Digital Health Blog

Legal & Policy Insight to Empower the Evolution of Health Care

  1. Federal Bill Targets Corporate Influence in Health Care and PC-MSO Structures

    On September 16, the Stop Corporate Takeovers of Physicians Act was introduced by Sens. Elizabeth Warren, Ron Wyden, and Jeff Merkley, along with Reps. Val Hoyle, Suhas Subramanyam, and Alexandria Ocasio-Cortez. The legislation largely mirrors Oregon’s SB 951, which took effect earlier this year, and comes amid growing state and federal efforts to address corporate involvement in health care, including increased scrutiny of physician practice management and PC-MSO arrangements in California.

    Key Provisions of the proposed federal legislation include:

    • Prohibition on private equity firms, insurers, and other for-profit corporations from owning or controlling medical practices.
    • Closing the longstanding “friendly physician” model by restricting MSO arrangements that effectively allow investors to control physician practices despite state CPOM prohibitions.
    • Bans on MSOs exercising control over core business, operational, and clinical functions, including hiring and firing decisions, physician compensation, scheduling, revenue targets, contracting, and billing practices.
    • Physician owners must be licensed and actively engaged in the delivery of care within the state where the practice operates.
    • Physician must retain authority over clinical judgement and a prohibition on contractual provisions, including non-compete, non-disclosure, and non-disparagement agreements are banned.

    For health care investors, MSOs, physician groups, and health systems, the legislation is another signal that scrutiny of management and ownership structures is likely to intensify. Although prior efforts to implement similar legislation in the states have failed, this bill may cause more states may look to reintroduce similar legislation in 2027 legislative sessions.

    For a deeper analysis of the proposal and its practical implications for providers and MSOs, see the HLB Digital Health Team’s article, Federal Bill Seeks to Outlaw the Friendly PC/MSO Model Nationwide, but State Enforcement Is the Real Near-Term Risk.

  2. California Enacts New AI and Consumer Privacy Laws

    California Gov. Gavin Newsom has signed several bills aimed at regulating the use of artificial intelligence in health care settings. Collectively, the new laws reinforce and clarify existing principles requiring meaningful human oversight of AI tools that influence clinical decision-making. Among them, AB 1979 prohibits providers from using an AI-enabled tool, system, or device to independently perform clinical functions that state law reserves for licensed professionals or from directing unlicensed personnel to perform those functions. The bill also emphasizes that licensed providers must retain independent professional judgment when evaluating and acting on AI-generated recommendations in patient care.

    AB 2575 protects the ability of health care professionals to override AI-generated recommendations and prohibits developers and deployers from using a clinician’s decision to override an AI system as a defense in litigation alleging harm caused by the system’s output. SB 503 requires developers to take reasonable steps to identify, assess, and mitigate foreseeable risks of bias arising from the use of AI-assisted clinical decision support systems.

    The legislature also approved , The Wellness for Oversight and Psychological Resources Act, SB 903, was signed into law and prohibits the provision or marketing of psychotherapy services through companion chatbots, including representations that a chatbot is a therapist or provides therapy. The bill, which parallels legislation first of its kind legislation which enacted in Illinois and replicated elsewhere, requires review and oversight by licensed professionals when AI is used for certain mental health-related functions, including therapeutic decision-making, triage, screening, and the detection or assessment of an individual’s mental or emotional state.

    Also enacted are two notable amendments to the California Consumer Privacy Act (CCPA). AB 1542 prohibits businesses from selling or sharing a consumer’s sensitive personal information with third parties unless the consumer intentionally discloses the information or intentionally interacts with the third party. SB 923 expands the CCPA’s deletion right to cover all information a business has collected about a consumer and requires businesses that operate exclusively online to provide a dedicated online mechanism, such as a webform or portal, for consumer requests in addition to an email address. Together, these measures strengthen consumer control over personal information and expand businesses’ compliance obligations under the CCPA.

