California: AI health laws

19 entries on the map: 14 in force, 1 enacted and not yet in force (main duties begin Jul 1, 2027) and 4 awaiting the governor.

Dates ahead

Payer and utilization review AI

Insurers', benefit managers' and utilization reviewers' use of AI, including prior authorization and claim denials.

In forceLaw

SB 1120, Health Care Coverage: Utilization Review

In force since Jan 1, 2025 (signed Sept 28, 2024)

Requires a plan or insurer that uses an AI, algorithm or other software tool, directly or through a contractor, for utilization review or management based in whole or in part on medical necessity to ensure the tool bases determinations on the enrollee's own medical or clinical history and individual clinical circumstances rather than solely on a group dataset, does not supplant provider decision-making or discriminate, is open to state inspection and audit, and is periodically reviewed; the tool may not deny, delay or modify care based on medical necessity, a determination reserved for a licensed physician or a licensed health care professional competent to evaluate the clinical issues.

Physician read. Since Jan. 1, 2025, a health plan or insurer regulated in California cannot deny, delay or modify requested care on medical necessity grounds through an AI or other software tool; only a licensed physician or a licensed health care professional competent to evaluate the specific clinical issues may make that determination. The tool must rest on the patient's own history, clinical circumstances as presented by the requesting provider and other clinical information in the record, not solely on a group dataset.

Applies to: Health care service plans, including specialized plans, and disability insurers that use AI or other software tools in utilization review or management, directly or through contractors

Notes: Chapter 879, Statutes of 2024, approved Sept. 28, 2024; amends Health and Safety Code Section 1367.01 (plans licensed by the Department of Managed Health Care) and Insurance Code Section 10123.135 (disability insurers regulated by the Department of Insurance). Status, dates and text are from LegiScan's bill page and chaptered text. The act has no urgency clause or operative date, so it took effect Jan. 1, 2025 under the state's default rule for regular-session statutes (California Constitution, art. IV, sec. 8(c)(1)); the Department of Managed Health Care's All Plan Letter 24-023 (Dec. 20, 2024) also gives Jan. 1, 2025 and set a March 21, 2025 compliance filing for plans. The Department of Insurance's guidance on the act is the next entry.

Checked against its sources
In forcePolicy

Department of Insurance Guidance SB 1120:1, Use of Artificial Intelligence, Algorithms and Other Software Tools in Utilization Management

In force since May 5, 2025

Explains how insurers meet SB 1120 when decision support tools are used in prospective, retrospective and concurrent utilization review: determinations must rest on the insured's own clinical history, circumstances and other relevant clinical information, tools may not deny, delay or modify care based on medical necessity or supplant provider decision-making, medical necessity determinations stay with a licensed physician or competent licensed professional, and insurers must disclose tool use in written policies, open tools to department inspection and audit, and review their performance.

Physician read. The guidance places no duty on physicians; it tells insurers regulated by the Department of Insurance that SB 1120's limits on AI and other decision support tools apply in prospective, retrospective and concurrent review alike. It also reminds insurers covered by Section 1557 of the Affordable Care Act of the federal duty to identify and mitigate discrimination risks from such tools.

Applies to: Health insurers regulated by the Department of Insurance and entities performing utilization review or management for them

Notes: Dated May 5, 2025 on the department's health guidance list. It sets no filing, attestation or reporting deadline. Health plans licensed by the Department of Managed Health Care are covered by SB 1120's parallel Health and Safety Code provision; no AI-specific All Plan Letter from that department was found in its 2024 to 2026 list.

Checked against its sources

Also relevant here: Attorney General's Legal Advisory on the Application of Existing California Law to Artificial Intelligence in Healthcare (under clinical decision and chatbot limits).

Patient disclosure of AI use

Telling patients that AI is used in their care or in messages to them.

In forceLaw

AB 3030, Health Care Services: Artificial Intelligence

In force since Jan 1, 2025 (signed Sept 28, 2024)

Requires a health facility, clinic, physician's office or group practice office that uses generative AI to generate written or verbal patient communications pertaining to patient clinical information to include a disclaimer that the communication was generated by generative AI, placed according to the medium, and clear instructions for reaching a human health care provider or other appropriate person, unless a licensed or certified human health care provider has read and reviewed the communication.

Physician read. Since Jan. 1, 2025, a patient message about clinical information generated by generative AI must carry a disclaimer (at the start of a letter or email, throughout a chat or video, and at the start and end of an audio call) and instructions for reaching a human, unless a licensed or certified provider read and reviewed it; messages about scheduling, billing and other administrative matters are outside the rule. A physician's violation falls under the jurisdiction of the Medical Board of California or the Osteopathic Medical Board of California.

