Use-case guide
AI in Healthcare
AI in healthcare touches the most sensitive personal data there is — and the wrong decision can kill someone. Regulators have responded with two layers of rules: data-protection laws that govern how you process health data, and AI-specific laws that treat clinical decision support, triage, and medical-device AI as high-risk by default. If your AI is used in diagnosis, triage, drug discovery, claims adjudication, or patient-facing chatbots, almost every major regulator currently has you in scope.
For: Clinicians, hospital systems, healthtech founders, payers, and regulators
What's at stake
Data is special-category by default
Under GDPR, health data is Article 9 'special category' data — you generally need explicit consent or a specific exemption (e.g. medical treatment, public-health interest) before processing it.
Clinical AI is high-risk by classification
Under the EU AI Act, AI used as a safety component of a medical device — or AI in healthcare contexts more broadly — is high-risk (Annex III, Article 6 + Annex I via the MDR/IVDR). That triggers documentation, risk-management, post-market monitoring, and human oversight duties.
Algorithmic bias is a discrimination risk
Training data that under-represents minorities or older patients can lead to worse predictions for those groups — exposing you to anti-discrimination claims in the US (e.g. Section 1557 of the ACA) and human-rights challenges in the EU.
Cross-border training data is risky
Most clinical AI today is trained on data from a handful of jurisdictions. Using it elsewhere without local validation can be a regulatory and a clinical problem.
Regulations that apply
EU AI Act
LawClinical decision support, AI medical devices, and patient-triage systems are high-risk. Need risk-management system, post-market monitoring, human oversight, and EU database registration.
Where in the text: Article 6 + Annex I (MDR/IVDR linkage); Article 9 (risk management); Article 14 (human oversight).
GDPR
LawHealth data is Article 9 special-category data — need explicit consent or a specific Art. 9(2) exemption. DPIA almost always required.
Where in the text: Articles 9, 35, 22 (no fully-automated decisions with legal effect).
Colorado AI Act
LawHealthcare is a 'consequential decision' domain. Deployers need risk-management policies and annual impact assessments; HIPAA-regulated activities are partly exempt but the AI duties still attach.
Where in the text: Sec. 6-1-1701(3) (definition); 6-1-1703 (deployer duties); HIPAA-exemption carve-outs.
China Generative AI Measures
LawApplies to generative AI medical chatbots offered in China. Add: PIPL for personal health information (cross-border transfer rules are strict).
Where in the text: Generative AI Measures Articles 7, 9, 14; PIPL Articles 28-29 (sensitive PI).
Do
- ✓Run a Data Protection Impact Assessment AND a clinical risk assessment before deploying — most regulators expect both.
- ✓Document the training data demographics and validate model performance on each subgroup you care about.
- ✓Keep a human-in-the-loop for any decision with material patient impact. Document who decides what.
- ✓Set up post-market monitoring — track real-world performance, drift, and adverse events.
- ✓Be explicit with patients about AI involvement in their care, especially for triage and diagnosis.
Don't
- ✗Don't deploy a clinical AI tool trained only on US data into European clinical practice without re-validation.
- ✗Don't use 'legitimate interest' as the GDPR basis for processing health data — it almost never works.
- ✗Don't rely on de-identification alone to escape GDPR — re-identification risk for clinical data is high.
- ✗Don't automate adverse-decision letters (e.g. claims denials) without a route for the affected person to appeal to a human.
- ✗Don't ship a generative AI patient chatbot in China without a CAC security assessment and algorithm filing.
Also worth knowing
If you're a US healthcare provider or business associate, the bulk of your AI compliance load currently flows through HIPAA (privacy + security rule) plus FDA premarket review for SaMD. The state AI laws (Colorado, NYC LL144 for hiring, etc.) sit on top of these — they don't replace them.
Want a tailored answer?
The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.
Start the wizard →Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.
Note: this guide was drafted with AI assistance — Anthropic Claude.