Last week, ONC held a webinar on updates to its Security Risk Assessment Tool. It brought me back to a question I keep hearing from healthcare leaders: how much AI governance should we build before we know what regulators will require?
I understand the instinct to build ahead. I have spent two decades telling healthcare executives to do exactly that. But when budgets are limited, the order matters.
The HIPAA Security Rule already requires organizations to assess risks to electronic protected health information, including risks introduced by AI tools. What OCR has not done is establish a separate HIPAA enforcement track for model cards, validation pipelines, or AI governance committees. ONC's SRA Tool is a useful starting point, but ONC itself says the tool may not identify every risk and that using it does not guarantee compliance.
That does not mean AI lacks regulatory oversight. It means leaders need to be precise about which regulator, which tool, and which obligation they are building for.
What The Enforcement Record Shows
In August, the FTC finalized three settlements involving Cox Media Group and two marketing firms. The companies agreed to pay a combined $930,000 over allegations that they falsely claimed their AI-powered advertising service could target people using conversations captured from smart devices. According to the FTC, the service did not use voice data, and consumers had not opted into the service the companies described. This was a case about deceptive claims, not evidence that the companies listened to consumers' conversations.
Also in August, the SEC filed settled charges against GenesisAI and its former CEO. The SEC alleged that they misled investors about projected revenue, valuation, partnerships, and customer demand for an AI marketplace. The defendants consented to proposed judgments without admitting the allegations.
Texas offers another example, though its timing matters. In August 2025, the attorney general opened an investigation into Meta AI Studio and Character.AI over concerns that their chatbots could mislead children about the nature of the interaction and the mental health support they offered. An investigation is not a finding of wrongdoing.
These actions do not prove that model performance is irrelevant. They show something more useful for setting priorities today: regulators are already examining what companies say their AI does, whether those claims are supportable, and how the products affect people. Those are concrete questions a healthcare organization can address now.
Colorado Changes The Calculation
Colorado is a real counterexample to the idea that AI governance can wait for OCR. Its revised Automated Decision-Making Technology Act and Chatbot Safety Act take effect January 1, 2027. The state has also published proposed implementing rules.
The automated decision law applies to covered technology used to materially influence consequential decisions, including decisions about access to healthcare services. It includes technical documentation, consumer notice, recordkeeping, and, after certain adverse outcomes, a right to request meaningful human review. The chatbot law separately addresses disclosures, safeguards for minors, and responses to suicide or self-harm content. The requirements depend on the product and how it is used; operating in Colorado alone does not make every clinical tool or patient chatbot subject to every provision.
Federal requirements also vary by use. ONC has transparency requirements for certain predictive tools in certified health IT, and the FDA oversees AI-enabled products that meet medical device requirements. A clinical AI product may need substantial model oversight today, regardless of whether OCR creates an AI-specific HIPAA rule.
Where I Would Put The First Dollar
If I were setting a health system's AI compliance priorities this quarter, I would start with three questions:
Can we support our AI claims? Review what your marketing, sales materials, contracts, and patient communications say the technology does. If a claim depends on a feature, accuracy level, or safeguard you cannot demonstrate, fix the claim or the product.
Do we know where patient data goes? Identify which AI tools receive protected health information, what each vendor is permitted to do with it, whether a business associate agreement is required, and whether the actual data flow matches the agreement. The FTC's Cox Media Group case is a reason to verify claims about data use; it is not evidence that those companies collected voice data without consent.
Have we mapped the rules to each use case? A tool that drafts internal notes presents different issues from one that influences access to care, interacts with minors, or functions as a medical device. Identify the decision the tool affects, the people it affects, and the jurisdictions involved before deciding what governance it needs. My AI Regulatory Intelligence Tracker follows exactly these developments, state by state, week to week.
The Path Forward
I am not telling healthcare leaders to stop building AI governance. I am asking them to build it in the order their actual risks and obligations demand.
Start with the claims you make, the patient data you use, and the decisions your tools influence. Then apply the model controls each use case requires. That work is more concrete than preparing every AI system for a hypothetical OCR model review, and it puts attention on the places patients and regulators can see the results.