Applies to: Health facilities, clinics, physician's offices and group practice offices that use generative AI to generate patient communications about clinical information

Notes: Chapter 848, Statutes of 2024, approved Sept. 28, 2024; adds Chapter 2.13 (commencing with Section 1339.75) to Division 2 of the Health and Safety Code. Status, dates and text are from LegiScan's bill page and chaptered text. The act has no urgency clause or operative date, so it took effect Jan. 1, 2025 under the state's default rule for regular-session statutes (California Constitution, art. IV, sec. 8(c)(1)). Violations by health facilities and clinics are enforced under existing Health and Safety Code licensing provisions. AB 1979 (2026), awaiting the governor, borrows this section's definitions of physician's office and office of a group practice.

Checked against its sources

Also relevant here: Attorney General's Legal Advisory on the Application of Existing California Law to Artificial Intelligence in Healthcare (under clinical decision and chatbot limits); AB 489, Health Care Professions: Deceptive Terms or Letters: Artificial Intelligence (under clinical decision and chatbot limits); CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations (under data and privacy); SB 243, Companion Chatbots (under clinical decision and chatbot limits); SB 903, Mental Health Professionals: Artificial Intelligence (Wellness and Oversight for Psychological Resources Act) (under mental health AI).

Clinical decision and chatbot limits

Limits on AI in clinical decisions and on health chatbots, including AI presenting itself as a licensed professional.

In forcePolicy

Attorney General's Legal Advisory on the Application of Existing California Law to Artificial Intelligence in Healthcare

In force since Jan 13, 2025

Sets out the Attorney General's Office's view of how existing California consumer protection, civil rights, competition and privacy laws apply to AI in health care, including that California law does not allow delegation of the practice of medicine to AI, that health plans may not use AI to deny, delay or modify care based on medical necessity, that AI with discriminatory effects can violate anti-discrimination law, that deceptive development, marketing or use of AI can violate the Unfair Competition Law, and that medical information handled by AI must stay confidential.

Physician read. The Attorney General's Office says California law does not allow delegation of the practice of medicine to AI, and that using AI to make decisions about patients' medical treatment, or to override licensed providers' determinations of a patient's medical needs, may violate the ban on the corporate practice of medicine. It also says physicians may violate conflict-of-interest law if they or a family member have a financial interest in AI services, and that discriminatory or deceptive uses of AI and mishandling of patients' medical information can violate existing civil rights, consumer protection and privacy laws.

Applies to: Health care providers, insurers, vendors, investors and other entities that develop, sell or use AI in health care
Also touches: Payer and utilization review AI; Patient disclosure of AI use; Data and privacy

Notes: Guidance on existing law; it creates no new statute or rule. The document carries no date; the Attorney General's release of Jan. 13, 2025 announced it together with a general consumer legal advisory on AI, which the health care advisory refers to. It cites SB 1120's amendments to the Knox-Keene Act and the Insurance Code but does not discuss AB 3030. It says providers 'should' be transparent with patients about whether patient information is used to train AI and how they use AI in decisions affecting health care.

Checked against its sources
In forceLaw

AB 489, Health Care Professions: Deceptive Terms or Letters: Artificial Intelligence

In force since Jan 1, 2026 (signed Oct 11, 2025)

Applies California's bans on terms, letters and phrases that imply a health care license to anyone who develops or deploys an AI or generative AI system that uses them in its advertising or functionality, and prohibits advertising or functionality indicating or implying that care, advice, reports or assessments offered through AI are provided by a natural person licensed as a health care professional; each use is a separate violation.

Physician read. Since Jan. 1, 2026, an AI or generative AI system may not use terms, letters or phrases in its advertising or functionality that indicate or imply that its care, advice, reports or assessments come from a licensed health care professional, and the ban reaches both those who develop and those who deploy such systems. Each use is a separate violation subject to the appropriate health care licensing board or enforcement agency, which may seek an injunction or restraining order.

Applies to: Any person or entity that develops or deploys an AI or generative AI system or device
Also touches: Patient disclosure of AI use

Notes: Chapter 615, Statutes of 2025, approved Oct. 11, 2025; adds Chapter 15.5 (commencing with Section 4999.8) to Division 2 of the Business and Professions Code, where health care profession means any profession licensed or regulated under that division. Status, dates and text are from LegiScan's bill page and chaptered text. The act has no urgency clause or operative date, so it took effect Jan. 1, 2026, the default date for statutes enacted at the 2025 regular session (California Constitution, art. IV, sec. 8(c)(1)) and the date the California Lawyers Association lists.

Checked against its sources
In forceLaw

SB 243, Companion Chatbots

In force since Jan 1, 2026 (signed Oct 13, 2025)

Requires companion chatbot operators to disclose clearly that the chatbot is artificially generated and not human when a reasonable person could be misled, maintain and publish a protocol for preventing suicidal ideation, suicide or self-harm content that refers users who express such thoughts to crisis services, add protections for users known to be minors, and report annually to the Office of Suicide Prevention from July 1, 2027; a person injured by a violation may sue for the greater of actual damages or $1,000 per violation.