  3. Comments on FDA’s Discussion Paper on GenAI in Health Care Due October 19

    The comment period remains open for the Food and Drug Administration’s discussion paper on regulatory considerations for generative artificial intelligence (GenAI)-enabled medical devices. The paper outlines a potential framework designed to address the unique capabilities and risks associated with GenAI technologies, including a two-axis risk assessment model and a premarket evaluation approach based on “competency assessment.” Under this approach, GenAI-enabled devices would be evaluated through a combination of non-clinical benchmarking and clinical confirmation to demonstrate that they perform as intended before reaching patients. The discussion paper also explores risk-based postmarket monitoring strategies and identifies key regulatory considerations for foundation models and increasingly autonomous agentic AI systems. Collectively, the proposals offer an early look at how the FDA may approach oversight of the next generation of AI-enabled medicine. Comments are due by October 19, 2026.

  4. Washington Court Rules that Patients Can’t Demand AI Scribe Recordings

    In Raphael v. Mantei, a recently reported Washington state court decision, the judge rejected a patient’s request for access to a raw audio recording used by an ambient AI tool during a telehealth visit to assist in the creation of a clinical note. The physician had used an ambient scribe to record the encounter and generate a draft note, which was subsequently reviewed, edited, and finalized before being incorporated into the patient’s medical record. The court agreed with the treating clinic’s position that the audio recording served solely an administrative purpose and therefore fell within an exception to disclosure under Washington’s Uniform Health Care Information Act.

    The clinic’s position was supported by an amicus brief filed by the American Medical Association, the Washington State Medical Association, and the Washington State Hospital Association. The groups jointly argued that AI-generated audio recordings should be treated similarly to physician dictation, handwritten notes, and other intermediate materials used in preparing the medical record, rather than as part of the medical record itself.

    Although the decision is limited to an interpretation of Washington law, it highlights issues that are likely to arise as ambient documentation technologies become more prevalent across healthcare settings. The ruling does not establish a nationwide standard, address patient consent requirements, or resolve how HIPAA’s right of access applies to AI-generated recordings. Providers and health systems implementing ambient scribe technologies should continue to monitor developments in state patient-access laws while maintaining a vigilant compliance posture.

  5. FTC, Utah, and California Sue Hims & Hers Over Billing Practices and Health Data Sharing

    On July 29, 2026, the Federal Trade Commission, joined by Utah and California, filed suit against telehealth company Hims & Hers in the Northern District of California. The complaint alleges that Hims shared consumers’ condition-specific health information with third-party advertising platforms, including Meta and Snap, through both customer-list uploads and tracking pixels that automatically transmitted website “Events”—despite representations to users that Hims would not disclose consumers’ health information to third parties. The complaint also alleges that Hims enrolled consumers in recurring prescription subscriptions and charged them shortly after they submitted an online intake form, before they had connected with a provider, and made subscription cancellation unreasonably difficult. The FTC asserts claims under Section 5 of the FTC Act and the Restore Online Shoppers’ Confidence Act, while Utah and California assert state consumer protection and false advertising claims.

    The case reflects the FTC and states’ continued use of general consumer protection laws to scrutinize digital health companies’ use of tracking technologies, advertising platforms, subscription practices, and privacy representations, as seen in recent regulatory actions involving BetterHelp and Flo Health. The complaint also reinforces that HIPAA is not the only privacy regime with meaningful enforcement risk. Even companies that fall outside HIPAA’s scope may face exposure under the FTC Act’s deception and unfairness theories, as well as increasingly active state consumer protection and false advertising laws, which may reach conduct that HIPAA does not, and often with broader remedies.

  6. CMS Proposes Significant Changes to RPM and RTM Services

    In the CY 2027 Medicare Physician Fee Schedule proposed rule, CMS is proposing several notable changes to Remote Physiologic Monitoring (RPM) and Remote Therapeutic Monitoring (RTM) services. First, CMS would limit RPM and RTM billing to established patients. CMS proposes requiring a separately billable initiating visit before RPM or RTM services begin, meaning the billing practitioner must initiate the services during an in-person or telehealth encounter. Additionally, CMS proposes that the clinical staff time used to furnish RPM and RTM services be provided only by individuals directly employed by the billing practitioner or practice, rather than outsourced third parties. CMS states that the proposal is responsive to multiple OIG reports raising concerns about care fragmentation and insufficient practitioner oversight when monitoring services are outsourced. Comments are due September 14, 2026.

