top of page

California Sets Health AI Guardrails: What Physician Practices Should Review Now

4 hours ago
2 min read

New laws address clinical judgment, patient privacy and biased outcomes from clinical decision-support tools.


When a clinical decision-support tool informs care, physicians need the authority to question its recommendations—and practices need a clear process for addressing problems.


Governor Gavin Newsom signed AB 1979 and SB 503 on September 30, adding protections governing technology in health care. With implementation expected January 1, 2027, Los Angeles practices should use the coming months to review their tools, oversight and vendor agreements.


AB 1979 requires physician offices, group practices, clinics and health facilities to take reasonable steps to preserve licensed professionals’ independent judgment when clinical decision-support tools inform care. It prohibits covered practices and facilities from using or deploying AI to independently perform clinical functions reserved for licensed professionals or to direct unlicensed personnel to perform those functions.


The clinical oversight section excludes automated documentation and communication that do not involve professional judgment, including record-update messages and reminders. Separately, the law extends California medical-information privacy protections to qualifying health care chatbot businesses.

Physician violations fall under the Medical Board of California or Osteopathic Medical Board of California. Appropriate licensing boards may also seek injunctions or restraining orders when a violation constitutes unlicensed practice.


SB 503 establishes responsibilities for developers and deployers of clinical decision-support systems. Both must make reasonable efforts to identify bias risks. Developers’ obligations include mitigation, and deployers’ include monitoring tools in use. For practices, that means examining vendor documentation and tracking concerns that emerge in patient care.


Five steps for your practice

These recommendations translate the laws’ priorities into practical preparation; they are not a verbatim compliance checklist.

  • Inventory clinical tools. Identify systems that influence diagnosis, treatment or timing of care, including features embedded in existing software. Record their purpose, vendor, data inputs and clinical use—even if they are not marketed as AI.

  • Name a clinical lead. Assign responsibility for each tool. Document how licensed professionals review and override output, report concerns and suspend use when necessary.

  • Request written bias documentation. Ask vendors about testing across patient groups, known limitations and mitigation measures. Establish a practice-level process for monitoring tools in use and documenting concerns and responses.

  • Map chatbot data handling. Confirm what information is collected or inferred, who can access it, retention periods, sharing arrangements and whether it is used for model training.

  • Test the route to a human. Make escalation clear for patients and staff, including after-hours handling of urgent concerns. Existing law requires an AI disclosure and human-contact instructions for covered generative-AI communications about patient clinical information. Communications read and reviewed by a licensed or certified health care provider are exempt from those requirements. Health and Safety Code § 1339.75


Begin with tools most likely to change a clinical decision. Keep a single register connecting each tool to its clinical lead, vendor documentation and next review date.

 
 
 

Recent Posts

See All
CMA Challenges California’s Renewed MCO Tax

The California Medical Association and the California Association of Health Plans have filed a lawsuit in the California Supreme Court challenging the managed care organization tax enacted through S

 
 
 

Comments


bottom of page