Physician read. It places no duty on physicians. Since Jan. 1, 2026, operators must refer users who express suicidal ideation, suicide or self-harm to crisis services such as a suicide hotline or crisis text line and must remind users known to be minors at least every three hours that the chatbot is AI, a duty SB 1119 deletes from Jan. 1, 2027; from July 1, 2027 operators report yearly to the Office of Suicide Prevention on crisis referrals and their protocols.

Applies to: Operators of companion chatbot platforms available in California (customer service, business operations, limited game bots and certain voice-activated devices excluded)
Also touches: Mental health AI; Patient disclosure of AI use

Notes: Chapter 677, Statutes of 2025, approved Oct. 13, 2025; adds Chapter 22.6 (commencing with Section 22601) to Division 8 of the Business and Professions Code. Status, dates and text are from LegiScan's bill page and chaptered text. The act has no urgency clause and no general operative date, so its duties began Jan. 1, 2026, the default date for statutes enacted at the 2025 regular session (California Constitution, art. IV, sec. 8(c)(1)); annual reporting starts July 1, 2027. SB 1119 (2026), signed Sept. 10, 2026, deletes the minor-specific duties from Section 22602 without setting a date, so that change takes effect Jan. 1, 2027 under the same rule, and adds broader child-safety duties operative July 1, 2027 (next entry). AB 1064 (2025), a stricter bill on minors' use of companion chatbots, was vetoed Oct. 13, 2025.

Checked against its sources
EnactedLaw

SB 1119, Companion Chatbots: Children's Safety

Signed Sept 10, 2026; main duties begin Jul 1, 2027

Requires companion chatbot operators to determine users' ages or apply child protections to all users, assess and mitigate risks to children, keep a crisis protocol that refers a child at risk of suicide or self-harm to crisis services and, for a credible and imminent threat, notifies a parent with a linked account unless that would risk serious harm to the child and offers streamlined access to the 988 crisis line, take reasonable measures to prevent chatbots from encouraging self-harm, suicidal ideation, narcotics or alcohol consumption or disordered eating and from attempting to diagnose or treat a child's health unless the chatbot is designed for that purpose and regulated by the FDA as a medical device and under HIPAA, limit advertising and data use, and obtain independent child-safety audits.

Physician read. It places no duty on physicians. From July 1, 2027, operators must take reasonable measures to prevent companion chatbots from encouraging a child's self-harm, suicidal ideation or disordered eating and from attempting to diagnose or treat the child's physical, mental or behavioral health, unless the chatbot is designed for that purpose and regulated by the FDA as a medical device and under HIPAA.

Applies to: Operators of companion chatbots available in California, as to users under 18 (workplace-only and postsecondary educational chatbots exempt)
Also touches: Mental health AI

Notes: Chapter 190, Statutes of 2026, approved and filed Sept. 10, 2026; amends Business and Professions Code Section 22602 (from SB 243) and adds Chapter 11.6 (commencing with Section 21810) to Division 8. Status, dates and text are from LegiScan's bill page and chaptered text. Sections 21812, 21812.5 and 21813, which hold the risk assessment, crisis protocol, default settings, record preservation, advertising and data duties, become operative July 1, 2027; Section 21811, on determining age or applying child protections to all users, sets no date of its own and refers to those protections. Parental default settings for children disable persistent conversational memory and push notifications and limit use to one hour per session and two hours per day. First child-safety audits are due by Jan. 1, 2029, or before a chatbot is first made publicly available, whichever is later, then every two years, with summaries to the Attorney General; operators with less than $500 million in prior-year gross revenue are exempt from audits before Jan. 1, 2032. Section 21814 exists in two versions keyed to AB 1405 (2025), which was approved Sept. 9, 2026 (Chapter 178, Statutes of 2026), so the version that applies when AB 1405 takes effect by Jan. 1, 2027 governs; it omits the other version's auditor independence and qualification subdivision, while the act still defines a child safety audit as one conducted by an independent third-party auditor. Public prosecutors, including the Attorney General and district attorneys, may seek civil penalties of $5,000 per affected child for a negligent violation and $15,000 for an intentional one, and a child who suffers actual harm (financial harm of more than $1,000 or serious emotional distress) from a violation of specified protections, or a parent or guardian on the child's behalf, may sue for actual damages and attorney's fees. The act has no urgency clause and sets no date for its amendment of Section 22602, which deletes SB 243's minor-specific duties; that change takes effect Jan. 1, 2027 under the default rule for regular-session statutes (California Constitution, art. IV, sec. 8(c)(1)). Kelley Drye's summary (secondary) also gives the Sept. 10, 2026 signing date.

Checked against its sources
PassedLaw

AB 1979, Health Care Services: Artificial Intelligence

Passed the legislature; awaiting the governor

Would deem a business that offers a health care chatbot to consumers, to let them manage their information or for diagnosis, treatment or management of a medical condition, a provider of health care under the Confidentiality of Medical Information Act, and would require health facilities, clinics, physician's offices and group practice offices to take reasonable steps so licensed professionals can exercise independent judgment when a clinical decision support system's output informs care, and bar them from using AI to direct unlicensed staff in, or independently perform, clinical functions that require a license.