  7. HHS OIG Updates Work Plan to Include HHS AI Audit

    The U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) announced an audit of HHS governance of artificial intelligence (AI). Given HHS’ reliance on AI tools to support public health surveillance, fraud detection, and administrative automation, OIG believes it is important that HHS fully establish and implement a comprehensive AI governance framework to manage risks. OIG will conduct the audit to determine whether HHS has established AI governance in accordance with Federal and HHS requirements.

  8. House passes KIDS Act, sending online child safety debate to the Senate

    On July 7, the House of Representatives passed the KIDS Act (H.R. 7757) in a vote of 267-117, advancing a package of online child safety measures aimed at establishing baseline federal protections for minors while allowing states to enact stronger safeguards. The legislation reflects years of congressional efforts to strengthen protections for children online and follows a bipartisan agreement reached in the House Energy and Commerce Committee.

    The package includes provisions requiring AI chatbots to disclose that they are not human, restricting minors’ access to disappearing messages, and requiring age-verification technologies for certain content. The bill also establishes federal standards for children’s online safety while preserving states’ ability to adopt more stringent protections and does not preempt state artificial intelligence laws.

    While House passage marks a significant milestone, substantial challenges remain before the legislation can become law. The House and Senate continue to differ on key elements of child online safety policy, including age-verification requirements, First Amendment concerns, and whether online platforms should be subject to a “duty of care” obligation requiring them to design products with children’s safety in mind. While this legislation may not see final passage this Congress, this has been an ongoing bipartisan area of interest as Congress looks to find agreement on how to regulate artificial intelligence and work will likely continue into the next Congressional session.

  9. California expands sales tax to SaaS and digital products

    On June 29, 2026, California Governor Gavin Newsom signed SB122 into law, expanding the state sales tax base to include SaaS, electronically delivered software, and certain digital products beginning in 2027. The legislation generally treats many digital products as taxable tangible personal property and adopts a customer-based sourcing methodology. For remotely accessed or electronically delivered products, sales are sourced to the purchaser’s “known address” in California.

    The new tax classifications will require both software providers and customers to reassess their sales and use tax compliance obligations. These changes also may increase costs for healthcare providers and other end users as software vendors seek to pass through newly imposed sales and use tax liabilities. Users may also see increased compliance costs associated with implementing the new regime and amending existing contractual arrangements.

  10. Illinois’ AI Safety Measures Act reflects the growing patchwork of state-level AI regulations

    Illinois Governor J.B. Pritzker signed the Artificial Intelligence Safety Measures Act into law on July 6, 2026. The legislation requires developers of frontier AI models to develop and publish a transparency framework describing how they apply recognized industry standards, evaluate model capabilities, and assess and mitigate risks of catastrophic harm to individuals and the public.

    The Illinois measure builds on transparency and accountability requirements included in California’s the Transparency in Frontier Artificial Intelligence Act and New York’s the Responsible AI Safety and Education (RAISE) Act, both enacted in late 2025. Like those laws, the Illinois framework imposes a range of obligations on developers of frontier models, including the publication of transparency reports and AI safety frameworks, incident reporting requirements, implementation of cybersecurity safeguards, and processes for identifying and responding to critical safety incidents.

    The new law also includes, for the first time, a requirement that large frontier model developers undergo annual independent third-party audits evaluating model risks, safety controls, and mitigation measures. These audits must be conducted in accordance with accepted auditing standards and recognized industry best practices, signaling a shift from voluntary commitments toward more formal oversight and accountability mechanisms.

    As transparency and accountability continue to emerge as central pillars of AI governance, particularly in healthcare, these disclosure and audit requirements may provide healthcare organizations with valuable information to support the assessment, procurement, monitoring, and governance of AI-enabled tools that incorporate frontier models. More broadly, the enactment of this law underscores the increasingly complex compliance landscape facing AI developers and deployers as states continue to advance AI-specific regulatory frameworks while federal lawmakers debate the appropriate scope and structure of national AI regulation. The result is a growing patchwork of state requirements that may create additional compliance, governance, and operational challenges for organizations deploying AI systems.