RatedWithAI

RatedWithAI

Accessibility scanner

AI Healthcare LawAugust 27, 2026

California AB 3030 Is a Workflow Rule Wearing a Disclosure Rule's Clothes

Since January 1, 2026, a generative-AI message about a patient's clinical care has to carry a disclaimer and a way to reach a human — unless a licensed provider reads it first. That one exception is the whole compliance strategy for most practices, and almost nobody has mapped their message flows against it.

Jan 1, 2026
Effective date, no phase-in
2 requirements
Disclaimer + human-contact path
1 exception
Licensed-provider review removes both

The Rule in One Sentence, Then the Fine Print

AB 3030 amends California's Health and Safety and Business and Professions codes to say this: when a health facility, clinic, physician's office, or group practice uses generative AI to create a written or verbal communication to a patient that pertains to the patient's clinical information, that communication must include a disclaimer that it was AI-generated and instructions for how to reach a human. Everything hard about the statute lives in the qualifiers — generative AI, clinical information, and the reviewed-by-a-licensed-provider carve-out.

It is not a general "tell patients you use AI" law. It is narrow, and its narrowness is what makes it easy to both over-comply and under-comply at the same time — bolting disclaimers onto appointment reminders that never needed them while missing the AI-drafted portal reply about a lab result that did.

What Counts as a Covered Communication

Three conditions all have to be true. Miss any one and the message is outside AB 3030.

1

It was generated by generative AI

A templated auto-reply, a mail-merge, or a rules-based chatbot that assembles fixed phrases is not generative AI. A large language model drafting the text is. If your vendor's tool composes novel sentences from a model, this condition is met — and most patient-messaging tools marketed as 'AI' in 2026 are exactly that.

2

It is a communication with the patient

The output has to actually go to the patient — a portal message, a text, an email, a chatbot reply, an outbound call or voicemail. Internal notes, chart documentation, and clinician-facing summaries are not communications with the patient and are out of scope, no matter how they were generated.

3

It pertains to the patient's clinical information

Symptoms, diagnosis, test and lab results, treatment and medication instructions, care plans, triage guidance. A pure logistics message — 'your appointment is Tuesday at 3' — that references no clinical content does not meet this condition. The gray zone is the message that starts logistical and drifts clinical ('reschedule because your provider wants to recheck your blood pressure'); treat drift as clinical.

Where the Disclaimer Has to Sit

The statute is specific about placement by channel, because a disclaimer a patient scrolls past is not a disclaimer. Match the format to the medium.

  • Written messages (email, portal, letter): the disclaimer appears prominently at the beginning of the message.
  • Continuous chat / chatbot interactions: the disclaimer is prominent and appears throughout the interaction, not just on the first bubble a patient may never re-read.
  • Audio messages / voicemail: a verbal disclaimer at the start and at the end of the message.
  • Video or live phone conversations using AI: a verbal disclaimer at the start and at the end of the interaction.

Paired with each of these is the second requirement: clear instructions for how the patient can reach a human — a named line, a portal action, a number to call. "Contact your provider" with no mechanism is not clear instructions. Give the actual path.

The Exception That Decides Your Whole Strategy

The requirements do not apply if the AI-generated communication is read and reviewed by a licensed or certified health care provider before it reaches the patient. This is not a technicality — it is the intended off-ramp. A practice that keeps a human in the loop on every AI-drafted patient message owes no disclaimer and no human-contact instruction, because a clinician has already taken responsibility for the content.

Which means the real compliance question is architectural: does any AI-generated clinical message ever reach a patient without a licensed provider reading it first?If the honest answer is no, you are compliant by workflow and should be able to prove it. If the answer is yes — an autonomous portal chatbot, an after-hours AI triage responder, an auto-sent result explanation — those specific unreviewed paths are the ones that must carry the disclaimer and the human-contact instructions.

A One-Afternoon Compliance Pass

Do This

  • Inventory every patient-facing message channel and mark which use generative AI
  • For each AI channel, decide: reviewed by a licensed provider before send, yes or no
  • For unreviewed channels, add the channel-correct disclaimer AND a human-contact path
  • Document the review step where it exists — it is your exception evidence
  • Confirm chatbot disclaimers persist throughout, not just on the first message
  • Name the human contact concretely: a line, a portal button, a number

Skip / Don't Overreach

  • Disclaimers on non-clinical logistics messages that reference no clinical content
  • Disclaimers on ambient scribe notes that never reach the patient
  • Blanket 'we use AI' banners in place of the specific two requirements
  • Treating a rules-based auto-reply as generative AI
  • Assuming vendor 'AB 3030 compliant' claims cover your review workflow
  • One disclaimer format reused across every channel regardless of medium

Frequently Asked Questions

We're not in California — does AB 3030 matter to us?

Directly, only if you communicate with California patients through a covered facility or practice. Indirectly, it matters a great deal: AB 3030 is the first US statute to put a specific, channel-by-channel shape on AI-in-patient-communication disclosure, and it is the template other states and health systems are copying. Building the reviewed-or-disclaimed workflow now is cheaper than retrofitting it per state later.

Does a HIPAA authorization or our general privacy notice cover this?

No. HIPAA governs the use and disclosure of protected health information; AB 3030 governs whether the patient is told a message was AI-generated and how to reach a human. They are different obligations with different triggers. A privacy notice buried in intake paperwork does not satisfy the prominent, in-message, channel-specific disclosure AB 3030 requires.

Our vendor says the tool is 'AB 3030 compliant.' Are we done?

Not automatically. A vendor can supply a compliant disclaimer template and a human-contact field, but only your practice knows whether a licensed provider reviews each message before send — the fact that decides whether the disclaimer is even required. Compliance lives in your workflow. Ask the vendor to show you exactly where in the send path the disclaimer is injected and whether it can be conditioned on a review step.

What if a nurse or medical assistant reviews the message instead of a physician?

The exception turns on review by a licensed or certified health care provider. A licensed nurse reviewing within their scope generally qualifies; unlicensed administrative staff clicking send does not. If your review step is performed by someone without the relevant license or certification, you have not met the exception and the message still needs the disclaimer and human-contact path.

How is this enforced if there's no per-message fine?

Through the licensing and facility-oversight machinery that already governs your practice — the Medical Board for physicians, the relevant department for licensed facilities, using their existing authority. That is a feature, not a gap: a documented pattern of unreviewed, undisclosed AI clinical messages becomes a professional-conduct matter, which for a licensed provider is a more consequential form of exposure than a schedule of fines.

The Compliance Artifact Is a Message-Flow Map

AB 3030 does not reward a policy document. It rewards a map: every patient-facing channel, which ones use generative AI, and for each of those, whether a licensed provider reads the message before it sends. That single table tells you which messages need the disclaimer and which are covered by the exception — and it is the evidence you would produce if a board ever asked.

Draw the map first. The disclaimers write themselves once you know which rows still need them.

This article is general information about a California statute, not legal or clinical-compliance advice. Statutory text and board guidance are updated over time — confirm the current requirements and your specific obligations with qualified California healthcare counsel.