Physician read. It binds no one yet; if it becomes law, from Jan. 1, 2027 a physician's office or group practice would have to take reasonable steps so that licensed clinicians keep the ability to exercise independent professional judgment whenever a clinical decision support system's output informs a patient's care, and could not use AI to direct unlicensed staff in, or independently perform, clinical functions that require a license. Violations by physicians would fall under the Medical Board of California or the Osteopathic Medical Board of California, and businesses offering health care chatbots to consumers would be treated as providers of health care under the Confidentiality of Medical Information Act.

Applies to: Businesses offering health care chatbots to consumers; health facilities, clinics, physician's offices and group practice offices
Also touches: Data and privacy

Notes: Passed the Assembly 48-15 on May 21, 2026 and the Senate 29-9 on Aug. 26; the Assembly concurred 66-10 on Aug. 27 and it was presented to the governor Sept. 4, 2026. The governor has until Sept. 30, 2026 to act: under the California Constitution (art. IV, sec. 10(b)(2)), a bill passed before Sept. 1 of the session's second year and in the governor's possession on or after Sept. 1 that is not returned by Sept. 30 becomes a statute without a signature. No signature or veto appeared on LegiScan or in the governor's legislative updates of Sept. 18, 20 and 27 and his bill releases through Sept. 29. Digital Democracy also showed it pending. Status, dates and text are from LegiScan's bill page and enrolled text. Would add Chapter 25.5 (commencing with Section 22758.5) to Division 8 of the Business and Professions Code and amend Civil Code Sections 56.05 and 56.06; the enrolled text has no urgency clause or operative date, so if enacted it would take effect Jan. 1, 2027 (art. IV, sec. 8(c)(1)). A health care chatbot is defined as a generative AI system with a natural language interface that provides adaptive, human-like responses, is marketed as facilitating or supporting health services and uses information about a consumer's physical or mental health or wellness that the consumer provides or that the chatbot collects, generates or infers. Automated systems for documentation and communication that do not involve professional judgment are exempt, as are trainees in supervised programs; the appropriate licensing board may seek an injunction or restraining order to enforce the section.

Checked against its sources
PassedLaw

AB 2575, Health Care Services: Artificial Intelligence

Passed the legislature; awaiting the governor

Would bar an employer from retaliating or discriminating against a worker providing direct patient care based solely on the worker's override of, or reliance on, an AI clinical decision support system's output when making an assessment or decision within the worker's scope of practice, enforced by the Labor Commissioner, and would bar a defendant who developed, modified, selected or deployed such a system from arguing, in a suit alleging the system caused harm, that a clinician's failure to override its output was a superseding cause cutting off liability.

Physician read. It binds no one yet; if it becomes law, from Jan. 1, 2027 an employer could not retaliate or discriminate against a clinician or other worker providing direct patient care based solely on the worker's override of, or reliance on, a clinical decision support system's output within scope of practice, and a policy requiring workers to accept, defer to or not override that output would not count among the worker's duties. In a suit alleging such a system caused harm, those who developed, modified, selected or deployed it could not argue that a clinician's failure to override its output was a superseding cause; the worker's duties to meet the standard of care and act within scope of practice would remain.

Applies to: Employers of direct patient care workers; those who develop, modify, select or deploy AI clinical decision support systems, when sued

Notes: Passed the Assembly 48-15 on May 27, 2026; the Senate refused passage 18-10 on Aug. 28, granted reconsideration the same day and passed it 21-10 on Aug. 31, and the Assembly concurred 51-16 the same day; presented to the governor Sept. 15, 2026. The governor has until Sept. 30, 2026 to act: under the California Constitution (art. IV, sec. 10(b)(2)), a bill passed before Sept. 1 of the session's second year and in the governor's possession on or after Sept. 1 that is not returned by Sept. 30 becomes a statute without a signature. No signature or veto appeared on LegiScan or in the governor's legislative updates of Sept. 18, 20 and 27 and his bill releases through Sept. 29. Status, dates and text are from LegiScan's bill page and enrolled text. Would add Civil Code Section 1714.48 and Article 2.7 (commencing with Section 2820) to Chapter 2 of Division 3 of the Labor Code, enforced by the Labor Commissioner; the enrolled text has no urgency clause or operative date, so if enacted it would take effect Jan. 1, 2027 (art. IV, sec. 8(c)(1)). A Labor Commissioner determination would not decide malpractice or licensing matters. A tracker summary in the project's leads described AB 2575 as a psychotherapy consent bill; the enrolled text concerns clinical decision support, Manatt's tracker itself describes its liability rule, and the psychotherapy bill is SB 903.

Checked against its sources
PassedLaw

SB 503, Health Care Services: Artificial Intelligence

Passed the legislature; awaiting the governor

Would require developers and deployers of AI clinical decision support systems to make reasonable efforts to identify systems with a known or reasonably foreseeable risk of biased impacts, meaning adverse effects on access to care, quality of care or outcomes based on protected characteristics, and to mitigate that risk, require developers to give deployers documentation on intended uses, training data, performance evaluation, data governance and bias risks, and require deployers to monitor the systems regularly.

