against unauthorized clinical automation.
Relationship to Other Instruments
AB 1979 should be read alongside California’s existing medical privacy and AI-related health rules. Civil Code Part 2.6, the CMIA, already restricts the intentional sharing, selling, or use of medical information for purposes not necessary to provide health care services. AB 1979 expands that framework by deeming health care chatbot businesses to be providers of health care for CMIA purposes when they offer the chatbot for managing information or for diagnosis, treatment, or management of a medical condition. It also builds on existing California law requiring generative AI patient communications in certain settings to include disclaimers and human-contact instructions, but it goes further by focusing on whether AI may replace licensed judgment or perform licensed clinical functions. The new act therefore complements, rather than replaces, the state’s earlier disclosure-based approach to generative AI in health care.
The statute also interacts with broader California concepts of sensitive services, mental health digital services, and reproductive or sexual health digital services. It does not redefine those regimes wholesale, but it imports their terminology to expand the privacy perimeter around consumer-facing health tools. That is significant because it means the AI chatbot rule sits within a wider pattern of California health-data protection law. The law also references Section 125.5 for injunctive enforcement and cross-references multiple Health and Safety Code definitions, which shows that it is designed to fit into an existing ecosystem of health regulation rather than stand alone. The relationship to other instruments is therefore cumulative: AB 1979 adds AI-specific limits to the general CMIA confidentiality regime and the licensing-board enforcement framework already governing health professions in California.
National/Federal Alignment
At the federal level, there is no single comprehensive AI statute that directly matches AB 1979’s combination of clinical judgment protection and consumer health chatbot confidentiality rules. Instead, California’s law aligns most closely with broader federal themes in health privacy, professional responsibility, and AI risk management, while going beyond them in specificity. Federal health privacy law under HIPAA protects certain medical information held by covered entities and business associates, but AB 1979 extends California confidentiality duties to businesses offering health care chatbots that may operate outside classic covered-entity structures. The state law is therefore broader in some respects than federal privacy baselines, especially for direct-to-consumer products that market themselves as health services. Likewise, federal law generally leaves clinical supervision and professional licensing to the states, so AB 1979 is consistent with that allocation of authority while using it to restrict AI substitution for licensed judgment.
The statute also aligns with the federal regulatory emphasis on transparency and accountability in AI, but it is more prescriptive in the healthcare context. Rather than relying on generalized AI principles, the law specifies what types of AI use are allowed, what constitutes a clinical decision support system, and which functions cannot be automated. It also contains an explicit exclusion for administrative automation that does not require professional judgment, which mirrors the federal preference for risk-based rather than technology-neutral regulation. Still, California’s approach is more interventionist than any current federal health AI baseline because it directly ties AI use to licensure, confidentiality, and enforcement remedies. In practical terms, organizations operating nationally will need to treat California as a higher-compliance jurisdiction for health AI, especially where consumer-facing chatbots, medical information, or clinical support systems are involved.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Approved by Governor | 2026-09-30 | Chaptered as Chapter 854, Statutes of 2026. |
| Filed with Secretary of State | 2026-09-30 | Official filing date recorded in the chaptered text. |
| General effective date | 2027-01-01 | Non-urgency statute; effective under California Constitution article IV, section 8(c). |
Compliance Checklist
| Check | Required Action |
|---|---|
| Clinical judgment preservation | Ensure licensed professionals can retain independent judgment when AI informs care. |
| Prohibited automation review | Do not deploy AI to independently perform licensed clinical functions. |
| Unlicensed personnel controls | Prevent AI from directing, guiding, supervising, or instructing unlicensed personnel in licensed clinical tasks. |
| Documentation carveout | Limit administrative AI to documentation and communication that do not involve professional judgment. |
| CMIA classification | Treat covered health care chatbot businesses as providers of health care for CMIA purposes. |
| Confidentiality safeguards | Maintain provider-level confidentiality standards for medical information handled by covered AI tools. |
| Vendor and workflow review | Review contracts, policies, and workflows before the 2027-01-01 effective date. |
Sources and References
| Source | Type |
|---|---|
| Assembly Bill No. 1979, Chapter 854, Statutes of 2026 — California Legislative Information | official |
| Governor of California — signing announcement, 30 September 2026 | official |
More AI regulation in United States
© Regulations.AI — created on 9 Oct 2026 using Gemini 3.6 Flash