Compliance Tool · AI & Emerging Tech

AI Vendor Risk Assessment

Ambient scribes, AI coding assistants, chart summarizers, and LLM-backed patient messaging are moving into healthcare faster than the contracts covering them. This checklist works three angles: the business associate agreement terms that decide whether your PHI trains someone else's model, the California rules that now govern AI touching patients, and the internal governance that makes AI a named risk area instead of a shadow one. Check items off as you confirm them; your progress saves in this browser.

Sources: 45 CFR Part 164 ↗  ·  AB 3030 ↗  ·  AB 489 ↗  ·  SB 1120 ↗  ·  Compiled as of July 19, 2026

Items shown
Checked off
Complete
Current view

Items are grouped into three lanes. Contract and BAA covers what the paper has to say before the vendor touches PHI: training-on-data prohibitions, model retention, subprocessor disclosure, and whether a vendor's de-identification claim would actually survive a look under 45 CFR §164.514. Clinical and patient-facing covers the California statutes that reach AI in the care setting, several of which land on the developer rather than the provider. Program governance maps AI onto the OIG seven elements, because AI governance is not a separate framework, it is your existing program applied to a new risk surface. Items badged High exposure are the ones where a gap carries direct statutory or contractual liability rather than process risk.

Contract & BAA

Training-on-data prohibitions, model and prompt retention, subprocessor and foundation-model disclosure, de-identification claims, output ownership, audit rights, and incident clocks that beat the federal 60 days.

Clinical & Patient-Facing

AB 3030 GenAI disclaimers on clinical communications, AB 489 limits on implying a licensed clinician, SB 1120 human review of medical-necessity decisions, and ambient-scribe notice and review workflows.

Program Governance

AI inventory and approval gate, shadow-AI policy, workforce training, AI in the annual risk assessment, bias and drift monitoring, and a reporting channel that captures AI concerns.

AB 3030 GenAI clinical-communication disclaimers effectiveJanuary 1, 2025
SB 1120 human review of medical-necessity determinations effectiveJanuary 1, 2025
AB 489 restriction on implying licensed-clinician status effectiveJanuary 1, 2026
SB 942 California AI Transparency Act operativeAugust 2, 2026 (moved once already, from January 1, 2026)
SB 942 generative AI hosting platformsJanuary 1, 2027
SB 942 large online platformsJanuary 1, 2028
SB 942 covered-provider thresholdMore than 1,000,000 monthly users in California
HIPAA de-identification pathwaysSafe Harbor (18 identifiers) or Expert Determination (45 CFR §164.514(b))

This checklist compiles selected federal and California requirements that bear on healthcare organizations adopting artificial intelligence (the HIPAA Privacy and Security Rules at 45 CFR Parts 160 and 164, and California's AB 3030, AB 489, SB 1120, and SB 942), for general compliance-learning purposes. AI regulation is moving quickly and unevenly, and this is not a complete inventory of the requirements that may apply to any particular AI deployment; it does not address FDA device regulation, state professional-practice rules outside California, or non-healthcare AI law. This is not legal advice. Brandon Goulter is not an attorney, and using this checklist creates no professional advisory relationship. Any contract language suggested here is illustrative and must be reviewed and adapted by your own counsel before use. Verify current requirements against primary sources (ecfr.gov and leginfo.legislature.ca.gov) and confirm your own program's compliance with a licensed attorney before relying on this checklist. Checked items are stored only in your browser's local storage, nothing is transmitted or saved to any server.