Physician read. It binds no one yet; if it becomes law, from Jan. 1, 2027 a physician's office or group practice that uses an AI clinical decision support system would have to make reasonable efforts to identify systems with known or reasonably foreseeable risks of biased impacts on patients based on protected characteristics, monitor them regularly and take reasonable, proportionate steps to mitigate those risks. Developers would owe the practice documentation on intended uses, training data, performance evaluation and bias risks, on request or at the initial sale, whichever is earlier.

Applies to: Developers of AI clinical decision support systems and the health facilities, clinics, physician's offices and group practices that use them

Notes: Introduced in 2025; passed the Senate 38-0 on May 29, 2025, was moved to the Assembly inactive file Sept. 10, 2025 and taken from it Aug. 12, 2026, passed the Assembly 70-1 on Aug. 24, 2026, and won Senate concurrence 39-0 on Aug. 25; presented to the governor Aug. 30, 2026. The governor has until Sept. 30, 2026 to act: under the California Constitution (art. IV, sec. 10(b)(2)), a bill passed before Sept. 1 of the session's second year and in the governor's possession on or after Sept. 1 that is not returned by Sept. 30 becomes a statute without a signature. No signature or veto appeared on LegiScan or in the governor's legislative updates of Sept. 18, 20 and 27 and his bill releases through Sept. 29. Status, dates and text are from LegiScan's bill page and enrolled text. Would add Chapter 25.3 (commencing with Section 22758) to Division 8 of the Business and Professions Code. The enrolled text names no enforcing agency, penalty, urgency clause or operative date, so if enacted it would take effect Jan. 1, 2027 (art. IV, sec. 8(c)(1)); it states that compliance is not a defense to a discrimination claim. Developers may meet some duties by following nationally recognized or widely adopted industry standards for bias testing or by providing algorithmic impact assessments.

Checked against its sources

Also relevant here: SB 903, Mental Health Professionals: Artificial Intelligence (Wellness and Oversight for Psychological Resources Act) (under mental health AI).

Mental health AI

AI in therapy and mental health care.

PassedLaw

SB 903, Mental Health Professionals: Artificial Intelligence (Wellness and Oversight for Psychological Resources Act)

Passed the legislature; awaiting the governor

Would limit AI in psychotherapy to administrative and supplementary support; require telling a patient, verbally or in writing, that AI will be used and its specific purpose, and obtaining consent, before AI records or transcribes psychotherapy sessions, psychotherapeutic communications or triage and screening; bar letting AI make therapeutic decisions, interact directly with patients in psychotherapeutic communication, generate recommendations, assessments, diagnoses or treatment plans, detect emotions or mental states, or perform triage or screening without a licensed professional's review and approval, except that FDA-approved or cleared, HIPAA-compliant tools may interact directly for their approved use; and bar advertising companion chatbot services as psychotherapy.

Physician read. It binds no one yet; if it becomes law, from Jan. 1, 2027 a psychiatrist or other licensed professional would have to tell the patient, verbally or in writing, that AI will be used and for what specific purpose, and obtain consent, before AI records or transcribes psychotherapy sessions, psychotherapeutic communications, or triage or screening, and a patient who declines keeps all rights to care. AI could not make therapeutic decisions, generate recommendations, assessments, diagnoses or treatment plans, detect emotions or mental states, or perform triage or screening without the professional's review and approval, and could not interact directly with patients in psychotherapeutic communication without that review unless the tool is approved or cleared by the FDA for that use and HIPAA-compliant.

Applies to: Anyone who provides or facilitates psychotherapy services, including psychiatrists and other licensed professionals and their employers
Also touches: Clinical decision and chatbot limits; Patient disclosure of AI use

Notes: Passed the Senate 39-0 on May 19, 2026 and the Assembly 74-1 on Aug. 30, 2026 (LegiScan roll call, four absent; the author's office reported 71-4); the Senate concurred 40-0 on Aug. 31 and it was presented to the governor Sept. 9, 2026. The governor has until Sept. 30, 2026 to act: under the California Constitution (art. IV, sec. 10(b)(2)), a bill passed before Sept. 1 of the session's second year and in the governor's possession on or after Sept. 1 that is not returned by Sept. 30 becomes a statute without a signature. No signature or veto appeared on LegiScan or in the governor's legislative updates of Sept. 18, 20 and 27 and his bill releases through Sept. 29. Status, dates and text are from LegiScan's bill page, roll call and enrolled text. Would add Chapter 13.6 (commencing with Section 4989.80) to Division 2 of the Business and Professions Code; the enrolled text has no urgency clause or operative date, so if enacted it would take effect Jan. 1, 2027 (art. IV, sec. 8(c)(1)). Licensing boards would enforce it and may seek injunctions; no penalty amount or private right of action is set. A licensed professional would not be disciplined for a violation caused solely by a tool feature outside the professional's control when the employer or contracting entity required the tool, and the employer or contracting entity would be responsible for compliant deployment. AI could still suggest that a person discuss psychotherapy with a licensed professional, administer and score standardized screening questionnaires for a professional's review, and handle scheduling that involves no psychotherapeutic communication. Religious counseling, peer support, self-help and educational materials that do not purport to offer psychotherapy, AI used solely for training or simulation, and research by academic or nonprofit institutions under federal human-subject and privacy rules are exempt. Psychotherapy data could not be shared, sold, stored or used to train models inconsistently with applicable law, and records must comply with the Confidentiality of Medical Information Act.

