Use-case guide

AI in Healthcare

AI in healthcare touches the most sensitive personal data there is — and the wrong decision can kill someone. Regulators have responded with two layers of rules: data-protection laws that govern how you process health data, and AI-specific laws that treat clinical decision support, triage, and medical-device AI as high-risk by default. If your AI is used in diagnosis, triage, drug discovery, claims adjudication, or patient-facing chatbots, almost every major regulator currently has you in scope.

For: Clinicians, hospital systems, healthtech founders, payers, and regulators

What's at stake

Data is special-category by default

Under GDPR, health data is Article 9 'special category' data — you generally need explicit consent or a specific exemption (e.g. medical treatment, public-health interest) before processing it.

Clinical AI is high-risk by classification

Under the EU AI Act, AI used as a safety component of a medical device — or AI in healthcare contexts more broadly — is high-risk (Annex III, Article 6 + Annex I via the MDR/IVDR). That triggers documentation, risk-management, post-market monitoring, and human oversight duties.

Algorithmic bias is a discrimination risk

Training data that under-represents minorities or older patients can lead to worse predictions for those groups — exposing you to anti-discrimination claims in the US (e.g. Section 1557 of the ACA) and human-rights challenges in the EU.

Cross-border training data is risky

Most clinical AI today is trained on data from a handful of jurisdictions. Using it elsewhere without local validation can be a regulatory and a clinical problem.

Regulations that apply

Do

  • ✓Run a Data Protection Impact Assessment AND a clinical risk assessment before deploying — most regulators expect both.
  • ✓Document the training data demographics and validate model performance on each subgroup you care about.
  • ✓Keep a human-in-the-loop for any decision with material patient impact. Document who decides what.
  • ✓Set up post-market monitoring — track real-world performance, drift, and adverse events.
  • ✓Be explicit with patients about AI involvement in their care, especially for triage and diagnosis.

Don't

  • ✗Don't deploy a clinical AI tool trained only on US data into European clinical practice without re-validation.
  • ✗Don't use 'legitimate interest' as the GDPR basis for processing health data — it almost never works.
  • ✗Don't rely on de-identification alone to escape GDPR — re-identification risk for clinical data is high.
  • ✗Don't automate adverse-decision letters (e.g. claims denials) without a route for the affected person to appeal to a human.
  • ✗Don't ship a generative AI patient chatbot in China without a CAC security assessment and algorithm filing.

Also worth knowing

If you're a US healthcare provider or business associate, the bulk of your AI compliance load currently flows through HIPAA (privacy + security rule) plus FDA premarket review for SaMD. The state AI laws (Colorado, NYC LL144 for hiring, etc.) sit on top of these — they don't replace them.

Want a tailored answer?

The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.

Start the wizard →

Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.

Note: this guide was drafted with AI assistance — Anthropic Claude.