AI Policy for Providers: What the Rules Actually Say in 2026

Kibu Team

Man on pink background gestures towards title

AI Policy for Providers: What the Rules Actually Say in 2026

AI is likely already in your organization's toolbox, whether that’s note drafting, scheduling, or chatbots. The question leaders keep asking isn't "should we use it," it's "are we allowed to, and how?" There is no one federal AI law for healthcare or human services yet. Instead there's a growing patchwork of federal rules and state laws, and it's evolving fast. We'll lay out the full picture, then give you a clear path forward.

The Big Picture: A Patchwork, Not a Rulebook

Congress has not passed comprehensive AI legislation for healthcare. States are leading. So a provider's obligations come from three places stacked together: existing federal privacy law (HIPAA), federal civil-rights law (Section 1557), and a growing set of state AI laws. So, what does that mean for those in charge? Waiting for one clear law is not a strategy. When several rules apply, build to the toughest standard, if you satisfy that, you’ll be compliant across the board.

HIPAA First: Your Federal Baseline for Protected Health Info

HIPAA wasn't written for AI, but AI doesn't get a pass. If a tool touches PHI, ++++HIPAA applies.
New development: HHS's proposed HIPAA Security Rule update (NPRM issued Dec 27, 2024) explicitly names AI among emerging technologies and would make safeguards like encryption, multi-factor authentication, and asset inventories mandatory. Keep in mind, it is still proposed, not final, as of mid-2026 — the current Security Rule remains in effect. Don't imply it's a law yet. The direction of travel is stricter, so building good habits now is cheap insurance.

Section 1557: Where AI Meets Disability Rights

This is the section that matters most for IDD and deserves the most weight.

HHS's Section 1557 final rule (effective July 5, 2024) applies anti-discrimination protections, including on the basis of disability, to "patient care decision support tools," which expressly includes AI and algorithms. Covered providers must make reasonable efforts to identify tools that use disability (and other protected traits) as factors, and mitigate any discriminatory effect. Compliance was required within 300 days of the effective date. Algorithmic bias isn't abstract for people with complex support needs. A tool trained on "typical" data can quietly disadvantage the people you serve.

What This Means for You: How to Build a Simple AI Policy

Pivot from landscape to action. A provider AI policy doesn't need to be long. It just needs to answer, in plain language:

  1. Which tools are approved (and which are banned for anything client related?)
  2. What may never go into a general AI tool? (Names, diagnoses, behaviors = PHI.)
  3. Who reviews AI output before it becomes part of a record? (Human in charge.)
  4. What do we disclose to members and families?
  5. Who owns this, and how often do we revisit it as laws change?

A Note for Frontline Staff

AI can save you time on notes and scheduling, but a few simple rules keep you and the people you support safe. When in doubt, ask your supervisor before you use any AI tool on the job.

Do:

  • Use your agency's approved tool. It's set up to protect member information.
  • Read everything the AI writes before you sign or submit it. You're still responsible for what goes in the record.

Don't: 

  • Paste a member's name, notes, or any personal details into a public chatbot like ChatGPT. Once it's in, you can't take it back.

Where Kibu Fits

The compliance burden is real, but providers shouldn't have to assemble a legal team to use AI safely. Kibu is purpose built for disability services: BAA already in place, AI tuned for ISPs/progress notes/person centered planning, safeguards baked in. Providers cut documentation time while increasing compliance. If you are ready to see how AI can fit into your agency without the implementation headache, and stress surrounding compliance, schedule a quick demo and we will walk you through what is possible. 

The Bottom Line

The rules will keep changing. You can't wait them out. Know your federal floor (HIPAA + 1557), watch out for your state's rules, write a simple policy, keep a human in charge, and use tools built for this work.  

Frequently Asked Questions 

Does HIPAA apply to AI tools?

Yes. If an AI tool touches Protected Health Information (PHI) — a member's name tied to a diagnosis, a service note, a progress summary, anything that identifies a person and their health — HIPAA applies, full stop. The technology being new doesn't create an exemption.

What this means in practice: any AI vendor that will handle PHI on your behalf is a business associate, and you need a signed Business Associate Agreement (BAA) before that data moves. Free, consumer-grade chatbots that haven't signed a BAA are not safe places to paste a member's information, no matter how convenient they are. Before adopting any AI tool, the question to ask is simple: "Will this touch PHI, and if so, will the vendor sign a BAA and meet HIPAA's security and privacy requirements?" If the answer is no, that tool doesn't belong anywhere near member data.

Can an AI tool discriminate against people with disabilities?

Yes, it can. That's not a hypothetical. AI systems learn from historical data, and when that data reflects bias against people with disabilities, the tool can reproduce and even amplify it in decisions about care, eligibility, or service levels.

Here's the part that matters most for providers: you can be held responsible for it. Section 1557 of the Affordable Care Act, under a rule with compliance required as of May 2025, explicitly extends nondiscrimination protections to "patient care decision support tools", which includes AI and clinical algorithms. If your organization receives federal financial assistance (Medicaid dollars count), you're a covered entity. The rule requires you to make reasonable efforts to identify whether the tools you use rely on factors like disability, and to take reasonable steps to mitigate any resulting discrimination. In other words, "the algorithm decided" is not a defense. The obligation to prevent discriminatory outcomes sits with you, not just the vendor.

 Do we have to tell members and families we're using AI?

It depends on your state and how you're using AI, but disclosure is clearly the direction things are heading, and in some places it's already the law.

California has moved first. Under AB 3030, effective January 1, 2025, health facilities, clinics, and physician practices that use generative AI to create communications about a patient's clinical information must include a disclaimer that the message was AI-generated, along with clear instructions for how to reach a human. There's a practical exemption: if a licensed provider reviews the AI-generated communication before it goes out, the disclaimer isn't required. And it doesn't apply to purely administrative messages like appointment reminders or billing.

Even if your state hasn't passed a law yet, the trend is unmistakable, and transparency builds trust with the members and families you serve. The safest posture is to be upfront now: tell members and families where AI is being used, keep a human in the loop, and make it easy for someone to reach a real person. That's good compliance and good practice, regardless of what your state requires today.

**This blog post is for general information and isn't legal advice. Regulations around AI in healthcare are evolving quickly and vary by state, so check with your compliance team or counsel before making decisions for your organization.