Checked against its sources

Also relevant here: AB 2089, Privacy: Mental Health Digital Services: Mental Health Application Information (under data and privacy); SB 243, Companion Chatbots (under clinical decision and chatbot limits); SB 1119, Companion Chatbots: Children's Safety (under clinical decision and chatbot limits).

Data and privacy

Health and consumer data, biometrics, and data used to train AI.

In forceLaw

AB 375, California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Proposition 24)

In force since Jan 1, 2020 (signed Jun 28, 2018)

Gives California consumers rights to know, delete and correct personal information, opt out of its sale or sharing, and limit a business's use and disclosure of sensitive personal information, which includes personal information collected and analyzed concerning health, biometric information processed to identify a person, precise geolocation and, since 2025, neural data; enforced by the California Privacy Protection Agency and the Attorney General, with a private right of action for certain data breaches.

Physician read. The act does not apply to medical information governed by the Confidentiality of Medical Information Act, protected health information collected by a HIPAA covered entity or business associate, or a provider of health care or covered entity to the extent it maintains patient information in the same manner as that information. A practice that meets one of the act's thresholds must honor consumers' rights to know, delete, correct, opt out of sale or sharing and limit use of sensitive personal information for other personal information it collects.

Applies to: For-profit businesses doing business in California with annual gross revenue over $26.625 million (the statute's $25 million, adjusted from Jan. 1, 2025), or that buy, sell or share the personal information of 100,000 or more consumers or households, or derive half or more of annual revenue from selling or sharing it

Notes: Chapter 55, Statutes of 2018, approved June 28, 2018; Section 1798.198 made the title operative Jan. 1, 2020. Voters approved Proposition 24, the California Privacy Rights Act, in November 2020; its amendments, including the sensitive personal information category and the California Privacy Protection Agency, began Jan. 1, 2023, according to the Attorney General. The statute's $25 million revenue threshold is adjusted for inflation; the agency lists $26.625 million from Jan. 1, 2025. The medical exemption is in Civil Code Section 1798.146(a), added by AB 713 (Chapter 172, Statutes of 2020), and appears as Section 1798.145(c)(1) in the statute text the agency posts: business associates are exempt to the same extent as covered entities, and clinical trial information and certain deidentified patient information are also exempt. The agency's posted statute text is current through a July 2024 amendment (AB 3286). Later amendments on this map: SB 1223 (neural data) and AB 1008 (AI systems as a format of personal information), both 2024; the agency's 2025 regulations cover automated decisionmaking technology, risk assessments and cybersecurity audits.

Checked against its sources
In forceLaw

AB 2089, Privacy: Mental Health Digital Services: Mental Health Application Information

In force since Jan 1, 2023 (signed Sept 28, 2022)

Amends the Confidentiality of Medical Information Act to include mental health application information in medical information and to deem a business that offers a mental health digital service, an app or website that collects information on a consumer's inferred or diagnosed mental health or substance use disorder, markets itself as facilitating mental health services and uses the information to do so, a provider of health care subject to the act.

Physician read. Since Jan. 1, 2023, mental health apps and websites offered to consumers in California must keep users' mental health information confidential to the standard the Confidentiality of Medical Information Act sets for providers of health care. A business that partners with a provider of health care to offer such a service must give the provider information on how to find data breaches reported on the Attorney General's website.

Applies to: Businesses that offer mental health apps or websites (mental health digital services) to consumers
Also touches: Mental health AI

Notes: Chapter 690, Statutes of 2022, approved Sept. 28, 2022; amends Civil Code Sections 56.05 and 56.06 and adds Chapter 4.1 (commencing with Section 56.251). Status, dates and text are from LegiScan's bill page and bill text. The act has no urgency clause or operative date, so it took effect Jan. 1, 2023 under the state's default rule for regular-session statutes (California Constitution, art. IV, sec. 8(c)(1)). AB 254 (2023) extended the same treatment to reproductive or sexual health apps, and AB 1979 (2026), awaiting the governor, would extend it to health care chatbots.

Checked against its sources
In forceLaw

AB 254, Confidentiality of Medical Information Act: Reproductive or Sexual Health Application Information

In force since Jan 1, 2024 (signed Sept 27, 2023)

Amends the Confidentiality of Medical Information Act to cover reproductive or sexual health application information, such as data on a consumer's reproductive health, menstrual cycle, fertility, pregnancy and sexual activity collected by an app or website that markets itself as facilitating reproductive or sexual health services, and deems a business offering such a service a provider of health care subject to the act.

Physician read. Since Jan. 1, 2024, period-tracking, fertility and other reproductive or sexual health apps offered to consumers in California must keep that information confidential to the standard the Confidentiality of Medical Information Act sets for providers of health care. It places no new duty on physicians.

Applies to: Businesses that offer reproductive or sexual health apps or websites to consumers

Notes: Chapter 254, Statutes of 2023, approved Sept. 27, 2023; amends Civil Code Sections 56.05 and 56.06. Status, dates and text are from LegiScan's bill page and bill text. The act has no urgency clause or operative date, so it took effect Jan. 1, 2024 under the state's default rule for regular-session statutes (California Constitution, art. IV, sec. 8(c)(1)). Builds on AB 2089 (2022), which did the same for mental health apps.

Checked against its sources
In forceLaw

AB 1008, California Consumer Privacy Act of 2018: Personal Information

In force since Jan 1, 2025 (signed Sept 28, 2024)

Specifies that personal information under the California Consumer Privacy Act can exist in physical formats, digital formats and abstract digital formats, including compressed or encrypted files, metadata and artificial intelligence systems capable of outputting personal information.

Physician read. Since Jan. 1, 2025, the act's definition of personal information states that it can exist in abstract digital formats, including AI systems capable of outputting personal information, so such systems held by a covered business can contain personal information subject to the act. For a medical practice that meets a threshold, this reaches only personal information outside the act's exemptions for medical information, protected health information and patient information a provider maintains in the same manner.

Applies to: Businesses covered by the California Consumer Privacy Act

Notes: Chapter 802, Statutes of 2024, approved Sept. 28, 2024; amends Civil Code Section 1798.140. Status, dates and text are from LegiScan's bill page and bill text. The act has no urgency clause or operative date, so it took effect Jan. 1, 2025 under the state's default rule for regular-session statutes (California Constitution, art. IV, sec. 8(c)(1)).

Checked against its sources
In forceLaw

SB 1223, Consumer Privacy: Sensitive Personal Information: Neural Data

In force since Jan 1, 2025 (signed Sept 28, 2024)

Adds neural data, defined as information generated by measuring the activity of a consumer's central or peripheral nervous system and not inferred from nonneural information, to the California Consumer Privacy Act's categories of sensitive personal information.

Physician read. Since Jan. 1, 2025, neural data, information generated by measuring the activity of a consumer's central or peripheral nervous system and not inferred from nonneural information, is sensitive personal information under the act, so consumers may direct a covered business that collects it to limit its use to what is necessary to provide the goods or services they reasonably expect, unless it is collected or processed without the purpose of inferring characteristics about them. For a medical practice that meets a threshold, the rule reaches only neural data outside the act's exemptions for medical information, protected health information and patient information a provider maintains in the same manner.

Applies to: Businesses covered by the California Consumer Privacy Act

Notes: Chapter 887, Statutes of 2024, approved Sept. 28, 2024; amends Civil Code Section 1798.140. Status, dates and text are from LegiScan's bill page and bill text. The act has no urgency clause or operative date, so it took effect Jan. 1, 2025 under the state's default rule for regular-session statutes (California Constitution, art. IV, sec. 8(c)(1)). The right to limit use of sensitive personal information is in Civil Code Section 1798.121, read in the statute text the California Privacy Protection Agency posts.

Checked against its sources
In forceLaw

AB 2013, Generative Artificial Intelligence: Training Data Transparency

In force since Jan 1, 2026 (signed Sept 28, 2024)

Requires developers, by Jan. 1, 2026 and before each later public release of a system or substantial modification, to post on their websites documentation of the data used to train a generative AI system, including dataset sources and owners, the number and types of data points, whether the datasets include copyrighted material, personal information or aggregate consumer information as defined in the California Consumer Privacy Act, any cleaning or processing, collection periods and use of synthetic data; systems whose sole purpose is security and integrity or the operation of aircraft in the national airspace, and systems developed for national security, military or defense purposes and made available only to a federal entity, are exempt.

Physician read. It places no duty on physicians who only use generative AI tools. Since Jan. 1, 2026, developers of generative AI systems made available to Californians, including clinical ones, must post whether their training datasets included personal information or aggregate consumer information.

Applies to: Developers of generative AI systems or services released on or after Jan. 1, 2022 and made publicly available to Californians

Notes: Chapter 817, Statutes of 2024, approved Sept. 28, 2024; adds Title 15.2 (commencing with Section 3110) to Part 4 of Division 3 of the Civil Code (Sections 3110 and 3111). Status, dates and text are from LegiScan's bill page and bill text. The statute took effect Jan. 1, 2025 under the state's default rule for regular-session statutes (California Constitution, art. IV, sec. 8(c)(1)); the first documentation was due Jan. 1, 2026, the date used.

Checked against its sources
In forceLaw

AB 45, Privacy: Health Data: Location and Research

In force since Jan 1, 2026 (signed Sept 26, 2025)

Bars collecting, using, disclosing, selling, sharing or retaining the personal information of people at or within a precise geolocation (a 1,850-foot radius) of a family planning center except as needed to provide the goods or services they request, bars geofencing an entity that provides in-person health care services to identify or track people seeking, receiving or providing care, collect their personal information, or send them notifications or advertisements related to their personal information or health care services, and limits release of personally identifying research records in response to out-of-state or foreign legal actions that interfere with reproductive rights.

Physician read. Since Jan. 1, 2026, no one may geofence an entity that provides in-person health care services in California to identify or track people seeking, receiving or providing care, collect their personal information, or send them notifications or advertisements related to their personal information or care, with a civil penalty of $25,000 per violation in actions by the Attorney General. A person that owns, operates, manages or provides services to the entity may still geofence the entity's own location to provide necessary health care services, and reproductive health care providers may use geofencing for security.

Applies to: Anyone collecting personal information at or near family planning centers or geofencing in-person health care providers

Notes: Chapter 134, Statutes of 2025, approved Sept. 26, 2025; adds Civil Code Sections 1798.99.91 to 1798.99.93 and amends Health and Safety Code Section 140 so geofencing penalties go to the California Reproductive Justice and Freedom Fund. Status, dates and text are from LegiScan's bill page and chaptered text. The act has no urgency clause or operative date, so it took effect Jan. 1, 2026, the default date for statutes enacted at the 2025 regular session (California Constitution, art. IV, sec. 8(c)(1)) and the date the California Lawyers Association lists. Providers of health care, health care service plans and contractors as defined in the Confidentiality of Medical Information Act, and HIPAA covered entities and business associates, are exempt from the family planning center provision, contractors and business associates only if contractually obligated to comply with applicable state and federal privacy laws; under that provision an aggrieved person or entity, including a family planning center, may sue within three years of discovery for three times actual damages and attorney's fees. Other geofencing exceptions cover lawful warrants or subpoenas, emergencies, research approved by an institutional review board with informed consent, and labor organizations.

Checked against its sources
In forceRule

CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations

In force since Jan 1, 2026 (adopted Jul 24, 2025)

Requires businesses that use automated decisionmaking technology to make significant decisions, including decisions that result in the provision or denial of health care services, to give consumers a pre-use notice, a right to opt out (subject to exceptions such as a human appeal process) and a right to access information about its use by Jan. 1, 2027; requires risk assessments for covered processing, including processing sensitive personal information and using such technology for significant decisions, with attestations and summaries due to the California Privacy Protection Agency by April 1, 2028; and phases in cybersecurity audit certifications due April 1, 2028, 2029 or 2030 depending on revenue.

Physician read. From Jan. 1, 2027, a business covered by the act that uses automated decisionmaking technology, meaning technology that replaces or substantially replaces human decisionmaking, to make a decision that results in the provision or denial of health care services must give consumers a pre-use notice, a right to opt out unless an exception such as a human appeal process applies, and a right to access information about the technology's logic and the decision's outcome. For a medical practice that meets a threshold, the rules reach only personal information outside the act's exemptions for medical information governed by the Confidentiality of Medical Information Act, protected health information and patient information a provider maintains in the same manner.

Applies to: Businesses subject to the California Consumer Privacy Act
Also touches: Patient disclosure of AI use

Notes: Adopted by the agency's board July 24, 2025; approved by the Office of Administrative Law and filed with the Secretary of State Sept. 22, 2025; effective Jan. 1, 2026, when risk assessment duties began. Section 7200(b) sets Jan. 1, 2027 as the compliance date for the automated decisionmaking rules (Article 11, Sections 7200 to 7222). Risk assessments for processing that began before Jan. 1, 2026 must be completed by Dec. 31, 2027, and attestations and summaries are due April 1, 2028. Cybersecurity audit certifications are due April 1, 2028 for businesses with revenue over $100 million, April 1, 2029 for $50 million to $100 million and April 1, 2030 for under $50 million. The agency's regulations page said it had no proposed regulation packages as of Sept. 29, 2026. Only the early sections of the approved text could be checked; its definitions of automated decisionmaking technology, significant decision and health care services were confirmed there, and the notice, opt-out, access and risk assessment duties come from the agency's final statement of reasons and its Sept. 23, 2025 announcement.

Checked against its sources

Also relevant here: Attorney General's Legal Advisory on the Application of Existing California Law to Artificial Intelligence in Healthcare (under clinical decision and chatbot limits); AB 1979, Health Care Services: Artificial Intelligence (under clinical decision and chatbot limits).

Federal law also applies in every state: see federal law and policy.

Most recently checked Sept 29, 2026. General information, not legal advice. How the map works, and the data.